Method and system for analyzing the risk of malicious command propagation across space

A two-layer network directed unweighted graph established through the Bayesian framework and infectious disease model solves the problem of accuracy in risk assessment of cross-space propagation of malicious instructions, realizes comprehensive risk assessment of the active distribution network cyber-physical system, and improves the system's adaptability and stability.

CN119766484BActive Publication Date: 2025-10-03STATE GRID LIAONING ELECTRIC POWER CO LTD +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411715504.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-27
Publication Date
2025-10-03
Estimated Expiration
2044-11-27

AI Technical Summary

Technical Problem

Existing technologies make it difficult to accurately assess the risk of cross-space propagation of malicious commands in the cyber-physical system of active distribution networks, resulting in low risk quantification accuracy and affecting the safe and stable operation of the power grid.

Method used

By combining the Bayesian framework with the infectious disease model, a two-layer network directed unweighted graph is established, the prior probability and posterior probability are calculated, and combined with the minimum load loss rate, a risk analysis method for the cross-space propagation of malicious instructions is constructed to achieve a comprehensive security impact assessment of the cyber-physical system.

Benefits of technology

It has achieved accurate risk assessment of the cyber-physical system of the active distribution network, can identify hidden risks, provide a basis for decision-making, improve the system's adaptability and stability, and ensure the smooth operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766484B_ABST
    Figure CN119766484B_ABST
Patent Text Reader

Abstract

The present invention provides a method for analyzing the risk of malicious instructions propagating across space. The method includes establishing a coupled network structure of an active power distribution network cyber-physical system, and then using prior probability, posterior probability theory, and minimum load loss rate theory to study the process of malicious instructions in the coupled network and establish a quantitative assessment model for cross-space propagation risk. This model considers the connection between information nodes and physical nodes after intrusion, as well as the spread of risk propagation. Finally, the Bayesian theory is used to approximate the three likelihood functions of the risk propagation after the malicious instruction intrusion, and a quantitative value is calculated, providing an indicator for the safe and stable operation of the active power distribution network. The method also considers the directionality and interdependence of the link between the physical layer and the information layer, and uses an infectious disease-based infection model to characterize the risk propagation mechanism between the information layer and the physical layer, thereby improving the comprehensiveness and accuracy of the risk analysis of malicious instructions propagating across space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of risk assessment of cross-space propagation of malicious instructions in the field of energy control, and in particular to a method and system for analyzing the risk of cross-space propagation of malicious instructions. Background Art

[0002] In recent years, with the advancement of information technology in distribution networks, the interaction between the information and physical layers of distribution network CPS (Cyber ​​Physical Systems) has become increasingly frequent. Cyber ​​attackers, through attacks on power information systems, can indirectly impact the physical power system, making this a common method of attacking power grids. If an active distribution network is compromised by malicious commands, it can trigger a cascading failure of the entire grid, ultimately leading to severe power outages. Therefore, studying the spatial propagation mechanism of malicious commands within active distribution network information systems is crucial for the safe and stable operation of power grids.

[0003] The cyber-physical system of an active distribution network is mainly divided into two network layers. The malicious instruction intrusion location studied in this invention is the information layer, which is composed of various information processing devices and covers the collection and processing of energy supply, demand and load data. The attack of malicious instructions on the information layer of the distribution network may cause the loss or tampering of important power data, affecting the accuracy and timeliness of the system's energy decision-making. In addition, malicious instructions may not only cause data loss, but also misoperate the physical equipment of the distribution network. Therefore, it is particularly important to protect the cyber-physical system of the active distribution network from the influence of malicious instructions, and studying the mechanism of its propagation in space becomes a necessary prerequisite. The establishment of a propagation model directly affects important issues such as the detection of subsequent malicious instructions and system protection.

[0004] However, the information and physical layers of distribution network cyber-physical systems often exhibit a coupling effect, primarily manifesting in the frequent interactions between physical and information domain nodes. Information and energy flows must operate in tandem. The information layer's primary function is to collect, transmit, and process power data from the distribution network. When the information layer is compromised by malicious commands, it faces the risk of data theft and the uploading of erroneous data, potentially leading to malfunctions in physical devices. This means that malicious commands received on the information side can impact the physical layer network. However, the composition of active distribution network cyber-physical systems is relatively complex, encompassing a large number of power communication devices and complex interconnection rules. Quantitatively assessing the risk propagation of active distribution network cyber-physical systems following the intrusion of malicious commands at the information layer presents significant challenges.

[0005] Prior Art Document 1 (CN118199960A) discloses a risk quantification method, device, and system for an electric power cyber-physical system. The method includes: obtaining a target topology map and a preset attack method, determining multiple first probabilities for each target node based on the preset attack method and the target topology map; determining a second probability for the target node based on the attack type of the preset attack method; performing a simulation based on the preset attack method and the target topology map to simulate the impact of the performance loss of each target node under the preset attack method; and calculating the product of each first probability, second probability, and impact level to obtain a risk score, which is used to characterize the threat level of the preset attack method to the power grid. However, Prior Art Document 1 does not consider the issue of load loss rate, and the risk quantification accuracy is low.

[0006] Prior art document 2 (CN115361150A) discloses a security assessment method for the risk cascade of distribution networks under network attacks, which solves security risk problems such as incomplete and unavailable data at the distribution network acquisition end, transmission channel and receiving end. By constructing a risk assessment model through this method, the risk factor set and vulnerability correlation relationship can be effectively identified, and the system risk value can be accurately assessed. This method is mainly based on UML construction technology to analyze the risk factors of the distribution network, rough set simplification of the risk factor set, the optimal ideal algorithm (TOPSIS) to quantify the risk factors and system vulnerability relationship, Bayesian graph theory to simulate risk cascades, and combined with the distribution network load loss to quantify the impact of the attack on the system, and finally the distribution network risk value and risk level are integrated. However, prior art document 2 only uses the optimal ideal algorithm (TOPSIS) to quantify the risk factors and system vulnerability relationship, the security assessment is not comprehensive, and the assessment accuracy is low. Summary of the Invention

[0007] The technical problem to be solved by the present invention is to address the shortcomings of the current quantitative assessment model for the risk of malicious instructions propagating across space, and propose a method for analyzing the risk of malicious instructions propagating across space. According to the topological correlation of the active distribution network and the coupling logic of the information layer and the physical layer, the distribution network information-physical system network is abstracted into a two-layer network directed unweighted graph, and a Bayesian framework is used to measure the impact of malicious instruction propagation on the comprehensive security of the active distribution network information-physical system. This model involves three core elements: prior probability, posterior probability, and minimum load loss rate. These three core elements are respectively reflected and calculated in the present invention through the cumulative distribution function, epidemic model, and optimal load reduction algorithm. It can perform more accurate and comprehensive risk assessments in the active distribution network information-physical system to ensure the smooth operation and effective management of the power system, and reveal hidden risks and safety implications.

[0008] The present invention adopts the following technical solutions.

[0009] A first aspect of the present invention provides a method for analyzing the risk of malicious instruction propagation across space, applicable to an active power distribution network cyber-physical system, comprising the following:

[0010] S1: Establish a characterization model for the cyber-physical system of the active distribution network, characterize the physical device layer through the physical network, characterize the information communication layer through the information network, and characterize the coupling relationship between the information communication layer and the physical device layer through the interaction between the physical nodes in the physical network and the information nodes in the information network.

[0011] S2: Calculate the prior probability of each information node being attacked by malicious instructions based on the defense strength and attack strength of the information node.

[0012] S3: Based on the propagation model of infectious diseases, the propagation path and rate of malicious instructions in the distribution network cyber-physical system are simulated, and the posterior probability of other nodes being attacked when the information node is attacked by malicious instructions is calculated based on the simulation results.

[0013] S4: Calculate the damage level of the distribution network cyber-physical system under malicious command attacks.

[0014] S5: Determine the risk value of malicious instructions spreading across space by combining the prior probability, posterior probability and damage degree value.

[0015] Optionally, in S1, the physical network is denoted as G p =<V p ,E p >, where V p is the set of physical nodes, E p is a set of physical network edges. Physical nodes include power plants, substations, and converter stations. Transmission lines between physical sites serve as edges of the physical network. The information network is denoted as G c =<V c ,E c >, where V c is the information node set, E c It is a collection of information network edges. Information nodes include servers, computing devices, and data acquisition devices. The communication lines between information nodes serve as the edges of the information network.

[0016] Optionally, in S1, the interaction between the physical device layer and the control center is carried out in the information communication layer, which is used to collect, transmit and process power data of the distribution network and control the physical sites of the physical device layer.

[0017] Optionally, in S1, the information-physical system of the active distribution network is abstracted as a two-layer network directed unweighted graph, which includes an information network directed unweighted graph and a physical network directed unweighted graph; according to the directionality and dependency between the links of the information layer and the physical layer, the links between the information nodes and the physical nodes are abstracted as edges of the information network directed unweighted graph and the physical network directed unweighted graph.

[0018] Optionally, in S3, based on the propagation pattern of infectious diseases, the propagation path and rate of malicious instructions in the distribution network cyber-physical system are simulated, and the posterior probability of other nodes being attacked when the information node is attacked by the malicious instruction is calculated based on the simulation results, including:

[0019] Based on the spread model of infectious diseases, the following formula is obtained:

[0020]

[0021] in,

[0022] S(t)| t=0 =S0,

[0023] S(t), I(t) and R(t) are the number of nodes in the cyber-physical system of the distribution network that are in the vulnerable, infected and recovered states at time t, respectively.

[0024] α is the prior probability of an information node being infected,

[0025] β is the probability that an infected node is recovered,

[0026] The posterior probability that other nodes will be attacked when the information node is attacked by malicious instructions.

[0027] Optionally, S2 includes:

[0028] Based on the defense strength and attack strength of information nodes, a cumulative distribution function is used to represent the influence of the vulnerability coefficient on the prior probability in the active distribution network cyber-physical system, and a probability model of each node in the information layer being attacked by malicious commands is constructed.

[0029] The prior probability of each information node being attacked by malicious instructions is calculated according to the following formula:

[0030]

[0031] in,

[0032] P p is the prior probability that the p-th information node is attacked by malicious instructions,

[0033] λ pis the vulnerability coefficient of the pth information node, k is the vulnerability coefficient,

[0034] x p is the defense strength of the p-th information node,

[0035] y p is the attack strength of the p-th information node,

[0036] When P p =1, it means that the pth information node cannot resist the attack of malicious instructions.

[0037] Optionally, the vulnerability coefficient λ of the p-th information node is calculated based on at least one of the following security risk indicators: p : Information layer network security indicators, physical layer network security indicators and encryption indicators in distribution network cyber-physical systems.

[0038] Optionally, calculating the vulnerability coefficient of the information node according to each security risk indicator includes:

[0039] Normalize each security risk indicator and calculate the corresponding weight of each security risk indicator;

[0040] Combined with the corresponding weights of each security risk indicator, an evaluation matrix is ​​constructed. The evaluation matrix is ​​used to quantitatively describe the risk level of each information node under different security risk indicators;

[0041] Perform weighted normalization on the evaluation matrix, and calculate the positive ideal solution and negative ideal solution based on the weighted normalized matrix. The positive ideal solution represents the security risk index corresponding to the highest level, and the negative ideal solution represents the security risk index corresponding to the lowest level.

[0042] Calculate the Euclidean distance between each security risk indicator of each information node and the positive ideal solution and the negative ideal solution;

[0043] The vulnerability coefficient of each information node is calculated based on the Euclidean distance between each security risk indicator of each information node and the positive ideal solution, the negative ideal solution, and the average value of all security risk indicators of each information node.

[0044] Optionally, in S4, calculating the damage degree value of the active distribution network cyber-physical system under the malicious instruction attack includes:

[0045] According to the following formula, the minimum load loss rate of the active distribution network cyber-physical system under malicious command attack is calculated based on the distribution network flow, voltage, current, node and branch power:

[0046]

[0047] in,

[0048] Pi and Q i are the active and reactive power flows of the cyber-physical system of the active distribution network,

[0049] Π(i) is the set of nodes connected to node i,

[0050] g ij and b ij are the conductance and susceptance of nodes i and j, respectively,

[0051] U i and U j are the voltage amplitudes at nodes i and j, respectively,

[0052] θ ij is the phase angle difference between nodes i and j,

[0053] U imin and U imax are the lower and upper limits of the node i voltage,

[0054] n is the number of nodes,

[0055] I imax is the upper limit of the current in branch i,

[0056] l is the number of observable branches in the active distribution network cyber-physical system,

[0057] N G 、N D and N L are the collections of generators, loads and branches in the active distribution network cyber-physical system,

[0058] P i represents the balance of input and output power,

[0059] P Gi 、 Respectively represent the generator power, the upper limit and lower limit of the generator power,

[0060] P j 、P dj The actual power and rated power of the node are loaded separately.

[0061] C l 、 They are the number of nodes restored on this branch and the maximum number of nodes restored.

[0062] Optionally, in S5, the risk value of the malicious instruction propagation across space is determined by combining the prior probability, the posterior probability, and the damage degree value, including:

[0063] The risk value of malicious instructions spreading across space is determined according to the following formula:

[0064]

[0065] in,

[0066] P(A i ) is the prior probability of the i-th information node being attacked in the power distribution;

[0067] P(B j ∣A i ) is the posterior probability that the jth physical node is attacked when the i-th information node is attacked;

[0068] L j It represents the minimum load loss rate after the j-th physical node is attacked.

[0069] A second aspect of the present invention provides a system for analyzing the risk of malicious instruction propagation across space, the system comprising:

[0070] Establish a model module for establishing a characterization model of the cyber-physical system of the active distribution network, respectively characterizing the physical layer devices through the physical network and the information communication layer through the information network, and characterizing the coupling relationship between the information communication layer and the physical device layer through the interaction between the physical nodes in the physical network and the information nodes in the information network;

[0071] A first calculation module is used to calculate the prior probability of each information node being attacked by malicious instructions based on the defense strength and attack strength of the information node;

[0072] The second calculation module is used to simulate the propagation path and rate of malicious instructions in the distribution network cyber-physical system based on the propagation model of infectious diseases, and calculate the posterior probability of other nodes being attacked when the information node is attacked by the malicious instruction based on the simulation results;

[0073] The third calculation module is used to calculate the damage degree value of the distribution network cyber-physical system under the attack of malicious instructions;

[0074] The determination module is used to determine the risk value of malicious instructions spreading across space by combining the prior probability, the posterior probability and the damage degree value.

[0075] The third aspect of the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when loaded into the processor, implements the above-mentioned method for risk analysis of cross-space propagation of malicious instructions.

[0076] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-mentioned method for analyzing the risk of malicious instruction propagation across space.

[0077] Compared with the prior art, the beneficial effects of the present invention include at least:

[0078] Compared with the existing information-physical system architecture of the distribution network, the present invention deeply integrates the power-physical network and the information-communication network to form a closely related integrated system, which helps to achieve more efficient information-physical interaction, improve the system response speed and control accuracy, and realize the distribution of hybrid computing through the interaction of information flow and energy flow, so that the system can respond in real time and adapt to various operating conditions, thereby improving the system's adaptability and stability.

[0079] The model proposed in this paper considers the bidirectional coupling between cyber and physical networks in smart grids. By introducing a characterization model for heterogeneous network structures, it can more accurately describe the complex topological characteristics of the system and the dynamic behavior of information propagation. Furthermore, the present invention considers the interactive influence of information flow and energy flow in cyber-physical systems, describing this coupling through a correlation matrix, making the assessment more comprehensive and accurate. The subsequent direct quantification of risk values ​​makes risk not only perceptible but also measurable. This is more accurate than qualitative assessments and facilitates the development of targeted defense strategies.

[0080] Based on the propagation patterns of infectious diseases, this invention achieves precise modeling for quantitative risk assessment of cyber-physical systems in active power distribution networks. It not only effectively simulates the propagation paths and rates of malicious commands within cyber-physical networks, but also quantifies risk propagation thresholds through a Bayesian risk assessment model to assess system stability and security. This approach enables the invention to predict the propagation thresholds of security risks in heterogeneous, partially coupled networks, thereby identifying and paving the way for subsequent response to potential risk outbreaks. This provides powerful decision-making and response strategies for system administrators and security experts.

[0081] The present invention adopts the minimum load loss rate to quantitatively evaluate the degree of damage caused by network attacks to the system, and proposes a minimum load loss rate optimization model based on optimal load reduction; by imposing a minimum loss rate constraint on the system, a smaller load reduction can be achieved after the system is attacked.

[0082] The present invention introduces the order preference technology by similarity with the ideal algorithm TOPSIS (Technique for Order Preference by Similarity to an Ideal Solution) and the information entropy method, and proposes an algorithm based on the entropy method and the TOPSIS algorithm to solve the vulnerability factor; even in complex environments, it can flexibly and accurately identify the correlation between risk factor sets and system vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort. Among them:

[0084] Figure 1 A schematic flow chart of a method for analyzing the risk of malicious instruction cross-space propagation provided by an embodiment of the present invention;

[0085] Figure 2 A schematic diagram of a distribution network cyber-physical system fusion architecture provided by an embodiment of the present invention;

[0086] Figure 3 A schematic diagram of the challenges faced by a cyber-physical system of a distribution network and its corresponding model foundation provided by an embodiment of the present invention;

[0087] Figure 4 A schematic diagram of a susceptible-infectious-recovered (SIR) model provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0088] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0089] like Figure 1 As shown, embodiment 1 of the present invention provides a method for analyzing the risk of malicious instructions propagating across space, which mainly includes the following contents:

[0090] S1: Establish a characterization model for the cyber-physical system of the active distribution network, characterize the physical device layer through the physical network, characterize the information communication layer through the information network, and characterize the coupling relationship between the information communication layer and the physical device layer through the interaction between the physical nodes in the physical network and the information nodes in the information network.

[0091] Combine Figure 2 and Figure 3 As shown in S1, the active distribution network physical information system includes a physical device layer and an information communication layer. The interaction between the physical device layer and the control center is carried out in the information communication layer. The information communication layer is used to collect, transmit and process the power data of the distribution network and control the physical sites of the physical device layer.

[0092] In this embodiment, a physical device layer characterization and an information communication layer characterization are established, and based on this, a characteristic model of the information-physical coupling network is established. The "one-to-many" and "partial coupling" situations that exist in real situations are taken into account, that is, there is energy flow between a physical node and multiple information nodes, and some nodes have a high degree of autonomy and can operate normally without relying on a coupling network.

[0093] S1 specifically includes:

[0094] S1.1: Construct information nodes and physical nodes separately. Information nodes include information network sites in the information communication layer, and physical nodes include physical sites in the physical device layer.

[0095] Specifically,

[0096] 1) Taking the plant level as the research unit, the information network sites (including the information systems and dispatching centers of each power station) and physical sites (including power plants, substations, and converter stations) are regarded as equivalent information nodes and physical nodes, respectively.

[0097] 2) The communication lines between information network sites are equivalent to the edge of the network. The transmission lines between physical sites are equivalent to the edge of the physical network.

[0098] 3) Considering the directionality and dependency between the links of the physical network and the information network, the links between layers are undirected edges, and the edges between different layers are directed edges.

[0099] 4) The loops and multiple edges of the information network will be merged. All sub-networks of the distribution network will be traversed and the communication lines between multiple affected nodes will be processed.

[0100] Based on complex network theory, the topological structures of the information layer and physical layer of the active distribution network are abstracted and represented as two unweighted partial directed graphs G c and G p , where G c represents the information layer, G p Represents the physical layer.

[0101] S1.2: Physical Device Layer Characterization

[0102] The physical network can be abstracted as a complex network unweighted graph, G p =<V p ,E p >, where V p are physical nodes, including power plants, substations, and converter stations. The transmission lines between physical sites serve as edges of the physical network. p ={1,2,3,…,N p} is a set of physical nodes, E p ={Epij} is the set of connected edges at the physical layer. The edges between physical nodes at the physical device layer do not consider direction or capacity. In the coupled model, if a physical node fails, the network nodes that depend on its energy will also fail.

[0103] S1.3: Information Communication Layer Characterization

[0104] The information node is the control and processing center of the physical node of the corresponding physical device layer. In the information network, all related functions are considered to be completed in the abstract node. Similar to the physical network, the information network is abstracted as a complex network unweighted graph, G c =<V c ,E c >, where V c Information nodes include servers, computing devices, and data acquisition devices. The communication lines between information nodes are used as the edges of the information network. c ={1,2,3,…,N c} is the information node set, E c ={E cij} is the set of connected edges of the information network, A c =(a cij ) is the adjacency matrix of the information network, which characterizes the relationships between links in the information network and the physical network, including link direction and link dependencies. Edges between information nodes also do not consider direction. In the coupled model, if an information node fails, it cannot communicate with its neighboring nodes. Furthermore, since the invalid information node controls the corresponding physical node, its corresponding physical node may also fail.

[0105] Furthermore, in S1, the information-physical system of the active distribution network is abstracted as a two-layer network directed unweighted graph, which includes an information network directed unweighted graph and a physical network directed unweighted graph; according to the directionality and dependency between the links of the information layer and the physical layer, the links between the information nodes and the physical nodes are abstracted as edges of the information network directed unweighted graph and the physical network directed unweighted graph.

[0106] S2: Calculate the prior probability of an information node being attacked by malicious instructions based on the defense strength and attack strength of the information node.

[0107] The prior probability is the probability that an information node is vulnerable to attack due to vulnerabilities in the cyber-physical system of the active distribution network. The vulnerability of an information node requires consideration not only of the security level of the information node but also of the strength of the defenses of the attacked information layer. The higher the vulnerability, the greater the probability of attack.

[0108] S2 specifically includes:

[0109] S2.1: Based on the defense strength and attack strength of information nodes, use the cumulative distribution function to represent the impact of the system vulnerability coefficient k on the prior probability in the active distribution network cyber-physical system, and construct a probability model for each node in the information layer to be attacked by malicious commands;

[0110] S2.2: Calculate the prior probability P of an information node being attacked by malicious instructions according to the following formula: p :

[0111]

[0112] Where λ p is the vulnerability coefficient of the pth information node, k is the vulnerability coefficient, x p is the defense strength of the p-th information node, y p is the attack strength of the p-th information node. p =1, it means that the pth information node cannot resist network attacks.

[0113] Specifically, the prior probability value of an information node that has been attacked is 1, and the probability of an information node that has not been attacked being attacked by a malicious instruction is calculated based on the vulnerability coefficient of the information node.

[0114] Optionally, the prior probability of the pth information node in the active distribution network cyber-physical system satisfies 0<P p ≤1.

[0115] Specifically, for the active distribution network cyber-physical system, the pth information node in the active distribution network cyber-physical system has security vulnerabilities in the operating system, application software, communication protocol, etc., so 0<λ p <1. At the same time, the attack strength y of the pth information node p and defense strength x p Satisfy p ≤x p So, for All available Therefore, according to the above formula, only when y p >>x p When 0<P p <1. Therefore, for You can get 0<P p ≤1.

[0116] Optionally, in S2.2, the vulnerability coefficient λ of the p-th information node is calculated according to at least one of the following security risk indicators: p : Information layer network security, physical layer network security and encryption in active distribution network cyber-physical systems.

[0117] Optionally, in S2.2, the order preference technique is introduced by similarity with the ideal solution (TOPSIS) and the information entropy method, and an algorithm for solving the vulnerability factor based on the information entropy method and TOPSIS is proposed to calculate the vulnerability coefficient λ of the p-th information node p . Specifically including the following:

[0118] The first step is to normalize each security risk indicator.

[0119] Specifically, each security risk indicator is normalized according to the following formula:

[0120]

[0121] Among them, X ij Indicates the level of the j-th risk assessment factor corresponding to the i-th security risk indicator.

[0122] The second step is to calculate the weight ω corresponding to each security risk indicator in X. i , i∈[1,m], X=(X ij ) m×n , i∈[1,m], j∈[1,n], where m represents the number of security risk indicators in the distribution network cyber-physical system, and n represents the number of security risk assessment factors.

[0123] Specifically, according to the entropy weight method, the weight ω of each security risk indicator can be obtained: i for

[0124]

[0125]

[0126]

[0127] Among them, E p is the information entropy of the p-th information node, Y ij is the level of the jth risk assessment factor corresponding to the normalized i-th security risk indicator, and m is the number of security risk indicators in the distribution network cyber-physical system.

[0128] The third step is to construct an evaluation matrix based on the weights corresponding to each security risk indicator. The evaluation matrix is ​​used to quantitatively describe the risk level of each information node under different security risk indicators.

[0129] Specifically, let Z = (Z pk ) s×m, where p∈[1,s], k∈[1,m], where s represents the number of branches (or nodes) in the active distribution network cyber-physical system, and m represents the number of security risk indicators in these branches (or nodes). pk It represents the security risk level of the p-th branch (or node) for the k-th security risk indicator. Then, Z s×m =[Z1,Z2,…,Z s ] T It is called the evaluation matrix of the active distribution network cyber-physical system.

[0130] The fourth step is to perform weighted normalization on the evaluation matrix.

[0131] Specifically, the evaluation matrix of the cyber-physical system with source distribution network is:

[0132] Z=(Z pk ) s×m ,p∈[1,s],k∈[1,m],ω k represents the weight of the k-th security risk indicator,

[0133] Then H={h pk} is called the weighted normalized matrix of the active distribution network cyber-physical system.

[0134] The fifth step is to calculate the positive ideal solution and the negative ideal solution, where the positive ideal solution and the negative ideal solution represent the security risk index corresponding to the highest level and the security risk index corresponding to the lowest level, respectively.

[0135] Specifically, let H = (h pk ) s×m ,p∈[1,s],k∈[1,m] represents the weighted normalized matrix of the active distribution network cyber-physical system, Indicates the highest level corresponding to the k-th security risk indicator, Indicates the lowest level corresponding to the kth security risk indicator. Then H + and H - They are called the positive ideal solution and negative ideal solution of the system respectively.

[0136] The sixth step is to calculate the distance between each security risk indicator of each information node and the positive ideal solution and the negative ideal solution based on the Euclidean distance formula.

[0137] Specifically, the Euclidean distance from the pth information node to the positive ideal solution in the active distribution network cyber-physical system is calculated according to the following formula:

[0138]

[0139] in, is the highest level corresponding to the kth security risk indicator, hpk is the level corresponding to the kth security risk indicator of the pth information node;

[0140] The Euclidean distance from the pth information node to the negative ideal solution in the active distribution network cyber-physical system is calculated according to the following formula:

[0141]

[0142] Among them, h k - Indicates the lowest level corresponding to the kth security risk indicator, h pk is the level corresponding to the kth security risk indicator of the pth information node.

[0143] In the seventh step, the vulnerability coefficient of each information node is calculated based on the Euclidean distance between each security risk indicator of each information node and the positive ideal solution, the negative ideal solution, and the average value of all security risk indicators of each information node.

[0144] Specifically, the vulnerability coefficient is calculated according to the following formula:

[0145]

[0146] in, represents the average value of all security risk indicators of the p-th information node in the active distribution network cyber-physical system, λ p is the vulnerability factor of the p-th information node.

[0147] S3. Based on the propagation model of infectious diseases, the propagation path and rate of malicious instructions in the distribution network cyber-physical system are simulated, and the posterior probability of other nodes being attacked when the information node is attacked by malicious instructions is calculated based on the simulation results.

[0148] Specifically, the a posteriori probability refers to the probability that other nodes or branches will also be attacked when a certain node or branch in the cyber-physical system of the active distribution network is attacked due to the complex topological structure, diverse communication environment, and high integration of information and physical systems. This will cause security risks to propagate between the information layer and the physical layer through the interaction of data streams.

[0149] In order to quantitatively analyze the probability of the qth node or branch being attacked when the pth node or branch in the distribution network is attacked, an embodiment of the present invention proposes a PP (Posterior Probability) model (PP-SIR) based on the SIR (Susceptible Infected Recovered) infectious disease model.

[0150] like Figure 4 As shown in the figure, α represents the prior probability of a node or branch being infected, which is related to the vulnerability of the active distribution network cyber-physical system; β represents the probability of an infected node or branch being recovered, which is related to the security tolerance of the active distribution network cyber-physical system.

[0151] Let N be the total number of nodes or branches in the active distribution network cyber-physical system, S(t), I(t), and R(t) be the number of nodes or branches in the active distribution network cyber-physical system that are in the susceptible, infected, and recovered states at time t, respectively. The equation can be obtained:

[0152] S(t)+I(t)+R(t)=N

[0153] Let S(t)| t=0 =S0,I(t)| t=0 =I0,R(t)| t=0 =0 According to the infectious disease model, the following equation can be obtained:

[0154]

[0155] Solving the above formula, we can get:

[0156]

[0157] Integrating the above formula, we can get:

[0158]

[0159] Let N be the total number of nodes or branches in the active distribution network cyber-physical system, S(t)| t=0 =S0>0,I(t)| t=0 =I0>0,I0+S0=N,lim t→+∞ S(t)>0. When t→+∞, there is lim t→+∞ R(t)=C, where C is a constant.

[0160] Set lim t→+∞ R(t)=C, we can get, From this we can get So, we get lim t→+∞ R(t)=lim t→+∞ (NS(t)-I(t))=N-S0-I0+C=C.

[0161] From the above analysis, we can see represents the probability of infection of a node or branch when a susceptible node or branch is attacked. as the posterior probability.

[0162] S4: Calculate the damage level of the distribution network cyber-physical system under malicious command attacks.

[0163] Security threats within the cyber-physical systems of active power distribution networks inevitably lead to load loss, voltage fluctuations, and unstable power angles from generators to the cyber-physical systems of active power distribution networks. Therefore, embodiments of the present invention integrate the degree of damage to the cyber-physical systems of active power distribution networks under cyber attacks into a quantitative risk assessment model. According to power safety accident regulations, the load loss ratio is a criterion for classifying power safety accidents, and the use of load loss to measure the extent of damage to physical systems caused by cyber attacks has been widely documented.

[0164] This embodiment of the present invention uses a minimum load loss ratio to quantitatively assess the damage caused by cyber attacks to the cyber-physical systems of active power distribution networks. Based on optimal load reduction, a minimum load loss optimization model is proposed. This model uses mathematical optimization to determine how to implement a reasonable load reduction strategy to minimize load losses in the event of a cyber attack, thereby mitigating damage to the cyber-physical systems of the active power distribution network and ensuring the safe and stable operation of the power system.

[0165] For nodes and branches in the active distribution network cyber-physical system, the threat model considered in the present invention covers the following two attack scenarios.

[0166] Scenario 1: False data is injected to tamper with the node power, causing the node to overload.

[0167] Scenario 2: Modifying the branch circuit breaker opening and closing commands causes the attacked branch to be disconnected.

[0168] Specifically, the minimum load loss ratio of the distribution network cyber-physical system under malicious command attacks is calculated according to the following formula:

[0169]

[0170] Where N is the number of nodes or branches in the active distribution network cyber-physical system, L is the minimum reduction of overload when the i-th node or branch is attacked. tol is the total load of the system under normal conditions.

[0171] More specifically, embodiments of the present invention employ an optimal load shedding algorithm to minimize the load loss of nodes or branches in an active power distribution network cyber-physical system under the influence of malicious commands. The objective function is to find the minimum load loss ratio that satisfies the power flow, node voltage, branch current, and node and branch power balance constraints after the malicious command intrusion. The following examples illustrate the calculation of the minimum load loss of a distribution network node after the malicious command intrusion.

[0172] The objective function and constraints are described as follows:

[0173]

[0174] In the above formula,

[0175] P i and Q i are the active and reactive power flows of the cyber-physical system of the active distribution network,

[0176] Π(i) is the set of nodes connected to node i,

[0177] g ij and b ij are the conductance and susceptance of nodes i and j, respectively,

[0178] U i and U j are the voltage amplitudes at nodes i and j, respectively,

[0179] θ ij is the phase angle difference between nodes i and j,

[0180] U imin and U imax are the lower and upper limits of the node i voltage,

[0181] n is the number of nodes,

[0182] I imax is the upper limit of the current in branch i,

[0183] l is the number of observable branches in the active distribution network cyber-physical system,

[0184] N G 、N D and N L are the collections of generators, loads and branches in the active distribution network cyber-physical system,

[0185] P i represents the balance of input and output power,

[0186] P Gi 、 Respectively represent the generator power, the upper limit and lower limit of the generator power,

[0187] P j 、P dj The actual power and rated power of the node are loaded separately.

[0188] C l 、 are the maximum values ​​of restored nodes and restored nodes on branches respectively.

[0189] S5: Determine the risk value of malicious instructions spreading across space by combining the prior probability, posterior probability and damage degree value.

[0190] Specifically, based on the prior probability, posterior probability and minimum load loss rate, a risk assessment model is constructed to calculate the risk value of malicious instructions spreading across space.

[0191] Specifically, D n×m ≡<C n ,P m > represents an active distribution network cyber-physical system, where C n ={c1,c2,...,c n} represents the number of information nodes, each c i The software in the power distribution network system consists of various terminals, system software and application programs. m ={p1,p2,...,p m} represents the number of physical nodes, each p j The physical distribution system consists of various data transmission units, remote terminal units, transformer terminal units, optical network units, circuit breakers, generators, branches and busbars.

[0192] In S5, the risk value of malicious instruction propagation across space is determined according to the following formula:

[0193]

[0194] in,

[0195] P(A i ) represents the probability of the i-th information node being attacked in the power distribution (called prior probability), P(B j ∣A i ) represents the probability that the jth physical node is attacked when the i-th information node is attacked (called the posterior probability), L j It represents the minimum load loss rate after the jth physical node is destroyed.

[0196] In this embodiment, a probability model for information layer attacks based on the cumulative distribution function is first proposed. Secondly, when the information layer is invaded by malicious instructions, the probability of the physical system being attacked is calculated based on an infectious disease model. Finally, an optimal load reduction algorithm is used to calculate the minimum load loss rate after the physical system is attacked. A quantitative risk assessment model for the distribution network cyber-physical system is constructed from the perspectives of prior probability, posterior probability, and minimum load loss rate. This allows for a more comprehensive and accurate quantitative assessment of the risk of malicious instructions propagating across space.

[0197] Embodiment 2 of the present invention provides a system for quantitatively analyzing the risk of malicious instruction propagation across space, which runs the method for quantitatively analyzing the risk of malicious instruction propagation across space as described in embodiment 1. The system includes:

[0198] A model module is established to establish a characterization model of the information-physical system of the active distribution network. The physical layer devices are represented by the physical network, and the information communication layer is represented by the information network. The coupling relationship between the information communication layer and the physical device layer is represented by the interaction between the physical nodes in the physical network and the information nodes in the information network.

[0199] The first calculation module is used to calculate the prior probability of each information node being attacked by a malicious instruction according to the defense strength and attack strength of the information node.

[0200] The second calculation module is used to simulate the propagation path and rate of malicious instructions in the distribution network information-physical system based on the propagation model of infectious diseases, and calculate the posterior probability of the physical node being attacked when the information node is attacked by malicious instructions based on the simulation results.

[0201] The third calculation module is used to calculate the damage level of the distribution network information-physical system under malicious instruction attacks.

[0202] The determination module is used to determine the risk value of malicious instructions spreading across space by combining the prior probability, the posterior probability and the damage degree value.

[0203] Embodiment 3 of the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded into the processor, the method for analyzing the risk of malicious instruction propagation across space as described in embodiment 1 is implemented.

[0204] Embodiment 4 of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the method for analyzing the risk of malicious instruction propagation across space according to embodiment 1.

[0205] Compared with the prior art, the beneficial effects of the present invention include at least:

[0206] Compared with the existing information-physical system architecture of the distribution network, the present invention deeply integrates the power-physical network and the information-communication network to form a closely related integrated system, which helps to achieve more efficient information-physical interaction, improve the system response speed and control accuracy, and realize the distribution of hybrid computing through the interaction of information flow and energy flow, so that the system can respond in real time and adapt to various operating conditions, thereby improving the system's adaptability and stability.

[0207] The model proposed in this paper considers the bidirectional coupling between cyber and physical networks in smart grids. By introducing a characterization model for heterogeneous network structures, it can more accurately describe the complex topological characteristics of the system and the dynamic behavior of information propagation. Furthermore, the present invention considers the interactive influence of information flow and energy flow in cyber-physical systems, describing this coupling through a correlation matrix, making the assessment more comprehensive and accurate. The subsequent direct quantification of risk values ​​makes risk not only perceptible but also measurable. This is more accurate than qualitative assessments and facilitates the development of targeted defense strategies.

[0208] Based on the propagation patterns of infectious diseases, this paper achieves precise modeling for quantitative risk assessment of cyber-physical systems in active power distribution networks. This theory not only effectively simulates the propagation paths and rates of malicious commands within cyber-physical networks, but also quantifies risk propagation thresholds through a Bayesian risk assessment model to assess system stability and security. This approach enables the present invention to predict the propagation thresholds of security risks in heterogeneous, partially coupled networks, thereby identifying and paving the way for subsequent response to potential risk outbreaks. This provides powerful decision-making and response strategies for system administrators and security experts.

[0209] It is particularly important to emphasize that the present invention is not limited to the construction of theoretical models, but also covers the wide applicability and practicality of this model in practical applications. In modern power systems, smart grids have become an important means to improve energy utilization efficiency and optimize power supply management. However, the information security threats they face are becoming increasingly severe. The cross-space propagation model of malicious instructions established by the present invention not only reveals the propagation mechanism of malicious instructions in active distribution networks, but also takes into account the complex coupling relationship between the information layer and the physical layer of the cyber-physical system, providing a model basis for the subsequent identification and protection of malicious instructions. The security risk propagation threshold proposed by the present invention can not only be used as a key indicator for predicting risk outbreaks, but also as a standard for evaluating the security of network topology. A high security risk propagation threshold means that the system is more secure, because security risks are more difficult to propagate within the system, which provides an important guarantee for the safe operation and reliability of smart grids.

[0210] The application prospects and technical scalability of this invention are also worthy of attention. The proposed quantitative risk assessment model for malicious command propagation is not only applicable to distribution networks, but can also be extended to the security analysis of other distributed cyber-physical systems, such as industrial control systems and intelligent transportation systems. In the future, with the continuous development and popularization of smart grid technology, the security management of power cyber-physical systems will face new challenges and opportunities. This invention provides an innovative methodology and technical foundation for addressing these challenges, injecting new vitality and possibilities into the future development of smart grid security.

[0211] In summary, this invention not only theoretically overcomes the limitations of traditional quantitative risk assessment models for malicious command propagation, but also demonstrates its significant security management value and technical advantages in practical applications. By deeply analyzing the characteristics and security requirements of smart grids, this invention provides a new perspective and solution for the security management of power cyber-physical systems. This method, with its significant innovation and practicality, is expected to have far-reaching impact and application value in the field of smart grid security.

[0212] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0213] The present disclosure may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0214] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination thereof. As used herein, a computer-readable storage medium is not to be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through an electrical wire.

[0215] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0216] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" language or similar programming languages. Computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., utilizing an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be personalized by utilizing the state information of the computer-readable program instructions. The electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0217] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for analyzing the risk of malicious command propagation across space, applied to the cyber-physical system of active power distribution network, characterized by: Includes the following: S1: Establish a characterization model for the cyber-physical system of the active distribution network. The physical device layer is represented by the physical network, and the information communication layer is represented by the information network. The coupling relationship between the information communication layer and the physical device layer is represented by the interaction between the physical nodes in the physical network and the information nodes in the information network. S2: Calculate the prior probability of each information node being attacked by malicious instructions based on the defense strength and attack strength of the information node; S3: Based on the propagation model of infectious diseases, the propagation path and rate of malicious instructions in the distribution network cyber-physical system are simulated. Based on the simulation results, the posterior probability of other nodes being attacked when an information node is attacked by a malicious instruction is calculated; S4: Calculate the damage level of the distribution network cyber-physical system under malicious command attacks; S5: Determine the risk value of malicious instructions spreading across space by combining the prior probability, posterior probability, and damage degree value; S2 includes: based on the defense strength and attack strength of the information node, using the cumulative distribution function to represent the influence of the vulnerability coefficient in the active distribution network cyber-physical system on the prior probability, and constructing a probability model for each node in the information layer to be attacked by malicious instructions; The prior probability of each information node being attacked by malicious instructions is calculated according to the following formula: Among them, P p is the prior probability that the pth information node is attacked by malicious instructions, λ p is the vulnerability coefficient of the pth information node, k is the vulnerability coefficient, x p is the defense strength of the p-th information node, y p is the attack strength of the p-th information node, when P p =1, it means that the pth information node cannot resist the attack of malicious instructions; In S3, based on the propagation model of infectious diseases, the propagation path and rate of malicious instructions in the distribution network cyber-physical system are simulated. Based on the simulation results, the posterior probability of other nodes being attacked when an information node is attacked by malicious instructions is calculated, including: Based on the spread model of infectious diseases, the following formula is obtained: Where, S(t)| t=0 =S0, S(t), I(t) and R(t) are the number of nodes in the cyber-physical system of the distribution network that are in the susceptible, infected and recovered states at time t, α is the prior probability of an information node being infected, β is the probability of an infected node being recovered, The posterior probability that other nodes will be attacked when the information node is attacked by malicious instructions; In S4, calculating the damage degree value of the active distribution network cyber-physical system under the malicious command attack includes: calculating the minimum load loss rate of the active distribution network cyber-physical system under the malicious command attack according to the distribution network flow, voltage, current, node and branch power according to the following formula: Among them, P i and Q i are the active and reactive power flows of the cyber-physical system of the active distribution network, Π(i) is the set of nodes connected to node i, and g ij and b ij are the conductance and susceptance of nodes i and j, respectively, U i and U j are the voltage amplitudes of nodes i and j, θ ij is the phase angle difference between nodes i and j, U imin and U imax are the lower and upper limits of the voltage at node i, n is the number of nodes, I imax is the current upper limit of branch i, l is the number of observable branches in the active distribution network cyber-physical system, N G 、N D and N L are the collection of generators, loads and branches in the active distribution network cyber-physical system, P i Indicates the balance of input and output power, P Gi 、 Respectively represent the generator power, the upper limit and lower limit of the generator power, P j 、P dj are the actual power and rated power of the node load, C l 、 The number of nodes restored and the maximum number of nodes restored for this branch are: In S5, the risk value of malicious instructions propagating across space is determined by combining the prior probability, the posterior probability, and the damage degree value, including: The risk value of malicious instructions spreading across space is determined according to the following formula: Among them, P(A i ) is the prior probability of the i-th information node being attacked in the power distribution; P(B j ∣A i ) is the posterior probability of the jth physical node being attacked when the i-th information node is attacked; L j It represents the minimum load loss rate after the j-th physical node is attacked.

2. The method for analyzing the risk of malicious instruction propagation across space according to claim 1, characterized in that: In S1, the physical network is denoted as G p =<V p ,E p >, where V p is the set of physical nodes, E p It is a set of physical network edges. Physical nodes include power plants, substations, and converter stations. The transmission lines between physical sites serve as the edges of the physical network. The information network is denoted as G c =<V c ,E c >, where V c is the information node set, E c It is a collection of information network edges. Information nodes include servers, computing devices, and data acquisition devices. The communication lines between information nodes serve as the edges of the information network.

3. The method for analyzing the risk of malicious instruction propagation across space according to claim 1 or 2, characterized in that: In S1, the interaction between the physical device layer and the control center takes place at the information communication layer. The information communication layer is used to collect, transmit and process power data of the distribution network and control the physical sites of the physical device layer.

4. The method for analyzing the risk of malicious instruction propagation across space according to claim 3, characterized in that: In S1, the active distribution network cyber-physical system is abstracted as a two-layer network directed unweighted graph, which includes an information network directed unweighted graph and a physical network directed unweighted graph. According to the directionality and dependency relationship between the links of the information layer and the physical layer, the links between the information nodes and the physical nodes are abstracted as the edges of the directed unweighted graph of the information network and the directed unweighted graph of the physical network.

5. The method for analyzing the risk of malicious instruction propagation across space according to claim 1, characterized in that: Calculate the vulnerability coefficient λ of the p-th information node based on at least one of the following security risk indicators: p : Information layer network security indicators, physical layer network security indicators and encryption indicators in distribution network cyber-physical systems.

6. The method for analyzing the risk of malicious instruction propagation across space according to claim 5, characterized in that: The vulnerability coefficient of an information node is calculated based on various security risk indicators, including: Normalize each security risk indicator and calculate the corresponding weight of each security risk indicator; Combined with the corresponding weights of each security risk indicator, an evaluation matrix is ​​constructed. The evaluation matrix is ​​used to quantitatively describe the risk level of each information node under different security risk indicators; Perform weighted normalization on the evaluation matrix, and calculate the positive ideal solution and negative ideal solution based on the weighted normalized matrix. The positive ideal solution represents the security risk index corresponding to the highest level, and the negative ideal solution represents the security risk index corresponding to the lowest level. Calculate the Euclidean distance between each security risk indicator of each information node and the positive ideal solution and the negative ideal solution; The vulnerability coefficient of each information node is calculated based on the Euclidean distance between each security risk indicator of each information node and the positive ideal solution, the negative ideal solution, and the average value of all security risk indicators of each information node.

7. A system for analyzing the risk of malicious instruction cross-space propagation using the method for analyzing the risk of malicious instruction cross-space propagation according to any one of claims 1 to 6, characterized in that: include: Establish a model module for establishing a characterization model of the cyber-physical system of the active distribution network, respectively characterizing the physical layer devices through the physical network and the information communication layer through the information network, and characterizing the coupling relationship between the information communication layer and the physical device layer through the interaction between the physical nodes in the physical network and the information nodes in the information network; A first calculation module is used to calculate the prior probability of each information node being attacked by malicious instructions based on the defense strength and attack strength of the information node; The second calculation module is used to simulate the propagation path and rate of malicious instructions in the distribution network cyber-physical system based on the propagation model of infectious diseases, and calculate the posterior probability of other nodes being attacked when the information node is attacked by the malicious instruction based on the simulation results; The third calculation module is used to calculate the damage degree value of the distribution network cyber-physical system under the attack of malicious instructions; The determination module is used to determine the risk value of malicious instructions spreading across space by combining the prior probability, the posterior probability and the damage degree value.

8. An electronic device comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is used to operate according to the instruction to execute the steps of the method for analyzing the risk of malicious instruction propagation across space according to any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method for analyzing the risk of cross-space propagation of malicious instructions as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Risk quantification method, device and system of electric power information physical system

    CN118199960A

  • A Method for Detecting Vulnerability of Large-scale Power Grid Based On Complex Network

    AU2020103195A4

  • Security risk assessment method for risk cascade of power distribution network under network attack

    CN115361150A