Power plant control system network monitoring and early warning method, system and program product
By collecting and integrating multi-source heterogeneous monitoring data from the power plant control system, network abnormality detection and long-term monitoring index calculations are solved, and the problem of insufficient comprehensive network security perception and high false alarm rate in the existing technology is solved, and accurate and reliable network security monitoring and early warning is achieved.
Patent Information
- Application Number
- CN202510502812.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing power plant control system network security situation awareness technology is not comprehensive enough in perception and control, resulting in isolation of alarms and high false alarm rates, difficulty in accurately identifying complex attacks, and insufficient dynamic perception capabilities for a long time.
By collecting network traffic information, system log information and control signal information of the power plant control system, feature vectors are extracted and weighted fusion is performed to form a high-dimensional splicing vector, input a preset network anomaly detection model for detection, and calculate a long-term monitoring index to output network security warning information.
It realizes the comprehensiveness and reliability of network monitoring of power plant control system, reduces the false alarm rate, improves the situational awareness ability of network abnormal monitoring, and meets the timing monitoring needs.
Smart Images

Figure CN120010363A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of system monitoring, and in particular relates to a network monitoring and early warning method, system and program product for a power plant control system. Background Art
[0002] A power plant control system is a system used to manage and control various equipment and processes in a power plant. Its main functions include automatic control, protection, monitoring and measurement. The power plant control system performs control and coordination functions during the startup, power ramp-up, power operation and shutdown conditions of the power plant to ensure the safe, stable and economical operation of the power plant. Therefore, network security monitoring of the power plant control system is crucial. Most of the existing network security situation awareness technologies for power plant control systems use a single data source to analyze and alert. The perception and control of system network security are not comprehensive enough, resulting in isolated alarms and high false alarm rates. It is difficult to accurately identify complex attacks, and most of them are monitoring and analysis of independent time nodes. The long-term dynamic perception capability is insufficient, and the monitoring timing needs to be improved. Summary of the invention
[0003] The purpose of the present invention is to provide a power plant control system network monitoring and early warning method, system and program product to solve the above problems existing in the prior art.
[0004] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, a power plant control system network monitoring and early warning method is provided, comprising: Collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period; Extracting network traffic feature vectors of network traffic information at each sampling time point, extracting system log feature vectors of system log information at each sampling time point, and extracting control signal feature vectors of control signal information at each sampling time point; Perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector; Perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period; When the abnormal detection value of the current time period does not exceed the set abnormal threshold, the abnormal detection value of the current time period is merged into a detection value set, and the detection value set includes abnormal detection values corresponding to several historical time periods; Determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter; When the long-term monitoring index exceeds the set index threshold, the network security warning information of the power plant control system is output.
[0005] In a possible design, extracting the network traffic feature vector of the network traffic information at each sampling time point, extracting the system log feature vector of the system log information at each sampling time point, and extracting the control signal feature vector of the control signal information at each sampling time point include: Determine each network traffic characteristic parameter corresponding to the network traffic information, wherein each network traffic characteristic parameter includes a network data packet size parameter, a network protocol type ratio parameter, and a network address access frequency parameter, and perform normalization processing on each network traffic characteristic parameter, and use each normalized network traffic characteristic parameter to form a network traffic characteristic vector corresponding to the network traffic information; Determine each system log characteristic parameter corresponding to the system log information, wherein each system log characteristic parameter includes a user login frequency parameter, a permission change number parameter, and an abnormal process trigger rate parameter, and normalize each system log characteristic parameter, and use each system log characteristic parameter after the normalization process to form a system log characteristic vector corresponding to the system log information; Determine each control signal characteristic parameter corresponding to the control signal information, wherein each control signal characteristic parameter includes a signal protocol type ratio parameter, a signal amplitude standard deviation parameter, and a signal timing correlation parameter, and normalize each control signal characteristic parameter, and use the normalized control signal characteristic parameters to form a control signal characteristic vector corresponding to the control signal information.
[0006] In a possible design, the weighted fusion of the network traffic feature vectors at each time point to obtain the fused network traffic feature vector includes: Using the preset query matrix W Q and bond matrix W K The network traffic feature vector X at the corresponding sampling time point i is i Perform a linear transformation to obtain the first query vector Q at the corresponding sampling time point 1i and the first key vector K 1i , where Q 1i =X i ×W Q +b,K 1i =X i ×W K +b, b is the set bias vector; Using the first query vector Q corresponding to sampling time point i1i and the first key vector K 1i Calculate the first attention score F corresponding to sampling time point i 1i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the first query vector Q 1i and the first key vector K 1i The vector dimension of the first query vector Q 1i and the first key vector K 1i The vector dimensions of are the same; The first weight parameter of each sampling time point is calculated based on the first attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 1i is the first weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the first weight parameter of each sampling time point, the network traffic feature vectors at each sampling time point are weightedly fused to obtain a fused network traffic feature vector X, where: .
[0007] In a possible design, the weighted fusion of the system log feature vectors at each time point to obtain the fused system log feature vector includes: Using the preset query matrix W Q and bond matrix W K The system log feature vector Y at the corresponding sampling time point i is i Perform a linear transformation to obtain the second query vector Q at the corresponding sampling time point 2i and the second key vector K 2i , where Q 2i =Y i ×W Q +b,K 2i =Y i ×W K +b, b is the set bias vector; Using the second query vector Q corresponding to the sampling time point i 2i and the second key vector K 2i Calculate the second attention score F corresponding to sampling time point i 2i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the second query vector Q 2i and the second key vector K 2i The vector dimension of the second query vector Q 2i and the second key vector K 2i The vector dimensions of are the same; The second weight parameter of each sampling time point is calculated based on the second attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 2i is the second weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the second weight parameter of each sampling time point, the system log feature vectors at each sampling time point are weightedly fused to obtain a fused system log feature vector Y, where: .
[0008] In a possible design, performing weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector includes: Using the preset query matrix W Q and bond matrix W K The control signal feature vector Z at the corresponding sampling time point i is i Perform a linear transformation to obtain the third query vector Q at the corresponding sampling time point 3i and the third bond vector K 3i , where Q 3i =Z i ×W Q +b,K 3i =Z i ×W K +b, b is the set bias vector; Using the third query vector Q corresponding to sampling time point i 3i and the third bond vector K 3i Calculate the third attention score F corresponding to the sampling time point i 3i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the third query vector Q 3i and the third bond vector K 3i The vector dimension of the third query vector Q 3i and the third bond vector K 3i The vector dimensions of are the same; The third weight parameter of each sampling time point is calculated based on the third attention score of each sampling time point, wherein: , i is the number of the sampling time point, n is the total number of sampling time points, W 3i is the third weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the third weight parameter of each sampling time point, the control signal feature vectors at each sampling time point are weightedly fused to obtain a fused control signal feature vector Z, where: .
[0009] In a possible design, before inputting the high-dimensional concatenated vector into a preset network anomaly detection model for network anomaly detection, the method further includes: A graph neural network model is constructed, and the graph neural network model is trained and tested using a preset training set and test set to obtain a network anomaly detection model after training and testing. The training set and test set respectively contain a number of high-dimensional spliced vector samples marked with corresponding outlier value labels.
[0010] In one possible design, determining a dynamic weight parameter of each abnormal detection value in the detection value set, and calculating a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter, includes: Substitute each abnormal detection value in the detection value set into the dynamic weight formula for calculation to obtain the dynamic weight parameter of each abnormal detection value. The dynamic weight formula is:
[0011] Among them, j represents the number of abnormal detection values, m represents the number of abnormal detection values in the detection value set, and f j The characterization number is j, the abnormal detection value, ω j Characterizing the abnormal detection value f j The dynamic weight parameter of , β is the set adjustment coefficient; Substitute each abnormal detection value and its dynamic weight parameter in the detection value set into the long-term monitoring index formula Calculation is performed to obtain the long-term monitoring index S.
[0012] In a second aspect, a power plant control system network monitoring and early warning system is provided, including an information collection unit, a feature extraction unit, a feature fusion unit, an anomaly detection unit, a numerical summary unit, an index calculation unit and a monitoring and early warning unit, wherein: An information collection unit is used to collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period; A feature extraction unit, used to extract a network traffic feature vector of the network traffic information at each sampling time point, extract a system log feature vector of the system log information at each sampling time point, and extract a control signal feature vector of the control signal information at each sampling time point; A feature fusion unit is used to perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector; An anomaly detection unit is used to perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period; A value aggregation unit, used to aggregate the abnormal detection value of the current time period into a detection value set when the abnormal detection value of the current time period does not exceed the set abnormal threshold, wherein the detection value set includes abnormal detection values corresponding to several historical time periods; An index calculation unit, used to determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter; The monitoring and early warning unit is used to output network security early warning information of the power plant control system when the long-term monitoring index exceeds the set index threshold.
[0013] In a third aspect, a power plant control system network monitoring and early warning system is provided, comprising: A memory for storing instructions; A processor is used to read the instructions stored in the memory and execute any one of the methods described in the first aspect according to the instructions.
[0014] In a fourth aspect, a computer-readable storage medium is provided, wherein instructions are stored on the computer-readable storage medium, and when the instructions are executed on a computer, the computer executes any one of the methods described in the first aspect. In addition, a computer program product is provided, and when the computer program product is executed on a computer, the computer executes any one of the methods described in the first aspect.
[0015] Beneficial effects: The present invention collects network traffic information, system log information and control signal information of the power plant control system for feature extraction and feature fusion to obtain a high-dimensional splicing vector, and then inputs the high-dimensional splicing vector into a pre-trained neural network for anomaly detection to obtain anomaly detection values for network anomaly monitoring in the current period, and finally uses the anomaly detection values of each period for dynamic weight allocation and long-term monitoring index calculation, and performs network security early warning according to the long-term monitoring index to achieve accurate and reliable network monitoring and early warning of the power plant control system. The present invention can improve the comprehensiveness and reliability of network monitoring of the power plant control system and reduce the false alarm rate by constructing multi-source heterogeneous monitoring data features for anomaly analysis, and can achieve long-term dynamic comprehensive anomaly evaluation through dynamic weight allocation and fusion calculation of monitoring results in different time periods, improve the situational awareness capability of network anomaly monitoring, and meet the needs of time-series monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 This is a schematic diagram of the steps of the method in Example 1 of the present invention; Figure 2 This is a schematic diagram of the structure of the system in Example 2 of the present invention; Figure 3 Schematic diagram of the system structure in Example 3 of the present invention. DETAILED DESCRIPTION
[0018] It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention. The specific structures and functional details disclosed herein are only used to describe the exemplary embodiments of the present invention. However, the present invention can be embodied in many alternative forms, and it should not be understood that the present invention is limited to the embodiments set forth herein.
[0019] It should be understood that unless otherwise clearly specified and limited, the corresponding terms should be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a direct connection, or an indirect connection through an intermediate medium, or it can be the internal communication of two elements. For ordinary technicians in this field, the specific meanings of the above terms in the embodiments can be understood according to specific circumstances.
[0020] In the following description, certain details are provided to facilitate a complete understanding of the example embodiments. However, it will be appreciated by those of ordinary skill in the art that the example embodiments may be implemented without these certain details. For example, devices may be shown in block diagrams to avoid obscuring the examples with unnecessary details. In other embodiments, well-known processes, structures, and techniques may not be shown in unnecessary detail to avoid obscuring the embodiments.
[0021] Embodiment 1: This embodiment provides a power plant control system network monitoring and early warning method, which can be applied to corresponding monitoring terminals, such as Figure 1 As shown, the method comprises the following steps: S1. Collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period.
[0022] During specific implementation, the monitoring terminal may collect corresponding monitoring information on the power plant control system in each continuous time period, such as collecting network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period. The network traffic information may include information such as network data packet size, network protocol and network address. The system log information may cover user login information, permission change information and abnormal process information. The control signal information may cover control signal protocol, type, amplitude, timing and other information.
[0023] S2. Extracting network traffic feature vectors of network traffic information at each sampling time point, extracting system log feature vectors of system log information at each sampling time point, and extracting control signal feature vectors of control signal information at each sampling time point.
[0024] In specific implementation, the monitoring terminal can determine each network traffic characteristic parameter corresponding to the network traffic information, wherein each network traffic characteristic parameter includes a network data packet size parameter, a network protocol type ratio parameter, and a network address access frequency parameter, and then normalize each network traffic characteristic parameter, and use each normalized network traffic characteristic parameter to form a network traffic characteristic vector corresponding to the network traffic information. Each system log characteristic parameter corresponding to the system log information can be determined, wherein each system log characteristic parameter includes a user login frequency parameter, a permission change number parameter, and an abnormal process trigger rate parameter, and then normalize each system log characteristic parameter, and use each normalized system log characteristic parameter to form a system log characteristic vector corresponding to the system log information. Each control signal characteristic parameter corresponding to the control signal information can be determined, wherein each control signal characteristic parameter includes a signal protocol type ratio parameter, a signal amplitude standard deviation parameter, and a signal timing correlation parameter, and then normalize each control signal characteristic parameter, and use each normalized control signal characteristic parameter to form a control signal characteristic vector corresponding to the control signal information.
[0025] S3. Perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector.
[0026] In specific implementation, the monitoring terminal can use the preset query matrix W Q and bond matrix W K The network traffic feature vector X at the corresponding sampling time point i is i Perform a linear transformation to obtain the first query vector Q at the corresponding sampling time point 1i and the first key vector K 1i , where Q 1i=X i ×W Q +b,K 1i =X i ×W K +b, b is the set bias vector; Then, the first query vector Q corresponding to the sampling time point i is used 1i and the first key vector K 1i Calculate the first attention score F corresponding to sampling time point i 1i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the first query vector Q 1i and the first key vector K 1i The vector dimension of the first query vector Q 1i and the first key vector K 1i The vector dimensions of are the same; Then, the first weight parameter of each sampling time point is calculated based on the first attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 1i is the first weight parameter of sampling time point i, exp represents the natural exponential function operation; Finally, based on the first weight parameter of each sampling time point, the network traffic feature vectors at each sampling time point are weightedly fused to obtain the fused network traffic feature vector X, where: .
[0027] Similarly, the monitoring terminal can use the preset query matrix W Q and bond matrix W K The system log feature vector Y at the corresponding sampling time point i is i Perform a linear transformation to obtain the second query vector Q at the corresponding sampling time point 2i and the second key vector K 2i , where Q 2i =Y i ×W Q +b,K 2i =Y i ×W K +b, b is the set bias vector; Then use the second query vector Q corresponding to the sampling time point i 2i and the second key vector K 2i Calculate the second attention score F corresponding to sampling time point i 2i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the second query vector Q 2i and the second key vector K 2iThe vector dimension of the second query vector Q 2i and the second key vector K 2i The vector dimensions of are the same; Then, the second weight parameter of each sampling time point is calculated based on the second attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 2i is the second weight parameter of sampling time point i, exp represents the natural exponential function operation; Finally, based on the second weight parameter of each sampling time point, the system log feature vectors at each sampling time point are weighted and fused to obtain the fused system log feature vector Y, where: .
[0028] Similarly, the monitoring terminal can use the preset query matrix W Q and bond matrix W K The control signal feature vector Z at the corresponding sampling time point i is i Perform a linear transformation to obtain the third query vector Q at the corresponding sampling time point 3i and the third bond vector K 3i , where Q 3i =Z i ×W Q +b,K 3i =Z i ×W K +b, b is the set bias vector; Then use the third query vector Q corresponding to the sampling time point i 3i and the third bond vector K 3i Calculate the third attention score F corresponding to the sampling time point i 3i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the third query vector Q 3i and the third bond vector K 3i The vector dimension of the third query vector Q 3i and the third bond vector K 3i The vector dimensions of are the same; Then, the third weight parameter of each sampling time point is calculated based on the third attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 3i is the third weight parameter of sampling time point i, exp represents the natural exponential function operation; Finally, based on the third weight parameter of each sampling time point, the control signal feature vectors at each sampling time point are weightedly fused to obtain a fused control signal feature vector Z, where: .
[0029] S4. Perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period.
[0030] In specific implementation, after obtaining the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector, the monitoring terminal performs vector splicing, such as row splicing or column splicing, on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector. The high-dimensional splicing vector is then input into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period. The network anomaly detection model can be obtained by training and testing a pre-built graph neural network model, and the training set and test set respectively contain a number of high-dimensional splicing vector samples labeled with corresponding anomaly value labels.
[0031] S5. When the abnormal detection value of the current time period does not exceed the set abnormal threshold, the abnormal detection value of the current time period is merged into a detection value set, and the detection value set includes abnormal detection values corresponding to several historical time periods.
[0032] In specific implementation, when the abnormal detection value of the current time period exceeds the set abnormal threshold, the monitoring terminal outputs the network abnormality alarm information of the power plant control system. When the abnormal detection value of the current time period does not exceed the set abnormal threshold, the monitoring terminal merges the abnormal detection value of the current time period into the detection value set, and the detection value set contains abnormal detection values corresponding to several (such as 3-5) historical time periods.
[0033] S6. Determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter.
[0034] In specific implementation, the monitoring terminal substitutes each abnormal detection value in the detection value set into the dynamic weight formula for calculation to obtain the dynamic weight parameter of each abnormal detection value. The dynamic weight formula is:
[0035] Among them, j represents the number of abnormal detection values, m represents the number of abnormal detection values in the detection value set, and f j The characterization number is j, the abnormal detection value, ω j Characterizing the abnormal detection value f j The dynamic weight parameter of , β is the set adjustment coefficient; Then substitute each abnormal detection value and its dynamic weight parameter in the detection value set into the long-term monitoring index formula Calculation is performed to obtain the long-term monitoring index S.
[0036] S7. When the long-term monitoring index exceeds the set index threshold, the network security warning information of the power plant control system is output.
[0037] In specific implementation, when the long-term monitoring index exceeds the set index threshold, the monitoring terminal outputs the network security warning information of the power plant control system to achieve accurate and reliable network monitoring and warning of the power plant control system.
[0038] This method can improve the comprehensiveness and reliability of power plant control system network monitoring and reduce the false alarm rate by constructing multi-source heterogeneous monitoring data features for anomaly analysis. It can also achieve long-term dynamic comprehensive anomaly evaluation through dynamic weight allocation and fusion calculation of time-divided monitoring results, improve the situational awareness capability of network anomaly monitoring, and meet the needs of temporal monitoring.
[0039] Embodiment 2: This embodiment provides a power plant control system network monitoring and early warning system, such as Figure 2 As shown, it includes an information collection unit, a feature extraction unit, a feature fusion unit, an anomaly detection unit, a numerical summary unit, an index calculation unit and a monitoring and early warning unit, wherein: An information collection unit is used to collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period; A feature extraction unit, used to extract a network traffic feature vector of the network traffic information at each sampling time point, extract a system log feature vector of the system log information at each sampling time point, and extract a control signal feature vector of the control signal information at each sampling time point; A feature fusion unit is used to perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector; An anomaly detection unit is used to perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period; A value aggregation unit, used to aggregate the abnormal detection value of the current time period into a detection value set when the abnormal detection value of the current time period does not exceed the set abnormal threshold, wherein the detection value set includes abnormal detection values corresponding to several historical time periods; An index calculation unit, used to determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter; The monitoring and early warning unit is used to output network security early warning information of the power plant control system when the long-term monitoring index exceeds the set index threshold, and to output network abnormality alarm information of the power plant control system when the abnormal detection value in the current time period exceeds the set abnormality threshold.
[0040] Embodiment 3: This embodiment provides a power plant control system network monitoring and early warning system, such as Figure 3 As shown, at the hardware level, it includes: Data interface, used to establish data connection between the processor and the power plant control system; A memory for storing instructions; The processor is used to read the instructions stored in the memory and execute the power plant control system network monitoring and early warning method in Example 1 according to the instructions.
[0041] Optionally, the system further includes an internal bus, through which the processor, the memory and the data interface can be interconnected, and the internal bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc.
[0042] The memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) and / or first in last out (FILO), etc. The processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
[0043] Embodiment 4: This embodiment provides a computer-readable storage medium, on which instructions are stored, and when the instructions are executed on a computer, the computer executes the power plant control system network monitoring and early warning method in Embodiment 1. The computer-readable storage medium refers to a carrier for storing data, which may include but is not limited to a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash drive, and / or a memory stick, etc., and the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0044] This embodiment also provides a computer program product, which, when executed on a computer, executes the power plant control system network monitoring and early warning method in Embodiment 1. The computer may be a general-purpose computer, a special-purpose computer, a computer network or other programmable device.
[0045] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A power plant control system network monitoring and early warning method, characterized in that: include: Collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period; Extracting network traffic feature vectors of network traffic information at each sampling time point, extracting system log feature vectors of system log information at each sampling time point, and extracting control signal feature vectors of control signal information at each sampling time point; Perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector; Perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period; When the abnormal detection value of the current time period does not exceed the set abnormal threshold, the abnormal detection value of the current time period is merged into a detection value set, and the detection value set includes abnormal detection values corresponding to several historical time periods; Determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter; When the long-term monitoring index exceeds the set index threshold, the network security warning information of the power plant control system is output.
2. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: The extracting of network traffic feature vectors of network traffic information at each sampling time point, extracting system log feature vectors of system log information at each sampling time point, and extracting control signal feature vectors of control signal information at each sampling time point include: Determine each network traffic characteristic parameter corresponding to the network traffic information, wherein each network traffic characteristic parameter includes a network data packet size parameter, a network protocol type ratio parameter, and a network address access frequency parameter, and perform normalization processing on each network traffic characteristic parameter, and use each normalized network traffic characteristic parameter to form a network traffic characteristic vector corresponding to the network traffic information; Determine each system log characteristic parameter corresponding to the system log information, wherein each system log characteristic parameter includes a user login frequency parameter, a permission change number parameter, and an abnormal process trigger rate parameter, and normalize each system log characteristic parameter, and use each system log characteristic parameter after the normalization process to form a system log characteristic vector corresponding to the system log information; Determine each control signal characteristic parameter corresponding to the control signal information, wherein each control signal characteristic parameter includes a signal protocol type ratio parameter, a signal amplitude standard deviation parameter, and a signal timing correlation parameter, and normalize each control signal characteristic parameter, and use the normalized control signal characteristic parameters to form a control signal characteristic vector corresponding to the control signal information.
3. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: The weighted fusion of the network traffic feature vectors at each time point to obtain a fused network traffic feature vector includes: Using the preset query matrix W Q and bond matrix W K The network traffic feature vector X at the corresponding sampling time point i is i Perform a linear transformation to obtain the first query vector Q at the corresponding sampling time point 1i and the first key vector K 1i , where Q 1i =X i ×W Q +b,K 1i =X i ×W K +b, b is the set bias vector; Using the first query vector Q corresponding to sampling time point i 1i and the first key vector K 1i Calculate the first attention score F corresponding to sampling time point i 1i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the first query vector Q 1i and the first key vector K 1i The vector dimension of the first query vector Q 1i and the first key vector K 1i The vector dimensions of are the same; The first weight parameter of each sampling time point is calculated based on the first attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 1i is the first weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the first weight parameter of each sampling time point, the network traffic feature vectors at each sampling time point are weightedly fused to obtain a fused network traffic feature vector X, where: .
4. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: The weighted fusion of the system log feature vectors at each time point to obtain the fused system log feature vector includes: Using the preset query matrix W Q and bond matrix W K The system log feature vector Y at the corresponding sampling time point i is i Perform a linear transformation to obtain the second query vector Q at the corresponding sampling time point 2i and the second key vector K 2i , where Q 2i =Y i ×W Q +b,K 2i =Y i ×W K +b, b is the set bias vector; Using the second query vector Q corresponding to the sampling time point i 2i and the second key vector K 2i Calculate the second attention score F corresponding to sampling time point i 2i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the second query vector Q 2i and the second key vector K 2i The vector dimension of the second query vector Q 2i and the second key vector K 2i The vector dimensions of are the same; The second weight parameter of each sampling time point is calculated based on the second attention score of each sampling time point, where: , i is the number of the sampling time point, n is the total number of sampling time points, W 2i is the second weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the second weight parameter of each sampling time point, the system log feature vectors at each sampling time point are weightedly fused to obtain a fused system log feature vector Y, where: .
5. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: The step of performing weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector includes: Using the preset query matrix W Q and bond matrix W K The control signal feature vector Z at the corresponding sampling time point i is i Perform a linear transformation to obtain the third query vector Q at the corresponding sampling time point 3i and the third bond vector K 3i , where Q 3i =Z i ×W Q +b,K 3i =Z i ×W K +b, b is the set bias vector; Using the third query vector Q corresponding to sampling time point i 3i and the third bond vector K 3i Calculate the third attention score F corresponding to the sampling time point i 3i ,in, , Softmax represents the normalized exponential function operation, T represents the vector transpose, and d is the third query vector Q 3i and the third bond vector K 3i The vector dimension of the third query vector Q 3i and the third bond vector K 3i The vector dimensions of are the same; The third weight parameter of each sampling time point is calculated based on the third attention score of each sampling time point, wherein: , i is the number of the sampling time point, n is the total number of sampling time points, W 3i is the third weight parameter of sampling time point i, exp represents the natural exponential function operation; Based on the third weight parameter of each sampling time point, the control signal feature vectors at each sampling time point are weightedly fused to obtain a fused control signal feature vector Z, where: .
6. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: Before inputting the high-dimensional concatenated vector into a preset network anomaly detection model for network anomaly detection, the method further includes: A graph neural network model is constructed, and the graph neural network model is trained and tested using a preset training set and test set to obtain a network anomaly detection model after training and testing. The training set and test set respectively contain a number of high-dimensional spliced vector samples marked with corresponding outlier value labels.
7. A power plant control system network monitoring and early warning method according to claim 1, characterized in that: The determining of the dynamic weight parameter of each abnormal detection value in the detection value set, and calculating the long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter, includes: Substitute each abnormal detection value in the detection value set into the dynamic weight formula for calculation to obtain the dynamic weight parameter of each abnormal detection value. The dynamic weight formula is: Among them, j represents the number of abnormal detection values, m represents the number of abnormal detection values in the detection value set, and f j The characterization number is j, the abnormal detection value, ω j Characterizing the abnormal detection value f j The dynamic weight parameter of , β is the set adjustment coefficient; Substitute each abnormal detection value and its dynamic weight parameter in the detection value set into the long-term monitoring index formula Calculation is performed to obtain the long-term monitoring index S.
8. A power plant control system network monitoring and early warning system, characterized in that: It includes information collection unit, feature extraction unit, feature fusion unit, anomaly detection unit, numerical summary unit, index calculation unit and monitoring and early warning unit, among which: An information collection unit is used to collect network traffic information, system log information and control signal information of the power plant control system at each sampling time point in the current time period; A feature extraction unit, used to extract a network traffic feature vector of the network traffic information at each sampling time point, extract a system log feature vector of the system log information at each sampling time point, and extract a control signal feature vector of the control signal information at each sampling time point; A feature fusion unit is used to perform weighted fusion on the network traffic feature vectors at each time point to obtain a fused network traffic feature vector, perform weighted fusion on the system log feature vectors at each time point to obtain a fused system log feature vector, and perform weighted fusion on the control signal feature vectors at each time point to obtain a fused control signal feature vector; An anomaly detection unit is used to perform vector splicing on the fused network traffic feature vector, the fused system log feature vector and the fused control signal feature vector to obtain a high-dimensional splicing vector, and input the high-dimensional splicing vector into a preset network anomaly detection model to perform network anomaly detection and obtain an anomaly detection value for the current time period; A value aggregation unit, used to aggregate the abnormal detection value of the current time period into a detection value set when the abnormal detection value of the current time period does not exceed the set abnormal threshold, wherein the detection value set includes abnormal detection values corresponding to several historical time periods; An index calculation unit, used to determine a dynamic weight parameter of each abnormal detection value in the detection value set, and calculate a long-term monitoring index using each abnormal detection value in the detection value set and its dynamic weight parameter; The monitoring and early warning unit is used to output network security early warning information of the power plant control system when the long-term monitoring index exceeds the set index threshold.
9. A power plant control system network monitoring and early warning system, characterized in that: include: A memory for storing instructions; A processor is used to read the instructions stored in the memory and execute the power plant control system network monitoring and early warning method described in any one of claims 1-7 according to the instructions.
10. A computer program product, characterized in that When the computer program product is run on a computer, the power plant control system network monitoring and early warning method described in any one of claims 1 to 7 is executed.
Citation Information
Patent Citations
Network traffic anomaly detection method and system based on self-attention mechanism
CN115630298A
Alarm based on network security
CN116405299A
High-dimensional time series data anomaly detection method based on multi-modal generative adversarial network
CN118690304A
Multi-modal network security situation awareness and fusion analysis method and system
CN119172119A
Network traffic abnormity monitoring method and device based on BiLSTM-Att network
CN119232490A
Cited By
Power system network security detection method, device, equipment and medium
CN120455155A
Abnormal behavior detection method and device for power network, equipment and medium
CN120710726A
Gear honing machining process monitoring method and system
CN121635161A
A method and system for monitoring the honing process
CN121635161B