Interference detection method and device for power system time service attack
By applying a joint detection method based on T inspection and Z_score inspection in the power system, the problem of timing attack detection in the power system is solved, efficient detection of timing interference is achieved, and the safety and stability of the power system is improved.
Patent Information
- Application Number
- CN202510141608.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-08
AI Technical Summary
The time synchronization device in the power system is susceptible to external timing attacks, which leads to the inability to achieve precise time synchronization, which in turn threatens the safe and stable operation of the power system.
A joint detection method based on T test and Z_score test is proposed. By obtaining clock difference data under normal timing, a prediction model is constructed to predict clock difference at the next moment. Combining the sliding window and false alarm probability, a T test model and Z_score detection model are constructed to realize effective detection of timing interference.
This method can effectively detect timing interference under the condition of few samples, simplifying the detection process, reducing hardware and computing costs, and improving the accuracy and timeliness of timing interference detection in the power system.
Smart Images

Figure CN119986707A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of satellite timing technology, and in particular to an interference detection method and device for power system timing attacks. Background Art
[0002] The power system is a key infrastructure that supports economic development and protects people's lives. As the power system develops towards intelligence, automation and informatization, its dependence on precise time synchronization is increasing. The timing system based on the Global Navigation Satellite System (GNSS) is widely used in the time synchronization of the power system due to its high precision and wide-area coverage.
[0003] However, the time synchronization device in the power system is vulnerable to external timing attacks, which makes the phasor measurement unit (PMU) that relies on precise time synchronization unable to accurately measure and record the phasor information of electrical quantities such as voltage and current at different locations, thereby threatening the safe and stable operation of the power system. Timing interference methods usually include spoofing and jamming. Spoofing usually misleads the receiver by forging or tampering with satellite signals, resulting in time synchronization errors; jamming covers or masks the signals transmitted by GNSS satellites by transmitting strong noise signals or other signals, making it difficult or impossible for GNSS receivers to receive real satellite signals.
[0004] At present, the detection methods for timing attacks mainly focus on the following categories: based on statistical features, based on time-frequency analysis, based on machine learning and neural networks, and innovative methods based on other perspectives. The principle of the statistical method is relatively simple, but it is insensitive to slight interference and relies on prior knowledge; the method based on time-frequency analysis can effectively process time-varying signals, but the calculation and hardware costs are high; the method based on machine learning has strong adaptability, but requires a large amount of data training. Although other innovative methods have their own advantages, they also have limitations. Based on this, the present invention obtains the clock error data in the form of B code output by the time synchronization device in the power system under different deception interference scenarios by building a practical experimental platform, and proposes a joint detection method based on T test and Z_score test under the condition of few samples. It does not require additional hardware facilities and complex mathematical tools, does not require a large amount of original training data, and can achieve effective detection of timing interference in static scenarios. Summary of the invention
[0005] Based on this, it is necessary to provide an interference detection method and device for power system timing attacks in response to the above technical problems.
[0006] A method for detecting interference against timing attacks on a power system, the method comprising:
[0007] Obtain the clock difference between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions;
[0008] Set the false alarm probability, whitening filter order, and sliding window size;
[0009] Calculate a prediction model of a whitening filter used to predict the timing signal based on the timing signal output by the time synchronization device under normal timing conditions;
[0010] Using the prediction model to predict the clock difference at the next moment to obtain a prediction value, and obtaining a normal residual value according to the prediction value and the actual value of the clock difference at the next moment;
[0011] The normal residual value is detected by sliding a sliding window to obtain the window clock error average value of the clock error in each window, as well as the normal clock error average value and the normal clock error variance;
[0012] According to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, a T test model and a Z_score detection model are respectively constructed;
[0013] After using the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested are calculated respectively, and the T test model and Z_score detection model are used to detect the interference of the power system timing attack.
[0014] In one of the embodiments, the method further includes: according to the equivalence between the M-order whitening filter and the M-1-order single-step predictor, obtaining:
[0015] A M (z) = 1 - z -1 H M-1 (z)
[0016] Among them, H M-1 (z) is the system function of the sampled response h(m) of the M-1 order best linear one-step predictor, and:
[0017] H M-1 (z) = h(1) + h(2)z -1 +…+h(M)z -(M-1)
[0018] Simplifying, we get:
[0019] A M (z)G(z)=G(z)-z -1 HM-1 (z)G(z)
[0020] =z -1 [F(z)-H M-1 (z)G(z)]
[0021] Further simplification gives:
[0022] ||a*g|| 2 =||fg*h|| 2
[0023] Where a represents the response of the M-order whitening filter, and h represents the response of the M-1-order single-step predictor;
[0024] According to the response characteristics of the single-step predictor, the output time series data [x(1), x(2), …, x(N)] of the time synchronization device under normal timing conditions is obtained, and the design matrix X and the target vector y are constructed as follows:
[0025]
[0026] Solve the parameter w through the canonical equation:
[0027] w=(X T X) -1 X T y
[0028] Among them, the parameter w is the parameter of the M-order whitening filter of the prediction model.
[0029] In one embodiment, the method further includes: using the prediction model to predict the clock difference at the next moment to obtain a predicted value Xw, and obtaining a normal residual value based on the predicted value and the actual value of the clock difference at the next moment:
[0030] res=y-Xw
[0031] Among them, res represents the normal residual value.
[0032] In one embodiment, the method further includes: constructing a T-test model according to the false alarm probability, the window clock error average value, the normal clock error average value and the normal clock error variance:
[0033] Null hypothesis H0 and alternative hypothesis H1:
[0034] H0:μ=μ0,H1:μ≠μ0
[0035]
[0036] Where T represents the T statistic, is the input data of the window clock error average value, μ0 is the input data of the normal clock error average value, s is the normal clock error variance, and n is the sample size;
[0037] According to the degrees of freedom df and the false alarm probability FA, the critical value Th is found from the distribution table of the T statistic, or calculated using the following formula:
[0038]
[0039] In one embodiment, the method further includes: calculating the Z-score as:
[0040]
[0041] The upper and lower thresholds of the Z_score detection model are calculated based on the Z-score score:
[0042] upper_th=μ+z_score×σ
[0043] lower_th=μ-z_score×σ
[0044] Among them, μ is the input data of the normal clock error average value, and σ is the input data of the normal clock error variance.
[0045] In one of the embodiments, the method further includes: performing a T test and a Z_score test simultaneously, and if both test abnormalities, determining that a timing attack exists.
[0046] An interference detection device for power system timing attack, the device comprising:
[0047] A clock error data acquisition module is used to obtain the clock error between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions;
[0048] A prediction model calculation module is used to set the false alarm probability, the order of the whitening filter and the size of the sliding window; based on the timing signal output by the time synchronization device under normal timing conditions, a prediction model of the whitening filter used to predict the timing signal is calculated;
[0049] A normal parameter calculation module is used to predict the clock difference at the next moment by using the prediction model to obtain a predicted value, and to obtain a normal residual value according to the predicted value and the actual value of the clock difference at the next moment; a sliding window is used to slide and detect the normal residual value to obtain the window clock difference average value of the clock difference in each window, as well as the normal clock difference average value and the normal clock difference variance;
[0050] A detection model construction module, used to construct a T test model and a Z_score detection model according to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance;
[0051] The interference detection module is used to use the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, and then calculate the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested, and use the T test model and Z_score detection model to detect the interference of the power system timing attack.
[0052] In one embodiment, the prediction model calculation module is further used to obtain the following equation based on the equivalence between the M-order whitening filter and the M-1-order single-step predictor:
[0053] A M (z) = 1 - z -1 H M-1 (z)
[0054] Among them, H M-1 (z) is the system function of the sampled response h(m) of the M-1 order best linear one-step predictor, and:
[0055] H M-1 (z) = h(1) + h(2)z -1 +…+h(M)z -(M-1)
[0056] Simplifying, we get:
[0057] A M (z)G(z)=G(z)-z -1 H M-1 (z)G(z)
[0058] =z -1 [F(z)-H M-1 (z)G(z)]
[0059] Further simplification gives:
[0060] ||a*g|| 2 =||fg*h|| 2
[0061] Where a represents the response of the M-order whitening filter, and h represents the response of the M-1-order single-step predictor;
[0062] According to the response characteristics of the single-step predictor, the output time series data [x(1), x(2), …, x(N)] of the time synchronization device under normal timing conditions is obtained, and the design matrix X and the target vector y are constructed as follows:
[0063]
[0064] Solve the parameter w through the canonical equation:
[0065] w=(X T X) -1 X T y
[0066] Among them, the parameter w is the parameter of the M-order whitening filter of the prediction model.
[0067] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0068] Obtain the clock difference between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions;
[0069] Set the false alarm probability, whitening filter order, and sliding window size;
[0070] Calculate a prediction model of a whitening filter used to predict the timing signal based on the timing signal output by the time synchronization device under normal timing conditions;
[0071] Using the prediction model to predict the clock difference at the next moment to obtain a prediction value, and obtaining a normal residual value according to the prediction value and the actual value of the clock difference at the next moment;
[0072] The normal residual value is detected by sliding a sliding window to obtain the window clock error average value of the clock error in each window, as well as the normal clock error average value and the normal clock error variance;
[0073] According to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, a T test model and a Z_score detection model are respectively constructed;
[0074] After using the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested are calculated respectively, and the T test model and Z_score detection model are used to detect the interference of the power system timing attack.
[0075] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the following steps:
[0076] Obtain the clock difference between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions;
[0077] Set the false alarm probability, whitening filter order, and sliding window size;
[0078] Calculate a prediction model of a whitening filter used to predict the timing signal based on the timing signal output by the time synchronization device under normal timing conditions;
[0079] Using the prediction model to predict the clock difference at the next moment to obtain a prediction value, and obtaining a normal residual value according to the prediction value and the actual value of the clock difference at the next moment;
[0080] The normal residual value is detected by sliding a sliding window to obtain the window clock error average value of the clock error in each window, as well as the normal clock error average value and the normal clock error variance;
[0081] According to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, a T test model and a Z_score detection model are respectively constructed;
[0082] After using the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested are calculated respectively, and the T test model and Z_score detection model are used to detect the interference of the power system timing attack.
[0083] The above-mentioned interference detection method and device for power system timing attacks, by utilizing the difference between normal and timing attack clock differences, transforms timing attack detection into clock difference abnormality detection, thereby simplifying the complexity of the problem; whitening filtering obtains residuals, and clearly distinguishes normal and abnormal clock differences based on their statistical characteristics, laying the foundation for accurate detection; the T test and Z_score test are combined and combined with the sliding window mechanism, which not only ensures the reliability of detection, but also can keenly capture subtle changes in the residual sequence, making the detection more sensitive and timely; and compared with traditional methods, it does not require a large amount of training data, complex algorithms and high hardware costs, and shows good generalization, effectively improving the accuracy, timeliness, economy and versatility of power system timing interference detection, and providing a strong guarantee for the safe and stable operation of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] Figure 1 A schematic flow chart of an interference detection method for power system timing attacks in one embodiment;
[0085] Figure 2 A schematic diagram of obtaining clock error data under normal timing conditions in an embodiment;
[0086] Figure 3 It is a structural block diagram of an interference detection device for power system timing attack in one embodiment;
[0087] Figure 4FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0088] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0089] In one embodiment, Figure 1 As shown, a method for detecting interference against timing attacks on a power system is provided, comprising the following steps:
[0090] Step 102, obtaining the clock difference between the 1PPS signal output by the time synchronization device under normal timing conditions and the 1PPS signal output by the reference time source.
[0091] like Figure 2 As shown, the time synchronization device receives the satellite timing signal through the receiving antenna and outputs a 1PPS signal. The 1PPS signal output by the reference time source is calculated by a time interval counter, and the clock difference is recorded by a recording and analysis device.
[0092] Step 104, setting the false alarm probability, the order of the whitening filter and the size of the sliding window, and calculating the prediction model of the whitening filter for predicting the timing signal based on the timing signal output by the time synchronization device under normal timing conditions.
[0093] The whitening filter is used as the prediction model because whitening converts data into a more standardized and normalized form, making it more suitable for efficient analysis and modeling, thereby improving the training efficiency and prediction accuracy of the model. When predicting data, the optimal linear prediction error (LPE) filter used for transient monitoring can perfectly decorrelate the signal. Therefore, in this step, the parameters of the whitening filter are calculated based on the equivalence principle of the single-step predictor and the whitening filter to establish a prediction model.
[0094] Step 106, using the prediction model to predict the clock difference at the next moment to obtain a predicted value, and according to the predicted value and the actual value of the clock difference at the next moment, obtain a normal residual value, and use a sliding window to slide and detect the normal residual value to obtain the window clock difference average value of the clock difference in each window, as well as the normal clock difference average value and the normal clock difference variance.
[0095] In this step, by establishing a prediction model, the average value of the window clock error when the window slides, as well as the average value of the normal clock error and the variance of the normal clock error can be calculated based on normal data, so as to anticipate normal data and provide a basis for subsequent detection.
[0096] Step 108, constructing a T-test model and a Z_score detection model respectively according to the false alarm probability, the window clock error average value, the normal clock error average value and the normal clock error variance.
[0097] This step is based on the idea of joint detection, in which the T test model can detect the significance of mean differences in data. It focuses on the sample mean, based on key indicators such as variance and degrees of freedom of sample data, and fully considers factors such as sample size and data distribution form. It is especially suitable for situations where the sample size is small and the data is approximately normally distributed. It can accurately test whether there are significant differences between the means of different groups of data and identify the central trend between data groups. The Z_score detection model can detect the abnormal fluctuation amplitude characteristics of outliers in the data. By converting the original data into a standard normal distribution form, the degree of deviation of each data point from the mean can be intuitively shown. If the mean of a window exceeds the specified threshold, it means that there may be abnormal fluctuations in the window, and the degree of deviation from the overall data distribution is too high. It is likely to be subject to abnormal interference, so those individual windows that are significantly different from the overall data distribution and may be affected by interference sources can be locked, thereby providing a basis for rapid interference detection.
[0098] In the above interference detection method for power system timing attacks, the difference between normal and timing attack clock differences is used to transform timing attack detection into clock difference abnormality detection, thus simplifying the complexity of the problem; whitening filtering is used to obtain residuals, and normal and abnormal clock differences are clearly distinguished based on their statistical characteristics, thus laying the foundation for accurate detection; the T test and Z_score test are combined and combined with the sliding window mechanism, which not only ensures the reliability of detection, but also can keenly capture subtle changes in the residual sequence, making the detection more sensitive and timely; and compared with traditional methods, it does not require a large amount of training data, complex algorithms and high hardware costs, and shows good generalization, effectively improving the accuracy, timeliness, economy and versatility of power system timing interference detection, and providing a strong guarantee for the safe and stable operation of the power system.
[0099] In one embodiment, according to the equivalence between the M-order whitening filter and the M-1-order single-step predictor, we obtain:
[0100] A M (z) = 1 - z -1 H M-1 (z)
[0101] Among them, H M-1 (z) is the system function of the sampled response h(m) of the M-1 order best linear one-step predictor, and:
[0102] H M-1 (z) = h(1) + h(2)z -1 +…+h(M)z -(M-1)
[0103] Simplifying, we get:
[0104] A M (z)G(z)=G(z)-z -1 H M-1 (z)G(z)
[0105] =z -1 [F(z)-H M-1 (z)G(z)]
[0106] Further simplification gives:
[0107] ||a*g|| 2 =||fg*h|| 2
[0108] Where a represents the response of the M-order whitening filter, and h represents the response of the M-1-order single-step predictor;
[0109] According to the response characteristics of the single-step predictor, the output time series data [x(1), x(2), …, x(N)] of the time synchronization device under normal timing conditions is obtained, and the design matrix X and the target vector y are constructed as follows:
[0110]
[0111] Solve the parameter w through the canonical equation:
[0112] w=(X T X) -1 X T y
[0113] Among them, the parameter w is the parameter of the M-order whitening filter of the prediction model.
[0114] In another embodiment, the prediction model is used to predict the clock difference at the next moment to obtain a predicted value Xw, and the normal residual value is obtained according to the predicted value and the actual value of the clock difference at the next moment:
[0115] res=y-Xw
[0116] Among them, res represents the normal residual value.
[0117] In one embodiment, a T-test model is constructed based on the false alarm probability, the window clock error average value, the normal clock error average value and the normal clock error variance:
[0118] Null hypothesis H0 and alternative hypothesis H1:
[0119] H0:μ=μ0,H1:μ≠μ0
[0120]
[0121] Where T represents the T statistic, is the input data of the window clock error average value, μ0 is the input data of the normal clock error average value, s is the normal clock error variance, and n is the sample size;
[0122] According to the degrees of freedom df and the false alarm probability FA, the critical value Th is found from the distribution table of the T statistic, or calculated using the following formula:
[0123]
[0124] In another embodiment, the Z-score is calculated as:
[0125]
[0126] The upper and lower thresholds of the Z_score detection model are calculated based on the Z-score score:
[0127] upper_th=μ+z_score×σ
[0128] lower_th=μ-z_score×σ
[0129] Wherein, μ is the input data of the normal clock error mean value, and σ is the input data of the normal clock error variance.
[0130] Therefore, the prediction model w is used to perform whitening filtering to obtain the residual res1 to be tested, and the residual res1 to be tested is averaged by sliding, and the T test and Z_score test are jointly tested. If both detect anomalies, it is judged that there may be a timing attack.
[0131] It should be understood that although Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0132] In one embodiment, Figure 3As shown, an interference detection device for power system timing attack is provided, including: a clock error data acquisition module 302, a prediction model calculation module 304, a normal parameter calculation module 306, a detection model construction module 308 and an interference detection module 310, wherein:
[0133] The clock error data acquisition module 302 is used to acquire the clock error between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions;
[0134] The prediction model calculation module 304 is used to set the false alarm probability, the order of the whitening filter and the size of the sliding window; according to the timing signal output by the time synchronization device under normal timing conditions, the prediction model of the whitening filter used to predict the timing signal is calculated;
[0135] The normal parameter calculation module 306 is used to predict the clock error at the next moment by using the prediction model to obtain a prediction value, and to obtain a normal residual value according to the prediction value and the actual value of the clock error at the next moment; to detect the normal residual value by sliding a sliding window to obtain the window clock error average value of the clock error in each window, as well as the normal clock error average value and the normal clock error variance;
[0136] A detection model building module 308 is used to build a T-test model and a Z_score detection model according to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance;
[0137] The interference detection module 310 is used to use the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, and then calculate the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested, and use the T test model and Z_score detection model to detect the interference of the power system timing attack.
[0138] For the specific definition of the interference detection device for power system timing attacks, please refer to the definition of the interference detection method for power system timing attacks mentioned above, which will not be repeated here. Each module in the above-mentioned interference detection device for power system timing attacks can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0139] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 4As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an interference detection method for timing attacks on a power system is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.
[0140] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0141] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in the above embodiment when executing the computer program.
[0142] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in the above embodiment are implemented.
[0143] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0144] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0145] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.
Claims
1. A method for detecting interference in timing attacks on power systems, characterized in that: The method comprises: Obtain the clock difference between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions; Set the false alarm probability, whitening filter order, and sliding window size; Calculate a prediction model of a whitening filter used to predict the timing signal based on the timing signal output by the time synchronization device under normal timing conditions; Using the prediction model to predict the clock difference at the next moment to obtain a prediction value, and obtaining a normal residual value according to the prediction value and the actual value of the clock difference at the next moment; The normal residual value is detected by sliding a sliding window to obtain the window clock error average value of the clock error in each window, as well as the normal clock error average value and the normal clock error variance; According to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, a T test model and a Z_score detection model are respectively constructed; After using the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested are calculated respectively, and the T test model and Z_score detection model are used to detect the interference of the power system timing attack.
2. The method according to claim 1, characterized in that According to the timing signal output by the time synchronization device under normal timing conditions, a prediction model of a whitening filter for predicting the timing signal is calculated, including: According to the equivalence between the M-order whitening filter and the M-1-order single-step predictor, we get: And M (z)=1-z -1 H M-1 (from) Among them, H M-1 (z) is the system function of the sampled response h(m) of the M-1 order best linear one-step predictor, and: H M-1 (z)=h(1)+h(2)z -1 +…+h(M)z -(M-1) Simplifying, we get: A M (z)G(z)=G(z)-z -1 H M-1 (z)G(z) =z -1 [F(z)-H M-1 (z)G(z)] Further simplification gives: ||a*g|| 2 =||f-g*h|| 2 Where a represents the response of the M-order whitening filter, and h represents the response of the M-1-order single-step predictor; According to the response characteristics of the single-step predictor, the output time series data [x(1), x(2), …, x(N)] of the time synchronization device under normal timing conditions is obtained, and the design matrix X and the target vector y are constructed as follows: Solve the parameter w through the canonical equation: w=(X T X) -1 X T y Among them, the parameter w is the parameter of the M-order whitening filter of the prediction model.
3. The method according to claim 1, characterized in that The prediction model is used to predict the clock difference at the next moment to obtain a prediction value, and a normal residual value is obtained according to the prediction value and the actual value of the clock difference at the next moment, including: The prediction model is used to predict the clock difference at the next moment to obtain a predicted value Xw. According to the predicted value and the actual value of the clock difference at the next moment, the normal residual value is obtained as follows: res=y-Xw Among them, res represents the normal residual value.
4. The method according to claim 1, characterized in that: A T-test model is constructed according to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, including: According to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance, a T test model is constructed as follows: Null hypothesis H0 and alternative hypothesis H1: H0:μ=μ0,H1:μ≠μ0 Where T represents the T statistic, is the input data of the window clock error average value, μ0 is the input data of the normal clock error average value, s is the normal clock error variance, and n is the sample size; According to the degrees of freedom df and the false alarm probability FA, the critical value Th is found from the distribution table of the T statistic, or calculated using the following formula:
5. The method according to claim 4, characterized in that According to the false alarm probability, the window clock error average value, the normal clock error average value and the normal clock error variance, a Z_score detection model is constructed, including: The Z-score is calculated as: The upper and lower thresholds of the Z_score detection model are calculated based on the Z-score score: upper_th=μ+z_score×σ lower_th=μ-z_score×σ Wherein, μ is the input data of the normal clock error average value, and σ is the input data of the normal clock error variance.
6. The method according to claim 5, characterized in that The T-test model and Z_score detection model are used to detect interference from power system timing attacks, including: The T test and Z_score test are performed together at the same time. If both detect anomalies, it is determined that a timing attack has occurred.
7. An interference detection device for power system timing attack, characterized in that: The device comprises: A clock error data acquisition module is used to obtain the clock error between the 1PPS signal output by the time synchronization device and the 1PPS signal output by the reference time source under normal timing conditions; A prediction model calculation module is used to set the false alarm probability, the order of the whitening filter and the size of the sliding window; based on the timing signal output by the time synchronization device under normal timing conditions, a prediction model of the whitening filter used to predict the timing signal is calculated; A normal parameter calculation module is used to predict the clock difference at the next moment by using the prediction model to obtain a predicted value, and to obtain a normal residual value according to the predicted value and the actual value of the clock difference at the next moment; a sliding window is used to slide and detect the normal residual value to obtain the window clock difference average value of the clock difference in each window, as well as the normal clock difference average value and the normal clock difference variance; A detection model construction module, used to construct a T test model and a Z_score detection model according to the false alarm probability, the window clock difference average value, the normal clock difference average value and the normal clock difference variance; The interference detection module is used to use the prediction model to predict the clock error data to be tested to obtain the predicted value of the data to be tested, and then calculate the window clock error average value, normal clock error average value and normal clock error variance of the predicted value of the data to be tested, and use the T test model and Z_score detection model to detect the interference of the power system timing attack.
8. The device according to claim 7, characterized in that The prediction model calculation module is also used to obtain the equivalent of the M-order whitening filter and the M-1-order single-step predictor: And M (z)=1-z -1 H M-1 (from) Among them, H M-1 (z) is the system function of the sampled response h(m) of the M-1 order best linear one-step predictor, and: H M-1 (z)=h(1)+h(2)z -1 +…+h(M)z -(M-1) Simplifying, we get: A M (z)G(z)=G(z)-z -1 H M-1 (z)G(z) =z -1 [F(z)-H M-1 (z)G(z)] Further simplification gives: ||a*g|| 2 =||f-g*h|| 2 Where a represents the response of the M-order whitening filter, and h represents the response of the M-1-order single-step predictor; According to the response characteristics of the single-step predictor, the output time series data [x(1), x(2), …, x(N)] of the time synchronization device under normal timing conditions is obtained, and the design matrix X and the target vector y are constructed as follows: Solve the parameter w through the canonical equation: w=(X T X) -1 X T y Among them, the parameter w is the parameter of the M-order whitening filter of the prediction model.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Time synchronization attack detection and correction method and device based on optimal estimation
CN112711039A
Beidou time service deception jamming detection method and device based on RDSS assistance
CN115840238A
Satellite navigation time service deception interference defense method and device, electronic equipment and medium
CN116449397A
Cited By
GNSS (Global Navigation Satellite System) time service anomaly monitoring method and device based on dynamic graph
CN121541227A