Network attack identification and blocking method and system based on deep packet inspection
By using deep packet detection technology in the smart substation network to identify and block network attacks, the service interruption and economic losses caused by network attacks in the power grid system are solved, and the stability and security of the power grid communication network are achieved.
Patent Information
- Application Number
- CN202411891678.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-06
AI Technical Summary
How to effectively identify and block network attacks against smart substation networks and prevent service interruptions and economic losses caused by network attacks by power grid systems.
Using a deep packet detection method, by capturing messages in the intelligent substation network, using DPI technology to parse messages, extracting key features in header information and application data, matching with the malicious network behavior fingerprint library to identify known attacks, and conducting traffic behavior analysis on unmatched data packets, identifying abnormal traffic patterns and behaviors, and finally taking corresponding blocking measures.
Effectively identify and block complex network attacks, reduce the risk of service interruption caused by network attacks in the power grid system, reduce economic losses, improve adaptability to new threats, and ensure the stability and security of the power grid communication network.
Smart Images

Figure CN119945718A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security technology, and in particular to a network attack identification and blocking method and system based on deep packet inspection. Background Art
[0002] With the integration of computer networks and traditional power grid systems, the power grid system is developing towards networking and intelligence. Through computer network technology, the power grid system can achieve more intelligent resource management and optimal configuration, but at the same time, it may also cause the power grid system to be subject to various network attacks, bringing different degrees of security risks. Once the power grid system, especially the substation in the power grid system, is interrupted due to malicious network attacks, it will cause serious economic losses and bring bad social impacts.
[0003] Cyber attacks can be understood as any network behavior that undermines the three elements of network security (confidentiality, integrity, and availability), tracks the behavior of communication systems and control systems without permission, and attacks the system itself or resources by exploiting loopholes and security flaws in the power grid system communication network. Cyber attack behavior refers to the attacker's malicious operation of computer systems, networks, or information through various technical means and strategies to achieve specific purposes. There are many types of network attack behaviors, including denial of service attacks (DDoS), SQL injection attacks, etc. How to use appropriate methods to identify and block network attacks to ensure the stability and security of substation network systems is an urgent problem that needs to be solved. Summary of the invention
[0004] The purpose of this section is to summarize some aspects of embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of this application to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.
[0005] In view of the above existing problems, the present invention is proposed.
[0006] Therefore, the present invention provides a network attack identification and blocking method and system based on deep packet inspection, which can solve the problems mentioned in the background technology.
[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0008] In a first aspect, the present invention provides a network attack identification and blocking method based on deep packet inspection, comprising capturing messages in a smart substation network;
[0009] Parse the message through DPI technology, extract key features from header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks;
[0010] Perform traffic behavior analysis on packets that do not match known attacks to identify abnormal traffic patterns and behaviors;
[0011] Take appropriate blocking measures based on the identification results.
[0012] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, the message in the smart substation network is captured, including
[0013] Capture messages by using network monitoring tools or network traffic packet capture tools;
[0014] The captured messages are preprocessed to obtain a message set MC = {M1, M2, ..., Mn}.
[0015] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, the header information includes but is not limited to IP address, port number, and timestamp.
[0016] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, the key features in the application data are extracted, including
[0017] According to the predefined content feature library, character strings containing key features are extracted from application data.
[0018] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, the flow behavior analysis of the data packets that do not match the known attack is performed, including
[0019] Analyze the sequence, size, frequency, and duration of packets to identify anomalies in traffic and determine changes in traffic patterns.
[0020] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, wherein: taking corresponding blocking measures, including
[0021] Use firewalls to control data traffic in and out of the network, and deploy honeypot technology to attract potential attackers to visit and analyze their behavior details.
[0022] As a preferred solution of the network attack identification and blocking method based on deep packet inspection of the present invention, the method further includes:
[0023] Update the newly identified malicious network attack behavior features into the malicious network behavior fingerprint library;
[0024] Regularly obtain the latest malware or attack pattern feature values from security agencies and open source community sources, and update them to the feature database.
[0025] In a second aspect, the present invention provides a network attack identification and blocking system based on deep packet inspection, comprising: a capture module for capturing messages in a smart substation network;
[0026] Parsing and matching module, used to parse the message through DPI technology, extract key features in header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks;
[0027] An analysis module that performs traffic behavior analysis on packets that do not match known attacks and identifies abnormal traffic patterns and behaviors;
[0028] The measures module is used to take corresponding blocking measures according to the identification results.
[0029] In a third aspect, the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0030] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when the computer program is executed by a processor.
[0031] Compared with the prior art, the beneficial effects of the present invention are as follows: through precise deep packet inspection and behavior analysis, it can effectively identify and block complex network attacks against smart substation networks, thereby reducing the risk of service interruption caused by network attacks on the power grid system, reducing potential economic losses, and improving the adaptability to new threats, ensuring the stability and security of the power grid communication network. At the same time, by real-time updating of the malicious network behavior fingerprint library, the system's defense capabilities against emerging network threats are enhanced. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:
[0033] Figure 1 The figure is a flowchart of a network attack identification and blocking method based on deep packet inspection.
[0034] Figure 2 Record instances for fingerprinting known malicious network behavior.
[0035] Figure 3 These are some of the known network attack types.
[0036] Figure 4 HTTP request header and response header instances.
[0037] Figure 5 To use honeypot technology to further analyze unidentified abnormal behaviors.
[0038] Figure 6 A schematic diagram of the internal structure of a computer device. DETAILED DESCRIPTION
[0039] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0040] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0041] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0042] Example 1
[0043] Reference Figure 1 to Figure 5 , which is the first embodiment of the present invention, and provides a network attack identification and blocking method based on deep packet inspection, which includes:
[0044] S1. Capture messages in the smart substation network.
[0045] Furthermore, the messages in the smart substation network are captured, including
[0046] Capture messages by using network monitoring tools or network traffic packet capture tools;
[0047] The captured messages are preprocessed to obtain a message set MC = {M1, M2, ..., Mn}.
[0048] It should be noted that the preprocessing includes denoising and filtering of the captured messages. The denoising operation is mainly to remove message errors caused by channel noise; the filtering operation is mainly to filter out messages that do not meet the specifications or have errors, and obtain a message set MC = {M1, M2, ..., Mn} that can be used for subsequent processing.
[0049] S2. Parse the message through DPI technology, extract key features from header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks.
[0050] It should be noted that Deep Packet Inspection (DPI), also known as full packet detection or information extraction, is a computer network packet filtering technology. DPI technology is a traffic detection and control technology based on the application layer. Compared with ordinary message detection, which only analyzes the content below the 4th layer of the IP packet, including the source address, destination address, source port, destination port, and protocol type; in addition to the previous layer analysis, DPI technology also adds application layer analysis to identify various applications and their contents. DPI technology can deeply read the content of the data packet payload to reorganize the application layer information in the OSI seven-layer protocol, thereby obtaining the content of the entire application.
[0051] It should be further explained that the Malicious Network Behavior Fingerprint Library (MNBFL) is a database used to identify, classify and defend against malicious network behaviors. MNBFL can be represented as a collection of malicious network behavior fingerprint records, that is, where is the i-th malicious network behavior fingerprint record in MNBFL. The content of each record includes a feature value (fingerprint), an application layer protocol, a malicious behavior type, a malicious behavior description, an update time, etc., that is, for each malicious network behavior fingerprint record R, it can be represented as where is the feature value of the record, is the application layer protocol used, is the malicious behavior type, a malicious behavior description, and indicates the update time of the record, such as Figure 2 The figure shows two malicious network behavior fingerprint records representing SQL injection and cross-site scripting attacks. Some commonly used network malicious behavior fingerprints use regular expressions to describe or define the characteristic values of the records. MNBFL contains known malicious network behavior fingerprints, including SQL injection attacks, command execution (cmd), code execution (code), cross-site scripting attacks XSS, backdoors, WebShell, etc. Some known network attack types are as follows: Figure 3 shown.
[0052] Furthermore, the header information includes but is not limited to IP address, port number, and timestamp.
[0053] It should be noted that the first message M1 is taken out from the message set MC, and the DPI technology is first used to decode the captured data packet header, and the data packet M1 is separated into two parts: the data packet header Head and the application data Data (according to the OSI seven-layer model and 802.3, 8802-3 standard specifications); then the header information (such as IP address, port number, etc.) and timestamp of the data packet M1 are obtained from the header Head; and then the application layer protocol P used in the data packet is identified by analyzing the specific fields or signatures in the data packet header. For example, for the HTTP protocol, DPI can determine whether it contains HTTP features by analyzing the header Head of the data packet, such as the request method (GET, POST, PUT, etc.), status code (200, 404, etc.), content type (Content-Type), user agent (User-Agent) and other fields, HTTP request message header and response message header such as Figure 4 shown.
[0054] Furthermore, key features of the application data are extracted, including
[0055] According to the predefined content feature library, character strings containing key features are extracted from application data.
[0056] It should be noted that the content feature library is one of the core components of deep packet inspection (DPI) technology, which is mainly used to store and manage the feature information of various network protocols. The PCD database helps network devices (such as firewalls, intrusion detection systems, traffic analyzers, etc.) identify and analyze data transmitted through the network. These features usually include: (1) Protocol name: a name that uniquely identifies the protocol (for example, HTTP, FTP, GOOSE, etc.); (2) Protocol type: a layer that defines the protocol (such as application layer, transport layer, network layer, etc.); (3) Feature string: a signature string or structure in the protocol (for example, HTTP's GET and POST methods, GOOSE's specific fields and structures, etc.); (4) Port number: some protocols use specific ports, and the PCD database will record this information (for example, HTTP usually uses port 80, and GOOSE usually uses port 102).
[0057] It is further necessary to explain that the content in the application data Data is parsed, and the string chaStr containing key features is extracted from the application data Data according to the keywords and regular expressions defined in the content feature library, for example: SQL statements, the string contains keywords such as Insert, Update, Drop, etc.; command execution, including system commands such as cat, cmd.exe, powershell, etc.; code execution, including the use of unique identifiers and function calls of programming languages, such as eval(), exec(), system(), shell_exec(), etc. Among them, regular expressions (regular expressions, referred to as regular expressions) are also called regular expressions. They are a powerful text processing tool for matching, searching and replacing specific patterns in text, including ordinary characters (for example, letters between a and z) and special characters (called "meta characters"). Regular expressions are a logical formula for string operations, that is, using some pre-defined specific characters and combinations of these specific characters to form a "regular string". This "regular string" is used to express a filtering logic for the string, and is usually used to retrieve and replace text that meets a certain pattern (rule). Its main functions include: (1) pattern matching, which can identify strings in a specific format, such as email addresses, phone numbers, etc.; (2) string search, which can quickly find content that matches a specific pattern in a large amount of text; (3) text replacement, which can replace strings according to the matched pattern; (4) input validation, which can check whether the user input conforms to the predetermined format (such as password complexity, date format, etc.), etc. For example, a regular expression used to match the basic syntax structure of the database table data insertion (INSERT) operation in an SQL statement can be designed as follows: INSERT\s+INTO\s+([\w\.]+)\s*$([\w,\s]+)$\s+VALUES\s*$([^)]+)$.
[0058] It should be further explained that the character string chaStr containing the key features is compared with the known malicious network behavior fingerprints in the malicious network behavior fingerprint library. If chaStr matches a specific malicious network behavior fingerprint, the corresponding fingerprint record is extracted and corresponding blocking measures are taken.
[0059] S3. Perform traffic behavior analysis on packets that do not match known attacks to identify abnormal traffic patterns and behaviors.
[0060] It should be noted that traffic behavior analysis refers to the monitoring and analysis of data packets transmitted in the network to identify the characteristics and patterns of normal traffic and detect abnormal or suspicious traffic. Its main goal is to discover potential security threats or performance issues by understanding the typical behavior of network traffic. Behavioral pattern detection refers to the identification of specific patterns of network traffic by building models, especially focusing on the detection of abnormal or malicious behavior. It usually uses statistical analysis, machine learning and artificial intelligence techniques to automatically identify and classify behavioral patterns from data. Traffic behavior analysis provides a basic data collection and analysis framework to identify the characteristics of normal and abnormal traffic. Behavioral pattern detection uses the characteristics obtained from traffic analysis to determine whether the current traffic is normal through models, and actively identifies potential risks.
[0061] Furthermore, traffic behavior analysis is performed on packets that do not match known attacks, including
[0062] Analyze the sequence, size, frequency, and duration of packets to identify anomalies in traffic and determine changes in traffic patterns.
[0063] It should be noted that the traffic behavior analysis of the data packet set MC is performed, and the order, size, frequency and duration of the data packets are determined according to the header information (such as IP address, port number, etc.) and timestamp in {M1, M2, …, Mn}, so as to identify the change of the traffic pattern. For example: check the timestamp and sequence number of the data packet to identify the order of sending the data packet. If most of the data packets are sent at a fixed interval, but at a certain moment, the time interval changes significantly, which indicates that abnormal traffic has occurred (a certain access host suddenly initiates a large number of requests); observe whether the duration is consistent with the normal access behavior. The normal user interaction session duration is generally within a few seconds to a few minutes. If the duration of the session is abnormally long (the response time of a request exceeds 10 minutes, especially if there are no new valid requests during this period), it may indicate that there is a problem or attack in the network, etc. If one of the above abnormal traffic behaviors exists, its traffic pattern change is determined.
[0064] It should be further explained that, based on the change in traffic pattern, behavior pattern detection is further performed. The present invention mainly adopts rule-based detection, that is, a series of rules or thresholds are defined, and suspicious activities (such as excessive requests, abnormal traffic on specific ports, etc.) are identified through these predefined rules to determine the behavior pattern of data packets. For example: two abnormal traffic rules are predefined: a) If the access request from the same IP address exceeds 50 times within 1 minute, it is marked as suspicious; b) If a certain IP address attempts to access multiple different ports (more than 5 ports) within 1 minute, it is marked as scanning behavior. If when analyzing {M1, M2, ..., Mn}, it is found that the host with IP address 172.16.1.150 sent 65 requests within 1 minute and attempted to scan 10 ports within 1 minute, then it can be considered that the IP comes from a host that has been infected with malware and is trying to carry out a DDoS attack.
[0065] S4. Take corresponding blocking measures based on the identification results.
[0066] Further, take corresponding blocking measures, including
[0067] Use firewalls to control data traffic in and out of the network, and deploy honeypot technology to attract potential attackers to visit and analyze their behavior details.
[0068] It should be noted that for known attacks and unauthorized access, a firewall is used to control the data flow in and out of the network according to the information in the fingerprint record R. By updating and configuring firewall rules, network traffic can be restricted from accessing specific host ports, IP addresses or applications in the power grid system, thereby effectively preventing malicious network attacks; for abnormal behaviors that cannot be identified, honeypot technology is used to set up bait systems (or resources) to attract potential attackers to visit, capture the behavior details of potential attackers and analyze them to determine whether they will pose a threat to the power grid system; at the same time, the real system in the power grid system is isolated to protect it from attacks, such as Figure 5 shown.
[0069] Furthermore, the method also includes
[0070] The newly identified malicious network attack behavior characteristics are updated to the malicious network behavior fingerprint library, wherein the newly identified malicious network attack behavior characteristics refer to the behavior characteristics or behavior patterns determined as malicious network attacks through the analysis results of the unidentified abnormal behaviors in the above steps.
[0071] Regularly obtain the latest malware or attack pattern feature values from security agencies and open source community sources, and update them to the feature database.
[0072] In summary, the beneficial effect of a network attack identification and blocking method based on deep packet inspection is that through precise deep packet inspection and behavior analysis, it can effectively identify and block complex network attacks against smart substation networks, thereby reducing the risk of service interruption caused by network attacks in the power grid system, reducing potential economic losses, and improving the adaptability to new threats, ensuring the stability and security of the power grid communication network. At the same time, by updating the malicious network behavior fingerprint library in real time, the system's defense capabilities against emerging network threats are enhanced.
[0073] Example 2
[0074] This embodiment provides a network attack identification and blocking system based on deep packet inspection, which includes a capture module for capturing messages in a smart substation network;
[0075] Parsing and matching module, used to parse the message through DPI technology, extract key features in header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks;
[0076] An analysis module that performs traffic behavior analysis on packets that do not match known attacks and identifies abnormal traffic patterns and behaviors;
[0077] The measures module is used to take corresponding blocking measures according to the identification results.
[0078] The above-mentioned unit modules may be embedded in or independent of the processor in the computer device in the form of hardware, or may be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above-mentioned modules.
[0079] Example 3
[0080] This embodiment provides a computer device, which may be a terminal, and its internal structure diagram may be as follows: Figure 6As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a network attack identification and blocking method based on deep packet inspection is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a button, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.
[0081] This embodiment also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements: capturing messages in a smart substation network;
[0082] Parse the message through DPI technology, extract key features from header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks;
[0083] Perform traffic behavior analysis on packets that do not match known attacks to identify abnormal traffic patterns and behaviors;
[0084] Take appropriate blocking measures based on the identification results.
[0085] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A network attack identification and blocking method based on deep packet inspection, characterized in that: include, Capture messages in the smart substation network; Parse the message through DPI technology, extract key features from header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks; Perform traffic behavior analysis on packets that do not match known attacks to identify abnormal traffic patterns and behaviors; Take appropriate blocking measures based on the identification results.
2. The network attack identification and blocking method based on deep packet inspection according to claim 1, characterized in that: The capturing of messages in the smart substation network includes: Capture messages by using network monitoring tools or network traffic packet capture tools; The captured messages are preprocessed to obtain a message set MC = {M1, M2, ..., Mn}.
3. The network attack identification and blocking method based on deep packet inspection according to claim 2, characterized in that: The header information includes but is not limited to IP address, port number, and timestamp.
4. The network attack identification and blocking method based on deep packet inspection as claimed in claim 3, characterized in that: The key features of the extracted application data include: According to the predefined content feature library, character strings containing key features are extracted from application data.
5. The network attack identification and blocking method based on deep packet inspection according to claim 4, characterized in that: The traffic behavior analysis of the data packets that do not match the known attack includes Analyze the sequence, size, frequency, and duration of packets to identify anomalies in traffic and determine changes in traffic patterns.
6. The network attack identification and blocking method based on deep packet inspection according to claim 5, characterized in that: The corresponding blocking measures mentioned include Use firewalls to control data traffic in and out of the network, and deploy honeypot technology to attract potential attackers to visit and analyze their behavior details.
7. The network attack identification and blocking method based on deep packet inspection according to any one of claims 1 to 6, characterized in that: The method further comprises Update the newly identified malicious network attack behavior features into the malicious network behavior fingerprint library; Regularly obtain the latest malware or attack pattern feature values from security agencies and open source community sources, and update them to the feature database.
8. A network attack identification and blocking system based on deep packet inspection, characterized in that: include: A capture module, used to capture messages in the smart substation network; Parsing and matching module, used to parse the message through DPI technology, extract key features in header information and application data, and match them with the malicious network behavior fingerprint library to identify known attacks; An analysis module that performs traffic behavior analysis on packets that do not match known attacks and identifies abnormal traffic patterns and behaviors; The measures module is used to take corresponding blocking measures according to the identification results.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Cross-site scripting attack detection method, electronic device, and storage medium
CN122554233A