Power communication network security situation prediction method, device and equipment and storage medium

By analyzing power grid communication data in the power communication network, constructing security potential fluctuations and adaptively determining the smoothing coefficient, the problem of difficulty in determining the smoothing coefficient in traditional methods is solved, and the accuracy and real-time prediction of network security potential is improved.

CN119945714APending Publication Date: 2025-05-06国网思极网安科技(北京)有限公司 +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411882530.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The traditional exponential smoothing method is difficult to determine the smoothing coefficient in the prediction of the security potential of the power communication network, resulting in low prediction accuracy and inability to accurately monitor the security potential of the network.

Method used

By acquiring the power grid communication data of the power communication network, the potential evaluation value is obtained, and the security potential fluctuation value is constructed based on the abnormal potential change value and the stable operation index, and then the smoothing coefficient is adaptively determined.

Benefits of technology

The accuracy of prediction of the security trend of power communication networks has been improved, and real-time and accurate monitoring of the security trend of power communication networks has been achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945714A_ABST
    Figure CN119945714A_ABST
Patent Text Reader

Abstract

The invention provides an electric power communication network security state prediction method, device and equipment and a storage medium, and the method comprises the steps: analyzing the security state of an electric power communication network, obtaining a state evaluation value, considering a state abnormal change value and a stable operation index, and constructing a security state fluctuation value. Furthermore, the smoothing coefficient is determined by using the security attitude fluctuation value, so that the smoothing coefficient can be matched with the response speed during prediction of the security attitude of the communication network, and the problem of low accuracy of prediction of the security attitude of the network caused by too large or too small smoothing coefficient determined manually in the prior art is solved. And the accuracy of predicting the network security state is improved, so that the network security state can be monitored in real time more accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things security technology, and in particular to a method, device, equipment and storage medium for predicting power communication network security status. Background Art

[0002] At present, in the development of power communication network security, security issues at the network communication level and the physical level are more prominent. For example, the destruction of power communication cables and the attack on the communication network will have a great impact on the normal use of the network, causing the power communication network security to be threatened to a great extent. Therefore, the current safe operation of the power communication network faces increasingly severe tests. Therefore, in the operation process of the power communication network, the monitoring of the security status of the power communication network has important practical significance and has a wide range of uses in the power communication network system.

[0003] Most existing technologies obtain power grid data through the Internet platform, extract features of network security trends based on power grid data, and use prediction algorithms and feature extraction to predict network security trends to achieve monitoring of network security trends. For example, common prediction algorithms such as exponential smoothing can achieve rapid prediction of network security trends. However, the smoothing coefficient of traditional exponential smoothing methods is often difficult to determine. When using exponential smoothing methods to predict network security trends, it is easy to encounter problems such as too large or too small smoothing coefficients, resulting in low accuracy in predicting network security trends, which in turn makes it impossible to accurately monitor network security trends. Summary of the invention

[0004] In view of this, the purpose of this application is to propose a method, device, equipment and storage medium for predicting the security situation of a power communication network to solve or partially solve the above-mentioned problems.

[0005] Based on the above purpose, in a first aspect, the present application provides a method for predicting the security status of a power communication network, comprising:

[0006] Acquire power grid communication data in the power communication network, wherein the power grid communication data includes at least one of an alarm identifier and a repair time sequence;

[0007] Analyzing the security status of the power communication network based on the power grid communication data to obtain a status evaluation value;

[0008] Determining an abnormal change value of the state of the power communication network by using the state evaluation value;

[0009] Based on the abnormal change value of the trend and the stable operation index of the power communication network security, a safety trend fluctuation value is obtained;

[0010] Determining a smoothing coefficient based on the safety state fluctuation value;

[0011] The exponential smoothing method is used to predict the network security situation based on the smoothing coefficient.

[0012] Optionally, the analyzing the security status of the power communication network based on the power grid communication data to obtain a status evaluation value further includes:

[0013] A sequence consisting of a plurality of alarm times corresponding to the alarm events of the plurality of alarm identifiers in chronological order is used as an alarm time sequence;

[0014] Calculating the first-order difference sequence of the alarm time series;

[0015] taking the mean of the elements in the first-order difference sequence as the average time difference of each alarm identifier in the plurality of alarm identifiers;

[0016] converting the average time difference into an average difference in seconds;

[0017] determining the frequency of each alarm identifier according to the power grid communication data;

[0018] Obtaining the urgency of the alarm event of each alarm identifier according to the ratio of the average second difference to the frequency;

[0019] The situation assessment value is obtained according to the urgency of the alarm event.

[0020] Optionally, obtaining the situation assessment value according to the urgency of the alarm event further comprises:

[0021] Calculating the mean of the repair durations in the repair duration sequence, and taking the mean as the average repair duration;

[0022] The situation assessment value is obtained according to the urgency of the alarm event and the average repair time.

[0023] Optionally, the determining the abnormal change value of the state of the power communication network by using the state evaluation value further comprises:

[0024] Taking a sequence of the plurality of state evaluation values ​​in ascending time order as a state time series of the power communication network security;

[0025] Obtaining a plurality of state distance values ​​according to each state evaluation value in the state time series;

[0026] Using the sequence composed of the multiple potential distance values ​​as a potential distance sequence;

[0027] The set of potential distance values ​​above the threshold is regarded as a high potential distance set;

[0028] The set of potential distance values ​​below the threshold is regarded as a low potential distance set;

[0029] The abnormal trend change value is obtained according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

[0030] Optionally, obtaining the safety trend fluctuation value based on the abnormal trend change value combined with the stable operation index of power communication network safety further includes:

[0031] Determining a dynamic time warping distance between the repair duration sequences;

[0032] determining a Jaccard similarity coefficient between the sets of alarm identifiers;

[0033] Obtaining the stable operation index according to the Jaccard similarity coefficient and the dynamic time warping distance;

[0034] The safety state fluctuation value is obtained based on the abnormal state change value and the stable operation index.

[0035] Optionally, determining a smoothing coefficient based on the safety situation fluctuation value further comprises:

[0036] Obtaining a trend change similarity based on the safety trend fluctuation value;

[0037] The smoothing coefficient is obtained by using the similarity of the trend change.

[0038] Optionally, determining a smoothing coefficient based on the safety state fluctuation value further comprises:

[0039] Obtaining the trend change similarity according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value;

[0040] An exponential function is used to negatively map the trend change similarity to obtain the smoothing coefficient.

[0041] In a second aspect of the present application, a power communication network security situation prediction device is provided, comprising:

[0042] An acquisition module is configured to acquire power grid communication data in the power communication network, wherein the power grid communication data includes at least one of an alarm identifier and a repair time sequence;

[0043] A first calculation module is configured to analyze the security status of the power communication network based on the power grid communication data to obtain a status evaluation value;

[0044] A second calculation module is configured to determine an abnormal change value of the state of the power communication network using the state evaluation value;

[0045] A third calculation module is configured to obtain a safety state fluctuation value based on the abnormal change value of the state and the stable operation index of the power communication network security;

[0046] a fourth calculation module, configured to determine a smoothing coefficient based on the safety state fluctuation value;

[0047] The prediction module is configured to predict the network security situation based on the smoothing coefficient using an exponential smoothing method.

[0048] Optionally, the first computing module is further configured to:

[0049] A sequence consisting of a plurality of alarm times corresponding to the alarm events of the plurality of alarm identifiers in chronological order is used as an alarm time sequence;

[0050] Calculating the first-order difference sequence of the alarm time series;

[0051] taking the mean of the elements in the first-order difference sequence as the average time difference of each alarm identifier in the plurality of alarm identifiers;

[0052] converting the average time difference into an average difference in seconds;

[0053] determining the frequency of each alarm identifier according to the power grid communication data;

[0054] Obtaining the urgency of the alarm event of each alarm identifier according to the ratio of the average second difference to the frequency;

[0055] The situation assessment value is obtained according to the urgency of the alarm event.

[0056] Optionally, the first computing module is further configured to:

[0057] Calculating the mean of the repair durations in the repair duration sequence, and taking the mean as the average repair duration;

[0058] The situation assessment value is obtained according to the urgency of the alarm event and the average repair time.

[0059] Optionally, the second computing module is further configured to:

[0060] Taking a sequence of the plurality of state evaluation values ​​in ascending time order as a state time series of the power communication network security;

[0061] Obtaining a plurality of state distance values ​​according to each state evaluation value in the state time series;

[0062] Using the sequence composed of the multiple potential distance values ​​as a potential distance sequence;

[0063] The set of potential distance values ​​above the threshold is regarded as a high potential distance set;

[0064] The set of potential distance values ​​below the threshold is regarded as a low potential distance set;

[0065] The abnormal trend change value is obtained according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

[0066] Optionally, the third calculation module is further configured to:

[0067] Determining a dynamic time warping distance between the repair duration sequences;

[0068] determining a Jaccard similarity coefficient between the sets of alarm identifiers;

[0069] Obtaining the stable operation index according to the Jaccard similarity coefficient and the dynamic time warping distance;

[0070] The safety state fluctuation value is obtained based on the abnormal state change value and the stable operation index.

[0071] Optionally, the fourth calculation module is further configured to:

[0072] Obtaining a trend change similarity based on the safety trend fluctuation value;

[0073] The smoothing coefficient is obtained by using the similarity of the trend change.

[0074] Optionally, the fourth calculation module is further configured to:

[0075] Obtaining the trend change similarity according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value;

[0076] An exponential function is used to negatively map the trend change similarity to obtain the smoothing coefficient.

[0077] In a third aspect of the present application, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.

[0078] According to a fourth aspect of the present application, a non-transitory computer-readable storage medium is provided, wherein the non-transitory computer-readable storage medium stores computer instructions, wherein the computer instructions are used to enable a computer to execute the method described in the first aspect.

[0079] From the above, it can be seen that the present application provides a method, device, equipment and storage medium for predicting the security situation of a power communication network. The method analyzes the security situation of the power communication network to obtain a situation evaluation value, and considers the abnormal change value of the situation and the stable operation index to construct a safety situation fluctuation value. Furthermore, the smoothing coefficient is determined by using the safety situation fluctuation value, so that the smoothing coefficient can match the response speed when predicting the security situation of the communication network, which solves the problem of low accuracy in predicting the network security situation due to the traditional manually determined smoothing coefficient being too large or too small, improves the accuracy of predicting the network security situation, and thus more accurately monitors the network security situation in real time. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] In order to more clearly illustrate the technical solutions in the present application or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0081] Figure 1 A schematic diagram showing an exemplary application scenario according to an embodiment of the present application is shown.

[0082] Figure 2 A flowchart of an exemplary power communication network security situation prediction method according to an embodiment of the present application is shown.

[0083] Figure 3 A flowchart of an exemplary power communication network security situation prediction method according to an embodiment of the present application is shown.

[0084] Figure 4 A schematic diagram of an exemplary power communication network security situation prediction device according to an embodiment of the present application is shown.

[0085] Figure 5 A schematic diagram of an exemplary electronic device according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0086] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0087] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present application belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0088] As mentioned above, most of the existing technologies obtain power grid data through the Internet platform, extract features of network security trends based on the power grid data, and use prediction algorithms to predict network security trends to achieve network security trend monitoring. For example, common prediction algorithms such as exponential smoothing can achieve rapid prediction of network security trends. However, the smoothing coefficient of the traditional exponential smoothing method is often difficult to determine. When using the exponential smoothing method to predict network security trends, it is easy to have problems due to the smoothing coefficient being too large or too small, resulting in low accuracy in predicting network security trends, which in turn leads to the inability to accurately monitor network security trends.

[0089] In order to at least solve the above problems, the present application proposes a method, device, equipment and storage medium for predicting the security situation of a power communication network. The method analyzes the security situation of the power communication network to obtain a situation evaluation value, and considers the abnormal change value of the situation and the stable operation index to construct a safety situation fluctuation value. Then, the smoothing coefficient is determined by using the safety situation fluctuation value, so that the smoothing coefficient can match the response speed when predicting the security situation of the communication network, solving the problem that the accuracy of predicting the network security situation is low due to the traditional manually determined smoothing coefficient being too large or too small, improving the accuracy of predicting the network security situation, and thus more accurately monitoring the network security situation in real time.

[0090] Figure 1 A schematic diagram of an exemplary application scenario 100 according to an embodiment of the present application is shown.

[0091] like Figure 1As shown, the application scenario 100 may include a terminal 102 and a server 104. The server 104 may be connected to the terminal 102 via a network, and the network may include but is not limited to a wide area network, a metropolitan area network, or a local area network. The terminal 102 includes but is not limited to a personal computer, a mobile phone, a tablet computer, etc. The power communication network security state prediction method of the embodiment of the present application may be executed by the server 104, or by the terminal 102, or by the terminal 102 and the server 104. Among them, the terminal 102 may execute the power communication network security state prediction method of the embodiment of the present application, or it may be executed by a client installed thereon.

[0092] Figure 2 A flowchart of an exemplary method for predicting power communication network security status according to an embodiment of the present application is shown. Figure 2 As shown, the method may include the following steps.

[0093] S101: Collect and pre-process grid communication data.

[0094] The purpose of this embodiment is to improve the smoothing coefficient in the exponential smoothing method according to the changes in the network security trend characteristics in the power grid communication data, so as to avoid the problem of low accuracy in predicting the network security trend due to the smoothing coefficient being too large or too small, and to improve the accuracy of monitoring the network security trend.

[0095] In some embodiments, a log collector can be used to obtain device logs of the power communication network system from the power communication network system, and the device logs include all alarm identifiers and alarm times recorded daily, the number of security vulnerabilities recorded daily, and the patching time of each security vulnerability.

[0096] Grid communication data is collected from the equipment log of the power communication network system, and the grid communication data includes equipment log information data for the last 30 days. At the same time, a data cleaning method is used to process missing values ​​and delete duplicate items in the alarm time recorded every day. Data cleaning is a well-known technology and the specific process will not be repeated here.

[0097] The sequence consisting of the patching time of all security vulnerabilities in the device log data every day is used as the daily patching time sequence.

[0098] S102: Analyze the security situation of the electric power communication network to obtain a situation evaluation value, use the situation evaluation value to obtain a situation abnormal change value, obtain a safety situation fluctuation value based on the situation abnormal change value and in combination with the stable operation characteristics of the electric power communication network security, obtain a situation change similarity based on the safety situation fluctuation value, and use the situation change similarity to improve the smoothing coefficient when predicting using the exponential smoothing method.

[0099] Network security trends include the changing trends and security status of the current communication network. Usually, when evaluating network security trends, we can analyze and summarize based on the alarm types, vulnerability patches and other information recorded in the device logs to construct an assessment result of the network security trends.

[0100] Generally speaking, when the power communication network is attacked by multiple types of attacks on a certain day, the alarm types on that day will be more complex. The higher the frequency of alarms in the power communication network system and the longer it takes to patch security vulnerabilities, the lower the network security situation of the power communication network, that is, the worse the stability of the power communication network security.

[0101] In some embodiments, a sequence consisting of all alarm times of alarm events corresponding to each alarm identifier recorded in the device every day in chronological order can be used as an alarm time sequence, and a first-order difference sequence of the alarm time sequence can be calculated. At this time, the elements in the first-order difference sequence represent the time difference between two adjacent alarm events of the same type. The calculation of the first-order difference sequence is a well-known technology, and the specific process will not be repeated here.

[0102] In some embodiments, the mean of all elements in the first-order difference sequence can be used as the average time difference of each alarm identifier, and the average time difference can be converted into an average second difference. For example, if the average time difference is 30 minutes, the average time difference can be converted into seconds to obtain an average second difference of 1800 seconds. The frequency of each alarm identifier recorded in the equipment every day is calculated, and the ratio of the frequency of each alarm identifier to the average second difference is used as the alarm event urgency of each alarm identifier. The greater the urgency of the alarm event, the more urgent it is to process the alarm event corresponding to this alarm identifier.

[0103] In some embodiments, the average of all the repair times in the repair time sequence of each day can be calculated and recorded as the average repair time of each day. The longer the average repair time is, the more difficult it is to repair the security vulnerabilities that appear on that day, and the worse the stability of the security situation of the power communication network is.

[0104] In some embodiments, a daily power communication network security status assessment value may be calculated:

[0105] Where D t is the security assessment value of the power communication network on the tth day, exp() is an exponential function with a natural constant as the base, is the average repair time on day t, n t is the number of all alarm identifiers recorded on day t, a t,iis the alarm event urgency of the ith alarm identifier recorded on the tth day. The longer the average repair time and the higher the alarm event urgency, to a certain extent, it shows that the security status of the power communication network on that day is worse and the change trend is more unstable, that is, the worse the stability of the communication network security situation is, the smaller the situation assessment value is.

[0106] In order to realize intelligent real-time monitoring of the security status of power communication network, this application uses exponential smoothing method to predict the status evaluation value to realize real-time monitoring of the security status of power communication network. However, the smoothing coefficient in the traditional exponential smoothing method is difficult to determine, and it is easy to have the problem of too large or too small smoothing coefficient, resulting in low accuracy in predicting the security status of communication network, and thus unable to accurately monitor the security status of communication network in real time. In order to solve the problems existing in the traditional exponential smoothing method, this application adaptively calculates the smoothing coefficient according to the changing characteristics of the security status of communication network.

[0107] In some embodiments, a sequence of power communication network security trend assessment values ​​within the last 30 days in ascending chronological order can be used as a power communication network security trend time series. A 1×11 window is set with each trend assessment value in the trend time series as the center. If there are less than 11 elements in the window, the mean filling method is used for filling.

[0108] In some embodiments, the Euclidean distance between each trend evaluation value in the trend time series and each other trend evaluation value in its window can be used as the trend distance value of each other trend evaluation value in the window, and the sequence composed of the trend distance values ​​of all other trend evaluation values ​​in the window can be used as the trend distance sequence of each trend evaluation value. The greater the distribution difference of the trend distance values ​​in the trend distance sequence, to a certain extent, it indicates that the abnormal change in the security trend of the power communication network on that day is greater.

[0109] In order to analyze the distribution differences of potential distance values ​​within the potential distance sequence, in some embodiments, the potential distance sequence can be used as the input of the maximum inter-class variance algorithm, the set of potential distance values ​​above the threshold is used as the high potential distance set, the set of potential distance values ​​below the threshold is used as the low potential distance set, and the output of the maximum inter-class variance algorithm is used as the high potential distance set and the low potential distance set, where the maximum inter-class variance algorithm is a well-known technology and the specific process will not be repeated here.

[0110] In some embodiments, the abnormal change value of the power communication network security trend can be calculated every day:

[0111] R t =δ t ×(sd t -sg t ), where R tis the abnormal change value of the power communication network security on day t, sd t and sg t are the means of the high potential distance set and the low potential distance set of the potential distance sequence of the power communication network security assessment value on the tth day, δ t is the mean square error of the potential distance sequence of the power communication network security assessment value on the tth day. The larger the mean square error of the potential distance sequence and the greater the difference between the means of the high potential distance set and the low potential distance set, the greater the distribution difference of the potential distance values ​​in the potential distance sequence, which to a certain extent reflects that the greater the abnormal change in the power communication network security situation on that day, the greater the abnormal change value of the situation.

[0112] Generally speaking, the higher the similarity between the alarm identifiers recorded on different days, the more it can be said that no new types of alarm events have occurred in the power communication network at this time. At the same time, the higher the similarity between the patching time sequences on different days, the more it can be said that the power communication network system is more stable in patching security vulnerabilities at this time, and the power communication network can operate safely and stably at this time.

[0113] Based on the above analysis, in some embodiments, the stable operation index of the power communication network security can be calculated every day:

[0114] In the formula, H t is the stable operation index of power communication network security on day t, m is the number of days for data collection, J t,j is the Jaccard similarity coefficient between the set of all alarm identifiers recorded on day t and the set of all alarm identifiers recorded on day j, Dt t,j is the DTW (dynamic time warping) distance between the repair time sequence of the tth day and the repair time sequence of the jth day, τ t,j is a criterion. When t=j, τ t,j The value of is 0; when t≠j, τ t,j The value of is 1, ∈ is an error parameter to avoid the denominator being 0. In this embodiment, the value is 0.1. The larger the Jaccard similarity coefficient and the smaller the DTW distance, the more it can be explained that there is no new type of alarm event in the current power communication network, and the more it can be explained that the power communication network system is more stable in patching security vulnerabilities at this time, and the greater the stable operation index of the power communication network security.

[0115] Generally speaking, the higher the stability of the secure operation of the power communication network and the smaller the abnormal changes in the security situation of the power communication network, to a certain extent, it means that the fluctuation of the security situation during the operation of the power communication network is smaller.

[0116] Based on the above analysis, in some embodiments, the safety trend fluctuation value of the power communication network operation can be calculated every day:

[0117] V t =H t / R t +∈, where V t is the safety trend fluctuation value of the power communication network operation on day t. The safety trend fluctuation value reflects the fluctuation characteristics of the security trend of the power communication network. The larger the safety trend fluctuation value, the greater the fluctuation characteristics of the safety trend when the power communication network is operating on that day.

[0118] Generally speaking, the higher the average level of the safety situation fluctuations on different days and the greater the discrete level of the safety situation fluctuations on different days, to a certain extent, it means that the similarity of the changes in the security situation of the power communication network is smaller. At this time, when using the exponential smoothing method for prediction, a larger smoothing coefficient should be selected to improve the response speed when predicting the security situation of the communication network.

[0119] In some embodiments, the smoothing coefficient after the modified exponential smoothing method can be calculated:

[0120] Where C is the similarity of the state change during the operation of the power communication network, is the mean of the fluctuation value of the safety situation during the operation of the power communication network in the past 30 days, and S is the variance of the fluctuation value of the safety situation during the operation of the power communication network in the past 30 days. The similarity of the situation change reflects the similar characteristics of the changes in the network security situation over time. The smaller the similarity of the situation change, the more unstable the changes in the network security situation in the past month, that is, the smaller the similarity of the situation change, which to a certain extent reflects the smaller similarity of the changes in the network security situation over time.

[0121] μ=exp(-C), where μ is the smoothing coefficient after the improved exponential smoothing method. By using the exponential function for negative mapping, the smoothing coefficient is made to range between 0 and 1. If the similarity of the changes in the security status of the power communication network is smaller, it means that the changes in the network security status in the past month are more unstable. At this time, the larger the smoothing coefficient should be selected, that is, the closer it is to 1, to improve the response speed when predicting the security status of the communication network, so as to obtain more accurate prediction results.

[0122] S103: Use the exponential smoothing method to predict the network security situation based on the smoothing coefficient, obtain the real-time monitoring result of the network security situation, and complete an intelligent monitoring method and system for the power communication network security situation.

[0123] In some embodiments, in order to achieve online monitoring of network security trends, the power communication network security trend time series is used as the input of the exponential smoothing method, the calculated smoothing coefficient is used as the smoothing parameter in the algorithm, and the output of the exponential smoothing method is used as the prediction result of the network security trend, wherein the exponential smoothing method is a well-known technology and the specific process will not be repeated here.

[0124] The prediction result of the network security situation is used as the current real-time monitoring result of the power communication network security situation, and the real-time monitoring result is transmitted to the display module of the network security situation monitoring system, and the display module is used to display the current real-time monitoring result of the power communication network security situation.

[0125] The method provided in the embodiment of the present application uses the exponential smoothing method to realize real-time monitoring of the security situation of the power communication network. Since the smoothing coefficient of the traditional exponential smoothing method is often difficult to determine, when the exponential smoothing method is used to predict the network security situation, it is easy to have the problem of too large or too small smoothing coefficient, resulting in low accuracy in predicting the network security situation. The method provided in the embodiment of the present application evaluates the network security situation and considers the abnormal characteristics of the situation during the operation of the communication network and the stable operation characteristics, and constructs a safety situation fluctuation value; then, the safety situation fluctuation value is used to calculate the similarity of the situation change, and the smoothing coefficient after the exponential smoothing method is improved so that the smoothing coefficient can match the response speed when predicting the communication network security situation, solves the problem of low accuracy in predicting the network security situation due to too large or too small smoothing coefficient, improves the accuracy of predicting the network security situation, and thus more accurately monitors the network security situation in real time.

[0126] Figure 3 FIG. 3 is a flowchart of an exemplary method 300 for predicting power communication network security status according to an embodiment of the present application. Figure 3 As shown, method 300 may include the following steps.

[0127] In step 302, grid communication data in the power communication network is acquired, wherein the grid communication data includes at least one of an alarm identifier and a repair time sequence.

[0128] In step 304, the security status of the electric power communication network is analyzed based on the power grid communication data to obtain a status evaluation value.

[0129] In some embodiments, a sequence consisting of multiple alarm times of alarm events corresponding to multiple alarm identifiers in chronological order is taken as an alarm time series; a first-order difference sequence of the alarm time series is calculated; the mean of the elements in the first-order difference sequence is taken as the average time difference of each alarm identifier in the multiple alarm identifiers; the average time difference is converted into an average second difference; the frequency of each alarm identifier is determined according to the power grid communication data; the urgency of the alarm event of each alarm identifier is obtained according to the ratio of the average second difference to the frequency; and the situation assessment value is obtained according to the urgency of the alarm event.

[0130] In some embodiments, the mean of the repair durations in the repair duration sequence is calculated and the mean is used as the average repair duration; and the situation assessment value is obtained according to the urgency of the alarm event and the average repair duration.

[0131] In step 306, the abnormal change value of the state of the power communication network is determined using the state evaluation value.

[0132] In some embodiments, a sequence consisting of multiple trend assessment values ​​in ascending time order is used as a trend time series for the security of the power communication network; multiple trend distance values ​​are obtained according to each trend assessment value in the trend time series; a sequence consisting of the multiple trend distance values ​​is used as a trend distance sequence; a set consisting of trend distance values ​​above a threshold is used as a high trend distance set; a set consisting of trend distance values ​​below a threshold is used as a low trend distance set; and the trend abnormal change value is obtained according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

[0133] In step 308, a safety trend fluctuation value is obtained based on the abnormal trend change value and the stable operation index of the power communication network security.

[0134] In some embodiments, the dynamic time warping distance between the repair duration sequences is determined; the Jaccard similarity coefficient between the sets of alarm identifiers is determined; the stable operation index is obtained based on the Jaccard similarity coefficient and the dynamic time warping distance; and the safety situation fluctuation value is obtained based on the abnormal situation change value and the stable operation index.

[0135] In step 310, a smoothing coefficient is determined based on the safety situation fluctuation value.

[0136] In some embodiments, the trend change similarity is obtained according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value; and the trend change similarity is negatively mapped using an exponential function to obtain the smoothing coefficient.

[0137] In step 312, the network security situation is predicted based on the smoothing coefficient using an exponential smoothing method.

[0138] The present application provides a method, device, equipment and storage medium for predicting the security situation of a power communication network. The method analyzes the security situation of the power communication network to obtain a situation evaluation value, and considers the abnormal change value of the situation and the stable operation index to construct a safety situation fluctuation value. Furthermore, the smoothing coefficient is determined by using the safety situation fluctuation value, so that the smoothing coefficient can match the response speed when predicting the security situation of the communication network, solving the problem of low accuracy in predicting the security situation of the network due to the traditional manually determined smoothing coefficient being too large or too small, improving the accuracy of predicting the network security situation, and thus more accurately monitoring the network security situation in real time.

[0139] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the described method.

[0140] It should be noted that the above describes some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0141] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a power communication network security situation prediction device.

[0142] refer to Figure 4 , the power communication network security situation prediction device comprises:

[0143] The acquisition module 401 is configured to acquire power grid communication data in the power communication network, wherein the power grid communication data includes at least one of an alarm identifier and a repair time sequence.

[0144] The first calculation module 402 is configured to analyze the security status of the power communication network based on the power grid communication data to obtain a status evaluation value.

[0145] The first calculation module 402 is also configured to take a sequence consisting of multiple alarm times of alarm events corresponding to multiple alarm identifiers in chronological order as an alarm time series; calculate a first-order difference sequence of the alarm time series; take the mean of the elements in the first-order difference sequence as the average time difference of each alarm identifier in the multiple alarm identifiers; convert the average time difference into an average second difference; determine the frequency of each alarm identifier according to the power grid communication data; obtain the alarm event urgency of each alarm identifier according to the ratio of the average second difference to the frequency; and obtain the situation assessment value according to the alarm event urgency.

[0146] The first calculation module 402 is further configured to calculate the mean of the repair durations in the repair duration sequence and use the mean as the average repair duration; and obtain the situation assessment value according to the urgency of the alarm event and the average repair duration.

[0147] The second calculation module 403 is configured to determine an abnormal change value of the state of the power communication network by using the state evaluation value.

[0148] The second calculation module 403 is also configured to use a sequence composed of multiple trend evaluation values ​​in ascending time order as the trend time series of the power communication network security; obtain multiple trend distance values ​​according to each trend evaluation value in the trend time series; use the sequence composed of the multiple trend distance values ​​as a trend distance sequence; use a set composed of trend distance values ​​higher than a threshold as a high trend distance set; use a set composed of trend distance values ​​lower than a threshold as a low trend distance set; and obtain the trend abnormal change value according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

[0149] The third calculation module 404 is configured to obtain a safety trend fluctuation value based on the abnormal trend change value and the stable operation index of the power communication network security.

[0150] The third calculation module 404 is also configured to determine the dynamic time warping distance between the repair duration sequences; determine the Jaccard similarity coefficient between the sets of alarm identifiers; obtain the stable operation index based on the Jaccard similarity coefficient and the dynamic time warping distance; and obtain the safety situation fluctuation value based on the abnormal situation change value and the stable operation index.

[0151] The fourth calculation module 405 is configured to determine a smoothing coefficient based on the safety situation fluctuation value.

[0152] The fourth calculation module 405 is further configured to obtain the trend change similarity according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value; and negatively map the trend change similarity using an exponential function to obtain the smoothing coefficient.

[0153] The prediction module 406 is configured to predict the network security situation based on the smoothing coefficient using an exponential smoothing method.

[0154] For the convenience of description, the above device is described in terms of functions divided into various modules. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0155] The device of the above embodiment is used to implement the corresponding method 300 in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0156] Based on the same technical concept, corresponding to any of the above-mentioned embodiments, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method 300 described in any of the above embodiments when executing the program.

[0157] Figure 5 A schematic diagram of an exemplary electronic device according to an embodiment of the present application is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other in communication within the device through the bus 1050.

[0158] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0159] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0160] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0161] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0162] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0163] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0164] The electronic device of the above embodiment is used to implement the corresponding method 300 in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0165] Based on the same technical concept, corresponding to any of the above-mentioned embodiments, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute method 300 described in any of the above embodiments.

[0166] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0167] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the method 300 described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0168] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0169] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented in the embodiments of the present application (that is, these details should be fully within the scope of understanding of those skilled in the art). In the case of elaborating specific details (e.g., circuits) to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.

[0170] Although the present application has been described in conjunction with specific embodiments of the present application, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0171] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.

Claims

1. A method for predicting the security status of a power communication network, comprising: Acquire power grid communication data in the power communication network, wherein the power grid communication data includes at least one of an alarm identifier and a repair time sequence; Analyzing the security status of the power communication network based on the power grid communication data to obtain a status evaluation value; Determining an abnormal change value of the state of the power communication network by using the state evaluation value; Based on the abnormal change value of the trend and the stable operation index of the power communication network security, a safety trend fluctuation value is obtained; Determining a smoothing coefficient based on the safety state fluctuation value; The exponential smoothing method is used to predict the network security situation based on the smoothing coefficient.

2. The method of claim 1, wherein: The analyzing the security status of the power communication network based on the power grid communication data to obtain a status evaluation value further comprises: A sequence consisting of a plurality of alarm times corresponding to the alarm events of the plurality of alarm identifiers in chronological order is used as an alarm time sequence; Calculating the first-order difference sequence of the alarm time series; taking the mean of the elements in the first-order difference sequence as the average time difference of each alarm identifier in the plurality of alarm identifiers; converting the average time difference into an average difference in seconds; determining the frequency of each alarm identifier according to the power grid communication data; Obtaining the urgency of the alarm event of each alarm identifier according to the ratio of the average second difference to the frequency; The situation assessment value is obtained according to the urgency of the alarm event.

3. The method of claim 2, wherein: The step of obtaining the situation assessment value according to the urgency of the alarm event further comprises: Calculating the mean of the repair durations in the repair duration sequence, and taking the mean as the average repair duration; The situation assessment value is obtained according to the urgency of the alarm event and the average repair time.

4. The method of claim 1, wherein: The determining the abnormal change value of the power communication network's state by using the state evaluation value further comprises: Taking a sequence of the plurality of state evaluation values ​​in ascending time order as a state time series of the power communication network security; Obtaining a plurality of state distance values ​​according to each state evaluation value in the state time series; Using the sequence composed of the multiple potential distance values ​​as a potential distance sequence; The set of potential distance values ​​above the threshold is regarded as a high potential distance set; The set of potential distance values ​​below the threshold is regarded as a low potential distance set; The abnormal trend change value is obtained according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

5. The method of claim 1, wherein: The obtaining of the safety state fluctuation value based on the abnormal change value of the state combined with the stable operation index of the power communication network safety further includes: Determining a dynamic time warping distance between the repair duration sequences; determining a Jaccard similarity coefficient between the sets of alarm identifiers; Obtaining the stable operation index according to the Jaccard similarity coefficient and the dynamic time warping distance; The safety state fluctuation value is obtained based on the abnormal state change value and the stable operation index.

6. The method of claim 1, wherein: The determining of the smoothing coefficient based on the safety state fluctuation value further comprises: Obtaining a trend change similarity based on the safety trend fluctuation value; The smoothing coefficient is obtained by using the similarity of the trend change.

7. The method of claim 6, wherein: The determining of the smoothing coefficient based on the safety state fluctuation value further comprises: Obtaining the trend change similarity according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value; An exponential function is used to negatively map the trend change similarity to obtain the smoothing coefficient.

8. A power communication network security situation prediction device, comprising: An acquisition module is configured to acquire power grid communication data in the power communication network, wherein the power grid communication data includes at least one of an alarm identifier and a repair time sequence; A first calculation module is configured to analyze the security status of the power communication network based on the power grid communication data to obtain a status evaluation value; A second calculation module is configured to determine an abnormal change value of the state of the power communication network using the state evaluation value; A third calculation module is configured to obtain a safety state fluctuation value based on the abnormal change value of the state and the stable operation index of the power communication network security; a fourth calculation module, configured to determine a smoothing coefficient based on the safety state fluctuation value; The prediction module is configured to predict the network security situation based on the smoothing coefficient using an exponential smoothing method.

9. The device of claim 8, wherein: The first computing module is further configured to: A sequence consisting of a plurality of alarm times corresponding to the alarm events of the plurality of alarm identifiers in chronological order is used as an alarm time sequence; Calculating the first-order difference sequence of the alarm time series; taking the mean of the elements in the first-order difference sequence as the average time difference of each alarm identifier in the plurality of alarm identifiers; converting the average time difference into an average difference in seconds; determining the frequency of each alarm identifier according to the power grid communication data; Obtaining the urgency of the alarm event of each alarm identifier according to the ratio of the average second difference to the frequency; The situation assessment value is obtained according to the urgency of the alarm event.

10. The device according to claim 8, wherein: The first computing module is further configured to: Calculating the mean of the repair durations in the repair duration sequence, and taking the mean as the average repair duration; The situation assessment value is obtained according to the urgency of the alarm event and the average repair time.

11. The device of claim 8, wherein: The second computing module is further configured to: Taking a sequence of the plurality of state evaluation values ​​in ascending time order as a state time series of the power communication network security; Obtaining a plurality of state distance values ​​according to each state evaluation value in the state time series; Using the sequence composed of the multiple potential distance values ​​as a potential distance sequence; The set of potential distance values ​​above the threshold is regarded as a high potential distance set; The set of potential distance values ​​below the threshold is regarded as a low potential distance set; The abnormal trend change value is obtained according to the mean of the high trend distance set, the mean of the low trend distance set and the mean square error of the trend distance sequence.

12. The device of claim 8, wherein: The third computing module is further configured to: Determining a dynamic time warping distance between the repair duration sequences; determining a Jaccard similarity coefficient between the sets of alarm identifiers; Obtaining the stable operation index according to the Jaccard similarity coefficient and the dynamic time warping distance; The safety state fluctuation value is obtained based on the abnormal state change value and the stable operation index.

13. The device of claim 8, wherein: The fourth computing module is further configured to: Obtaining a trend change similarity based on the safety trend fluctuation value; The smoothing coefficient is obtained by using the similarity of the trend change.

14. The device of claim 13, wherein: The fourth computing module is further configured to: Obtaining the trend change similarity according to the mean of the safety trend fluctuation value and the variance of the safety trend fluctuation value; An exponential function is used to negatively map the trend change similarity to obtain the smoothing coefficient.

15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.

16. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.