Intelligent substation network intrusion detection method based on dense connection neural network

By applying a densely connected neural network model in an intelligent substation to analyze the packet data and identify abnormal traffic, the problem of network intrusion detection of intelligent substations is solved, and the intrusion detection effect with high accuracy and fast response is achieved.

CN120017331APending Publication Date: 2025-05-16BAZHOU POWER SUPPLY CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510076713.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Because the smart substation adopts the open IEC61850 standard protocol, it cannot provide sufficient security guarantees and faces security problems such as network intrusion. Especially when communication delay requirements are strict, conventional encryption algorithms are difficult to effectively prevent packet tampering and intercepting.

Method used

The intelligent substation network intrusion detection method based on densely connected neural networks is adopted. By pre-processing and feature extraction of packet data such as SMV/SV, GOOSE, MMS, etc., the DenseCNN model of the densely connected neural network is used to identify abnormal traffic, and high accuracy detection of intelligent substation network intrusion is achieved.

Benefits of technology

It realizes high accuracy detection of network intrusion of smart substations, ensures the safe and stable operation of the substation and the entire power system, and has the advantages of high accuracy, rapid response and online deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017331A_ABST
    Figure CN120017331A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent substation network intrusion detection method based on a dense connection neural network, and the method comprises the steps: extracting data features through a dense connection neural network DenseCNN after processing the data of three main messages SMV / SV, GOOSE and MMS of an intelligent substation; according to the method, feature vectors of original data after multi-layer convolution are directly sent into a global maximum pooling layer for pooling operation, classification is carried out through a full connection layer, intrusion traffic in the data is found out, and therefore abnormal traffic recognition is achieved. Compared with other intrusion detection schemes, the method has the advantages of high accuracy, quick response, online deployment and the like. Meanwhile, the model based on the neural network has remarkable robustness and has good adaptability to different working environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power systems, and in particular to a network intrusion detection method for an intelligent substation based on a densely connected neural network. Background Art

[0002] With the advancement of smart grid construction and the rapid development of computer network technology, the intelligence of power transmission and distribution has gradually become a new development requirement for the power system. Smart substations that are highly integrated with the Internet meet the needs of safe and stable operation and flexible scheduling of smart grids with their advantages in digitization and informatization, and have therefore become the mainstream development trend. However, smart substations that apply Internet communication technology also face security issues such as network intrusion.

[0003] The IEC61850 standard protocol adopted by smart substations is an open communication protocol, which cannot provide sufficient security for the network system of smart substations. The information security problem of smart substations is becoming increasingly prominent. In the IEC61850 standard protocol, smart substations are logically divided into three layers, namely the station control layer, the bay layer and the process layer. There are a large number of communication data transmissions between each layer and between the same layers, such as MMS messages for communication between the station control layer and the bay layer, GOOSE messages for transmitting information between substation IDEs, and SV / SMV messages for transmitting real-time measurement data. Due to the rigid requirements of substation real-time performance, the IEC 61850 standard protocol stipulates that the maximum communication delay of smart substations is 4ms. Therefore, conventional encryption algorithms cannot be used in the transmission process of messages. Smart substations face a series of network intrusion risks such as message tampering and interception. Therefore, it is of great significance to efficiently detect and accurately identify network intrusions in smart substations. Summary of the invention

[0004] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a smart substation network intrusion detection method based on a densely connected neural network. By analyzing the SMV / SV, GOOSE, MMS and other message data of the smart substation network, a densely connected neural network model is used to identify abnormal traffic, thereby achieving high-accuracy detection of smart substation network intrusions and ensuring the safe and stable operation of the substation and even the entire power system.

[0005] To achieve the above-mentioned purpose of the invention, the present invention provides a network intrusion detection method for a smart substation based on a densely connected neural network, which is characterized in that the densely connected neural network model is first trained, the preprocessed data set is input into the densely connected neural network model, the characteristics of different types of traffic are analyzed, and then classified to obtain a densely connected neural network model that can stably and efficiently identify intrusion traffic, including the following steps:

[0006] (1) Preprocess the message data, including data cleaning and data standardization:

[0007] First, the original message data set is preprocessed to delete the message data with missing values ​​and the message data containing NaN characters that represent erroneous content, delete the message data in which adjacent messages are completely repeated and only retain one of them, and delete the special message data in which all characters are zero. After the above preprocessing, a high-quality and high-accuracy data set is obtained. Since the content of the message data is in hexadecimal format, it is converted into a decimal format that is easy to handle;

[0008] Considering that the magnitude differences between different message data are very significant, it is necessary to standardize the cleaned message data: use Z-Score standardization to transform the original data set into a data set that conforms to the standard normal distribution. The formula for Z-Score standardization is as follows:

[0009]

[0010] Among them, x is the element in each set of data, μ is the mean of the data set, and σ is the variance of the data set;

[0011] The standardized data sets are unified to the same order of magnitude, which can greatly reduce the amount of calculation and effectively increase the accuracy of the classification results;

[0012] Finally, the discrete data is converted to continuous data through One-hot encoding.

[0013] (2) Use densely connected neural network DenseCNN to extract features of the dataset

[0014] The convolutional neural network consists of convolutional layers, pooling layers, and fully connected layers. First, the spatial features of the data set are extracted through convolution operations in multiple convolutional layers, and no additional pooling layer is added in each convolutional layer. The feature vectors after convolution all enter the next convolutional layer. The feature vector h after convolution is expressed as:

[0015] h=g(x*ω+b)

[0016] Among them, g represents the activation function; * is used as the symbol of convolution here; ω represents the set convolution kernel; x represents the input data set, which is specifically expressed as a matrix of size m×n; b represents the bias;

[0017] (3) All feature vectors after convolution enter the global maximum pooling layer, in which the maximum pooling operation is used to process the output feature vector. The calculation formula of maximum pooling is as follows:

[0018] output[i,j]=max(input[i*pool_size:(i+1)*pool_size,

[0019] j*pool_size:(j+1)*pool_size])

[0020] Among them, output[i,j] represents the element in the i-th row and j-th column of the feature vector matrix output after global maximum pooling; input represents the input feature vector matrix; pool_size represents the window size of the pooling operation, and max is the maximum value function, which means selecting the maximum value in the selected window;

[0021] (4) The high-level features extracted after global maximum pooling enter the fully connected layer and are classified by the Sigmoid function:

[0022] O = Sigmoid(W*X+b)

[0023] Among them, O is the classification formula, W is the weight of the fully connected layer, X is the feature vector of the convolutional graph obtained after the pooling operation, and b is the bias of the fully connected layer.

[0024] The classified results are compared and verified with the true values, the loss value is calculated, and the recognition accuracy of the model is evaluated. If the accuracy meets the requirements, the model converges. Otherwise, the parameters in the model are continuously adjusted and updated until the loss value meets the requirements. At this time, the model converges.

[0025] The object of the present invention is achieved in this way.

[0026] The network intrusion detection method for smart substations based on densely connected neural networks of the present invention processes the data of the three main messages SMV / SV, GOOSE, and MMS of the smart substation, extracts data features through densely connected neural networks DenseCNN, and directly sends the feature vectors of the original data after multi-layer convolution to the global maximum pooling layer for pooling operation, and then classifies it through the fully connected layer to find out the intrusion traffic, thereby realizing the identification of abnormal traffic. Compared with other intrusion detection schemes, the present invention has the advantages of high accuracy, fast response, and online deployment. At the same time, the model based on neural networks has significant robustness and good adaptability to different working environments.

[0027] At the same time, the present invention also has the following beneficial effects:

[0028] (1) The present invention is a model based on deep reinforcement learning and has high adaptability and robustness.

[0029] (2) The present invention performs residual connection operations on the convolutional layers in the neural network model, thereby ensuring the convergence of the neural network and improving the stability of the model at different depths.

[0030] (3) The present invention introduces a dense connection mechanism into the neural network model, which greatly reduces the amount of parameter calculation, and thus has good calculation efficiency. In actual application scenarios, it can meet the real-time requirements of information transmission in smart substations. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is a flowchart of a specific implementation method of the intelligent substation network intrusion detection method based on densely connected neural network of the present invention;

[0032] Figure 2 It is a schematic diagram of the structure of the neural network designed in the present invention. DETAILED DESCRIPTION

[0033] The specific implementation of the present invention is described below in conjunction with the accompanying drawings so that those skilled in the art can better understand the present invention. It should be noted that in the following description, when the detailed description of known functions and designs may dilute the main content of the present invention, these descriptions will be omitted here.

[0034] Based on the shortcomings of the prior art, the present invention proposes a network intrusion detection method for smart substations based on densely connected neural networks. The method analyzes the message communication data in the smart substation, uses a densely connected convolutional neural network model to extract the features of the message, identifies and classifies normal traffic and intrusion traffic, thereby detecting abnormal intrusion traffic and providing protection for the safe and stable operation of the smart substation. Compared with other intrusion detection schemes, the present invention has the advantages of high accuracy, fast response, and online deployment. At the same time, the model based on neural networks has significant robustness and good adaptability to different working environments.

[0035] In this embodiment, if Figure 1 As shown, the present invention provides a method for detecting network intrusion in smart substations based on a densely connected neural network, comprising the following steps:

[0036] (1) Preprocess the acquired SMV / SV, GOOSE, MMS and other message data and intrusion data. The main steps can be divided into three parts: data cleaning, data standardization and data encoding.

[0037] 1. During the data cleaning process, the following types of data will be eliminated:

[0038] Message data with missing values;

[0039] Message data containing NaN characters and other error contents;

[0040] Special message data where all characters are zero;

[0041] Message data that is completely repeated in adjacent messages;

[0042] Among them, for message data with missing values ​​and NaN characters representing erroneous content, the dropna function in the pandas library can be used to delete them; for message data with complete duplication of adjacent messages, the drop_duplicates function can be used to delete them, and only the first occurrence record is retained;

[0043] 2. In the process of data standardization, Z-Score standardization is used to transform the original data set into a data set that conforms to the standard normal distribution to eliminate the order of magnitude differences between different data and facilitate subsequent calculations and processing. The formula for Z-Score standardization is as follows:

[0044]

[0045] Among them, x is the element in each set of data, μ is the mean of the data set, and σ is the variance of the data set.

[0046] 3. For discrete data fields and fields with label attributes in the data set, one-hot encoding is used to convert them into continuous data.

[0047] After the above preprocessing, a high-quality and high-accuracy data set is obtained, which is in the form of a matrix composed of vectors. Since the message content is in hexadecimal format, it is converted into a decimal format that is easy to process. At this time, the data set consists of complete and non-repetitive normal network messages and abnormal intrusion traffic, and then feature recognition and classification processing are carried out.

[0048] (2) Use the densely connected neural network DenseCNN to extract the features of the data set. The convolutional neural network is generally composed of a convolutional layer, a pooling layer, and a fully connected layer. The neural network structure designed by the present invention is as follows: Figure 2 shown.

[0049] First, the cleaned data enters the convolution layer, where the local space of the data set matrix is ​​multiplied by the convolution kernel to extract the local spatial features of the corresponding area of ​​the data set. The convolution operation is continuously performed, and all the local spatial features obtained are passed to the next convolution layer. And for each convolution layer, no additional pooling layer is added at the output end. The purpose is to retain the complete feature information when the feature vector matrix after convolution enters the next convolution layer.

[0050] The convolutional feature vector h is expressed as:

[0051] h=g(x*ω+b)

[0052] Among them, g represents the activation function; * is used as the symbol of convolution here; ω represents the set convolution kernel, and the size of the convolution kernel is 3x3; x represents the input data set, which is specifically represented by a matrix of size m×n; b represents the bias of the convolution layer.

[0053] (3) After multiple layers of convolution, all feature vectors enter the global maximum pooling layer, where the maximum pooling operation is used to process the input feature vectors. The calculation formula of maximum pooling is as follows:

[0054] output[i,j]=max(input[i*pool_size:(i+1)*pool_size,

[0055] j*pool_size:(j+1)*pool_size])

[0056] Among them, output[i,j] represents the element in the i-th row and j-th column of the high-level feature vector matrix output after global maximum pooling; input represents the input feature vector matrix; pool_size represents the window size of the pooling operation, which can be 2x2; max is the maximum value function, which means that the maximum value in the selected window is selected as the output.

[0057] After pooling, the dimension of the data set is reduced and the features are further streamlined, becoming features with lower complexity and higher information content.

[0058] (4) The high-level features extracted after global maximum pooling enter the fully connected layer. Considering that the purpose of this invention is only to identify abnormal intrusion traffic in smart substations, it can be considered that there are only two types of data in the original data set, namely normal traffic containing communication messages such as SMV / SV, GOOSE, and MMS, and abnormal traffic containing intrusion attacks. Therefore, the Sigmoid function commonly used for binary classification problems is used as the activation function for classification. The input high-level features are transformed into outputs on (0,1).

[0059] The Sigmoid function form is:

[0060]

[0061] Its derivative form is:

[0062] f′(x)=f(x)[1-f(x)]

[0063] The classification formula of the fully connected layer is:

[0064] O = Sigmoid(W*X+b)

[0065] Among them, O is the classification formula; W is the weight of the fully connected layer; X is the feature vector of the convolution graph obtained after the global maximum pooling operation; b is the bias of the fully connected layer.

[0066] The output result after the fully connected layer will classify the original data set into two categories: normal traffic and abnormal traffic. The classified results are compared and verified with the true values, the loss value is calculated, and the performance indicators such as the overall recognition accuracy, abnormal traffic recognition accuracy and false alarm rate of the model are evaluated.

[0067] The overall recognition accuracy evaluation formula of the model is:

[0068]

[0069] Among them, Data_Normal represents the amount of normal traffic data in the verification set, and Data_Invasion represents the amount of intrusion traffic data in the verification set; Output_Normal_Right represents the amount of data correctly classified as normal traffic in the output results, and Output_Invasion_Right represents the amount of data correctly classified as intrusion traffic in the output results.

[0070] The evaluation formula for the model's abnormal traffic identification accuracy is:

[0071]

[0072] The meanings of the parameters are the same as above.

[0073] The model false alarm rate evaluation formula is:

[0074]

[0075] Output_Normal_Wrong indicates the amount of data in the output result that is incorrectly classified as normal traffic. The meanings of the other parameters are the same as above.

[0076] If all indicators meet the set requirements, the model is considered to have converged. If not, the parameters of each layer in the model are continuously adjusted and updated, and training is performed again until the size of each indicator meets the set requirements. At this time, the model finally converges and can meet the actual application needs, realizing accurate identification of abnormal intrusion traffic in smart substations.

[0077] In summary, the present invention is a method for intrusion detection of a smart substation network based on a densely connected neural network. The method constructs an intrusion detection and identification model for a smart substation network. After data processing of several main messages of the substation, the neural network model is trained to identify and classify abnormal traffic, thereby achieving the effect of intrusion detection. The method has high accuracy and has good application prospects. At the same time, the model has the characteristics of rapid response, which can meet the needs of instant communication in smart substations. In practical applications, it can achieve instant response and identify intrusion traffic and abnormal messages. In addition, the model can also be deployed online.

[0078] Although the above describes the illustrative specific embodiments of the present invention to facilitate the understanding of the present invention by those skilled in the art, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.

Claims

1. A method for detecting network intrusion in smart substations based on densely connected neural networks, characterized in that: First, the densely connected neural network model is trained, and the preprocessed data set is input into the densely connected neural network model to analyze the characteristics of different types of traffic, and then classify them to obtain a densely connected neural network model that can stably and efficiently identify intrusion traffic, including the following steps: (1) Preprocess the message data, including data cleaning and data standardization: First, the original message data set is preprocessed to delete the message data with missing values ​​and the message data containing NaN characters representing error content, delete the message data in which adjacent messages are completely repeated and only retain one of them, and delete the special message data in which all characters are zero. After the above preprocessing, a high-quality and high-accuracy data set is obtained. Since the content of the message data is in hexadecimal format, it is converted into a decimal format that is easy to process; Considering that the magnitude differences between different message data are very significant, it is necessary to standardize the cleaned message data: use Z-Score standardization to transform the original data set into a data set that conforms to the standard normal distribution. The formula for Z-Score standardization is as follows: Among them, x is the element in each set of data, μ is the mean of the data set, and σ is the variance of the data set; The standardized data sets are unified to the same order of magnitude, which can greatly reduce the amount of calculation and effectively increase the accuracy of the classification results; Finally, the discrete data is converted into continuous data through One-hot encoding; (2) Use densely connected neural network DenseCNN to extract features of the dataset The convolutional neural network consists of convolutional layers, pooling layers, and fully connected layers. First, the spatial features of the data set are extracted through convolution operations in multiple convolutional layers, and no additional pooling layer is added in each convolutional layer. The feature vectors after convolution all enter the next convolutional layer. The feature vector h after convolution is expressed as: h=g(x*ω+b) Among them, g represents the activation function; * is used as the symbol of convolution here; ω represents the set convolution kernel; x represents the input data set, which is specifically expressed as a matrix of size m×n; b represents the bias; (3) All feature vectors after convolution enter the global maximum pooling layer, in which the maximum pooling operation is used to process the output feature vector. The calculation formula of maximum pooling is as follows: output[i,j]=max(input[i*pool_size:(i+1)*pool_size, j*pool_size: (j+1)*pool_size]) Among them, output[i, j] represents the element in the i-th row and j-th column of the feature vector matrix output after global maximum pooling; input represents the input feature vector matrix; pool_size represents the window size of the pooling operation, and max is the maximum value function, which means selecting the maximum value in the selected window; (4) The high-level features extracted after global maximum pooling enter the fully connected layer and are classified by the Sigmoid function: O = Sigmoid(W*X+b) Among them, O is the classification formula, W is the weight of the fully connected layer, X is the feature vector of the convolutional graph obtained after the pooling operation, and b is the bias of the fully connected layer; The classified results are compared and verified with the true values, the loss value is calculated, and the recognition accuracy of the model is evaluated. If the accuracy meets the requirements, the model converges. Otherwise, the parameters in the model are continuously adjusted and updated until the loss value meets the requirements. At this time, the model converges.

2. The method for detecting network intrusion in smart substation based on densely connected neural network according to claim 1 is characterized in that: The message data includes SMV / SV, GOOSE and MMS data.

Citation Information

Cited By

  • Network intrusion detection method, system and device based on multi-dimensional features and storage medium

    CN121664510A

  • A network intrusion detection method, system, device and storage medium based on multi-dimensional features

    CN121664510B