Microgrid key controlled component rapid identification and attack traceability method and system

By combining the two-layer probability model of risk assessment and graph convolutional neural network, we quickly identify key controlled components and attack methods of the microgrid, solving the problem of low identification efficiency in the existing technology, achieving more reasonable defense resource allocation and rapid recovery of microgrid operation.

CN119995992AInactive Publication Date: 2025-05-13NORTH CHINA ELECTRIC POWER UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510146543.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is difficult to quickly identify key controlled components and attack methods of microgrids, resulting in improper allocation of defense resources and difficulty in resuming operation of microgrids.

Method used

A two-layer probability model combined with risk assessment and a graph convolutional neural network are used to construct a microgrid scene topology map, identify intrusion firewalls and microgrid controllers as attack targets, and accelerate the identification of attacked key components and attack methods through deep learning training.

Benefits of technology

It improves the efficiency of identifying key components of the microgrid and identifying attack methods, helps the system allocate defense resources more reasonably, enhances the resilience of the microgrid network, and promotes rapid recovery of operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995992A_ABST
    Figure CN119995992A_ABST
Patent Text Reader

Abstract

The invention discloses a micro-grid key controlled component rapid identification and attack traceability method and system, and the method comprises the steps: constructing a micro-grid scene topological graph, taking an attacker attack entry mode as a classification, setting an intrusion firewall as a class of attack targets, and setting a class of attack targets as a class of attack targets; directly accessing an IP-based micro-grid controller MCD from a remote access point of a power distribution network, and setting the MCD as a second-class attack target; according to the attack graph and the semi-Markov chain, performing two types of attack success probability calculation and key controlled component identification by using a double-layer probability model combined with risk assessment; and inputting the load loss quantity characteristic and the attack success probability characteristic parameter of the attacked controlled component and the Markov steady-state topological graph into a graph convolutional neural network to carry out deep learning training so as to accelerate the identification of the attacked key component and the attack mode. By adopting the technical scheme of the invention, the efficiency of micro-grid key component identification and attack mode identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of intelligent microgrid system defense, and in particular relates to a method and system for rapid identification and attack tracing of key controlled components of a microgrid. Background Art

[0002] Wireless communication is a promising means of monitoring and controlling smart microgrids because it offers high flexibility at a lower cost compared to wired communication. However, wireless communication is more vulnerable to cyberattacks—such as data theft and false data injection attacks (FDIAs)—in which attackers intercept messages exchanged between parties to obtain information, modify data, or access devices they are not authorized to access. And cyberattacks on energy infrastructure have surged worldwide in recent years.

[0003] Previous studies have assumed that microgrids are only subject to a single type of cyberattack. In reality, some microgrids are vulnerable to cyberattacks on the SCADA system, while others may be directly attacked from remote IP access to the microgrid controller (MCD), or attackers may launch both types of cyberattacks at the same time. This requires different defense resources to protect the microgrid. For example, to defend against cyberattacks in the SCADA system, operators can invest in trusted server upgrades and hire cybersecurity professionals. When defending against direct MCD attacks based on IP addresses, they need to strengthen real-time key protection or strengthen personnel authentication systems. Therefore, if the type of cyberattack that may occur can be identified in advance, it can help system operators quickly and correctly allocate defense resources. In addition, most of the current research focuses on cyberattacks in the microgrid SCADA system, when all components related to the microgrid will be tripped, because these studies assume that shutting down all components connected to the target microgrid area will cause the most serious damage to the power system. However, it has been proven that shutting down only some transmission lines can achieve the attacker's goal of disrupting the normal operation of the microgrid, and it helps to improve the concealment of the attack. At the same time, when facing an attack, the microgrid cannot determine the controlled components and rudely suspends all components, which is not conducive to the recovery of the microgrid. Moreover, if the attacker improves the means of attack, such as controlling only some key components of the microgrid, the current detection system cannot accurately identify the controlled components alone. Summary of the invention

[0004] The technical problem to be solved by the present invention is to provide a method and system for rapid identification and attack tracing of key controlled components of a microgrid, so as to improve the efficiency of identifying key components of the microgrid and identifying attack methods.

[0005] To achieve the above object, the present invention adopts the following technical solution:

[0006] A method for rapid identification and attack tracing of key controlled components of a microgrid, comprising:

[0007] Step 1: Construct a microgrid scenario topology diagram, set the intrusion firewall as the first attack target, and directly access the IP-based microgrid controller MCD from the remote access point of the distribution network as the second attack target;

[0008] Step 2: Based on the attack graph and semi-Markov chain, a two-layer probability model combined with risk assessment is used to calculate the success probability of two types of attacks and identify key controlled components;

[0009] Step 3: Input the load loss characteristics of the attacked controlled components, the characteristic parameters of the attack success probability, and the Markov steady-state topology map into the graph convolutional neural network for deep learning training to accelerate the identification of attacked key components and attack methods.

[0010] Preferably, in step 2, the combined success attack probability of a type of network attack on the microgrid is calculated as follows:

[0011] PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n

[0012] Among them, PS n It is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times.

[0013] The combined attack success probability of the two types of network attacks on the microgrid is calculated as follows:

[0014] PB n =P(MCD1,...,MCD e ,P1)

[0015] =P(MCD1|P1)·...·P(MCD e |P1)·P(P1)

[0016] =π(S9)1·...·π(S9) e ·P(P1)

[0017] Among them, MCD e are discrete random variables, representing MCD respectively. e Has been successfully hacked.

[0018] Preferably, in step 3, the constraint function of the double-layer double-layer probability model is as follows:

[0019]

[0020] Among them, constraints (11a)-(11b) are the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked, and the right side of (11a) specifies the attack budget of the MCD, k n is the total number of MCDs installed in the microgrid, M2 is the attack budget of the MCDs through the second type of network attack estimated by the microgrid system defense personnel; constraint (11c) is the number of MCDs damaged in different types of network attacks. If a n =z n =1, the microgrid suffers from a type I network attack, and the attacker controls the controlled MCD to disconnect all components; if a n =1,z n =0, the microgrid where the MCD is located suffers from a second-class network attack, and at least one microgrid controller in the microgrid will be damaged; constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action; constraints (11e)-(11f) ensure that when the MCD is damaged, the line l controlled by it i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack; constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

[0021] Preferably, in step S3, a graph convolutional neural network is used to extract features from the attack graph and the semi-Markov chain graph, and feature recognition is used to perform attack source tracing and controlled component identification.

[0022] The present invention also provides a microgrid key controlled component rapid identification and attack tracing system, comprising:

[0023] The first processing device is used to construct a microgrid scenario topology map, set the intrusion firewall as a first-class attack target, and directly access the IP-based microgrid controller MCD from a remote access point of the distribution network as a second-class attack target;

[0024] A second processing device is used to calculate the success probability of two types of attacks and identify key controlled components based on the attack graph and the semi-Markov chain using a double-layer probability model combined with risk assessment;

[0025] The third processing device is used to input the load loss characteristics of the attacked controlled components, the characteristic parameters of the attack success probability and the Markov steady-state topology map into the graph convolutional neural network, so as to perform deep learning training to accelerate the identification of attacked key components and attack methods.

[0026] As a preferred method, the combined success attack probability of a type of network attack on the microgrid is calculated as follows:

[0027] PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n

[0028] Among them, PS n It is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times.

[0029] The combined attack success probability of the two types of network attacks on the microgrid is calculated as follows:

[0030] PB n =P(MCD1,...,MCD e ,P1)

[0031] =P(MCD1|P1)·...·P(MCD e |P1)·P(P1)

[0032] =π(S9)1·...·π(S9) e ·P(P1)

[0033] Among them, MCD e are discrete random variables, representing MCD respectively. e Has been successfully hacked.

[0034] Preferably, the constraint function of the two-layer two-layer probability model is as follows:

[0035]

[0036] Among them, constraints (11a)-(11b) are the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked, and the right side of (11a) specifies the attack budget of the MCD, k n is the total number of MCDs installed in the microgrid, M2 is the attack budget of the MCDs through the second type of network attack estimated by the microgrid system defense personnel; constraint (11c) is the number of MCDs damaged in different types of network attacks. If a n =z n =1, the microgrid suffers from a type I network attack, and the attacker controls the controlled MCD to disconnect all components; if a n =1,z n=0, the microgrid where the MCD is located suffers from a second-class network attack, and at least one microgrid controller in the microgrid will be damaged; constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action; constraints (11e)-(11f) ensure that when the MCD is damaged, the line l controlled by it i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack; constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

[0037] Preferably, the third processing device uses a graph convolutional neural network to extract features from the attack graph and the semi-Markov chain graph, and performs attack tracing and controlled component identification through feature recognition.

[0038] The present invention builds a microgrid scenario, analyzes the attack graph and semi-Markov chain of two types of network attacks, and further analyzes the probability of attack success and the network risk caused to the microgrid during a joint attack. After that, the attack probability, network risk, attack graph and semi-Markov chain are input into the graph convolutional neural network for feature extraction and classification to accelerate attack tracing and even attack path identification. In addition, the type of network attack and key controlled components can be identified, which can help the system allocate defense resources more reasonably and enhance the resilience of the microgrid network. In this way, the application of the two-layer probability model is extended to the identification of hidden network attacks, especially attacks on microgrids, which is beneficial for network security personnel to focus on new network attack methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0040] Figure 1 This is a flow chart of a method for rapid identification and attack tracing of key controlled components of a microgrid according to an embodiment of the present invention;

[0041] Figure 2 Build a schematic for the microgrid scenario;

[0042] Figure 3 It is a path diagram of two types of attack methods;

[0043] Figure 4 Schematic diagram of a semi-Markov chain for a network attack. DETAILED DESCRIPTION

[0044] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0045] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0046] Embodiment 1:

[0047] like Figure 1 As shown, an embodiment of the present invention provides a method for quickly identifying key controlled components of a microgrid and tracing attacks, including:

[0048] Step S1, first build a microgrid scenario, which consists of a power generation unit, an energy storage unit, a load unit, a local SCADA system, a firewall, and a microgrid controller (MCD). The components are interconnected using wireless communication to form a conventional microgrid scenario with efficient energy management, certain defense measures, remote monitoring and intelligent control, which is convenient for using Markov chains to analyze the success probability of attacking key components in the subsequent attack.

[0049] like Figure 1 As shown in the figure, the operation of the microgrid supplying power to the load is controlled by the microgrid controller MCD, and each microgrid controller is coordinated and controlled by the intelligent interconnection unit. There is a firewall defense between each component. The traditional microgrid protection mechanism is that the energy flow controller and SCADA are used to monitor the load change. When the microgrid controller is attacked, the load change exceeds the set value, which will trigger an alarm. The SCADA or microgrid controller disconnects the entire microgrid internal components to prevent the attack from further damaging the components. However, studies have shown that disconnecting individual attacked key components can not only ensure the operation of the rest of the microgrid to the greatest extent, but also improve the speed of microgrid investigation of attack sources and overall load recovery. Therefore, it is necessary to improve the success rate and speed of identifying key controlled components.

[0050] Step S2, modeling and probability analysis of two types of network attacks, classifying the attack steps, clarifying the attack path, and forming an attack graph. The attack graph can clearly show all possible paths for attackers to enter the system from the external environment and gradually penetrate into the core assets, which is convenient for analyzing the probability of successful attack. Generally speaking, the attack targets may include but are not limited to destroying the stability of the system, changing the working point, or triggering the protection isolation device to isolate the healthy components. The main attack targets of the present invention are Figure 1The microgrid controller (MCD) and the SCADA monitored devices in the microgrid. The switch attack that disconnects the microgrid components can be carried out by directly connecting to the microgrid controller based on IP remote access or by invading the local SCADA monitoring system. The two types of network attacks may attack different components separately or in combination. The joint attack is the focus of this invention. The following describes the two types of attack methods in detail and gives the attack diagram.

[0051] 1. Type I cyberattack. After breaking through the firewall, the attacker invades the local SCADA system (control monitoring center). After gaining full access to the control center, the attacker sends a command to the microgrid controller to disconnect all components connected to the target microgrid.

[0052] 2. Second type of network attack. The attacker directly accesses the IP-based microgrid controller (MCD) from the remote access point of the distribution network. In this way, key components such as energy flow controllers, smart interconnectors and loads will be disconnected from the grid separately through the microgrid controller. In addition, the present invention considers that each microgrid controller is protected by a key, there is a high-security key that changes in real time, and the process of invading the microgrid controller is conditionally independent.

[0053] The present invention adopts attack graph to analyze the network risk of the intrusion process, so as to calculate the steady-state probability of the distribution network intrusion.

[0054] like Figure 2 As shown in the figure, the attack paths of two types of attacks are described. The nodes are the states that the attacker can reach, and the edges are the operations that the attacker performs for state transition. The left path simulates the process of logging into the SCADA system and shutting down all connection lines. The right path represents an independent intrusion into the MCD from remote access. Figure 2 The nodes describe all the states that the attacker can reach, and the state transitions represent the actions that the attacker may take to change the current state with different probabilities and rates. Specifically, P1 represents the transition probability of successfully cracking the firewall rules, while P2 represents the failure probability of cracking the firewall rules. P3 represents the transition probability of successfully logging into the microgrid controller, P4 represents the probability of cutting off all component connections through SCADA, P5 and P6 represent the probabilities of successfully destroying the MCD device and disconnecting the remaining components from the microgrid through MCD, respectively, and P7 represents the success probability of manipulating the energy controller through the control center. Since the process of invading the microgrid controller is conditionally independent. Therefore, the conditional intrusion probability of the microgrid controller in the distribution network n satisfies:

[0055] P(MCD1,...,MCD m |P1)=P(MCD1|P1)·...·P(MCD m |P1) (1)

[0056] MCDm and P1 represents MCD m and the microgrid’s firewall has been successfully breached.

[0057] Step S3: Based on the attack graph, taking into account the time variation of the attack and the time variation of the successful or failed defense of the firewall, a semi-Markov chain of two types of attacks is proposed, such as Figure 3 shown.

[0058] S0 to S9 are the states in the semi-Markov chain during the attack process. S0 is the initial vulnerability scan and attack attempt, S1-S3 are the states of the firewall invasion process, S4 represents the successful invasion of the firewall, S6 represents the successful login to the SCADA system, and then disconnecting all components S7, S8 represents the closing of all component connections after the real-time key protection, and S9 represents the separate invasion of the microgrid MCD after logging in through the remote IP. It can be obtained that the steady-state probability of breaking through the firewall is the sum of the steady-state probabilities of π(S5), π(S6), π(S7), ..., π(S9), that is:

[0059] P1=π(S5)+π(S6)+...+π(S9) (2)

[0060] P1 is a discrete random variable, indicating that the firewall of the distribution network has been breached, and represents the steady-state probability of this state.

[0061] Therefore, the joint successful attack probability (JAP) of multiple type-one cyber attacks on the microgrid can be calculated as follows:

[0062] PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n (3)

[0063] PS n It is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times.

[0064] The success probability of the combined attack of the two types of network attacks on the microgrid can be calculated as follows.

[0065]

[0066] MCD e are discrete random variables, representing MCD respectively. e The attack probability and attack success rate of the two attacks can be obtained.

[0067] Step S4, identify the microgrid, MCD and other controlled components and attack methods through a two-layer probability model combined with risk assessment. Since different microgrids usually adopt different security mechanisms, some microgrids can be successfully invaded through type I network attacks, while other microgrids may be easily attacked through type II network attacks, and the benefits obtained after being attacked by different microgrids are also different. Therefore, when determining the attack target, the attacker will consider both the probability of successful attack and the benefits that can be brought after success. Therefore, the present invention takes into account the situation where the probability of being attacked varies due to the different values ​​of different components in different microgrids.

[0068] Combined with risk assessment, it can be seen that the calculation of system risk value can be obtained by taking the risk value R as the product of the value loss V caused by the attack event and the risk occurrence probability P to give the microgrid network risk R:

[0069] R=P r ·V (5)

[0070] This is also the objective function of the upper-level probability model, which simulates the attacker's behavior and aims to maximize the network risk in (5). r is the success rate of type I and type II combined network attacks subjected to n network attacks, calculated as follows:

[0071]

[0072]

[0073] z n is a binary variable whose value is equal to 1, indicating that the microgrid is attacked. i It is a binary variable, and when it is 1, it means MCD i Under attack, a n is a binary variable used to distinguish the types of cyber attacks suffered by the microgrid. n =1, it means that a Type I attack is received. If z n =1 and a n =0, the microgrid suffers from the second type of network attack.

[0074] V in formula (5) is the quantification of the value loss caused by the control of microgrid system components.

[0075] V=uP e (F)+vΔD (7)

[0076] Where u and v are the associated value ratio coefficients. The loss includes physical loss P e(F) and information loss ΔD. Physical loss is related to components. The greater the proportion or importance of components in the entire microgrid system, the higher the possible physical loss. The present invention uses the load loss after the attack to measure the information loss.

[0077] The importance of each component in a microgrid is different. It is generally believed that monitoring and control components such as SCADA and microgrid controllers belong to the host computer and are of high importance, while remote terminal units and programmable distributed power supplies are of low importance. You can judge the importance and availability of microgrid components according to general logic. The probability of availability of components in a microgrid is P e The component score can be divided by the total score of all components of the microgrid, that is:

[0078] P e =score i / totalscore (8)

[0079]

[0080] The load loss ΔD is the sum of the load losses of the microgrid after each attack.

[0081] ΔD=∑ΔD i (10)

[0082] The minimization of equation (10) is the objective function of the lower-level probability model, which is used to simulate the target of the defender.

[0083] The constraint function of the two-layer probability model is as follows:

[0084]

[0085] Constraints (11a)-(11b) specify the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked. The right side of (11a) specifies the attack budget of the MCDs. n is the total number of MCDs installed in the microgrid, and M2 is the attack budget estimated by the microgrid system defenders to attack MCDs through the second type of cyber attacks. Constraint (11c) takes into account the number of MCDs damaged in different types of cyber attacks. For example, if a n =z n =1, the microgrid suffers from a type I network attack. At this time, the attacker controls the controlled MCD to disconnect all components. n =1,z n= 0, the microgrid where the MCD is located is subject to a second-class network attack, and at least one microgrid controller in the microgrid will be damaged. Constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action. Constraints (11e)-(11f) ensure that once the MCD is damaged, the line l controlled by it will be i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack. It is a binary value. Constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

[0086] Step S5, use graph convolutional neural network to extract features from attack graph and semi-Markov chain graph, and perform attack tracing and controlled component identification through feature recognition. Images have translation invariance, but graphs do not have this property. Therefore, it is not feasible to directly migrate the convolution kernel on the convolutional neural network CNN to the graph structure, that is, traditional discrete convolution cannot be used to extract features. Therefore, a graph convolutional neural network (GCN) is adopted. The graph convolutional neural network mainly makes the connection between nodes visible, and its core idea is to aggregate the information of each node and its neighboring nodes. In the attack graph, the node represents the microgrid component that can be attacked, the edge represents the attack path, the node in the semi-Markov chain represents the state reached by the attack, and the edge represents the transition probability.

[0087] For node v in the attack graph i , its neighbor node set N(i) contains the nodes that can reach v through the attack path i Or from v i In the present invention, the adjacency matrix A is used to represent the connection relationship between nodes in the graph. ij Indicates whether there is an attack path or conversion possibility between node i and node j (if so, A ij =1, otherwise A ij =0). The feature vectors of all nodes form a feature matrix X, whose dimension is n×d, where d is the dimension of each node feature vector. The GCN layer formula is:

[0088]

[0089] Among them, H (l) is the node feature matrix of the lth layer, W (l) is the learnable weight matrix of the lth layer, and σ is the activation function. In the present invention, (I is the identity matrix), and the node information itself is also added when aggregating information. The degree matrix of and Normalization of the adjacency matrix makes it more reasonable to aggregate neighbor node information in the graph. For example, in an attack graph containing multiple attack paths pointing to a high-value target node, this normalization operation can balance the contribution of different attack paths to the target node characteristics. The new feature matrix H is calculated by formula (12): (l+1) , the feature representation of the nodes in the graph is updated. The new features contain the original security-related information of the node itself and the information of its neighboring nodes (nodes connected by attack paths or probabilities). For example, a microgrid controller that originally indicated a good security status will change its feature representation after aggregating the information of its neighboring nodes (which may be SCADA with high-risk vulnerabilities), which can better reflect the potential risk of the node in the entire attack graph.

[0090] One layer of graph convolution is far from enough. Multiple graph convolution layers are stacked together. Each layer further extracts and fuses feature information such as risk and probability of successful attack in the graph based on the previous layer. As the number of layers increases, the feature representation of the node will gradually contain more global structural information. The first layer mainly aggregates the attack information of directly adjacent nodes, while the second layer takes into account the information of neighbor nodes of neighbor nodes, so that more complex attack paths and potential attack threat combinations can be identified. The calculation formula between layers is as follows:

[0091]

[0092] in, is the output representation of the nth layer of node i, represents the initial state of node i. For n-layer GCN, n∈[1,2,...,N], is the final state of node i, W n is the linear transformation weight, b n is the bias term, and σ is the activation function. ReLU is used as the activation function here:

[0093] σ(x)=y=max(0,x) (14)

[0094] This activation function helps solve the gradient vanishing problem, allowing gradients to be transferred more efficiently during back propagation, thereby accelerating model training. After the graph convolutional layer updates the node features, the ReLU function can perform nonlinear transformations on the new features, enabling the model to learn more complex node representations.

[0095] After passing through multiple layers of graph convolutional layers, the feature representation of a node incorporates information about itself and its neighboring nodes. For attack tracing, these features can reflect the location and association of the node in the attack path. The feature vector of each node contains information about its distance from the potential attack source node and how closely it is connected to other suspicious nodes. Information about the direction of attack propagation can also be extracted from node features. By analyzing the changing trends of different dimensions in the feature vector, because the values ​​of some dimensions decrease or increase monotonically with the increase in the distance from the potential attack source, it is possible to infer which nodes the attack started to spread from. For example, if a dimension in a node's feature vector represents the "likelihood of being attacked", the value of this dimension will gradually increase on the path from the attack source to the target, so the source of the attack can be tracked through these node features.

[0096] Step S6: A classifier is set after the output layer through the graph convolutional neural network for attack tracing, and the nodes are divided into k categories such as "possible attack source", "intermediate propagation node", and "attacked target". The input of the classifier is the node features extracted by the graph convolution layer, and the output layer is a fully connected layer with k neurons. The vector output by the output layer passes through the NAF activation function, and the result is normalized. The final output is the next possible attack node or the complete attack path probability distribution, which helps to trace back the starting point of the attack in the attack graph, that is, tracing the source.

[0097] If used for key controlled component identification, the vulnerability-related features of the device can be extracted from the node features. After graph convolution, the node features contain information such as the network risk of the neighboring node itself, the number of vulnerabilities, and the attack records, so that the network risk of the device being attacked can be evaluated. Node features can also reflect the importance of the device in the attack graph. Through graph convolution to aggregate information, the feature vectors of device nodes that are on the key attack path or connected to multiple high-risk areas will be reflected accordingly. At this time, the output layer of the classifier is also activated by the NAF function, and then normalized, and finally mapped to a risk score interval. The higher the score, the greater the potential risk of the device being attacked in the attack graph. This can help security managers quickly identify high-risk devices, and at the same time, they can quickly lock controlled components in combination with the load loss amount. The specific operations are as follows.

[0098] The classifier uses a multi-layer perceptron (MLP) linear layer, and the input is the final feature vector of each node Outputted by the graph convolutional neural network, the weight matrix connecting the input layer and the hidden layer is h is the number of neurons in the hidden layer (generally twice the latitude of the feature vector), and the bias vector is The input to the hidden layer neurons is The calculation formula is:

[0099]

[0100] After the feature vector passes through the hidden layer and then through the activation function σ, the output a of the hidden layer neuron can be obtained. i :

[0101] a ij =σ(u ij ) (16)

[0102] The weight matrix connecting the hidden layer and the output layer is The bias vector is The output component function f can be obtained i (z):

[0103]

[0104] Finally, the NAF activation function is used to obtain the output of the classifier. The calculation formula is as follows:

[0105]

[0106] Because the final result is a scalar value that combines the calculation results of multiple component functions and cannot be used directly, it needs to be converted into a form similar to probability distribution for classification and y is normalized. Expanded to k dimensions, we finally get Assume the normalized probability distribution vector is in

[0107]

[0108] Probability distribution vector This is the final probability distribution, which indicates the possibility that a node belongs to each tracing category or vulnerability category.

[0109] The embodiment of the present invention is based on the actual situation of microgrid network attack and defense, builds a microgrid scenario, focuses on key components with destructive value, analyzes two types of network attacks, and establishes an attack graph and a corresponding semi-Markov chain based on the microgrid scenario graph and the characteristics of the two types of attacks.

[0110] Based on the existing microgrid attack situation, the embodiment of the present invention proposes a two-layer probability model combined with risk assessment, which performs joint attack success probability analysis and network risk assessment on the microgrid for two types of network attacks. At the same time, it attempts to attack only a single component in the microgrid, making the attack more covert, filling the gap in attack methods, and enriching the experience of defense personnel.

[0111] The embodiment of the present invention inputs the attack graph, semi-Markov chain, network risk and joint attack success probability into the graph convolutional neural network to perform node feature aggregation and extraction. The graph convolutional neural network can quickly process the complex topology graph of the microgrid system. There is no need to convert the graph structure data into other forms as in traditional methods, thereby avoiding the structural information that may be lost during the conversion process. Moreover, once properly trained, the graph convolutional neural network can trace different types of attack methods and microgrid scenarios, thereby improving the rate of analyzing attack paths.

[0112] In the process of probabilistically classifying the output results of the graph convolutional neural network, the embodiment of the present invention innovatively adopts NAF as the activation function. In the classification of graph convolutional neural network (GCN) results, graph data often has complex structures and node relationships, and there may be interactions between multiple features that affect the classification results. NAF can better mine these complex patterns and better model feature interactions. At the same time, the NAF activation function has a certain adaptive learning ability. Its component functions can learn different feature representations and classification rules during the training process according to the characteristics of the data. For different types of graph data (such as different node degree distributions, different types of edge weights, etc.), NAF can flexibly adjust the parameters of its component functions to adapt to the data. The form of the traditional activation function is relatively fixed, and the adaptability to different data characteristics is relatively weak. In the present invention, both attack path characteristics and node network risk characteristics are required, and the traditional activation function is not competent.

[0113] Embodiment 2:

[0114] The embodiment of the present invention also provides a device for quickly identifying key controlled components of a microgrid and tracing attacks, including:

[0115] The present invention also provides a microgrid key controlled component rapid identification and attack tracing system, comprising:

[0116] The first processing device is used to construct a microgrid scenario topology map, set the intrusion firewall as a first-class attack target, and directly access the IP-based microgrid controller MCD from a remote access point of the distribution network as a second-class attack target;

[0117] A second processing device is used to calculate the success probability of two types of attacks and identify key controlled components based on the attack graph and the semi-Markov chain using a double-layer probability model combined with risk assessment;

[0118] The third processing device is used to input the load loss characteristics of the attacked controlled components, the characteristic parameters of the attack success probability and the Markov steady-state topology map into the graph convolutional neural network, so as to perform deep learning training to accelerate the identification of attacked key components and attack methods.

[0119] As an implementation method of an embodiment of the present invention, the combined success attack probability of a type of network attack on a microgrid is calculated as follows:

[0120] PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n

[0121] Among them, PS n It is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times.

[0122] The combined attack success probability of the two types of network attacks on the microgrid is calculated as follows:

[0123] PB n =P(MCD1,...,MCD e ,P1)

[0124] =P(MCD1|P1)·...·P(MCD e |P1)·P(P1)

[0125] =π(S9)1·...·π(S9) e ·P(P1)

[0126] Among them, MCD e are discrete random variables, representing MCD respectively. e Has been successfully hacked.

[0127] As an implementation method of an embodiment of the present invention, the constraint function of the double-layer double-layer probability model is as follows:

[0128]

[0129] Among them, constraints (11a)-(11b) are the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked, and the right side of (11a) specifies the attack budget of the MCD, k n is the total number of MCDs installed in the microgrid, M2 is the attack budget of the MCDs through the second type of network attack estimated by the microgrid system defense personnel; constraint (11c) is the number of MCDs damaged in different types of network attacks. If a n =z n =1, the microgrid suffers from a type I network attack, and the attacker controls the controlled MCD to disconnect all components; if a n =1,z n=0, the microgrid where the MCD is located suffers from a second-class network attack, and at least one microgrid controller in the microgrid will be damaged; constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action; constraints (11e)-(11f) ensure that when the MCD is damaged, the line l controlled by it i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack; constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

[0130] As an implementation method of an embodiment of the present invention, the third processing device uses a graph convolutional neural network to extract features from the attack graph and the semi-Markov chain graph, and performs attack tracing and controlled component identification through feature recognition.

[0131] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.

Claims

1. A method for rapid identification and attack tracing of key controlled components of a microgrid, characterized in that: include: Step 1: Construct a microgrid scenario topology diagram, and classify the attacker’s attack entry method into the target class I, and set the intrusion firewall as the first-class attack target, and directly access the IP-based microgrid controller MCD from the remote access point of the distribution network as the second-class attack target; Step 2: Based on the attack graph and semi-Markov chain, a two-layer probability model combined with risk assessment is used to calculate the success probability of two types of attacks and identify key controlled components; Step 3: Input the load loss characteristics of the attacked controlled components, the characteristic parameters of the attack success probability, and the Markov steady-state topology map into the graph convolutional neural network for deep learning training to accelerate the identification of attacked key components and attack methods.

2. The method for rapid identification and attack tracing of key controlled components of a microgrid as claimed in claim 1, characterized in that: In step 2, the joint success attack probability of a type of network attack on the microgrid is calculated as follows: PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n Among them, PS n is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times; The combined attack success probability of the two types of network attacks on the microgrid is calculated as follows: PB n =P(MCD1,...,MCD e ,P1) =P(MCD1|P1)·...·P(MCD e |P1)·P(P1) =π(S9)1·...·π(S9) e ·P(P1) Among them, MCD e are discrete random variables, representing MCD respectively. e Has been successfully hacked.

3. The method for rapid identification and attack tracing of key controlled components of a microgrid as claimed in claim 2, characterized in that: In step 2, the constraint function of the two-layer two-layer probability model is as follows: Among them, constraints (11a)-(11b) are the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked, and the right side of (11a) specifies the attack budget of the MCD, k n is the total number of MCDs installed in the microgrid, M2 is the attack budget of the MCDs through the second type of network attack estimated by the microgrid system defense personnel; constraint (11c) is the number of MCDs damaged in different types of network attacks. If a n =z n =1, the microgrid suffers from a type I network attack, and the attacker controls the controlled MCD to disconnect all components; if a n =1,z n =0, the microgrid where the MCD is located suffers from a second-class network attack, and at least one microgrid controller in the microgrid will be damaged; constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action; constraints (11e)-(11f) ensure that when the MCD is damaged, the line l controlled by it i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack; constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

4. The method for rapid identification and attack tracing of key controlled components of a microgrid as claimed in claim 3, characterized in that: In step S3, a graph convolutional neural network is used to extract features from the attack graph and the semi-Markov chain graph, and feature recognition is used to trace the attack source and identify the controlled components.

5. A system for rapid identification and attack tracing of key controlled components of a microgrid, characterized in that: include: The first processing device is used to construct a microgrid scenario topology map, set the intrusion firewall as a first-class attack target, and directly access the IP-based microgrid controller MCD from a remote access point of the distribution network as a second-class attack target; A second processing device is used to calculate the success probability of two types of attacks and identify key controlled components based on the attack graph and the semi-Markov chain using a double-layer probability model combined with risk assessment; The third processing device is used to input the load loss characteristics of the attacked controlled components, the characteristic parameters of the attack success probability and the Markov steady-state topology map into the graph convolutional neural network, so as to perform deep learning training to accelerate the identification of attacked key components and attack methods.

6. The microgrid key controlled component rapid identification and attack tracing system as claimed in claim 5, characterized in that: The joint success attack probability of a type of cyber attack on the microgrid is calculated as follows: PA n =P(PS n ,P1)=π(S6)·π(S7)·[π(S5)+π(S6)+...+π(S9)] n Among them, PS n It is a discrete random variable, which means that after successfully logging into the SCADA system, all components inside the microgrid are disconnected, and n means that the microgrid is attacked using a certain method n times. The combined attack success probability of the two types of network attacks on the microgrid is calculated as follows: PB n =P(MCD1,...,MCD e ,P1) =P(MCD1|P1)·...·P(MCD e |P1)·P(P1) =π(S9)1·...·π(S9) e ·P(P1) Among them, MCD e are discrete random variables, representing MCD respectively. e Has been successfully hacked.

7. The microgrid key controlled component rapid identification and attack tracing system as claimed in claim 6, characterized in that: The constraint function of the two-layer two-layer probability model is as follows: Among them, constraints (11a)-(11b) are the attack budget of the microgrid controller. The left side of (11a) ensures that at least M1 MCDs are attacked, and the right side of (11a) specifies the attack budget of the MCD, k n is the total number of MCDs installed in the microgrid, M2 is the attack budget of the MCDs through the second type of network attack estimated by the microgrid system defense personnel; constraint (11c) is the number of MCDs damaged in different types of network attacks. If a n =z n =1, the microgrid suffers from a type I network attack, and the attacker controls the controlled MCD to disconnect all components; if a n =1,z n =0, the microgrid where the MCD is located suffers from a second-class network attack, and at least one microgrid controller in the microgrid will be damaged; constraint (11d) ensures that if the microgrid where the MCD is located is safe, the MCD will be excluded from the calculation and the defense personnel will not take any action; constraints (11e)-(11f) ensure that when the MCD is damaged, the line l controlled by it i Will trip, v i=o(l) With v i=y(l) It is used to determine whether the MCDs at both ends of the line are under attack; constraint (11g) ensures that if both MCDs at both ends of the line are in a safe state, line l i The connection will remain.

8. The microgrid key controlled component rapid identification and attack tracing system as claimed in claim 7, characterized in that: The third processing device uses a graph convolutional neural network to extract features from the attack graph and the semi-Markov chain graph, and performs attack tracing and controlled component identification through feature recognition.