Method and device for determining attack behavior of charging pile network and electronic equipment
By acquiring data from the charging pile network, extracting features, and using secondary cluster centers and updated subspaces to identify attack behaviors, the problem of low accuracy of traditional clustering detection methods in the charging pile network is solved, accurate classification and rapid response to attack behaviors are achieved, and security protection is enhanced.
Patent Information
- Application Number
- CN202411611690.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-11-12
AI Technical Summary
Existing traditional clustering detection methods have low accuracy in detecting charging pile network attacks and are unable to adapt to the complex and changeable situations of network attacks, resulting in the inability to guarantee the security of important information systems and information infrastructure of charging piles.
By acquiring charging pile data, extracting charging features, and using secondary cluster center features and updated subspaces, the distance between charging features and multiple target cluster center features is determined, and then the attack behavior category is identified. The fitness function is used to adjust the charging pile parameters to improve detection accuracy.
It achieves accurate identification and classification of charging pile network attack behaviors, improves detection accuracy and response speed, and enhances the security protection capabilities of the charging pile network.
Smart Images

Figure CN119544280B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data processing, in particular to a charging pile network attack behavior determination method and device and electronic equipment. BACKGROUND
[0002] At present, when detecting charging pile network attacks, the method commonly used is to use an abnormal intrusion detection model based on traditional clustering technology for detection. However, the traditional clustering detection method has the problem of low accuracy in the detection process, and cannot adapt to the current complex and variable network attack links, so that the security of the charging pile important information system and information infrastructure cannot be guaranteed.
[0003] In view of the above problems, no effective solution has been proposed so far. SUMMARY
[0004] The embodiments of the present application provide a charging pile network attack behavior determination method and device and electronic equipment to at least solve the technical problem of low attack detection accuracy when using a traditional clustering detection method to detect whether the charging pile network is attacked in the related art.
[0005] According to an aspect of an embodiment of the present application, a charging pile network attack behavior determination method is provided, comprising: obtaining charging pile data in a charging pile system; extracting charging features corresponding to the charging pile data; determining distances of the charging features corresponding to a plurality of target cluster center features, to obtain a plurality of target distances, wherein the plurality of target cluster center features are obtained according to a plurality of initial cluster center features, the plurality of initial cluster center features are obtained according to sub-sample features included in a corresponding update subspace, the plurality of update subspaces are subspaces corresponding to sample densities greater than a first threshold value determined from a plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering target sample features; and determining an attack behavior category corresponding to the charging pile system according to the plurality of target distances.
[0006] Optionally, before determining the distances of the charging features corresponding to the plurality of target cluster center features to obtain the plurality of target distances, it further comprises: determining a plurality of initial sample densities corresponding to the plurality of initial subspaces respectively; comparing the plurality of initial sample densities with the first threshold value respectively to obtain a plurality of comparison results, wherein the plurality of comparison results correspond to the plurality of initial sample densities one by one; determining a plurality of target results from the plurality of comparison results, which are the subspaces with the corresponding initial sample densities greater than the first threshold value; and determining the initial subspaces corresponding to the plurality of target results as the plurality of update subspaces.
[0007] Optionally, before determining the distances between the charging features and the target clustering center features, the method further comprises: determining a densest subspace with the highest sample density from the plurality of updated subspaces; determining a first initial clustering center feature according to the average distance of the charging pile sample points in the densest subspace; determining a plurality of initial distances between the first initial clustering center feature and a plurality of first remaining subspace centers, wherein the plurality of first remaining subspaces are the subspaces remaining in the plurality of updated subspaces except the densest subspace; determining a farthest subspace with the farthest distance from the first initial clustering center feature according to the plurality of initial distances; determining a second initial clustering center feature according to the average distance of the charging pile sample points in the farthest subspace; determining a first distance between the first initial clustering center feature and a plurality of second remaining subspace centers, and determining a plurality of second distances between the second initial clustering center feature and the plurality of second remaining subspace centers, wherein the plurality of second remaining subspace centers are the subspaces remaining in the plurality of updated subspaces except the densest subspace and the farthest subspace; determining a plurality of distance sums of the plurality of first distances and the corresponding second distances to obtain a plurality of distances; and determining a third initial clustering center feature according to the plurality of distances until a plurality of initial clustering center features are determined, wherein the third initial clustering center feature is the updated subspace center corresponding to the largest distance sum.
[0008] Optionally, before determining the distances between the charging features and the target clustering center features, the method further comprises: determining a subspace with an initial sample density less than or equal to a first threshold from the plurality of initial subspaces to obtain a centerless subspace; determining sample distances between a plurality of charging pile sample points included in the centerless subspace and a plurality of initial clustering center features; clustering the plurality of charging pile sample points into corresponding updated subspaces based on the plurality of sample distances to obtain a plurality of target subspaces; and obtaining the plurality of target clustering center features according to the plurality of target subspaces, wherein the target subspaces and the target clustering center features are in one-to-one correspondence.
[0009] Optionally, after determining the attack behavior category corresponding to the charging pile system according to the plurality of target distances, the method further comprises: determining an initial charging pile parameter corresponding to the charging pile system; and adjusting the initial charging pile parameter based on the attack behavior category to obtain a target charging pile parameter.
[0010] Optionally, based on the attack behavior category, the initial charging pile parameter is adjusted to obtain a target charging pile parameter, including: determining an fitness function according to the plurality of target distances, wherein the fitness function is used to determine the probability of the charging pile system being attacked by the attack behavior category; determining a predetermined number of candidate charging pile parameters according to the initial charging pile parameter and the fitness function, wherein the predetermined number of candidate charging pile parameters are all parameters corresponding to an adaptability greater than a second threshold; and obtaining the target charging pile parameter according to the predetermined number of candidate charging pile parameters.
[0011] Optionally, the charging feature corresponding to the charging pile data is extracted, including: performing numerical value processing on the charging pile data to obtain charging pile numerical value data corresponding to the charging pile data; and performing normalization processing on the charging pile numerical value data to obtain the charging feature.
[0012] According to an aspect of an embodiment of the present application, an attack behavior determination apparatus of a charging pile network is provided, including: an acquisition module configured to acquire charging pile data in a charging pile system; an extraction module configured to extract charging features corresponding to the charging pile data; a first determination module configured to determine distances of the charging features corresponding to a plurality of target cluster center features, respectively, to obtain a plurality of target distances, wherein the plurality of target cluster center features are obtained according to a plurality of initial cluster center features, the plurality of initial cluster center features are obtained according to sub-sample features included in a plurality of update subspaces, the plurality of update subspaces are subspaces corresponding to sample densities greater than a first threshold determined from a plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering target sample features; and a second determination module configured to determine an attack behavior category corresponding to the charging pile system according to the plurality of target distances.
[0013] According to an aspect of an embodiment of the present application, an electronic device is provided, including: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the attack behavior determination method of the charging pile network of any of the above.
[0014] According to an aspect of an embodiment of the present application, a computer-readable storage medium is provided, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device can execute the attack behavior determination method of the charging pile network of any of the above.
[0015] In the embodiment of the present application, the charging pile data in the charging pile system is acquired. The charging feature corresponding to the charging pile data is extracted. The distances of the charging feature from a plurality of target cluster center features are determined, to obtain a plurality of target distances, wherein the plurality of target cluster center features are obtained according to a plurality of initial cluster center features, the plurality of initial cluster center features are obtained according to the sub-sample features included in the corresponding update subspace, the plurality of update subspaces are subspaces corresponding to the sample density greater than a first threshold value, which are determined from a plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering the target sample features. The attack behavior category corresponding to the charging pile system is determined according to the plurality of target distances. It can be known that the embodiment of the present application determines the distances of the charging feature from a plurality of target cluster centers, to achieve the purpose of determining the attack behavior category. Since the target cluster center is a center obtained by secondary clustering, the target cluster center feature is a feature that more accurately and representatively reflects the attack information represented by the corresponding subspace, that is, can accurately represent whether the corresponding subspace is attacked and what kind of attack is received, so as to accurately determine the attack behavior category by determining the similarity of the charging feature to the cluster center, and thus solve the technical problem of low attack detection accuracy when using the traditional clustering detection method to detect whether the charging pile network is attacked in the related art. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are included to provide a further understanding of the present application and are incorporated in and constitute a part of this application, illustrate embodiments of the present application and serve to explain the present application. In the drawings:
[0017] Figure 1 is a flowchart of an attack behavior determination method of a charging pile network according to an embodiment of the present application;
[0018] Figure 2 is a charging pile attack detection flowchart based on an improved multi-clustering method provided by an optional embodiment of the present application;
[0019] Figure 3 is a charging pile network attack security protection system flowchart of improved multi-clustering provided by an optional embodiment of the present application;
[0020] Figure 4 is an improved grey wolf optimization algorithm flowchart provided by an optional embodiment of the present application;
[0021] Figure 5 is a structural block diagram of an attack behavior determination device of a charging pile network according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative work should belong to the protection scope of the present application.
[0023] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product, or device.
[0024] Embodiment 1
[0025] According to the embodiments of the present application, an embodiment of a charging pile network attack behavior determination method is provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that herein.
[0026] Figure 1 is a flowchart of a charging pile network attack behavior determination method according to an embodiment of the present application, as Figure 1 shown, the method comprises the following steps:
[0027] Step S102, acquiring charging pile data in a charging pile system.
[0028] In the present application, the charging pile data in the charging pile system is acquired in step S102.
[0029] Among them, the charging pile system refers to a network system that provides charging services for electric vehicles. It can include charging pile equipment, charging management software, payment systems, monitoring systems, etc.
[0030] The charging pile data refers to various data generated by the charging pile system during operation, which can include but is not limited to charging pile network traffic, security logs, monitoring videos, charging capacity, charging time, charging frequency, user information, payment information, device status, network traffic data, security logs, etc., wherein the network traffic includes various data packets transmitted through the network, and the security logs include security log records of various network devices and systems.
[0031] In this step, the charging pile data in the charging pile system is obtained, which means collecting real-time or historical charging pile data from the charging pile system. This is the basic step of charging pile network attack detection, because only with sufficient data, possible attack behaviors can be identified through data analysis methods.
[0032] It should be noted that data acquisition can be achieved through various means such as sensors installed on the charging pile, network traffic monitoring tools, user operation log recording systems, etc., to ensure that the system can fully understand the running state of the charging pile and user operation, and the specific way is not limited here, and can be adaptively set according to actual application and scene.
[0033] Step S104, extracting charging features corresponding to the charging pile data.
[0034] In step S104 provided in the present application, charging features corresponding to the charging pile data are extracted.
[0035] The charging features are extracted from the charging pile data and can describe key indicators or attributes of the charging process characteristics. These features can be charging duration, charging power curve, charging frequency, charging pile usage time distribution, etc., which are of great significance to determine whether the charging behavior is normal or whether there is a potential security problem.
[0036] In this step, the charging features corresponding to the charging pile data are extracted, that is, from the data collected by the charging pile system, the key attributes directly related to the charging process are identified. This process can involve data cleaning, removing irrelevant information, standardization, normalization, and feature selection steps, with the purpose of converting the original charging pile data into a feature set suitable for data analysis and machine learning models. For example, charging features can include daily charging peak hours, current and voltage variation patterns during charging, user charging habits, etc.
[0037] Through the extraction of charging features, network attack behaviors can be more accurately identified. For example, if the charging pile has abnormally high current or voltage during non-peak charging hours, or the user's charging behavior suddenly changes, these may be signs of network attacks or other security threats. The extraction of features enables the model to make judgments based on these specific indicators, improving the accuracy and sensitivity of detection.
[0038] In step S106, distances between the charging features and the target cluster center features are determined, obtaining a plurality of target distances, wherein the plurality of target cluster center features are obtained based on the plurality of initial cluster center features, the plurality of initial cluster center features are obtained based on the sub-sample features included in the corresponding update subspace, the plurality of update subspaces are obtained by determining the subspaces with sample density greater than the first threshold from the plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering the target sample features.
[0039] In step S106, distances between the charging features and the target cluster center features are determined, obtaining a plurality of target distances, wherein the plurality of target cluster center features are obtained based on the plurality of initial cluster center features, the plurality of initial cluster center features are obtained based on the sub-sample features included in the corresponding update subspace, the plurality of update subspaces are obtained by determining the subspaces with sample density greater than the first threshold from the plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering the target sample features.
[0040] Among them, the target cluster center is involved, and the target cluster center feature is determined after the secondary clustering process, representing the center point of the normal operation behavior of the charging pile. Through these center points, the samples in the data set can be compared with the normal behavior.
[0041] Among them, the plurality of target distances are involved, and the plurality of target distances refer to the distances between the charging features and the plurality of target cluster center features. In clustering analysis, these distances are used to measure the similarity between the current feature point and the cluster center feature. The smaller the distance, the closer the sample point to the cluster center, that is, the more consistent with the corresponding behavior of the corresponding subspace.
[0042] Among them, the plurality of initial cluster center features are involved, and the plurality of initial cluster center features are the center point features determined in the first clustering operation, which are usually based on the initial sample distribution in the data set, and are used to preliminarily divide the data set into different clusters.
[0043] Among them, the plurality of update subspaces are involved, and in the secondary clustering process, the system analyzes the initial subspace and determines the subspace with sample density greater than the first threshold.
[0044] Among them, the target sample feature is involved, and the target sample feature refers to the sample feature analyzed and clustered in the charging pile network. These features should be able to describe the key aspects of the charging pile usage, such as charging duration, charging frequency, charging power, network traffic, etc. The target sample feature is the basis of clustering analysis, and by clustering these features, features exhibiting the same attack behavior can be grouped into an initial subspace, so as to form a plurality of initial subspaces reflecting different attack behaviors.
[0045] Among them, the plurality of initial subspaces are involved, and the plurality of initial subspaces refer to the plurality of subspaces obtained by clustering the target sample features. This operation is usually to perform clustering analysis more efficiently, and each subspace can contain part of the features in the feature set to reflect different attack behaviors.
[0046] Among them, subsample features are involved. Subsample features are concepts related to multiple initial subspaces, and refer to the sample features included in each subspace.
[0047] Among them, the first threshold is involved, which is a parameter used to screen high-density subspaces in the clustering process. By setting the first threshold, subspaces with low sample density and that may contain abnormal or irrelevant data can be filtered out, thereby improving the accuracy of the clustering effect.
[0048] In this step, the distances between the charging signature and the corresponding features of multiple target cluster centers are directly determined. Since the target cluster center is the center obtained after secondary clustering, the target cluster center feature is a more accurate and representative feature reflecting the attack information represented by the corresponding subspace. In other words, it can accurately indicate whether the corresponding subspace represents the attack and the type of attack. By determining which cluster center the charging signature is similar to, the attack behavior category can be accurately determined. In other words, through the use of secondary clustering and updated subspaces, the system can more accurately identify the attack behavior category, thereby improving the accuracy of attack category detection.
[0049] Step S108: determining the attack behavior category corresponding to the charging pile system based on the multiple target distances.
[0050] In step S108 provided in the present application, the attack behavior category corresponding to the charging pile system is determined based on multiple target distances.
[0051] This involves attack behavior classification, which categorizes potential network attacks into different types, such as denial of service (DoS) attacks, man-in-the-middle (MITM) attacks, and malware propagation, based on anomaly detection results from charging pile network data. By identifying attack behavior categories, specific security measures can be taken to address different types of threats.
[0052] In this step, the attack behavior category corresponding to the charging pile system is determined based on multiple target distances. Specifically, the system calculates the distance between each charging feature and all target cluster centers. Based on the size and distribution of these distances, it determines whether the charging feature fits into a known attack behavior pattern. If a charging feature has a very small distance to a specific cluster center, the system can mark it as belonging to the corresponding attack behavior category.
[0053] Through the steps S102-S108, the charging pile data in the charging pile system is obtained. The charging feature corresponding to the charging pile data is extracted. The distances of the charging feature corresponding to a plurality of target cluster center features are determined, and a plurality of target distances are obtained, wherein the plurality of target cluster center features are obtained according to a plurality of initial cluster center features, the plurality of initial cluster center features are obtained according to the sub-sample features included in the corresponding update subspace, the plurality of update subspaces are subspaces corresponding to the sample density greater than a first threshold value determined from a plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering the target sample features. According to the plurality of target distances, the attack behavior category corresponding to the charging pile system is determined. It can be known that the embodiment of the present application determines the distances of the charging feature corresponding to a plurality of target cluster centers to achieve the purpose of determining the attack behavior category. Since the target cluster center is the center obtained after secondary clustering, the target cluster center feature is a feature that more accurately and representatively reflects the attack information represented by the corresponding subspace, that is, it can accurately represent whether the corresponding subspace is attacked and what kind of attack is made, so as to accurately determine the attack behavior category by determining the similarity between the charging feature and the cluster center, and further solve the technical problem of low attack detection accuracy when using the traditional clustering detection method to detect whether the charging pile network is attacked in the related art.
[0054] As an optional embodiment, extracting the charging feature corresponding to the charging pile data comprises: performing numerical value processing on the charging pile data to obtain charging pile numerical value data corresponding to the charging pile data; and performing normalization processing on the charging pile numerical value data to obtain the charging feature.
[0055] In this embodiment, further steps of extracting the charging feature corresponding to the charging pile data are described.
[0056] Among them, the charging pile numerical value data refers to the process result of converting non-numeric information in the charging pile data into a numeric format. For example, converting the text description of the charging state into a binary value of 0 or 1, converting the geographic location information into latitude and longitude values, and converting the time stamp into a calculable time difference value.
[0057] In the steps involved in this embodiment, first, the non-numerical information in the charging pile data is converted into numerical format so that computer algorithms can process it. For example, the geographic location of the charging pile is converted into longitude and latitude numerical values, and the time stamp in the user operation record is converted into a time difference numerical value from a certain reference point. Numerical processing is an important step in data preprocessing, which converts unstructured information into structured numerical data, facilitating subsequent data analysis and algorithm model processing. Next, the charging pile numerical data is normalized, that is, the values of all features are scaled to the same range, usually [0, 1]. Normalization helps to eliminate the influence of different feature scales, ensuring that all features are on the same level in subsequent clustering analysis and model training, avoiding the dominance of features with large scales in model behavior, and improving the stability and prediction accuracy of the model. The normalized data, i.e., charging features, will be used for subsequent attack detection and behavior analysis.
[0058] In this way, the data format after numerical and normalization processing is unified, facilitating fast processing and analysis, reducing the complexity of algorithm calculation, and improving the speed of detection and response. Moreover, normalization ensures that the model is not affected by feature scales when processing data, improving the accuracy of the model in analyzing charging pile data and reducing the risk of false positives and false negatives. In addition, numerical processing converts complex data into simple numerical format, facilitating feature selection and engineering, reducing the difficulty of feature selection, and improving the effectiveness of features.
[0059] As an optional embodiment, before determining the distances between the charging features and the target clustering center features, the method further includes: determining a plurality of initial sample densities corresponding to a plurality of initial subspaces; comparing the plurality of initial sample densities with a first threshold value respectively to obtain a plurality of comparison results, wherein the plurality of comparison results correspond one-to-one to the plurality of initial sample densities; from the plurality of comparison results, determining a plurality of target results of subspaces whose corresponding initial sample densities are greater than the first threshold value; and determining the initial subspaces corresponding to the plurality of target results as a plurality of updated subspaces.
[0060] In this embodiment, the step of determining the plurality of updated subspaces is described before determining the distances between the charging features and the target clustering center features.
[0061] Here, the initial sample density refers to the distribution density of sample features in each initial subspace, that is, the number of sample features per unit space. A high-density subspace usually indicates an area where sample points are concentrated.
[0062] wherein the first threshold is a set numerical standard used to filter out high-density subspaces. Only when the sample density of the initial subspace exceeds the first threshold, the subspace will be considered as an update subspace for subsequent clustering analysis.
[0063] In the steps involved in this embodiment, first, the initial sample densities corresponding to the multiple initial subspaces are determined, i.e., the density of charging pile data points in the subspace. Then, compare each initial sample density with the preset first threshold to get the comparison result. Only those subspaces with sample density exceeding the first threshold, i.e., high-density subspaces, will be further retained as update subspaces for subsequent clustering analysis and anomaly detection.
[0064] In this way, the screening of high-density subspaces helps to exclude noise and irrelevant data in low-density areas, improving the accuracy of clustering results. Moreover, by screening, only high-density subspaces are retained, which can significantly reduce the computational resource demand of subsequent clustering and anomaly detection, improving the overall processing efficiency and response speed. In addition, the use of update subspaces enhances the system's adaptability to changes in charging pile network data, maintaining high clustering accuracy and anomaly detection ability even in the presence of noise or abnormal points.
[0065] It should be noted that the first threshold can be dynamically adjusted according to the real-time state and historical data of the charging pile network to adapt to different data distribution and load conditions, improving the flexibility and accuracy of screening. In addition, real-time stream data processing technology can be combined to realize real-time update of subspace screening and clustering analysis, enhancing the real-time response and protection capabilities of the charging pile network. Furthermore, the clustering analysis based on the update subspace can be combined with deep learning models such as convolutional neural networks (CNN) and long short-term memory networks (LSTM) to utilize the feature extraction and pattern recognition capabilities of deep learning models, further improving the accuracy and robustness of charging pile network anomaly detection. In addition, during the subspace screening and sample density calculation, data security and privacy protection should be considered, and techniques such as data desensitization and differential privacy can be used to ensure that sensitive information is not leaked.
[0066] As an optional embodiment, before the step of determining distances between the charging features and the target clustering center features, the method further comprises: determining a densest subspace from the plurality of updated subspaces, the densest subspace including the most sample features; determining a first initial clustering center feature according to an average distance of the charging pile sample points in the densest subspace; determining a plurality of initial distances between the first initial clustering center feature and a plurality of first remaining subspace centers, the plurality of first remaining subspace being the remaining subspaces in the plurality of updated subspaces except the densest subspace; determining a farthest subspace according to the plurality of initial distances, the farthest subspace being the farthest from the first initial clustering center feature; determining a second initial clustering center feature according to an average distance of the charging pile sample points in the farthest subspace; determining a first distance between the first initial clustering center feature and a plurality of second remaining subspace centers, and determining a plurality of second distances between the second initial clustering center feature and the plurality of second remaining subspace centers, the plurality of second remaining subspace centers being the remaining subspaces in the plurality of updated subspaces except the densest subspace and the farthest subspace; determining a plurality of distance sums of the first distances and the corresponding second distances, to obtain a plurality of distance sums; and determining a third initial clustering center feature according to the plurality of distance sums, until a plurality of initial clustering center features are determined, wherein the third initial clustering center feature is the updated subspace center corresponding to the largest distance sum.
[0067] In this embodiment, the step of determining a plurality of initial clustering center features before determining distances between the charging features and the target clustering center features is illustrated.
[0068] The densest subspace refers to the updated subspace including the most sample features in the plurality of updated subspaces. That is, the densest subspace is selected from the plurality of updated subspaces, and the subspace with the highest sample density. It usually represents the most typical and frequent attack behavior category in the charging pile network.
[0069] The first initial clustering center feature refers to the center feature of the plurality of charging features included in the densest subspace. The center feature of the updated subspace including the most charging features is determined as the first initial clustering center feature. Since the subspace with the highest sample density includes the most features, the center feature determined in this way is representative and can better capture the clustering features and structure of the data, thereby improving the accuracy and quality of clustering.
[0070] The first remaining subspace refers to the remaining subspace in the plurality of updated subspaces except the densest subspace.
[0071] The farthest subspace refers to an update subspace corresponding to a center feature farthest from the first initial clustering center feature among the plurality of update subspaces. The farthest subspace is selected from the first remaining subspace and is a subspace farthest from the first initial clustering center feature, which may represent another type of attack behavior category in the charging pile network.
[0072] The second initial clustering center feature refers to a center feature of the plurality of charging features included in the farthest subspace. The update subspace farthest from the first initial clustering center feature is selected, and the center feature of the subspace is determined as the second initial clustering center feature. In this way, the distance between the two initial clustering center features is maximized, so that the clustering centers are more evenly distributed in the plurality of update subspaces, increasing the diversity and separation of clustering, helping to better distinguish different clustering groups, reducing the overlap of different clustering groups, and making the result more stable and reliable.
[0073] The second remaining subspace center refers to a center feature of a remaining subspace among the plurality of update subspaces, excluding the closest subspace and the farthest subspace.
[0074] The first distance and the second distance refer to distances from the first initial clustering center feature and the second initial clustering center feature to the plurality of second remaining subspace centers, respectively. That is, the first distance and the second distance refer to distances between the charging pile sample points and the first initial clustering center feature and the second initial clustering center feature, respectively, for measuring the similarity between the sample points and the clustering centers.
[0075] The third initial clustering center feature refers to a center feature of the plurality of charging features included in the update subspace with the maximum distance sum of the first distance and the corresponding second distance. After the first initial clustering center feature and the second initial clustering center feature are determined, the distance sum of the plurality of first distances and the corresponding second distances is determined, the maximum distance sum is obtained, and the center feature of the subspace corresponding to the maximum distance sum is determined as the third initial clustering center feature. In this way, the distance between different clusters is maximized, so that each clustering center feature is evenly distributed in the data space, which is conducive to better representing different clustering groups and increasing the stability and accuracy of the detection result.
[0076] In the steps involved in this embodiment, first, the most dense subspace with the highest sample density is identified from the plurality of update subspaces, which ensures that the selection of the cluster center is based on the most dense and most typical attack behavior category in the charging pile network data. Then, the average distance of the charging pile sample points in the most dense subspace is calculated as the first initial cluster center feature, which provides the center point of a certain type of attack behavior in the charging pile network. Next, the farthest subspace farthest from the first initial cluster center feature is found from the first remaining subspace, which is used as the second initial cluster center feature, which helps to expand the range of cluster analysis and ensure that more types of attack behaviors can be covered. Then, the distances from the plurality of second remaining subspace centers to the first initial cluster center feature and the second initial cluster center feature are calculated to form a distance sum, which is used to determine the third initial cluster center feature, until a plurality of initial cluster center features are determined, ensuring that all major attack behavior categories in the charging pile network are covered.
[0077] In this way, the clustering accuracy can be improved. By selecting the initial cluster center feature from the high-density subspace and then determining a plurality of initial cluster center features, the error in the clustering process can be effectively reduced, and the accuracy of the clustering result can be improved. Moreover, the initial cluster center is selected by using the sample density and distance criteria, which can enhance the anti-interference ability of the clustering algorithm to abnormal points and noise in the charging pile network data and improve the robustness of the algorithm. Moreover, through the above steps, the cluster centers can be gradually screened and optimized to ensure that each cluster center determined is optimal, and the amount of data that needs to be analyzed in detail is reduced, thereby improving the overall calculation efficiency and response speed.
[0078] As an optional embodiment, before determining the distances between the charging features and the plurality of target cluster center features to obtain a plurality of target distances, the method further includes: determining, from the plurality of initial subspaces, a subspace with an initial sample density less than or equal to a first threshold to obtain a centerless subspace; determining sample distances between a plurality of charging pile sample points included in the centerless subspace and the plurality of initial cluster center features; clustering the plurality of charging pile sample points into corresponding update subspaces based on the plurality of sample distances to obtain a plurality of target subspaces; and obtaining the plurality of target cluster center features according to the plurality of target subspaces, wherein the target subspaces and the target cluster center features correspond one-to-one.
[0079] In this embodiment, the step of determining the plurality of target cluster center features is explained before determining the distances between the charging features and the plurality of target cluster center features to obtain a plurality of target distances.
[0080] The non-central subspaces are selected from the plurality of initial subspaces based on a sample density of the initial subspaces. The sample density of a subspace is a measure of the number of sample points in the subspace. The non-central subspaces are the subspaces whose sample density is less than or equal to a first threshold. The first threshold is a predetermined value that is used to determine whether a subspace is a non-central subspace. The non-central subspaces are the subspaces that are not included in the high-density update subspaces. These subspaces may contain valuable information, especially when it comes to abnormal or rare attack behaviors.
[0081] The target subspaces are formed by clustering the plurality of charging features in the non-central subspaces into the corresponding update subspaces. The target subspaces are the new subspace set obtained by clustering the plurality of charging sample points in the non-central subspaces into the update subspaces. These subspaces are used as the refined analysis units in the subsequent clustering analysis.
[0082] The sample distance is the distance between a charging sample point and an initial cluster center feature. The sample distance is used to measure the similarity between a sample point and a cluster center. The sample distance is a key factor in determining the attribution of a sample point.
[0083] The target cluster center features are the new cluster centers formed in the target subspaces. The target cluster center features are more accurate in reflecting the attack behavior categories of the charging network through continuous iteration and optimization.
[0084] In the steps involved in this embodiment, the non-central subspaces are selected from the plurality of initial subspaces based on the sample density of the initial subspaces. The sample density of a subspace is a measure of the number of sample points in the subspace. The non-central subspaces are the subspaces whose sample density is less than or equal to a first threshold. The first threshold is a predetermined value that is used to determine whether a subspace is a non-central subspace. The non-central subspaces are the subspaces that are not included in the high-density update subspaces. These subspaces may contain valuable information, especially when it comes to abnormal or rare attack behaviors. The sample distance between the charging sample points in the non-central subspaces and the plurality of initial cluster center features is determined. The sample distance is used to measure the similarity between a sample point and a cluster center. The plurality of charging sample points are re-clustered into the corresponding update subspaces based on the sample distance, obtaining the plurality of target subspaces. This step compares the data points in the sparse areas with the cluster centers in the high-density areas and reasonably allocates them to more suitable clusters. The new target cluster center features are determined based on the plurality of target subspaces. This process may involve multiple iterations until the cluster centers are stable, ensuring that all major attack types in the charging network are covered and identified.
[0085] By this way, the comprehensiveness of the clustering analysis can be ensured, that is, by processing the sample points in the non-central subspace, it can be ensured that the clustering analysis covers all areas in the charging pile network, avoiding the sample points in low-density areas being ignored, improving the comprehensiveness and accuracy of the clustering results. Moreover, the detection ability of abnormal behavior can be enhanced, the sample points in the non-central subspace often represent relatively rare or abnormal behavior patterns, by clustering them into the target subspace, these abnormal behaviors can be more effectively identified, and the detection ability of the system to potential attacks can be improved. In addition, by processing the sample points in the non-central subspace after processing the high-density subspace, the calculation resources can be reasonably allocated, and excessive resources can be avoided in the calculation-intensive clustering analysis. Moreover, since the center feature of the target subspace is offset by re-clustering, the center feature needs to be re-determined, so that the target clustering center feature can better represent the respective clustering population, optimize the clustering results, and improve the clustering quality.
[0086] As an optional embodiment, after determining the attack behavior category corresponding to the charging pile system according to the plurality of target distances, the method further comprises: determining an initial charging pile parameter corresponding to the charging pile system; and adjusting the initial charging pile parameter based on the attack behavior category to obtain a target charging pile parameter.
[0087] In this embodiment, after determining the attack behavior category corresponding to the charging pile system according to the plurality of target distances, the initial charging pile parameter of the charging pile system is adjusted to obtain the target charging pile parameter.
[0088] Among them, the initial charging pile parameter is a series of parameters previously set by the charging pile system, including but not limited to charging power, charging rate, communication frequency, safety threshold, data acquisition frequency, etc.
[0089] Among them, the target charging pile parameter is also involved, after identifying the attack behavior category, the charging pile system adjusts the initial charging pile parameter according to the specific attack behavior, and the target charging pile parameter is a set of adjusted parameters, in order to enhance the defense ability of the system to attacks or optimize the running efficiency in the attack environment.
[0090] In the steps involved in this embodiment, the system determines the initial charging pile parameters required for its normal operation based on the current operating state. These parameters may be set to optimal values to ensure efficient and safe operation under normal conditions. Then, when the charging pile network detection system identifies a specific attack behavior category, the charging pile system will adjust its initial charging pile parameters according to the type and characteristics of the attack. For example, in the face of a DoS attack, the charging pile system may increase its security threshold or adjust other parameters; in the face of a data tampering attack, the system may increase the data collection frequency and increase the data integrity check to quickly identify and respond to potential security threats, etc. Without limitation, more specific attack behavior categories are set to obtain target charging pile parameters to better defend against network attacks of the corresponding attack behavior category.
[0091] In this way, by adjusting the charging pile parameters to cope with specific attack behaviors, the charging pile system can take more precise and effective defensive measures, improving its adaptive security protection capabilities. Moreover, while defending against network attacks, adjusting the charging pile parameters can also optimize the charging pile's operating efficiency in an attack environment, avoiding unnecessary resource waste and ensuring the continuity and quality of charging services. In addition, the setting of target charging pile parameters can increase the system's resistance to unknown or future network attacks, so that the charging pile system can maintain its basic functions and security even in a complex and changing network environment.
[0092] As an optional embodiment, adjusting the initial charging pile parameters based on the attack behavior category to obtain the target charging pile parameters comprises: determining an fitness function according to a plurality of target distances, wherein the fitness function is used to determine the probability of the charging pile system being attacked by the attack behavior category; determining a predetermined number of candidate charging pile parameters according to the initial charging pile parameters and the fitness function, wherein the predetermined number of candidate charging pile parameters are all parameters corresponding to a fitness greater than a second threshold; and obtaining the target charging pile parameters according to the predetermined number of candidate charging pile parameters.
[0093] In this embodiment, the specific steps of adjusting the initial charging pile parameters based on the attack behavior category to obtain the target charging pile parameters are described.
[0094] Among them, the fitness function is a core concept in optimization algorithms, used to measure the effectiveness of parameter configuration in solving a specific problem. In the context of charging pile security protection, the fitness function is used to calculate the probability of the charging pile system being attacked under a given parameter configuration, i.e. the sensitivity of the attack, i.e. in this scenario, the fitness function can determine the probability of a set of charging pile parameters causing the charging pile system to be attacked by the attack behavior category in the automatic response process of the charging pile system to the network attack behavior.
[0095] Wherein, the second threshold value is another set of numerical criteria for screening out charging pile parameter configurations with higher fitness, i.e., those that can effectively reduce the attack probability.
[0096] Wherein, the to-be-selected charging pile parameter is a parameter set that has been evaluated by the fitness function and has a fitness greater than the second threshold value. These parameters are considered to be better operating configurations for the charging pile system when under attack.
[0097] Wherein, the target charging pile parameter is the best parameter set determined from the to-be-selected charging pile parameter, which is used to actually adjust the charging pile system to enhance its security protection capability.
[0098] In the steps involved in this embodiment, a fitness function is constructed based on multiple target distances. This function quantifies the likelihood of the charging pile system being attacked under different parameter configurations, helping the system evaluate the security of different parameter configurations. Then, the system uses the initial charging pile parameter and the fitness function to screen out to-be-selected charging pile parameters with a fitness higher than the second threshold value through an optimization algorithm. The setting of the second threshold value ensures that only those parameter configurations that can significantly reduce the attack probability are further considered, thereby avoiding unnecessary parameter adjustments. Finally, the system determines the best target charging pile parameter from these to-be-selected charging pile parameters with higher fitness through further optimization or selection. These parameters will be actually applied to the charging pile system in order to reduce the risk of network attacks while ensuring service quality and efficiency.
[0099] In this way, the system security can be improved, i.e., by adjusting the charging pile parameters to reduce the probability of being attacked by network attacks, the system can actively optimize its operating state and enhance its defense capability against network attacks. Moreover, screening out parameter configurations with high fitness avoids unnecessary waste of resources, ensuring efficient operation of the charging service while maintaining security protection. In addition, the setting of the fitness function enables the charging pile system to adaptively adjust its parameters according to the type and intensity of network attacks, improving the flexibility and robustness of the system.
[0100] Based on the above embodiments and optional embodiments, an optional implementation is provided, which is specifically described as follows.
[0101] The present application provides a method for determining attack behavior of a charging pile network in the optional implementation of the application, Figure 2 which is a charging pile attack detection process based on improved multi-cluster method, as shown in Figure 2 , the target distance can be obtained through the improved K-means clustering algorithm and the improved evidence accumulation clustering algorithm based on the obtained charging pile data set, and finally the abnormality of the charging pile operation behavior is determined and the type of attack behavior is determined.
[0102] The specific steps involved in the optional embodiments of the application are introduced below.
[0103] S1, acquiring charging pile data in a charging pile system;
[0104] Specifically, the charging pile data can include charging pile network traffic, security logs, monitoring videos, and other data, and these data are connected into a data set.
[0105] Among them,
[0106] 1) Charging pile network traffic refers to various data packets transmitted through the network. By analyzing the industrial control network traffic, abnormal network traffic such as attack traffic and malicious software propagation can be detected.
[0107] 2) Security log data: The security log data includes security log records of various network devices and systems.
[0108] S2, numerical processing of the charging pile data to obtain charging pile numerical data corresponding to the charging pile data;
[0109] S3, normalizing the charging pile numerical data to obtain charging characteristics, and mapping the numerical values of the charging pile in the interval [0, 1], as shown in the following formula:
[0110]
[0111] Among them, X' is the normalized numerical feature vector, and X is the numerical feature vector before normalization.
[0112] It should be noted that the above S2-S3 are parameter initialization and preprocessing operations of the charging pile network observation data set, and the steps of selecting the features of the data set.
[0113] The step specifically includes the following steps:
[0114] A1, numerical processing of the data to be measured to obtain a numerical feature vector;
[0115] A2, standardizing the numerical feature vector to obtain a normalized numerical feature.
[0116] The above A1, A2 and S1, S2 steps correspond respectively.
[0117] It should be noted that, through standardization processing, if the numerical feature vector has inconsistent feature scales in different dimensions, the model may be too sensitive to some features without standardization processing, thereby affecting the reliability and stability of the model. In order to convert all features to the same scale, the data needs to be standardized for better analysis and comparison. The standardized data maintains the same linear distribution relationship as the original data, which is beneficial to the convergence speed and accuracy of the model. Therefore, the feature is normalized, and the numerical value of the industrial control network security data macro parameter is mapped in the interval [0, 1].
[0118] S4, determine the distance corresponding to the charging feature and the plurality of target clustering center features respectively, obtain a plurality of target distances, wherein the plurality of target clustering center features are obtained according to the plurality of initial clustering center features, the plurality of initial clustering center features are obtained according to the sub-sample features included in the corresponding update subspace, the plurality of update subspaces are the subspaces corresponding to the sample density greater than the first threshold value determined from the plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering the target sample features;
[0119] S5, determining the attack behavior category corresponding to the charging pile system according to the plurality of target distances.
[0120] It should be noted that after determining the charging pile network attack behavior type, an abnormal data detection report is generated, which includes the specific attack behavior category and the initial charging pile parameter corresponding to the charging pile system. After inputting the charging pile data and determining the charging pile network attack behavior type according to the improved clustering algorithm, an abnormal data detection report is generated. Based on the report, the initial charging pile parameter can be automatically adjusted by improving the grey wolf optimization algorithm to determine the target charging pile parameter of the charging pile, so as to better defend against this type of attack.
[0121] Figure 3 is the flow chart of the improved multi-clustering charging pile network attack security protection system provided by the optional embodiment of the present application, as shown in Figure 3 The process of determining the target charging pile parameter of the charging pile is described in steps S6-S8, which will be introduced as follows:
[0122] S6, determining the initial charging pile parameter corresponding to the charging pile system;
[0123] S7, determining the fitness function according to the plurality of target distances, wherein the fitness function is used to determine the probability of the charging pile system being attacked by the attack behavior category;
[0124] Specifically, it can include the following steps:
[0125] C1, designing a fitness function:
[0126] The initial parameters of the charging pile and the target distance D corresponding to the charging pile attacked by the network can be determined according to the generated abnormal data detection report a(i) ;
[0127] According to the target distance D a(i) , the fitness function is designed
[0128] The fitness function f(x c ,y c ) is designed as
[0129]
[0130] Where D s(i) represents the target distance corresponding to the target parameter determined subsequently, sigma is a positive number between 0 and 0.05, is a correction term
[0131] It should be noted that the optional embodiment of the present application adds part of the information of the gray wolf optimal individual when designing the fitness function, which can solve the information distortion and information loss problem generated in the iteration process when the population base is too large, and better identify the charging pile network attack behavior.
[0132] S8, according to the initial charging pile parameters and the fitness function, a predetermined number of selected charging pile parameters are determined, wherein the predetermined number of selected charging pile parameters are all parameters corresponding to the fitness greater than the second threshold value
[0133] S9, according to the predetermined number of selected charging pile parameters, the target charging pile parameters are obtained.
[0134] The execution specific mode of the above steps S8-S9 can be as follows:
[0135] Specifically, it can include the following steps:
[0136] C2, population exploration and iteration:
[0137] Figure 4 is the flow chart of the improved gray wolf optimization algorithm provided by the optional embodiment of the present application, as shown in Figure 4 , first initialize the gray wolf population, assuming the population size is k, T is the iteration number, use the chaotic vector m k to generate the initial reverse solution X k :
[0138] x k =x min +m k (x max -x min )
[0139] X k = (x max + x min ) · rand() - x k
[0140] x max and x min correspond to the maximum and minimum values of the corresponding dimension of the population, respectively, X k represents the initial gray wolf population position, rand() is a random number between [0, 1], and thus the initial gray wolf population is obtained.
[0141] According to the fitness function determined before, the fitness of each gray wolf individual is determined, and the greedy algorithm is used to select the gray wolf individuals, and the top two wolves a and b with the best fitness are saved. The positions of other gray wolves are determined by the positions of a and b:
[0142]
[0143] where, represents point-to-point multiplication, and Levy represents a path subject to Levy distribution. According to the above algorithm, the current gray wolf position is updated.
[0144] According to the current gray wolf position, the fitness of all gray wolves is determined again. The gray wolf algorithm and Levy flight strategy are used to iterate the gray wolf population. In the D-dimensional search space, the position of the kth gray wolf individual at the tth iteration is represented as X k (t), and X α (t) represents the optimal solution:
[0145] D = |C · X p (t) - X k,(t) |
[0146] X k (t+1) = X p (t) - A · D
[0147] where D is the search step, X p (t) is the current prey position, X k (t+1) is the updated position of the current individual, A and C are disturbance factors, and the disturbance factors of the leader gray wolves are defined as follows:
[0148]
[0149] where a is a nonlinear convergence factor, and the disturbance factors of a and b are A1, A2 and C1, C2, respectively. The position update formula is:
[0150]
[0151] where Dα , D β are the search step lengths of alpha and beta wolves respectively.
[0152] The new generation population is generated by the Levy flight strategy, and the specific parameter settings of the Levy flight strategy are as follows:
[0153]
[0154] Wherein, the parameter beta is a random number in [0, 2], and mu and nu obey normal distribution: The value of lambda gradually decreases from 1 to 0 with the increase of the number of iterations, reaches the maximum number of iterations, and obtains the target charging pile parameter.
[0155] C3: Automatic adjustment of parameters of the charging pile system:
[0156] The charging pile system automatically locates the abnormal node, that is, the abnormal parameter, according to the search process of the improved grey wolf algorithm, responds to the abnormal node, that is, adjusts the initial charging pile parameter corresponding to the charging pile system, and obtains the target charging pile parameter.
[0157] It should be noted that the optional embodiment of the application introduces chaos mapping, flight strategy and mutation strategy on the basis of grey wolf optimization algorithm, and the improved grey wolf optimization algorithm has the advantages of relatively simple implementation, strong global convergence, fast convergence speed and good adaptability.
[0158] It should be noted that before step S4, the operation of determining a plurality of target cluster centers is also included.
[0159] Specifically, the improved K-means clustering algorithm can be used for clustering operation of data, and the improved evidence accumulation clustering algorithm can be used for operation of calculating the cumulative Markov distance of isolated points to cluster centers, which will be introduced as follows.
[0160] S401, determine a plurality of initial sample densities corresponding to a plurality of initial subspaces respectively;
[0161] Specifically, the improved K-means clustering algorithm can be used for clustering and classification operation of each space in the following way:
[0162] The charging characteristics corresponding to the charging pile system are used as the input data set of the improved K-means clustering algorithm, wherein the data sample to be clustered is X', the number of data samples is n, the dimension is m, and the space range is R N .
[0163] x={X' i |x i ∈r N ,I=1,2,...,n}
[0164] Define the sample density of a subspace r (r∈R N ) as the number of samples in the subspace, denoted as ρ r . If the sample density of a subspace is not less than ρ m i n , the subspace is a high-density subspace, ρ m i n is the threshold of the high-density subspace.
[0165] Set the cluster number k and the first threshold ρ min ;
[0166] Determine a plurality of initial subspaces: select a positive integer l, divide the m-dimensional space where the plurality of charging features are located into l m (l m >2k) initial subspaces, and ρ r denotes the initial sample density corresponding to each initial subspace, respectively.
[0167] Further determine the initial sample density of each initial subspace
[0168] S402, compare the plurality of initial sample densities with the first threshold, respectively, to obtain a plurality of comparison results, wherein the plurality of comparison results correspond one-to-one to the plurality of initial sample densities;
[0169] S403, from the plurality of comparison results, determine a plurality of target results of the subspaces whose corresponding initial sample densities are greater than the first threshold;
[0170] S404, determine the initial subspaces corresponding to the plurality of target results as a plurality of updated subspaces.
[0171] Specifically, the plurality of updated subspaces can be determined from the plurality of initial subspaces in the following manner: put the initial subspaces whose initial sample densities are not less than ρ min into an updated subspace set D ρ , and count the number of updated subspaces. If the number of updated subspaces is less than the cluster number k, return to the step of adjusting the first threshold ρ min ;
[0172] S405, from the plurality of updated subspaces, determine a most dense subspace with the highest sample density;
[0173] S406, determine a first initial clustering center feature according to the average distance of the charging pile sample points in the most dense subspace;
[0174] S407: Determine a plurality of initial distances corresponding to the first initial cluster center feature and the centers of a plurality of first residual subspaces, wherein the plurality of first residual subspaces are the subspaces remaining in the plurality of updated subspaces except for the densest subspace;
[0175] Specifically, the distance from c1 to the center features of other updated subspaces can be determined to obtain multiple initial distances;
[0176] S408, determining a long-distance subspace farthest from the first initial cluster center feature based on the multiple initial distances;
[0177] Specifically, we can select the updated subspace farthest from c1 and calculate the average distance of the charging features in the space;
[0178] S409: Determine a second initial cluster center feature based on the average distance of charging pile sample points in the long-distance subspace;
[0179] Specifically, the second initial cluster center feature c2 can be determined;
[0180] S410: determining first distances between the first initial cluster center feature and a plurality of second residual subspace centers, and determining a plurality of second distances between the second initial cluster center feature and a plurality of second residual subspace centers, wherein the plurality of second residual subspace centers are subspaces remaining in the plurality of updated subspaces excluding the densest subspace and the distant subspace;
[0181] S411, determining the sum of distances between a plurality of first distances and the corresponding second distances, to obtain a plurality of distance sums;
[0182] Specifically, the sum of the distances from c1 and c2 to the center features of other updated subspaces can be determined, and the maximum distance and the corresponding updated subspace can be selected to obtain the initial cluster center feature c3;
[0183] The distance x1(α1,α2,...,α m ) and x2(β1,β2,...,β m ) is defined as:
[0184]
[0185] S412. Determine a third initial cluster center feature based on the multiple distance sums, until multiple initial cluster center features are determined, wherein the third initial cluster center feature is the updated subspace center corresponding to the maximum distance sum.
[0186] Specifically, the above steps can be performed to continue searching for cluster center features until the kth cluster center feature is found;
[0187] It should be noted that the clustering set output in the second stage, i.e. the above-mentioned multiple initial clustering center features, is taken as the input object of this stage, the density decomposition method is used as the clustering and joint operation strategy of the improved evidence accumulation clustering algorithm, and multiple target clustering center features are obtained.
[0188] S413, from the multiple initial subspaces, a subspace corresponding to an initial sample density less than or equal to a first threshold value is determined, and a centerless subspace is obtained.
[0189] Specifically, from the multiple initial subspaces, a subspace corresponding to an initial sample density less than or equal to p min is determined, and a centerless subspace is obtained.
[0190] Among them, clustering the multiple charging features in the centerless subspace into the update subspace corresponding to the nearest initial clustering center feature can be realized by using the traditional K-means clustering algorithm, and obtaining multiple target clustering center features according to multiple target subspaces can be completed by using the density decomposition method as the clustering and joint operation strategy of the improved evidence accumulation clustering algorithm.
[0191] S414, determine the sample distance between the multiple charging pile sample points included in the centerless subspace and the multiple initial clustering center features.
[0192] Suppose the dimension of the sample space set R is m, the data sample points are y={y1,y2,...,y m} and z={z1,z2,...,z m}, then the distance between the sampling points y and z is calculated as:
[0193]
[0194] Among them, CM -1 is the covariance standard matrix, and z are the corresponding coordinate vectors, respectively.
[0195] S415, based on the multiple sample distances, the multiple charging pile sample points are respectively clustered into the corresponding update subspace, and multiple target subspaces are obtained.
[0196] Specifically, the distance threshold can be set according to the actual environment. The multiple target distances D corresponding to the charging features are compared with the distance threshold, and multiple comparison results are obtained. Through the multiple comparison results, the charging pile network attack behavior is judged.
[0197] S416, according to the multiple target subspaces, multiple target clustering center features are obtained, wherein the target subspace and the target clustering center feature are one-to-one.
[0198] Through the above optional implementation, at least the following beneficial effects can be achieved:
[0199] (1) The charging pile data is numerically processed to obtain charging pile numerical data corresponding to the charging pile data, facilitating subsequent analysis and comparison; the charging pile numerical data is normalized to make the numerical feature vector have a consistent feature scale, improving the convergence speed and accuracy of the subsequent algorithm;
[0200] (2) The densest subspace is selected, the average distance of the charging features in the densest subspace is determined, and the center feature is determined as the first initial clustering center feature. Since the subspace with the highest sample density includes the most charging features, the center feature determined in this way is representative and can better capture the clustering features and structure of the data, thereby improving the accuracy and quality of clustering;
[0201] (3) The sum of the distances from c1 and c2 to the center features of other updated subspaces is determined, the maximum distance and the corresponding updated subspace are selected, and the initial clustering center feature c3 is obtained. In this way, the distance between different clusters is maximized, and the clustering center features are uniformly distributed in the data space, which is conducive to better representing different cluster groups and increasing the stability and accuracy of the detection results;
[0202] (4) The distances from the multiple charging features in the centerless subspace to the multiple initial clustering center features are determined, the multiple charging features in the centerless subspace are clustered into the updated subspaces corresponding to the nearest initial clustering center features, and the multiple target subspaces are obtained. According to the multiple target subspaces, the multiple target clustering center features are obtained, and the multiple charging features in the centerless subspace are re-clustered. This way makes the clustering results more complete and accurate. Since the center features of the target subspaces are shifted by re-clustering, the center features need to be determined again to make the target clustering center features better represent their respective cluster groups, optimize the clustering results, and improve the clustering quality;
[0203] (5) The distance threshold is set according to the actual environment. The multiple target distances D corresponding to the charging features are compared with the distance threshold to obtain multiple comparison results. Through the multiple comparison results, it can be accurately determined whether there is an attack in the charging pile network and the type of network attack behavior;
[0204] (6) Based on the attack behavior type, the initial charging pile parameters are adjusted, the positioning problem of the attack node is mapped to the gray wolf foraging process, the gray wolf individuals are selected through the improved fitness function and the greedy algorithm, the gray wolf population is updated through the improved gray wolf algorithm and the Levy flight strategy, and the target charging pile parameters are obtained. The charging pile system automatically responds to the network attack behavior.
[0205] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the action sequence described, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0206] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and a necessary general hardware platform, and of course it can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the method of each embodiment of the present application.
[0207] Embodiment 2
[0208] According to the embodiments of the present application, a device for implementing the attack behavior determination method of the charging pile network is also provided, Figure 5 is a structural block diagram of the attack behavior determination device of the charging pile network according to the embodiments of the present application, as Figure 5 shown, the device comprises an acquisition module 502, an extraction module 504, a first determination module 506 and a second determination module 508, which will be described in detail below.
[0209] The acquisition module 502 is configured to acquire charging pile data in the charging pile system; the extraction module 504 is connected to the acquisition module 502 and configured to extract charging characteristics corresponding to the charging pile data; the first determination module 506 is connected to the extraction module 504 and configured to determine distances of the charging characteristics corresponding to a plurality of target cluster center characteristics, to obtain a plurality of target distances, wherein the plurality of target cluster center characteristics are obtained according to a plurality of initial cluster center characteristics, the plurality of initial cluster center characteristics are obtained according to sub-sample characteristics included in a corresponding update subspace, the plurality of update subspaces are subspaces corresponding to sample densities greater than a first threshold value, which are determined from a plurality of initial subspaces, and the plurality of initial subspaces are obtained by clustering target sample characteristics; the second determination module 508 is connected to the first determination module 506 and configured to determine an attack behavior category corresponding to the charging pile system according to the plurality of target distances.
[0210] It should be noted that the above obtaining module 502, the extracting module 504, the first determining module 506 and the second determining module 508 correspond to steps S102 to S108 in the method for determining attack behavior of a charging pile network, and the plurality of modules have the same instances and application scenarios as the corresponding steps, but are not limited to the above embodiment 1.
[0211] Embodiment 3
[0212] According to another aspect of the embodiments of the present application, an electronic device is also provided, comprising: a processor; and a memory for storing processor-executable instructions, wherein the processor is configured to execute the instructions to implement the method for determining attack behavior of a charging pile network according to any of the above.
[0213] Embodiment 4
[0214] According to another aspect of the embodiments of the present application, a computer-readable storage medium is also provided, which, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the method for determining attack behavior of a charging pile network according to any of the above.
[0215] The above embodiment numbers of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0216] In the above embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0217] In the several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the unit embodiment described above is only schematic. For example, the division of the units can be a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, and can be electrical or other forms.
[0218] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.
[0219] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.
[0220] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application, essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0221] The above is only the preferred embodiment of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present application.
Claims
1. A method for determining attack behavior of a charging pile network, characterized in that: include: Obtain charging pile data in the charging pile system; Extracting charging characteristics corresponding to the charging pile data; Determining distances between the charging feature and a plurality of target cluster center features, respectively, to obtain a plurality of target distances, wherein the plurality of target cluster center features are obtained based on a plurality of initial cluster center features, the plurality of initial cluster center features are obtained based on subsample features included in corresponding updated subspaces, the plurality of updated subspaces being subspaces whose corresponding sample densities are greater than a first threshold, determined from the plurality of initial subspaces, the plurality of initial subspaces being obtained by clustering the target sample features; Determining an attack behavior category corresponding to the charging pile system based on the multiple target distances; Among them, before determining the distances between the charging characteristics and the multiple target cluster center characteristics, and obtaining the multiple target distances, it also includes: determining, from the multiple initial subspaces, a subspace whose corresponding initial sample density is less than or equal to a first threshold, to obtain a centerless subspace; determining the sample distances between the multiple charging pile sample points included in the centerless subspace and the multiple initial cluster center characteristics; based on the multiple sample distances, clustering the multiple charging pile sample points into corresponding update subspaces, to obtain multiple target subspaces; based on the multiple target subspaces, obtaining multiple target cluster center characteristics, wherein the target subspaces correspond one-to-one to the target cluster center characteristics.
2. The method according to claim 1, characterized in that Before determining the distances between the charging feature and the multiple target cluster center features, and obtaining the multiple target distances, the method further includes: Determine a plurality of initial sample densities corresponding to the plurality of initial subspaces respectively; Comparing the multiple initial sample densities with the first threshold respectively to obtain multiple comparison results, wherein the multiple comparison results correspond to the multiple initial sample densities one by one; Determining, from the plurality of comparison results, a plurality of target results for a subspace whose corresponding initial sample density is greater than a first threshold; Initial subspaces corresponding to the multiple target results are determined as the multiple updated subspaces.
3. The method according to claim 1, characterized in that Before determining the distances between the charging feature and the multiple target cluster center features, and obtaining the multiple target distances, the method further includes: Determining a densest subspace having the highest sample density from the multiple updated subspaces; Determining a first initial cluster center feature based on an average distance between charging pile sample points in the densest subspace; Determining a plurality of initial distances corresponding to the first initial cluster center feature and the centers of a plurality of first residual subspaces, wherein the plurality of first residual subspaces are the subspaces remaining in the plurality of updated subspaces excluding the densest subspace; According to the multiple initial distances, a long-distance subspace with the farthest distance from the first initial cluster center feature is determined; Determining a second initial cluster center feature based on the average distance of the charging pile sample points in the long-distance subspace; Determining first distances between the first initial cluster center feature and a plurality of second residual subspace centers, and determining a plurality of second distances between the second initial cluster center feature and a plurality of second residual subspace centers, wherein the plurality of second residual subspace centers are the remaining subspaces in the plurality of updated subspaces excluding the densest subspace and the distant subspace; Determine the sum of the distances between the plurality of first distances and the corresponding second distances, to obtain a plurality of distance sums; A third initial cluster center feature is determined based on the multiple distance sums, until the multiple initial cluster center features are determined, wherein the third initial cluster center feature is the updated subspace center corresponding to the maximum distance sum.
4. The method according to claim 1, wherein After determining the attack behavior category corresponding to the charging pile system based on the multiple target distances, the method further includes: Determining initial charging pile parameters corresponding to the charging pile system; Based on the attack behavior category, the initial charging pile parameters are adjusted to obtain target charging pile parameters.
5. The method according to claim 4, characterized in that Based on the attack behavior category, adjusting the initial charging pile parameters to obtain target charging pile parameters includes: Determining a fitness function based on the multiple target distances, wherein the fitness function is used to determine a probability that the charging pile system is attacked by the attack behavior category; Determining a predetermined number of charging pile parameters to be selected based on the initial charging pile parameters and the fitness function, wherein the predetermined number of charging pile parameters to be selected are all parameters whose corresponding fitness is greater than a second threshold; The target charging pile parameters are obtained according to the predetermined number of charging pile parameters to be selected.
6. The method according to any one of claims 1 to 5, characterized in that Extract charging characteristics corresponding to charging pile data, including: Performing numerical processing on the charging pile data to obtain numerical charging pile data corresponding to the charging pile data; The charging pile numerical data is normalized to obtain the charging characteristics.
7. A device for determining attack behavior of a charging pile network, characterized in that: include: An acquisition module is used to obtain charging pile data in the charging pile system; An extraction module, used to extract charging characteristics corresponding to charging pile data; a first determination module, configured to determine distances between the charging feature and a plurality of target cluster center features, respectively, to obtain a plurality of target distances, wherein the plurality of target cluster center features are obtained based on a plurality of initial cluster center features, the plurality of initial cluster center features are obtained based on subsample features included in corresponding update subspaces, the plurality of update subspaces being subspaces whose corresponding sample densities are determined to be greater than a first threshold value from the plurality of initial subspaces, the plurality of initial subspaces being obtained by clustering the target sample features; A second determination module is configured to determine an attack behavior category corresponding to the charging pile system based on the multiple target distances; Among them, the first determination module is used to determine, from the multiple initial subspaces, a subspace whose corresponding initial sample density is less than or equal to a first threshold, to obtain a centerless subspace; determine the sample distances between the multiple charging pile sample points included in the centerless subspace and the multiple initial cluster center features; based on the multiple sample distances, cluster the multiple charging pile sample points into corresponding update subspaces to obtain multiple target subspaces; based on the multiple target subspaces, obtain multiple target cluster center features, wherein the target subspaces correspond one-to-one to the target cluster center features.
8. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the method for determining attack behavior of a charging pile network according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method for determining attack behavior of a charging pile network according to any one of claims 1 to 6.
Citation Information
Patent Citations
Traffic data clustering method and device, equipment and medium
CN115563522A
Intrusion detection method and device, equipment and storage medium
CN116260654A