A novel two-layer detection method and system for DoS attacks in power systems
By adopting a two-layer detection method in the new power system, using state features and packet features for feature filtering and information entropy calculation, combining attack prediction models and dynamic thresholds to generate baseline probability, early detection and prevention of LDoS and DDoS attacks is achieved, and system stability and computing resource utilization efficiency are improved.
Patent Information
- Application Number
- CN202510401262.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-04-01
AI Technical Summary
The new power system is vulnerable to DoS attacks at the information level, resulting in the physical-sided regulatory services being unable to be implemented in a timely and effective manner. The existing protective measures cannot effectively avoid the impact of DoS attacks, especially LDoS and DDoS attacks are difficult to detect.
The two-layer detection method is adopted to obtain the state characteristics and packet characteristics of the new power system when transmitting electrical data, and feature filtering and information entropy calculation are performed in the first layer detection. If a potential attack exists, the second layer detection is performed. The pre-constructed attack prediction model is used to output the probability distribution prediction value of the DoS attack, and the baseline probability is generated in combination with the dynamic threshold, and the final DoS attack detection is performed.
Detect in advance whether there are various potential DoS attacks in the network, and route and schedule in advance when an attack is detected to occur, ensuring the transmission of key data and instructions, improving system stability, reducing misjudgment rates, and reducing computing resource consumption.
Smart Images

Figure CN119906591B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system attack detection, and in particular to a novel double-layer detection method and system for DoS attacks on power systems. Background Art
[0002] Energy storage, electric vehicles and other electricity consumption scenarios have further enriched the connotation of the power grid. The structure and operation mode of the power system are undergoing profound changes, allowing a new power system to be built to adapt to these changes. The new power system gathers various adjustable resources such as source, network, load and storage. The control technology analyzes the power grid information collected by the information network and flexibly calls on various resources to ensure the stable operation of the power system, deepening the coupling relationship between the physical system and the information system, making the new power system a cyber-physical coupled power system (CPPS).
[0003] The formation of a new power system has alleviated the problems of energy shortage and green power generation, but it has also brought new challenges: at the information level, a large number of distributed power generation equipment has generated a large amount of data. At the same time, wireless and open interconnection scenarios are vulnerable to various network attacks, resulting in the inability to timely and effectively execute the regulation business on the physical side. All existing protection measures cannot effectively prevent the new power system from being affected by denial of service attacks (DoS). Once a DoS attack occurs, a large amount of useless data will occupy the channel bandwidth or make the receiving end unable to process business normally. Therefore, it is an urgent problem to detect and respond to DoS attacks before network attacks affect the regulation business on the physical side. At the same time, in DoS attacks, low-rate Denial of Service (LDoS) attacks are difficult to detect because their sending speed is not enough to trigger capacity security alarms; while distributed DoS attacks (DDoS) send massive requests to the target at the same time through a large-scale coordinated malicious node network, instantly flooding the target's bandwidth or resources; these two types of DoS attacks are highly concealed and destructive, which will have a serious impact on the power grid, so more attention needs to be paid during the detection process. At the physical level, a large number of distributed source-load-storage resources require real-time data to monitor power generation, electricity demand, grid load, etc., in order to make timely scheduling decisions, generating a large amount of data to support the above scheduling decisions to ensure the safe, stable and economic operation of the power grid. As a result, a large amount of data generated by business needs is often misjudged as DoS attacks, affecting the normal operation of business.
[0004] Therefore, how to proactively detect various types of DoS attacks, including LDoS and DDoS, in advance while reducing the misjudgment rate is crucial to ensuring the safe and stable operation of the system. Summary of the invention
[0005] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a novel double-layer detection method and system for DoS attacks in power systems, which can predict whether there are potential various types of DoS attacks in the system, perform routing scheduling in advance when an attack is detected, ensure the transmission of key data and instructions, and improve the stability of the system.
[0006] To achieve the above object, the present invention is implemented by adopting the following technical solutions:
[0007] On the one hand, the present invention provides a novel two-layer detection method for DoS attacks in power systems, comprising:
[0008] Obtain state characteristics and packet characteristics of new power systems when transmitting electrical data;
[0009] In the first layer of detection, the state feature is subjected to feature filtering to obtain the attack feature, and whether the attack feature has a potential attack is determined according to the preset first judgment basis; if a potential attack has occurred, a potential state feature is obtained, and the potential state feature is subjected to a second layer of detection;
[0010] In the first layer detection, the information entropy of the packet feature is calculated, and the second judgment basis is obtained by using the information entropy. According to the second judgment basis, it is judged whether the packet feature has a potential attack; if a potential attack has occurred, the potential packet feature is obtained, and the second layer detection is performed on the potential packet feature;
[0011] When performing the second layer detection, the potential state features and the potential packet features are input into a pre-built attack prediction model, and a probability distribution prediction value of the DoS attack is output;
[0012] A baseline probability is generated according to the obtained dynamic threshold, and the baseline probability is compared with the predicted value of the probability distribution of the DoS attack to obtain a DoS attack detection result.
[0013] Optionally, the preset first judgment basis includes a first judgment basis for a DDoS attack and a first judgment basis for an LDoS attack;
[0014] The first judgment basis of the DDoS attack includes four judgment conditions, and the first judgment basis of the LDoS attack includes two judgment conditions;
[0015] If the attack feature satisfies any one of the first judgment criteria of the DDoS attack or the first judgment criteria of the LDoS attack, then the attack feature generates a potential attack, a potential state feature is obtained, and a second layer detection is performed on the potential state feature.
[0016] Optionally, the first judgment basis of the DDoS attack includes four judgment conditions, which are expressed as follows:
[0017] ;
[0018] ;
[0019] ;
[0020] ;
[0021] In the formula, Indicates the delay feature in the attack feature The numerical value and; Indicates the transmission time; represents the delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the packet loss rate feature in the attack feature The numerical value and; Indicates the packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate; Indicates the transmission rate correction parameter; Indicates the minimum value of the port transmission rate in the attack signature; Indicates the minimum port transmission rate that the system can tolerate; Indicates the maximum CPU usage in the attack signature; Indicates CPU usage correction parameter; Indicates the maximum CPU usage that the system can tolerate.
[0022] Optionally, the first judgment basis of the LDoS attack includes two judgment conditions, which are expressed as:
[0023] ;
[0024] ;
[0025] In the formula, The function represents the number of values that satisfy the condition; Indicates the delay feature in the attack feature; represents the periodic delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the attack frequency of LDoS attack; Indicates the packet loss rate feature in the attack feature; Indicates the periodic packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate.
[0026] Optionally, calculating the information entropy of the packet feature includes:
[0027] ;
[0028] In the formula, Information entropy representing packet characteristics; Indicates package characteristics; Indicates the number of package features; Represents the probability of the i-th packet feature.
[0029] Optionally, judging whether a potential attack occurs in the packet feature according to the second judgment basis includes:
[0030] The second judgment basis includes the following five judgment conditions:
[0031] ;
[0032] ;
[0033] ;
[0034] ;
[0035] ;
[0036] In the formula, Indicates the transmission time The entropy of the source IP address of the packet feature; Indicates the number of package features; Indicates the number of the i-th package feature is the probability of the source IP address appearing; Indicates the transmission time The entropy of the destination IP address of the packet feature; represents the number of regulatory centers; Indicates the number of the o-th control center The probability of the destination IP address appearing; Indicates the transmission time Entropy of the source port address of the packet feature; Indicates the entropy of a normal source port address; Indicates the transmission time The entropy of the destination port address of the packet feature; Indicates the entropy of a normal destination port address; Indicates the transmission time Entropy of packet type of packet features; The entropy representing the characteristic type of normal packets;
[0037] If the packet feature satisfies any one of the discrimination conditions in the second judgment basis, then a potential attack occurs to the packet feature, a potential packet feature is obtained, and a second layer detection is performed on the potential packet feature.
[0038] Optionally, the construction of the attack prediction model includes:
[0039] The parallel temporal attention mechanism, convolutional attention mechanism, and multimodal fusion module are sequentially added between the hidden state layer and the fully connected layer of the BILSTM model to obtain a constructed attack prediction model.
[0040] Optionally, generating a baseline probability according to the acquired dynamic threshold includes:
[0041] ;
[0042] ;
[0043] In the formula, represents the initial baseline probability; Represents the moving average of the historical normal traffic attack probability; represents the confidence coefficient; The standard deviation representing the sampling window size; represents the final baseline probability; represents the adjustment coefficient; Indicates the business importance coefficient.
[0044] Optionally, comparing the baseline probability with the predicted value of the probability distribution of the DoS attack to obtain a DoS attack detection result includes:
[0045] If the predicted value of the probability distribution of the DoS attack is greater than the baseline probability, a DoS attack occurs; if the predicted value of the probability distribution of the DoS attack is not greater than the baseline probability, no DoS attack occurs.
[0046] On the other hand, the present invention provides a novel dual-layer detection system for DoS attacks on power systems, comprising:
[0047] A feature acquisition module is used to acquire state features and packet features of the new power system when transmitting electrical data;
[0048] The state feature pre-detection module is used to perform feature filtering on the state feature in the first layer detection to obtain the attack feature, and judge whether the attack feature has a potential attack according to the preset first judgment basis; if a potential attack has occurred, obtain the potential state feature, and perform the second layer detection on the potential state feature;
[0049] A packet feature pre-detection module is used to calculate the information entropy of the packet feature in the first layer detection, use the information entropy to obtain a second judgment basis, and judge whether a potential attack occurs in the packet feature according to the second judgment basis; if a potential attack occurs, obtain a potential packet feature, and perform a second layer detection on the potential packet feature;
[0050] A DoS attack detection module, for inputting the potential state features and potential packet features into a pre-built attack prediction model when performing the second layer detection, and outputting a probability distribution prediction value of the DoS attack;
[0051] A baseline probability is generated according to the obtained dynamic threshold value, and is used to compare the baseline probability with the predicted value of the probability distribution of the DoS attack to obtain a DoS attack detection result.
[0052] Compared with the prior art, the present invention has the following beneficial effects:
[0053] 1. The present invention solves the prediction problem of traditional LDoS attacks and DDoS attacks through state feature pre-detection, packet feature pre-detection and DoS attack detection method based on attack prediction model, detects in advance whether there are potential various DoS attacks in the network, performs routing scheduling in advance when an attack is detected, ensures the transmission of key data and instructions, and improves the stability of the system;
[0054] 2. The present invention solves the problem of misjudgment caused by the information demand of normal business. Changes in normal business will lead to changes in information demand, which will be transformed into fluctuations in traffic information on the information side. Traditional methods cannot distinguish between normal traffic information fluctuations and information fluctuations caused by attacks, resulting in subsequent attack response strategies affecting the normal operation of the business. The impact of the business on traffic information is considered in the packet feature pre-detection part and the DoS attack judgment part in the second layer detection, and corresponding constraints are imposed;
[0055] 3. The present invention solves the problem of high resource consumption in DoS attack detection. When processing large-scale traffic data, traditional detection technology will consume a lot of computing resources, which will affect the normal operation of the network and thus the normal operation of the service. The present invention proposes a state feature pre-detection method and a packet feature pre-detection method to perform pre-detection before adopting a learning algorithm that consumes a lot of computing resources, filter normal traffic, and only detect traffic with potential attack possibilities, which greatly reduces the consumption of computing resources and solves the problem. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A schematic diagram of a flow chart of a novel double-layer detection method for DoS attacks on a power system in an embodiment of the present invention;
[0057] Figure 2 It is a flow chart of another embodiment of the double-layer detection method of the novel power system DoS attack of the present invention;
[0058] Figure 3 It is an information coupling architecture diagram of a novel power system in one embodiment of the present invention;
[0059] Figure 4 for Figure 3 In one embodiment, the information coupling method performs a flow chart. DETAILED DESCRIPTION
[0060] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. The embodiments of the present invention and the technical features in the embodiments may be combined with each other unless there is a conflict.
[0061] The term "and / or" is only a description of the association relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " generally indicates that the related objects are in an "or" relationship.
[0062] Example 1
[0063] like Figure 1 As shown, this embodiment introduces a new two-layer detection method for DoS attacks in power systems. The new power system information coupling architecture is as follows: Figure 3 As shown, the execution method flow is as follows Figure 4 As shown, it includes the top-level control center and equipment, the middle-level routing communication network, and the bottom-level source-load-storage distributed resources; when the sensors of the source-load-storage distributed resources collect relevant electrical data, such as wind power data, photovoltaic data, energy storage data, and load data, and upload them to the control center and equipment through the routing communication network, the DoS attacks that may exist in the transmission process are detected, and it is determined whether a DoS attack will occur in the future.
[0064] The method comprises the following steps:
[0065] Step 1: Collect relevant state characteristics and perform data preprocessing: collect the state characteristics of the new power system when transmitting electrical data, that is, network state information and equipment statistical information as state characteristics, and then perform data preprocessing;
[0066] Step 2: In the first layer of detection, the state features are filtered to separate the attack features and determine whether to perform the second layer of detection: the state features are filtered to obtain the attack features, and according to the preset first judgment basis, it is determined whether the attack features have a potential attack; if a potential attack has occurred, the potential state features are obtained, and the potential state features are subjected to the second layer of detection;
[0067] Step 3: In the first layer of detection, data packet features are collected and information entropy is calculated, and whether to perform the second layer of detection is determined by considering the information needs of the business: the data packet header information when the new power system transmits electrical data is collected as the data packet feature, the information entropy of the packet feature is calculated, and the second judgment basis is obtained by using the information entropy. According to the second judgment basis, it is determined whether the packet feature has a potential attack; if a potential attack has occurred, the potential packet feature is obtained, and the second layer of detection is performed on the potential packet feature;
[0068] Step 4: When the second layer detection is required, the attack probability distribution prediction value is calculated based on the dual-channel BiLSTM-Attention prediction model and it is determined whether a DoS attack will occur: When the second layer detection is performed, the potential state features and potential packet features are input into the pre-built attack prediction model, and the probability distribution prediction value of the DoS attack is output;
[0069] Step 5: Generate a baseline probability based on the obtained dynamic threshold, compare the baseline probability with the predicted value of the probability distribution of the DoS attack, and obtain the DoS attack detection result.
[0070] This embodiment solves the prediction problem of traditional LDoS attacks and DDoS attacks through state feature pre-detection, packet feature pre-detection and DoS attack detection method based on attack prediction model, detects in advance whether there are potential various DoS attacks in the network, performs routing scheduling in advance when an attack is detected, ensures the transmission of key data and instructions, and improves the stability of the system.
[0071] Example 2
[0072] On the basis of Example 1, Figure 2 As shown, this embodiment introduces a novel two-layer detection method for DoS attacks in power systems, including the following steps:
[0073] Step 1: Collect relevant status features and perform data preprocessing: Collect the status features of the new power system when transmitting electrical data, that is, network status information and equipment statistical information as status features, and then perform data preprocessing, specifically:
[0074] Starting from a certain transmission time t, the state feature set collected within k transmission times is recorded as S, and the state feature of each transmission time t It can be expressed as ;in, is the delay of the current transmission moment; For transmission time To the current transmission time The average packet loss rate; The device port transmission rate at the current transmission moment; The device CPU usage at the current transmission time.
[0075] The collected state features are preprocessed and the data is normalized using the min-max standardization method. The formula of the min-max standardization method is:
[0076] ;
[0077] in, Indicates the transmission status characteristics at a certain moment; express Normalized value; and are the maximum and minimum values of each measured state characteristic, respectively.
[0078] After the state feature set S is preprocessed, the preprocessed state feature set is obtained .
[0079] Step 2: In the first layer of detection, the state features are filtered to separate the attack features and determine whether to perform the second layer of detection: the state features are filtered to obtain the attack features, and according to the preset first judgment basis, it is determined whether the attack features have a potential attack; if a potential attack has occurred, the potential state features are obtained, and the potential state features are subjected to the second layer of detection; if no potential attack has occurred, the detection is stopped, specifically:
[0080] First, a normal state feature set with a time length of k transmission moments is collected and preprocessed, denoted as ;
[0081] Then separate the state characteristics of the mixed normal traffic from the state characteristics of the attack traffic, and refer to the normal network state characteristics , filter the state features to be detected , separate attack features that deviate from normal network status features In this embodiment, the affine projection (APA) algorithm is used for feature filtering, and the state feature set And the normal state feature set after preprocessing As the input of the APA algorithm, the attack characteristics are solved by the APA algorithm ;
[0082] Finally, determine the attack characteristics Whether the various state characteristics in meet the preset first judgment basis, the preset first judgment basis includes the first judgment basis of DDoS attack and the first judgment basis of LDoS attack. The first judgment basis of DDoS attack includes four judgment conditions, and the first judgment basis of LDoS attack includes two judgment conditions. The specific process is as follows:
[0083] The first basis for designing a DDoS attack based on the characteristics of the DoS attack is:
[0084] Delay basis: DoS attacks send a large number of useless data packets or requests, occupying network bandwidth and system resources, causing legitimate users' request processing time to be longer, resulting in significant delays. Therefore, the following judgment basis is designed:
[0085] ;
[0086] In the formula, Indicates attack characteristics Delay characteristics in The numerical value and; Indicates the delay correction parameter to ensure early warning when an attack is discovered; Indicates the additional delay that the system can tolerate;
[0087] Packet loss rate basis: DoS attacks cause the network bandwidth to be fully occupied by attack traffic, resulting in network bandwidth saturation, making it impossible for normal data packets to be transmitted in time, resulting in an increase in packet loss rate. Therefore, the following judgment basis is designed:
[0088] ;
[0089] In the formula, Indicates attack characteristics Packet loss rate characteristics in The numerical value and; Indicates the packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate;
[0090] Port transmission rate basis: The increase in packet loss rate will further affect the stability of network communication; due to the impact of attack traffic, normal traffic is blocked, resulting in a decrease in port transmission rate, affecting system stability, so the following judgment basis is designed:
[0091] ;
[0092] In the formula, Indicates the transmission rate correction parameter; Indicates attack characteristics The minimum value of the port transmission rate; Indicates the minimum port transmission rate that the system can tolerate;
[0093] CPU usage basis: The attack causes the system to process a large number of invalid requests. The device allocates resources for each request and tries to complete the request process, which causes the CPU usage to rise sharply. Therefore, the following judgment basis is designed:
[0094] ;
[0095] In the formula, Indicates attack characteristics The maximum value of CPU usage; Indicates CPU usage correction parameter; Indicates the maximum CPU usage that the system can tolerate.
[0096] LDoS attacks may periodically affect the quality of network services, causing increased latency and packet loss rates during a specific period of time. Therefore, the first basis for judging LDoS attacks is to design them based on their characteristics:
[0097] Periodic delay based on:
[0098] ;
[0099] In the formula, The function represents the number of values that satisfy the condition; Indicates a collection of attack signatures Medium delay greater than the number of Indicates the delay feature in the attack feature; represents the periodic delay correction parameter, and ; Indicates the attack frequency of LDoS attack;
[0100] Periodic packet loss rate is based on:
[0101] ;
[0102] In the formula, Indicates a collection of attack signatures The packet loss rate is greater than the number of Indicates the packet loss rate feature in the attack feature; represents the periodic packet loss rate correction parameter, and .
[0103] Attack judgment is performed on each feature in the attack feature. If any of the first judgment criteria of DDoS attack or the first judgment criteria of LDoS attack is met, the attack feature is Set to 1 to obtain the potential state characteristics and perform the second layer detection. Otherwise, it is considered that no potential attack has occurred and the detection is stopped.
[0104] Step 3: In the first layer of detection, data packet features are collected and information entropy is calculated, and the information needs of the business are considered to determine whether to perform the second layer of detection: the data packet header information when the new power system transmits electrical data is collected as the data packet feature, the information entropy of the packet feature is calculated, and the second judgment basis is obtained using the information entropy. According to the second judgment basis, it is determined whether the packet feature has a potential attack; if a potential attack occurs, the potential packet feature is obtained, and the second layer of detection is performed on the potential packet feature; if no potential attack occurs, the detection is stopped, specifically:
[0105] Information entropy is used as a basis for pre-detection of DDoS attacks. The specific process is as follows:
[0106] The data packet header information when the new power system transmits electrical data is collected as the packet feature. Starting from a certain transmission time, the packet feature set collected within k transmission times is recorded as , the packet characteristics of each transmission time t It can be expressed as ;in The source IP address representing the characteristics of the packet at transmission time t; The destination IP address representing the characteristics of the packet at transmission time t, The source port address representing the characteristics of the packet at transmission time t; The destination port address representing the characteristics of the packet at transmission time t; The packet type that represents the characteristics of the packet at transmission time t.
[0107] Calculate the information entropy of packet features, the information entropy of packet features The formula is:
[0108] ;
[0109] In the formula, Indicates package characteristics; Indicates the number of package features; Represents the probability of the i-th packet feature.
[0110] The entropy set of data packet features collected within k transmission moments is recorded as , the entropy of the packet characteristics at each transmission time t It can be expressed as ;in, The entropy of the source IP address representing the characteristics of the packet at transmission time t; The entropy of the destination IP address representing the characteristics of the packet at transmission time t, The entropy of the source port address representing the characteristics of the packet at transmission time t, The entropy of the destination port address representing the characteristics of the packet at transmission time t, The entropy of the packet type representing the characteristics of the packet at transmission time t.
[0111] Using information entropy, we design the second basis for judging DDoS attacks. The second basis for judging DDoS attacks includes the following five criteria:
[0112] In normal traffic, the distribution of source IP addresses is relatively concentrated due to optimal path selection and load balancing, while in DDoS attacks, the attack traffic may come from a large number of evenly distributed controlled source IP addresses, resulting in an increase in entropy; in DDoS attacks, the destination IP addresses may be concentrated on the attack target, so during the attack, the entropy of the destination IP addresses will decrease; in normal traffic, the source port addresses are usually random and have high entropy; in DDoS attacks, if the attacker uses a specific port to attack, the entropy of the source port address may decrease; DDoS attacks may target specific service ports, causing the entropy of the destination port address to decrease during the attack; in normal traffic, the distribution of packet types (such as TCP, UDP, etc.) may be relatively uniform; DDoS attacks may use specific types of packets to attack, causing the entropy of the packet type to decrease during the attack, so the following judgment basis is designed:
[0113] Source IP address determination basis:
[0114] ;
[0115] In the formula, Indicates the entropy of a normal source IP address;
[0116] The basis for determining the destination IP address is:
[0117] ;
[0118] In the formula, Indicates the entropy of a normal destination IP address;
[0119] Source port address determination basis:
[0120] ;
[0121] In the formula, Indicates the entropy of a normal source port address;
[0122] The basis for determining the destination port address is:
[0123] ;
[0124] In the formula, Indicates the entropy of a normal destination port address;
[0125] Package type determination basis:
[0126] ;
[0127] in, Indicates the entropy of normal packet types.
[0128] Considering that the power data required by different services is different and the deployment locations of the service control algorithms are different, the source IP address and destination IP address of normal traffic may differ greatly. Therefore, it is necessary to calculate the source IP address entropy of normal traffic under multiple types of services. and destination IP address entropy , the calculation process is as follows:
[0129] The network exists data sources, the corresponding source IP address set is , the transmission frequency set of the data source is ,in, , and Respectively represent the 1st, 2nd and mth transmission frequencies, represents the set of natural numbers; exists Control center, control business collection , , and Respectively represent the first, second and jth control centers, there are Each control business It can be expressed as ;in, belong Indicates regulation business The IP address where the control algorithm is located; Represents a length of Boolean vector of IP addresses, ;in, Represents the rth IP address Boolean vector, whose value is 1 or 0, indicating regulation service Whether there is a demand for the data source corresponding to the rth IP address;
[0130] Source IP address entropy of normal traffic under multiple types of services and destination IP address entropy The calculation formula is as follows:
[0131] ;
[0132] in, Indicates the number of features in the i-th package is The probability of the source IP address appearing, , Indicates the number of features in the i-th package is The source IP address; express The transpose of represents the rth IP address Boolean vector;
[0133] ;
[0134] Then, the source IP address is determined based on:
[0135] ;
[0136] The destination IP address is determined based on:
[0137] ;
[0138] In the formula, Indicates the number of the i-th package feature is the probability of the source IP address appearing; represents the number of regulatory centers; Indicates the number of the o-th control center The probability of the destination IP address appearing.
[0139] The attack is judged for each feature in the packet feature. If any of the judgment conditions in the second judgment basis is met, the packet feature is Set to 1 to obtain potential packet features and perform second-layer detection, otherwise it is considered that no potential attack has occurred.
[0140] Step 4: When the second layer detection is required, the attack probability distribution prediction value is calculated based on the dual-channel BiLSTM-Attention prediction model and it is determined whether a DoS attack will occur: When the second layer detection is performed, the potential state features and potential packet features are input into the pre-built attack prediction model, and the probability distribution prediction value of the DoS attack is output; the baseline probability is generated based on the obtained dynamic threshold, and the baseline probability is compared with the probability distribution prediction value of the DoS attack to obtain the DoS attack detection result, which is as follows:
[0141] First, we build an attack prediction model, namely the dual-channel BiLSTM-Attention prediction model, which takes the latent state features and latent packet features as dual-channel inputs, and builds a multimodal fusion module to splice the dual-channel features, thereby calculating the attack probability distribution prediction value; finally, by comparing it with the baseline probability generated by the dynamic threshold, we determine whether a DoS attack will occur. The specific process is as follows:
[0142] First, follow steps 2 and 3 to get the latent state features and potential package characteristics ;
[0143] Then, a dual-channel BiLSTM-Attention prediction model is constructed. The dual-channel BiLSTM-Attention prediction model includes state feature channel, data packet feature channel, input gate, forget gate, cell state, output gate, hidden state, parallel temporal attention mechanism layer and convolutional attention mechanism layer, multimodal fusion module, and fully connected layer.
[0144] They are calculated by the following formulas:
[0145] State feature channel input :
[0146] ;
[0147] Packet feature channel input: construct a cross matrix , where the cross matrix Elements in It is expressed as:
[0148] ;
[0149] in, , Respectively represent and entropy feature vector.
[0150] Input Gate :
[0151] ;
[0152] in, is the sigmoid function; is the time step Input; is the hidden state of the previous step; is the cell state at the previous step; , and They are the time weight matrix of the input gate, the hidden state weight matrix, and the cell state weight matrix; is the bias term of the input gate;
[0153] Forget Gate :
[0154] ;
[0155] in, , and They are the time weight matrix of the forget gate, the hidden state weight matrix, and the cell state weight matrix; is the bias term of the forget gate;
[0156] Cell state :
[0157] ;
[0158] in, and They are the temporal weight matrix of the cell state and the hidden state weight matrix; is the bias term of the cell state; is the hyperbolic tangent function; represents a candidate memory value;
[0159] Output Gate :
[0160] ;
[0161] in, , and They are the time weight matrix of the output gate, the hidden state weight matrix, and the cell state weight matrix; is the bias term of the output gate;
[0162] Hidden State :
[0163] ;
[0164] Temporal Attention Mechanism:
[0165] ①Attention score :
[0166] ;
[0167] in, is the transpose of the learnable weight vector; is the hidden state weight matrix; It is a two-way state. , denote the forward and backward hidden states respectively; is the bias term of the hidden state;
[0168] Normalized attention score :
[0169] ;
[0170] in, , Respectively represent and Attention scores of temporal features; Indicates the number of temporal features;
[0171] ②Weighted output :
[0172] ;
[0173] in, Indicates The attention score after normalization of temporal features;
[0174] Convolutional Attention Mechanism:
[0175] ①Convolution operation :
[0176] ;
[0177] in, is the convolution weight matrix; is the activation function; is the convolution bias term;
[0178] ②Attention Gate :
[0179] ;
[0180] in, is the convolution weight matrix, is a function that reshapes a matrix into a column vector by columns. is the convolution bias term.
[0181] ③Gated output :
[0182] ;
[0183] in, It is a function that converts multi-dimensional convolution features into one-dimensional vectors;
[0184] Splicing features for:
[0185]
[0186] in, represents the weighted output of temporal attention, Represents the gated output of the convolutional attention;
[0187] Calculate the importance of timing channels separately and entropy channel importance :
[0188] ;
[0189] ;
[0190] Weighted Output :
[0191] ;
[0192] Fully connected layer :
[0193] ;
[0194] in, is the convolution weight matrix; is the convolution bias term;
[0195] Probability distribution prediction value of DoS attack :
[0196] ;
[0197] in, Indicates whether the DoS attack is true or false. Indicates that the DoS attack is real. Indicates that a DoS attack occurred which is a false occurrence; represents the output of the fully connected layer;
[0198] Compare the predicted value of the probability distribution of DoS attacks with the baseline probability generated by the dynamic threshold to determine whether a DoS attack will occur. First, build the baseline probability generated by the dynamic threshold:
[0199] ;
[0200] ;
[0201] In the formula, represents the initial baseline probability; Represents the moving average of the historical normal traffic attack probability; It represents the confidence coefficient, and the value should correspond to a confidence interval of 95% or above; The standard deviation representing the sampling window size; represents the final baseline probability; represents the adjustment coefficient; Indicates the business importance coefficient.
[0202] Then, if the predicted value of the probability distribution of the DoS attack is greater than the baseline probability, a DoS attack occurs; if the predicted value of the probability distribution of the DoS attack is not greater than the baseline probability, no DoS attack occurs.
[0203] Example 3
[0204] Based on Examples 1 and 2, this example introduces an experimental example of a novel two-layer detection method for DoS attacks on a power system, including:
[0205] First, construct a data set. Select source IP address, destination IP address, source port, destination port, packet type and transmission rate features from the public data set; simulate the network topology through mininet software to generate normal traffic and record relevant feature data; use tools such as Scapy to generate attacks and record relevant feature data. The constructed data set includes a training set and a validation set. The training set contains 100,000 samples, of which 80% are normal samples and 20% are attack samples. The validation set includes 60,000 samples. The attack types of the training set and validation set include: 10,000 SYN Flood, DDoS and LDoS, and 30,000 normal samples.
[0206] Secondly, the constructed attack prediction model is trained. The optimizer selected during training is Adam, and the learning rate is ; The number of training rounds is 150, and the training is stopped when the validation set loss does not decrease for 10 consecutive rounds. The final loss is , indicating that the model has achieved higher performance in classification tasks.
[0207] The trained model was then verified using the validation set. 10,000 SYN Flood samples and 10,000 normal samples were used to verify the detection effect of ordinary DoS attacks: the final verification detection rate was 97.3%, and the false alarm rate of normal business traffic was 0.8%; 10,000 DDoS samples and 10,000 normal samples were used to verify the detection effect of distributed DoS attacks: the final verification detection rate was 96.8%, and the false alarm rate of normal business traffic was 1.2%; 10,000 LDoS samples and 10,000 normal samples were used to verify the detection effect of low-frequency DoS attacks: the final verification detection rate was 95.6%, and the false alarm rate of normal business traffic was 1.5%; the average judgment delay was 14.572ms.
[0208] Finally, the attack samples in the validation set are selected for simulation.
[0209] Select one of the SYN Flood samples to test its accuracy. First, calculate its baseline: , , Select 2, Set to 0.9, Select 0.025, and the final baseline probability is . Secondly, the model output probability is obtained through model training , it is determined that there is a DoS attack.
[0210] Select one of the DDoS samples to test its accuracy and first calculate its baseline: , , Select 2, Set to 0.7, Select 0.025, and the final baseline probability is . Secondly, the model output probability is obtained through model training , it is determined that there is a DoS attack.
[0211] Select one of the LDoS samples to test its accuracy and first calculate its baseline: , , Select 2, Set to 0.6, Select 0.025, and the final baseline probability is . Secondly, the model output probability is obtained through model training , it is determined that there is a DoS attack.
[0212] Verification has proven that the model can quickly and accurately detect DoS attacks, with an average judgment delay of less than 15ms, an average accuracy of 96.56%, and an average false alarm rate as low as 1.17%.
[0213] Example 4
[0214] Based on Examples 1 and 2, this example introduces a novel two-layer detection system for DoS attacks on a power system, including:
[0215] A feature acquisition module is used to acquire state features and packet features of the new power system when transmitting electrical data;
[0216] The state feature pre-detection module is used to perform feature filtering on the state feature in the first layer detection to obtain the attack feature, and judge whether the attack feature has a potential attack according to the preset first judgment basis; if a potential attack has occurred, the potential state feature is obtained, and the second layer detection is performed on the potential state feature;
[0217] The packet feature pre-detection module is used to calculate the information entropy of the packet feature in the first layer detection, use the information entropy to obtain the second judgment basis, and judge whether the packet feature has a potential attack according to the second judgment basis; if a potential attack has occurred, obtain the potential packet feature and perform the second layer detection on the potential packet feature;
[0218] The DoS attack detection module is used to input the potential state features and the potential packet features into a pre-built attack prediction model when performing the second layer detection, and output the probability distribution prediction value of the DoS attack;
[0219] A baseline probability is generated according to the obtained dynamic threshold, which is used to compare the baseline probability with the predicted value of the probability distribution of the DoS attack to obtain the DoS attack detection result.
[0220] The specific functional implementation of each of the above modules can be found in the relevant contents of the method in Example 1 or 2 and will not be elaborated here.
[0221] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0222] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0223] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0224] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0225] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the enlightenment of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which all fall within the protection of the present invention.
Claims
1. A novel two-layer detection method for DoS attacks in power systems, characterized in that: include: Obtain state characteristics and packet characteristics of the new power system when transmitting electrical data; In the first layer detection, the state feature is subjected to feature filtering to obtain the attack feature, and according to the preset first judgment basis, it is judged whether the attack feature has a potential attack: if a potential attack has occurred, a potential state feature is obtained, and the potential state feature is subjected to the second layer detection; In the first layer detection, the information entropy of the packet feature is calculated, and the second judgment basis is obtained by using the information entropy. According to the second judgment basis, it is judged whether a potential attack occurs in the packet feature: if a potential attack occurs, the potential packet feature is obtained, and the second layer detection is performed on the potential packet feature; When performing the second layer detection, the potential state features and the potential packet features are input into a pre-built attack prediction model, and a probability distribution prediction value of the DoS attack is output; Generate a baseline probability according to the obtained dynamic threshold, compare the baseline probability with the probability distribution prediction value of the DoS attack, and obtain a DoS attack detection result; The preset first judgment basis includes a first judgment basis for a DDoS attack and a first judgment basis for a LDoS attack; The first judgment basis of the DDoS attack is expressed as: ; ; ; ; In the formula, Indicates the delay feature in the attack feature The numerical value and; Indicates the transmission time; represents the delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the packet loss rate feature in the attack feature The numerical value and; Indicates the packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate; Indicates the transmission rate correction parameter; Indicates the minimum value of the port transmission rate in the attack signature; Indicates the minimum port transmission rate that the system can tolerate; Indicates the maximum CPU usage in the attack signature; Indicates CPU usage correction parameter; Indicates the maximum CPU usage that the system can tolerate; The first judgment basis of the LDoS attack is expressed as: ; ; In the formula, The function represents the number of values that satisfy the condition; Indicates the delay feature in the attack feature; represents the periodic delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the attack frequency of LDoS attack; Indicates the packet loss rate feature in the attack feature; Indicates the periodic packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate.
2. The novel double-layer detection method for DoS attack in power system according to claim 1 is characterized in that: If the attack feature satisfies any one of the first judgment criteria of the DDoS attack or the first judgment criteria of the LDoS attack, then the attack feature generates a potential attack, a potential state feature is obtained, and a second layer detection is performed on the potential state feature.
3. The novel double-layer detection method for DoS attack in power system according to claim 1 is characterized in that: Calculating the information entropy of the packet feature includes: ; In the formula, Information entropy representing packet characteristics; Indicates package characteristics; Indicates the number of package features; Represents the probability of the i-th packet feature.
4. The novel double-layer detection method for DoS attack in power system according to claim 1 is characterized in that: Judging, according to the second judgment basis, whether a potential attack occurs in the packet feature includes: The second judgment basis includes the following five judgment conditions: ; ; ; ; ; In the formula, Indicates the transmission time The entropy of the source IP address of the packet feature; Indicates the number of package features; Indicates the number of features in the i-th package is The probability of the source IP address appearing; Indicates the transmission time The entropy of the destination IP address of the packet feature; represents the number of regulatory centers; Indicates the number of the o-th control center The probability of the destination IP address appearing; Indicates the transmission time Entropy of the source port address of the packet feature; Indicates the entropy of a normal source port address; Indicates the transmission time The entropy of the destination port address of the packet feature; Indicates the entropy of a normal destination port address; Indicates the transmission time Entropy of packet type of packet features; The entropy representing the characteristic type of normal packets; If the packet feature satisfies any one of the discrimination conditions in the second judgment basis, then a potential attack occurs to the packet feature, a potential packet feature is obtained, and a second layer detection is performed on the potential packet feature.
5. The novel double-layer detection method for DoS attack in power system according to claim 1 is characterized in that: The construction of the attack prediction model includes: The parallel temporal attention mechanism, convolutional attention mechanism, and multimodal fusion module are sequentially added between the hidden state layer and the fully connected layer of the BILSTM model to obtain a constructed attack prediction model.
6. The novel double-layer detection method for DoS attack on power system according to claim 1 is characterized in that: Generating a baseline probability according to the acquired dynamic threshold comprises: ; ; In the formula, represents the initial baseline probability; Represents the moving average of the historical normal traffic attack probability; represents the confidence coefficient; The standard deviation representing the sampling window size; represents the final baseline probability; represents the adjustment coefficient; Indicates the business importance coefficient.
7. The novel double-layer detection method for DoS attack in power system according to claim 1 or 6, characterized in that: Comparing the baseline probability with the predicted value of the probability distribution of the DoS attack, a DoS attack detection result is obtained, including: If the predicted value of the probability distribution of the DoS attack is greater than the baseline probability, a DoS attack occurs; if the predicted value of the probability distribution of the DoS attack is not greater than the baseline probability, no DoS attack occurs.
8. A new dual-layer detection system for DoS attacks on power systems, characterized in that: include: A feature acquisition module is used to acquire state features and packet features of the new power system when transmitting electrical data; A state feature pre-detection module is used to perform feature filtering on the state feature in the first layer detection to obtain attack features, and determine whether a potential attack occurs with the attack features according to a preset first judgment basis; If a potential attack occurs, a potential state feature is obtained, and a second layer detection is performed on the potential state feature; A packet feature pre-detection module, used to calculate the information entropy of the packet feature in the first layer detection, obtain a second judgment basis using the information entropy, and judge whether the packet feature has a potential attack according to the second judgment basis; If a potential attack occurs, a potential packet feature is obtained, and a second layer detection is performed on the potential packet feature; A DoS attack detection module, for inputting the potential state features and potential packet features into a pre-built attack prediction model when performing the second layer detection, and outputting a probability distribution prediction value of the DoS attack; Generate a baseline probability according to the obtained dynamic threshold, and compare the baseline probability with the predicted value of the probability distribution of the DoS attack to obtain a DoS attack detection result; The preset first judgment basis includes a first judgment basis for a DDoS attack and a first judgment basis for a LDoS attack; The first judgment basis of the DDoS attack is expressed as: ; ; ; ; In the formula, Indicates the delay feature in the attack feature The numerical value and; Indicates the transmission time; represents the delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the packet loss rate feature in the attack feature The numerical value and; Indicates the packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate; Indicates the transmission rate correction parameter; Indicates the minimum value of the port transmission rate in the attack signature; Indicates the minimum port transmission rate that the system can tolerate; Indicates the maximum CPU usage in the attack signature; Indicates CPU usage correction parameter; Indicates the maximum CPU usage that the system can tolerate; The first judgment basis of the LDoS attack is expressed as: ; ; In the formula, The function represents the number of values that satisfy the condition; Indicates the delay feature in the attack feature; represents the periodic delay correction parameter; Indicates the additional delay that the system can tolerate; Indicates the attack frequency of LDoS attack; Indicates the packet loss rate feature in the attack feature; Indicates the periodic packet loss rate correction parameter; Indicates the packet loss rate that the system can tolerate.
Citation Information
Patent Citations
Ocean sensor network DOS attack intrusion detection method based on RESNETCNN
CN117834269A
LDDoS attack detection method based on multi-model feature fusion arbitration
CN118487786A