Method for Detecting Power System Network Security Behaviors Based on Deep Learning Dynamic Graph Neural Network Technology
By applying a dynamic graph neural network and autoencoder model based on deep learning in the power system, the problem that traditional static graph neural networks are difficult to detect the network security behavior of the power system is solved, and efficient and fast network security behavior detection is achieved.
Patent Information
- Application Number
- CN202510323919.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-19
AI Technical Summary
Traditional static graph neural networks have difficulty capturing dynamic data and rapidly changing patterns when detecting network security behavior of power systems, resulting in inefficiency and difficulty in detecting advanced persistent threats.
Using a dynamic graph neural network (DGNN) and an autoencoder model based on deep learning, the model is trained to detect the network security behavior of the power system by constructing a graph attention embedding module, a node dynamic information memory memory module, a node nearest neighbor relationship module and a node behavior scoring module.
It realizes effective detection of network security behavior of power system, can quickly adapt to data changes, reduce resource consumption, support unsupervised learning, and does not require manual tags.
Smart Images

Figure CN119854043B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of deep learning dynamic graph neural network applications, and particularly to a method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology. Background Art
[0002] Network security behaviors usually involve monitoring and analyzing data such as network traffic, user activities, and system logs. The data volume is large, and traditional machine learning detection methods have high requirements for server resources. Moreover, network behavior threats often evolve rapidly, and traditional analysis and detection methods are difficult to capture rapidly changing patterns. Advanced Persistent Threats (APT) attacks usually go through multiple stages, and the behaviors at each stage are relatively concealed and difficult to detect. In the power system network, due to the uninterrupted operation of the production system, the network access between devices often has no time pattern, and the access between some devices is very frequent, while the access between some devices is very rare. These characteristics often make some traditional detection algorithms inefficient.
[0003] Traditional static graph neural networks assume a model with a fixed graph structure during training and inference. When facing dynamic or time-evolving data, they have great limitations and cannot meet the requirements of power system network security behavior detection.
[0004] Therefore, in view of the deficiencies of the prior art, it is very necessary to provide a method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology to overcome the deficiencies of the prior art. Summary of the Invention
[0005] The purpose of the present invention is to avoid the deficiencies of the prior art and provide a method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology. After training the model, it can effectively detect power system network security behaviors.
[0006] The purpose of the present invention is achieved through the following technical measures.
[0007] Provide a method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology, which is carried out through the following steps:
[0008] S1, construct a dynamic graph model and an autoencoder model;
[0009] S2, construct a pre-training dataset and a validation dataset;
[0010] S3, train the model, including:
[0011] First, use the edge relationship feature data between two device nodes to train a dynamic graph model; use the positive and negative sample comparison method to simulate negative samples, and use a binary classification algorithm to calculate the estimated value of the edge relationship feature of each sample; cache the estimated value results of positive samples in memory;
[0012] According to all source device IPs within a time period, read the binary classification estimated values of each source device IP for all device nodes in the global scope from memory as training data to train an autoencoder model;
[0013] S4, save the trained dynamic graph model and autoencoder model;
[0014] S5, use the dynamic graph model and autoencoder model to detect real-time data, and use the detection result of the autoencoder model as the detection result of power system network security behavior.
[0015] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, the dynamic graph model constructed in S1 is provided with a graph attention embedding module, a node dynamic information memory module, a node nearest neighbor relationship module, and a node behavior scoring module;
[0016] The attention embedding module is a graph attention mechanism implemented by introducing a TransformerConv layer based on the Transformer architecture, enabling the dynamic graph model to adaptively focus on important neighbor nodes and edge information; and encoding the difference between the node's last update time and the current interaction time, and combining it with the message feature, enabling the dynamic graph model to capture the time evolution pattern;
[0017] The node dynamic information memory module realizes a dynamic memory mechanism by introducing a TGNMemory component, which is used to determine whether to retain or update the historical state of the node, enabling the dynamic graph model to consider long-term dependencies when making decisions; when nodes in the dynamic graph interact (edges), generate messages and aggregate historical messages to update the memory state of the node;
[0018] The node nearest neighbor relationship module is responsible for collecting and maintaining the connected neighbor nodes of each node, and recording the time information at the time of connection to provide more accurate context information; and when comparing positive and negative samples, judging whether it is a negative sample according to the connection information;
[0019] The node behavior scoring module scores the edge relationship using a binary classifier model according to the training data to identify whether the access between devices is an abnormal access.
[0020] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, S2 includes: preprocessing historical data, summarizing to obtain common service ports, and using them as global features of device nodes; statistically segmenting historical data by hour to obtain the access relationships between two device nodes within each time period.
[0021] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, S2 specifically includes the following steps:
[0022] S21, collect the original communication pair data within a certain time period as historical data, summarize it by hour and port, and obtain the hourly port summary data. The hourly port summary data is constructed in the format of hour segment, source device IP, target device IP, port, and access times;
[0023] S22, based on the hourly port summary data, obtain the global static features of all device nodes and save them as the node_feature.csv file;
[0024] S23, in the hourly port summary data, divide it by each hour, and extract the access situation between two device nodes as the edge relationship feature of the dynamic graph;
[0025] S24, divide the processed node relationship feature file into a training set, a validation set, and a test set in chronological order, and store them in the train, eval, and test directories respectively.
[0026] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, S22 specifically obtains the features of the number of devices accessed by all devices, the number of devices being accessed, as well as the features of common ports, well-known ports, registered ports, and dynamic or private ports in the entire power network system based on the hourly port summary data.
[0027] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, the specific process of training the model in S3 is as follows:
[0028] S31, model initialization, including initializing the dynamic graph model and initializing the autoencoder model;
[0029] Among them, initializing the dynamic graph model includes initializing the graph attention embedding module, initializing the node dynamic information memory module, initializing the node nearest neighbor relationship module, and setting the training parameters of the initial dynamic graph model;
[0030] Initializing the autoencoder model includes setting the parameters of the encoder module and the decoder module, and setting the training parameters of the autoencoder model;
[0031] S32, Initialize the global node feature data;
[0032] S33, Read the feature file by time period to train the dynamic graph model, specifically including:
[0033] S331, Read the node relationship feature file in chronological order, and the read node relationship feature file is defined as the current batch of data;
[0034] S332, Calculate the time step value of the current batch of data;
[0035] S333, According to the nodes in the current batch of data, read their nearest neighbor nodes from the node nearest neighbor relationship module, and jointly form the nodes of the current batch of data, that is, the local graph nodes;
[0036] S334, According to the local graph nodes and the time step value, read the nearest node state from the node dynamic information memory module;
[0037] S335, According to the local graph nodes, read the node static features from the global node feature data cache, and merge the relationship features with the current nodes to form new node relationship combination information features; that is:
[0038] Combined feature information = source device node static feature + target device node static feature + relationship feature of the two nodes;
[0039] S336, Update the graph attention embedding layer according to the memory state of the local graph nodes and the node relationship combination information features;
[0040] S337, Calculate the loss rate using the positive and negative sample contrast method; specific calculation method:
[0041] Count all the nodes in a batch of data. According to these nodes, in the node nearest neighbor relationship module, obtain all the neighbor nodes and randomly generated negative sample nodes of the current batch of data; for the positive and negative samples, use the binary classifier model to predict the predicted values between 0 and 1 respectively. Then, according to the positive sample true value of 1 and the negative sample true value of 0, use the torch.nn.BCEWithLogitsLoss() loss function to separately calculate the loss of the positive sample and the loss of the negative sample, and then add them up to get the loss of the sample;
[0042] S338, Update the node dynamic information memory module according to the local graph node data;
[0043] S339, Update the node nearest neighbor relationship module according to the local graph node data;
[0044] S34, Train the autoencoder model, specifically including:
[0045] Obtain the source device nodes where access events occurred at the current time step, obtain the binary classification prediction score data of the edges between these nodes and all other nodes within a certain time step range, and perform training on the autoencoder model;
[0046] When training the dynamic graph model using edge feature data, after each time step in the training process of the dynamic graph model is completed, use the dynamic graph model to perform binary classification prediction on the edge features included in that time step and update the results to the cache; obtain the source device nodes that have changed at this time step from the edge data, read the score data of this node for the global node set from the cache according to the changed source device nodes, and construct the feature data for training the autoencoder to train the autoencoder; the input feature data is compressed into a low-dimensional representation (encoded) by the encoder and then reconstructed into the original input through the decoder; use the torch.nn.MSELoss() mean squared error loss function to calculate the reconstruction error between the original data and the reconstructed data;
[0047] S35. Cycle training to generate an optimal model;
[0048] Set the number of learning steps; after each step of training is completed, use the validation data set to verify the average loss rate and average accuracy of the model for the node relationship feature data of the validation data; when the average loss rate is better than the previously generated model, update and generate a new model file.
[0049] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology above, add a cache for the global node set to each node to cache the time step and binary classification prediction scores of the edges of this node with other nodes.
[0050] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology above, it further includes: online learning of node relationship changes and updating the model. Specifically, when the system determines that the access between network devices is relatively frequent and conforms to normal access characteristics, update this access relationship to the model, update the node dynamic information memory module and the node nearest neighbor relationship module, and in subsequent detections, recognize the access of this network device as normal access.
[0051] Preferably, for the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology above, it further includes: discovering node changes and retraining the model. Specifically, when there is an increase in nodes, re-summarize the data by hour and port, collect the data for the latest time period, retrain and generate a model file, and overwrite the original model file.
[0052] The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology of the present invention discloses a system for detecting network security behavior by establishing a deep learning dynamic graph neural network model and an autoencoder model. According to core modules such as a graph attention embedding module, a node dynamic information memory module, a node nearest neighbor relationship module, and a node behavior scoring module, a DGNN model is constructed, and an autoencoder model is set to detect node network behavior. By collecting historical communication pair data in the power system, preprocessing is performed to extract device node features and relationship features between devices in each time period. After the trained model is used for data detection, network behavior can be effectively detected. The method of the present invention has a fast training speed and low resource consumption; it can continuously monitor changes in device nodes and can quickly update the model; the present invention is an unsupervised learning and does not require manual labeling of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The present invention is further described with reference to the accompanying drawings, but the content in the drawings does not constitute any limitation to the present invention.
[0054] Figure 1 It is a schematic diagram of a method for detecting power system network security behavior based on deep learning dynamic graph neural network technology of the present invention.
[0055] Figure 2 It is a table of "hourly port summary data" in Embodiment 1 of the present invention.
[0056] Figure 3 It is a partial result of the "global static features of all device nodes" obtained in step S22 in Embodiment 1 of the present invention.
[0057] Figure 4 It is the result of the edge relationship features of the dynamic graph obtained in step S23 in Embodiment 1 of the present invention.
[0058] Figure 5 It is a flowchart of training the model of the present invention.
[0059] Figure 6 It is the result of reading the node relationship feature file in chronological order in Embodiment 2 of the present invention.
[0060] Figure 7 It is the result of the edge feature score at one time step in Embodiment 2 of the present invention.
[0061] Figure 8 It is the result of statistically calculating the average loss rate up to the previous period samples in Embodiment 2 of the present invention.
[0062] Figure 9 It is the result of statistically calculating the average accuracy of the validation set data in Embodiment 2 of the present invention.
[0063] Figure 10 It is the average accuracy result of each training obtained after 20 times of cyclic training in Embodiment 2 of the present invention.
[0064] Figure 11 It is the result of detecting the abnormal security behavior of nodes by the autoencoder model in Embodiment 2 of the present invention. Detailed implementation manners
[0065] The present invention will be further described in conjunction with the following embodiments.
[0066] Embodiment 1
[0067] A method for detecting the network security behavior of a power system based on the deep learning dynamic graph neural network technology is carried out through the following steps:
[0068] S1. Construct a dynamic graph model and an autoencoder model;
[0069] S2. Construct a pre-training data set and a validation data set;
[0070] S3. Train the models, including:
[0071] First, use the edge relationship feature data between two device nodes to train the dynamic graph model; simulate negative samples using the positive and negative sample comparison method, and calculate the estimated value of the edge relationship feature of each sample using the binary classification algorithm; cache the estimated value results of the positive samples in the memory;
[0072] According to all source device IPs within a time period, read the binary classification estimated values of each source device IP for all device nodes in the whole network from the memory as training data to train the autoencoder model;
[0073] S4. Save the trained dynamic graph model and autoencoder model;
[0074] S5. Use the dynamic graph model and the autoencoder model to detect real-time data, and use the result detected by the autoencoder model as the detection result of the network security behavior of the power system.
[0075] Dynamic Graph Neural Networks (DGNN) is a technical direction in the field of deep learning, focusing on processing graph-structured data that changes over time. It not only meets the needs of processing dynamic graph data in the real world, but also shows great potential in multiple fields. AutoEncoder (AE) is a deep learning neural network and an unsupervised learning model that can identify potential anomalies by comparing the differences between input data and its reconstructed output.
[0076] Specifically, the dynamic graph model of the S1 structure is provided with a graph attention embedding module, a node dynamic information memory module, a node nearest neighbor relationship module, and a node behavior scoring module.
[0077] The attention embedding module is a graph attention mechanism implemented by introducing the TransformerConv layer based on the Transformer architecture, enabling the dynamic graph model to adaptively focus on important neighbor node and edge information; and encoding the difference between the last update time of the node and the current interaction time, and combining it with the message features, enabling the dynamic graph model to capture the time evolution pattern.
[0078] The node dynamic information memory module realizes the dynamic memory mechanism by introducing the TGNMemory component, which is used to determine whether to retain or update the historical state of the node, enabling the dynamic graph model to consider long-term dependencies when making decisions. When nodes in the dynamic graph interact (edges), messages are generated and historical messages are aggregated to update the memory state of the node.
[0079] The node nearest neighbor relationship module is responsible for collecting and maintaining the connected neighbor nodes of each node and recording the time information at the time of connection to provide more accurate context information. And when comparing positive and negative samples, it determines whether it is a negative sample according to the connection information.
[0080] The node behavior scoring module scores the edge relationship using a binary classifier model based on the training data to identify whether the access between devices is an abnormal access.
[0081] The method for detecting power system network security behavior based on the deep learning dynamic graph neural network technology of the present invention, S2 includes: preprocessing historical data, and inducing common service ports as the global features of device nodes. According to the historical data, it is statistically segmented by hour to obtain the access relationship between two device nodes within each time period (the number of access ports, the total number of accesses, the two ports with the highest number of accesses, etc.) within each time period, that is, the (edge) relationship features between the nodes of the dynamic graph.
[0082] S2 specifically includes the following steps:
[0083] S21, collect the original communication pair data within a certain time period (such as 13 weeks, 3 months) as historical data. The data volume is relatively large, and it is summarized by hour and port to obtain the hourly port summary data. After summarization, the data volume is significantly reduced compared with the original data. The "hourly port summary data" is constructed in the format of hour segment, source device IP, target device IP, port, and access times.
[0084] Such as Figure 2Shown below is an example of "hourly port summary data". In the first row of data, it indicates that within the one-hour period from 5:00:00 to 5:59:59 on that day, the number of times device A (source device IP = 10.146.145.70) accessed the service port (8080) of device B (destination device IP = 192.168.131.30) was 80 times.
[0085] S22. According to the hourly port summary data, obtain the global static features of all device nodes and save them as the node_feature.csv file.
[0086] Specifically, based on the hourly port summary data, S22 obtains the features of the number of devices accessed by all devices, the number of devices being accessed, as well as the features of commonly used ports, well-known ports, registered ports, dynamic or private ports in the entire power network system. These features are the global static features of all device nodes.
[0087] It can be seen from the hourly port summary data that:
[0088] 1) A certain device node has accessed multiple other target device nodes. For example, how many target devices has device A (source device IP = 10.146.145.70) accessed, and obtain the feature "number of devices accessed" of this device.
[0089] 2) How many other device nodes have accessed a certain device node. For example, how many device nodes have accessed device B (destination device IP = 192.168.131.30), and obtain the feature "number of devices being accessed" of this device.
[0090] 3) The target device node provides several port services, and it can be summarized that ports 80, 81, 161, 162, 443, 514, 1521, 3306, 6379, 8000, 8080, 8081, 8082, 8848, 8876, 10081 are commonly used ports in the entire power network system. These commonly used ports are used as the features of this device, where 0 indicates that the port does not provide services, and 1 indicates that the port provides services. In addition to using commonly used ports as device features, 3 other features are added, namely well-known ports (0 to 1023), registered ports (1024 to 49151), and dynamic or private ports (49152 to 65535). These 3 features are represented by non-negative integers, indicating how many ports in this port segment provide external services.
[0091] Calculate the global static features of all device nodes in the above manner and save them as the node_feature.csv file.
[0092] Such as Figure 3The data shown in the first row indicates that a certain device (IP = 192.168.113.11) will access 8 other device nodes, be accessed by 6 other device nodes, the well-known port segment exposes one port, the registered port segment exposes 4 ports, and the dynamic or private port segment exposes 2 ports. And external services are provided on ports 80, 443, 8000, 8080, 8081, and 8082.
[0093] S23. In the hourly port summary data, divide by each hour and extract the access situation between two device nodes as the edge relationship feature of the dynamic graph. For example, Figure 4 As shown in the first row of data, it indicates that within the one-hour time period from 5:00:00 to 5:59:59 on that day, the total number of times device A (source device IP = 10.146.145.70) accesses device B (target device IP = 192.168.131.30) is 104 times, and the total number of ports is 4. Among them, the most frequently accessed port is 8080, with 80 access times, and the second most frequently accessed port is 8082, with 12 access times.
[0094] S24. Divide the processed relationship feature file between nodes into a training set, a validation set, and a test set in chronological order, and store them in the three directories train, eval, and test respectively.
[0095] For example, the processed relationship feature file between nodes can be divided into a training set (10 weeks), a validation set (2 weeks), and a test set (1 week) in chronological order. Store them in the three directories train, eval, and test respectively. Under each dataset directory, divide the date directory by daily data, such as the 20240801 directory. There are 24-hour csv files under each date directory. The structure is as follows:
[0096] / dataset
[0097] |--node_feature.csv (node feature file)
[0098] | / train
[0099] | / 20240801
[0100] |--hour1.csv (relationship feature file of nodes per hour)
[0101] |-- .......
[0102] | / 20240802
[0103] | / eval ......
[0104] | / test
[0105] ...... 。
[0106] The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology of the present invention, the specific process of S3 training the model is as Figure 5 shown below:
[0107] S31, model initialization, including initializing the dynamic graph model and initializing the autoencoder model;
[0108] Among them, initializing the dynamic graph model includes initializing the graph attention embedding module, initializing the node dynamic information memory module, initializing the node nearest neighbor relationship module, and setting the training parameters of the initial dynamic graph model.
[0109] Initializing the autoencoder model includes setting the parameters of the encoder module and the decoder module, and setting the training parameters of the autoencoder model.
[0110] S32, initialize the global node feature data. Through data preprocessing, the global node feature data is obtained as a global cache for convenient subsequent program calls. The node features are mainly common port features, whether to use the common port to provide external services.
[0111] S33, read the feature file by time period to train the dynamic graph model, specifically including:
[0112] S331, read the node relationship feature file in chronological order, and the read node relationship feature file is named as the current batch of data.
[0113] S332, calculate the time step value of the current batch of data. The calculation method of the time step value: for example, set 0:00 on August 1, 2024 as 1, and for each subsequent hour, the value increases by 1.
[0114] S333, according to the nodes in the current batch of data, read their nearest adjacent nodes from the node nearest neighbor relationship module, and jointly form the nodes in the current batch of data, that is, the local graph nodes.
[0115] S334, according to the local graph nodes and the time step value, read the nearest node status from the node dynamic information memory module.
[0116] S335, according to the local graph nodes, read the node static features from the global node feature data cache, and merge the relationship feature between the current node and the new node relationship combination information feature; that is:
[0117] Combined feature information = source device node static feature + target device node static feature + relationship feature between two nodes.
[0118] S336. Update the graph attention embedding layer according to the memory state of local graph nodes and the information feature of node relationship combination.
[0119] S337. Calculate the loss rate using the positive and negative sample contrast method; specific calculation method:
[0120] Count all the nodes in a batch of data. According to these nodes, in the node nearest neighbor relationship module, obtain all the neighbor nodes and randomly generated negative sample nodes of the current batch of data; for the positive and negative samples, use the binary classifier model to predict the predicted values between 0 and 1 respectively. Then, with the true value of the positive sample being 1 and the true value of the negative sample being 0, use the torch.nn.BCEWithLogitsLoss() loss function to separately calculate the losses of the positive and negative samples, and then add them up to obtain the loss of the samples.
[0121] S338. Update the node dynamic information memory module according to the local graph node data.
[0122] S339. Update the node nearest neighbor relationship module according to the local graph node data.
[0123] S34. Train the autoencoder model, specifically including:
[0124] Obtain the source device nodes that have access events at the current time step, and obtain the binary classification prediction score data of the edge features between these nodes and all other nodes within a certain time step range for training the autoencoder model.
[0125] For the training of the autoencoder model, it is necessary to obtain the source device nodes that have access events at the current time step, and obtain the binary classification prediction score data of the edge features between these nodes and all other nodes within a certain time step range. For example, set 48 time step ranges (the time step range can be set differently according to the actual situation). In the program, add a cache for each node to the global node set to cache the time step and the binary classification prediction score of the edge features of this node to other nodes.
[0126] When training the dynamic graph model using the edge feature data, after each time step of the dynamic graph model training is completed, use the dynamic graph model to perform binary classification prediction on the edge features included in this time step and update the results to the cache; obtain the source device nodes that have changed from the edge data at this time step, read the score data of this node to the global node set from the cache according to the changed source device nodes, and construct the feature data for training the autoencoder to train the autoencoder; the input feature data is compressed into a low-dimensional representation (encoding) by the encoder, and then the original input is reconstructed through the decoder; use the torch.nn.MSELoss() mean squared error loss function to calculate the reconstruction error between the original data and the reconstructed data.
[0127] S35. Generate the optimal model through cyclic training.
[0128] Set the number of learning steps, such as setting it to 20 steps. After each step of training is completed, use the validation dataset to verify the average loss rate and average accuracy of the model for the feature data of each node relationship in the validation data. When the average loss rate is better than the previously generated model, update and generate a new model file.
[0129] The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology of the present invention discloses a system for detecting network security behavior by establishing a deep learning dynamic graph neural network model and an autoencoder model. According to core modules such as a graph attention embedding module, a node dynamic information memory module, a node nearest neighbor relationship module, and a node behavior scoring module, a DGNN model is constructed, and an autoencoder model is set to detect node network behavior. By collecting historical communication pair data in the power system, preprocessing is performed to extract device node features and relationship features between devices in each time period. The trained model is used for data detection, which can effectively detect network behavior. The method of the present invention has a fast training speed and low resource consumption; it can continuously monitor changes in device nodes and can quickly update the model; the present invention is an unsupervised learning and does not require manual labeling of data.
[0130] Embodiment 2
[0131] Taking a specific application example, the method for detecting power system network security behavior based on deep learning dynamic graph neural network technology in Embodiment 1 is used for power system network security behavior detection.
[0132] In this example, the data preprocessing is specifically as follows: Collect the original communication pair data, generate the global static features of all 648 nodes by summarizing and extracting features, and generate a relationship feature file between nodes. It is divided into a training set, a validation set, and a test set in chronological order. They are respectively stored in three directories: train, eval, and test. Under each dataset directory, the date directory is divided according to the daily data, and there are 24-hour csv files under each date directory. The structure is as follows:
[0133] / dataset
[0134] |--node_feature.csv (node feature file)
[0135] | / train
[0136] | / 20240801
[0137] |--hour1.csv (node relationship feature file for each hour)
[0138] |--.......
[0139] | / 20240802
[0140] | / eval ......
[0141] | / test
[0142] ...... 。
[0143] In this embodiment, the training model is specifically as follows:
[0144] 1) Read the node relationship feature file in chronological order.
[0145] Read the file for each hour segment, and calculate the time step value according to the time corresponding to the file. The result is as Figure 6 shown.
[0146] 2) After training all the feature files (i.e., after each time step is completed), calculate the binary classification prediction score for each edge feature. As Figure 7 shown (this figure is only for showing the edge feature score situation of this time step).
[0147] Update the score of the source device node that changes at this time step to the cache, and train the autoencoder model with the score data of itself and the entire node set obtained from the cache according to the changed source device node.
[0148] 3) After training each feature file, count the current sample loss, summarize it into the total loss, and count the average loss rate up to the previous samples. The result is as Figure 8 shown.
[0149] 4) After training all the feature files, use the validation set data for detection, and count the average accuracy of the validation set data. The result is as Figure 9 shown.
[0150] After 20 rounds of cyclic training, obtain the average accuracy of each training, as Figure 10 shown.
[0151] After the model is trained, use the autoencoder model to detect real-time data, and use the result of the model detection as the detection result of the power system network security behavior.
[0152] Adopt the sliding time window method to preprocess the original data between nodes within the past 48 hours to obtain edge feature data, perform binary classification prediction scoring through the dynamic graph model, and put it into the in-memory cache of the node pair global node set. Construct the data of each source node through the cache, and detect the abnormal security behavior of the node through the autoencoder model. As Figure 11As shown, the threshold is set to 0.01, and network behaviors of nodes above the threshold are abnormal.
[0153] The present invention performs data detection through a trained model and can effectively detect network behaviors. The method of the present invention has a fast training speed and low resource consumption; it can continuously monitor changes in device nodes and can quickly update the model; the present invention is unsupervised learning and does not require manual labeling of data.
[0154] Embodiment 3
[0155] The method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology in this embodiment has the same other features as Embodiment 1 or 2. The difference is that it further includes: online learning of node relationship changes and updating the model. Specifically, when the system determines that the access between network devices is relatively frequent and conforms to normal access characteristics, this access relationship is updated into the model, the node dynamic information memory module and the node nearest neighbor relationship module are updated, and in subsequent detections, the access of this network device is recognized as normal access.
[0156] The method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology further includes: discovering node changes and retraining the model. Specifically, when a node is added, the data is summarized by hour and port again, the data for the latest time period is collected, the model is retrained and a model file is generated, and the original model file is overwritten.
[0157] The method for detecting power system network security behaviors based on deep learning dynamic graph neural network technology in this embodiment can adjust and update the model in a timely manner according to the actual node changes in the power system.
[0158] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit the protection scope of the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the essence and scope of the technical solutions of the present invention.
Claims
1. A method for detecting power system network security behavior based on deep learning dynamic graph neural network technology, characterized in that: Proceed as follows: S1, construct dynamic graph model and autoencoder model; S2, construct pre-training data set and verification data set; S3, training model, including: First, use the edge relationship feature data between two device nodes to train the dynamic graph model; use the positive and negative sample comparison method to simulate negative samples, and use the binary classification algorithm to calculate the estimated value of each sample edge relationship feature; cache the estimated value result of the positive sample into memory; Based on all source device IPs within a time period, read the binary classification estimates of each source device IP for all global device nodes from the memory as training data to train the autoencoder model; S4, save the trained dynamic graph model and autoencoder model; S5, using the dynamic graph model and the autoencoder model to detect real-time data, and using the detection result of the autoencoder model as the detection result of the power system network security behavior; The dynamic graph model constructed by S1 is equipped with a graph attention embedding module, a node dynamic information memory module, a node nearest neighbor relationship module, and a node behavior scoring module; The attention embedding module is a graph attention mechanism implemented by introducing the TransformerConv layer based on the Transformer architecture, which enables the dynamic graph model to adaptively focus on important neighbor nodes and edge information; and encodes the difference between the last update time of the node and the current interaction time, and combines it with the message features, so that the dynamic graph model can capture the time evolution pattern; The node dynamic information memory module is implemented by introducing the TGNMemory component to implement a dynamic memory mechanism to decide whether to retain or update the historical state of the node, so that the dynamic graph model can take into account long-term dependencies when making decisions; when the nodes in the dynamic graph interact, messages are generated and historical messages are aggregated to update the memory state of the node; The node nearest neighbor relationship module is responsible for collecting and maintaining the connected neighbor nodes of each node and recording the time information when connected to provide more accurate context information; and for determining whether it is a negative sample based on the connection information when comparing positive and negative samples; The node behavior scoring module scores edge relationships using a binary classifier model based on training data to identify whether access between devices is abnormal access.
2. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 1 is characterized in that S2 include: Preprocess historical data and summarize common service ports as global features of device nodes; According to the historical data, the access relationship between the two device nodes in each time period is obtained by performing hourly segment statistics.
3. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 2 is characterized in that: S2 specifically includes the following steps: S21, collecting original communication pair data within a certain period of time as historical data, summarizing them by hour and port, and summarizing to obtain hourly port summary data, wherein the hourly port summary data is constructed in the format of hourly period, source device IP, target device IP, port, and number of accesses; S22, obtaining the global static features of all device nodes according to the hourly port summary data, and saving them as a node_feature.csv file; S23, in the hourly port summary data, the access situation between two device nodes is extracted by each hour as the edge relationship feature of the dynamic graph; S24, divide the processed node relationship feature files into training set, validation set and test set in chronological order, and store them in three directories: train, eval and test respectively.
4. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 3 is characterized in that: S22 specifically obtains the number of devices accessed and the number of devices accessed by all devices based on the hourly port summary data, as well as the characteristics of the commonly used ports, recognized ports, registered ports, dynamic or private ports in the entire power network system.
5. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to any one of claims 1 to 4, characterized in that: The specific process of S3 training model is as follows: S31, model initialization, including initializing the dynamic graph model and initializing the autoencoder model; Among them, initializing the dynamic graph model includes initializing the graph attention embedding module, initializing the node dynamic information memory module, initializing the node nearest neighbor relationship module, and setting the initialization dynamic graph model training parameters; Initialize the autoencoder model, including setting the encoder module, decoder module parameters, and setting the autoencoder model training parameters; S32, initializing global node feature data; S33, reading feature files according to time periods to train dynamic graph models, specifically including: S331, reading the node relationship feature file in chronological order, and naming the read node relationship feature file as the current batch data; S332, calculating the time step value of the current batch of data; S333, according to the nodes of the current batch of data, read the nearest neighbor nodes from the node nearest neighbor relationship module, and together form the nodes of the current batch of data, that is, the local graph nodes; S334, reading the most recent node state from the node dynamic information memory module according to the local graph node and the time step value; S335, according to the local graph node, read the node static feature from the global node feature data cache, and merge the new node relationship combination information feature with the relationship feature between the current nodes; that is: Combined feature information = source device node static feature + target device node static feature + relationship feature between the two nodes; S336, updating the graph attention embedding layer according to the memory state of the local graph nodes and the node relationship combination information features; S337, use the positive and negative sample comparison method to calculate the loss rate; specific calculation method: Count all the nodes in a batch of data. Based on these nodes, in the node nearest neighbor relationship module, obtain all the neighboring nodes of the batch of data and the randomly generated negative sample nodes; for positive and negative samples, use the binary classifier model to predict the predicted value between 0 and 1, and then use the torch.nn.BCEWithLogitsLoss() loss function to count the loss of positive samples and the loss of negative samples respectively, and then add them together to get the loss of the sample; S338, updating the node dynamic information memory module according to the local graph node data; S339, updating the node nearest neighbor relationship module according to the local graph node data; S34, training the autoencoder model, specifically including: Get the source device nodes where the access event occurred in the current time step, get the binary classification prediction score data of the edge features of these nodes with all other nodes within a certain time step range, and train the autoencoder model; When using edge feature data to train a dynamic graph model, after each time step in the dynamic graph model training process is completed, the edge features contained in the time step are used to perform binary classification prediction scores using the dynamic graph model, and the results are updated to the cache; the source device node that has changed in the time step is obtained from the edge data, and the score data of the node for the global node set is read from the cache according to the changed source device node, and the feature data for training the autoencoder is constructed for training the autoencoder; the input feature data is compressed into a low-dimensional representation by the encoder, and then the original input is reconstructed by the decoder; the torch.nn.MSELoss() mean square error loss function is used to calculate the reconstruction error between the original data and the reconstructed data; S35, cyclic training to generate the optimal model; Set the number of learning steps; after each step of training, use the validation data set to verify the average loss rate and average accuracy of the model for each node relationship feature data of the validation data; when the average loss rate is better than the original generated model, update and generate a new model file.
6. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 5 is characterized in that: A cache of the global node set is added to each node to cache the binary classification prediction scores of the time step and edge features of other nodes.
7. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 5 is characterized in that: Also includes: Online learning of node relationship changes and updating of models. Specifically, when the system determines that the access between network devices is frequent and meets the normal access characteristics, this access relationship is updated to the model, the node dynamic information memory module and the node nearest neighbor relationship module are updated. In subsequent detections, the access of this network device is identified as normal access.
8. The method for detecting power system network security behavior based on deep learning dynamic graph neural network technology according to claim 5 is characterized in that: It also includes: discovering node changes and retraining the model. Specifically, when a node is added, the data is re-aggregated by hourly port, the data of the latest time period is collected, the model file is retrained and generated, and the original model file is overwritten.
Citation Information
Patent Citations
Power system data anomaly detection method and system based on graph neural network
CN118861956A