Multi-source heterogeneous alarm method, device and equipment for network security state of control system

Through the multi-source associated alarm trigger model, combined with the STGCN network and star network, the problem of insufficient security situation awareness capability of power network in the prior art is solved, and more accurate alarms and more efficient security situation awareness are achieved.

CN120017427AActive Publication Date: 2025-05-16北京网藤科技有限公司 +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510502368.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-05-16
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

The existing power network security situation awareness technology has problems such as incomplete perception capabilities, insufficient recognition capabilities, too slow response speed and too many security alarms in terms of pre-warning and monitoring, in-process emergency response, and post-tracement and defect removal, making it difficult to effectively correlate alarm events from multiple heterogeneous data sources.

Method used

A multi-source heterogeneous alarm method for controlling network security status of the control system is adopted. By obtaining historical alarm events of multiple heterogeneous data sources, the correlation coefficients of any two event types are calculated, and a star network is constructed to generate multi-frame network security status alarm diagrams, and input them to the deep learning model based on the STGCN network for rate-determined verification modeling to obtain the multi-source association alarm trigger model.

Benefits of technology

It effectively improves the accuracy of alarms and the network security situation awareness capability of the control system, solves the problems of isolated alarms, high false alarm rates and difficult to identify complex attacks, and is especially suitable for power network control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017427A_ABST
    Figure CN120017427A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-source heterogeneous alarm method, device and equipment for a network security state of a control system, and relates to a power network security situation awareness technology. The method comprises the following steps: firstly, according to all historical network security state alarm events which are triggered for a target control system and come from a plurality of heterogeneous data sources, calculating to obtain correlation coefficients of any two event types; any event type is constructed, and sample data which not only comprehensively reflects the correlation characteristics of the network security states of the plurality of heterogeneous data sources but also reflects the time sequence characteristics of the network security states are obtained; all corresponding sample data are imported into a deep learning model based on an STGCN network for calibration verification modeling, a corresponding multi-source associated alarm triggering model is obtained, and finally, the model is applied to instantly output and obtain an alarm triggering result of any event type. Therefore, the alarm accuracy can be effectively improved, and the network security situation awareness capability of the control system can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to electric power network security situation awareness technology, and specifically relates to a control system network security status multi-source heterogeneous alarm method, device and equipment. Background Art

[0002] The existing power network security situation awareness technology has exposed many problems in practical applications, and it is difficult to meet the safety production needs of the power network in terms of pre-warning monitoring, in-process emergency response, and post-event traceability and fault elimination; specifically, it is manifested in incomplete perception capabilities, insufficient recognition capabilities, slow response speed, and too many security alarms, etc. In response to the problems existing in the existing power network security situation awareness technology, the newly released "Power Monitoring System Security Protection Regulations" put forward higher requirements based on the structural security principles of "security partitioning, network dedicated, horizontal isolation, and vertical authentication", namely "strengthening security immunity, situation awareness, dynamic evaluation and backup emergency measures, and building a continuously developing and perfect protection system". This measure aims to promote the security protection work of the power monitoring system to a more complete and efficient direction.

[0003] At present, in the situational awareness technology of power network control systems, security alarm events may come from multiple heterogeneous data sources, including the network security monitoring device of the Huadian Ruilan control system, the network security monitoring device of the Huadian Ruilan control system private protocol, the network traffic (especially the industrial control protocol traffic) monitoring device, and various control system log (such as host log, network security equipment log and industrial equipment log, etc.) analysis devices, etc. However, due to the significant differences in the format, trigger mechanism and timing characteristics of these data sources (for example, industrial control protocol traffic alarms are usually triggered based on illegal instructions, communication mode mutations or traffic anomalies, with large data volume and high frequency; system logs cover hosts, network security equipment and industrial equipment, etc., and their alarms involve access control, policy changes and intrusion behaviors, etc., with strong context dependence; Huadian Ruilan control system network security monitoring and Huadian Ruilan control system private protocol network security monitoring reflect control operations at the execution level, such as controller logic anomalies and controller unavailability, etc., with small data volume but strong real-time performance), it is difficult for traditional single alarm analysis methods to effectively associate them, resulting in isolated alarms and high false alarm rates, making it difficult to accurately identify and trace complex attacks. Therefore, how to comprehensively analyze network security status alarm events from multiple heterogeneous data sources to trigger multi-source correlation alarms, thereby improving the accuracy of alarms and the network security situation awareness capabilities of the control system, is a topic that technical personnel in this field urgently need to study. Summary of the invention

[0004] The purpose of the present invention is to provide a multi-source heterogeneous alarm method, device, computer equipment, computer-readable storage medium and computer program product for the network security status of a control system, so as to solve the problems of isolated alarms, high false alarm rate and difficulty in identifying complex attacks and issuing alarms in the existing control system network security situation awareness technology.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, a multi-source heterogeneous alarm method for a control system network security status is provided, comprising: Acquire all historical network security status alarm events triggered for a target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes an event type and a triggering time; Based on all historical network security status alarm events, the correlation coefficient between any two event types is calculated; The sample data of any event type is obtained in the following manner: first, a star network is constructed with the any event type as a central node and all other event types as peripheral nodes, and the distance from the central node to any peripheral node is negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods that are consecutive in time sequence is generated based on the star network; finally, the multi-frame network security status alarm diagram is used as a model input item, and the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods is used as a model output item, so as to obtain sample data including the model input item and the model output item; For any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source correlation alarm trigger model; For any event type, according to all network security status alarm events triggered in the current multiple unit time periods, the current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods is generated based on the corresponding star network, and the generated result is imported into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

[0006] Based on the above invention content, a new scheme is provided that can comprehensively analyze network security status alarm events from multiple heterogeneous data sources to perform multi-source associated alarm triggering, that is, first, according to all historical network security status alarm events triggered for the target control system and from multiple heterogeneous data sources, the correlation coefficient of any two event types is calculated, and sample data of any event type that comprehensively reflects both the associated characteristics of the network security status of multiple heterogeneous data sources and the temporal characteristics of these network security statuses is constructed, and then for any event type, all corresponding sample data are imported into a deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source associated alarm triggering model, and finally the model is applied to instantly output the alarm triggering result of any event type, so that the accuracy of the alarm and the network security situation awareness capability of the control system can be effectively improved through the multi-source associated alarm triggering based on the STGCN network, and the problems of isolated alarms, high false alarm rate and difficulty in identifying complex attacks and alarms in the existing control system network security situation awareness technology are solved. It is particularly suitable for power network control systems and is convenient for practical application and promotion.

[0007] In one possible design, the multiple heterogeneous data sources include a control system network security monitoring device, a control system private protocol network security monitoring device, a control system network traffic monitoring device and / or a control system log analysis device.

[0008] In a possible design, based on all historical network security status alarm events, the correlation coefficients of any two event types are calculated, including: For each heterogeneous data source among the multiple heterogeneous data sources, according to the event type and trigger time of all corresponding historical network security status alarm events, the corresponding historical time series data of various event types are generated, wherein the historical time series data contains the The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, It represents a positive integer greater than 100. A binary label value of "1" indicates that an alarm event of the corresponding event type occurs in the corresponding time period. A binary label value of "0" indicates that an alarm event of the corresponding event type does not occur in the corresponding time period. For the historical time series data corresponding to the first event type in any two event types Perform a normal distribution KS test to calculate the first test statistic value , and the historical time series data corresponding to the second event type in the arbitrary two event types Perform a normal distribution KS test to calculate the second test statistic value ; If the first check statistic value and the second check statistic value If both are greater than the preset threshold, the correlation coefficient of any two event types is calculated according to the following formula :

[0009] In the formula, represents a positive integer, Indicated in The tag value, Indicated in The tag value, express The mean of express The mean of .

[0010] In a possible design, according to all historical network security status alarm events corresponding to the any event type and the other event type, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods sequentially in time sequence is generated based on a star network, including: Generate historical time series data of any event type according to the triggering time of all historical network security status alarm events corresponding to the any event type, and generate historical time series data of the other event type according to the triggering time of all historical network security status alarm events corresponding to the other event type, wherein the historical time series data contains the The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, It represents a positive integer greater than 100. A binary label value of "1" indicates that a network security status alarm event of the corresponding event type occurs in the corresponding period. A binary label value of "0" indicates that a network security status alarm event of the corresponding event type does not occur in the corresponding period. Extract the time series data of the event type and the other event type respectively to obtain the time series data. Binarized label values ​​for unit time periods, and for For each unit time period in the unit time period, the binary label value of any event type extracted in the corresponding time period is reflected on the central node in the star network, and the binary label value of the other event type extracted in the corresponding time period is reflected on the peripheral nodes corresponding to the other event type in the star network, and the network security status alarm diagram of the corresponding time period is obtained, wherein, Indicates greater than or equal to 2 and less than A positive integer.

[0011] In a possible design, for any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source correlation alarm trigger model, including: For any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and validation modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and use them to make the objective function Minimize the optimization search results, where the objective function The calculation formula is as follows:

[0012] In the formula, Indicates the output error indicator value of the deep learning model. Indicates the time required for calculation of the deep learning model; The optimized search results and the model parameters obtained during the optimization process and corresponding to the optimized search results are imported into the deep learning model to obtain a multi-source correlation alarm triggering model corresponding to any of the event types.

[0013] In one possible design, the optimization algorithm uses a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a gray wolf optimization algorithm, a whale optimization algorithm, or a tuna school optimization algorithm.

[0014] In a second aspect, a multi-source heterogeneous alarm device for the network security status of a control system is provided, comprising an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, a correlation alarm model training unit and a correlation alarm model application unit; The alarm event acquisition unit is used to acquire all historical network security status alarm events triggered for the target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes an event type and a triggering time; The correlation coefficient calculation unit is communicatively connected to the alarm event acquisition unit and is used to calculate the correlation coefficient of any two event types based on all historical network security status alarm events; The sample data generating unit is respectively connected to the alarm event acquiring unit and the correlation coefficient calculating unit in communication, and is used to obtain sample data of any event type in the following manner: first, a star network is constructed with the any event type as a central node and all other event types as peripheral nodes, and the distance from the central node to any peripheral node is negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods that are consecutive in time sequence is generated based on the star network; finally, the multi-frame network security status alarm diagram is used as a model input item, and the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods is used as a model output item, so as to obtain sample data including the model input item and the model output item; The associated alarm model training unit is communicatively connected to the sample data generating unit, and is used to import all corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling for any event type, so as to obtain a corresponding multi-source associated alarm triggering model; The associated alarm model application unit is communicatively connected to the associated alarm model training unit, and is used to generate, for any event type, a current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods based on a corresponding star network according to all network security status alarm events triggered in the current multiple unit time periods, and import the generated result into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

[0015] In a third aspect, the present invention provides a computer device comprising a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the personnel positioning method as described in the first aspect or any possible design of the first aspect.

[0016] In a fourth aspect, the present invention provides a computer-readable storage medium having instructions stored thereon, which, when executed on a computer, executes the personnel positioning method as described in the first aspect or any possible design of the first aspect.

[0017] In a fifth aspect, the present invention provides a computer program product, comprising a computer program or instructions, which, when executed by a computer, implements the personnel positioning method as described in the first aspect or any possible design of the first aspect.

[0018] Beneficial effects of the above scheme: The invention provides a new scheme that can comprehensively analyze network security status alarm events from multiple heterogeneous data sources to trigger multi-source associated alarms, that is, first, based on all historical network security status alarm events triggered for a target control system and from multiple heterogeneous data sources, calculate the correlation coefficient of any two event types, and construct sample data of any event type that comprehensively reflects both the associated characteristics of the network security status of multiple heterogeneous data sources and the temporal characteristics of these network security statuses, then for any event type, import all corresponding sample data into a deep learning model based on the STGCN network for calibration and verification modeling, and obtain the corresponding multi-source associated alarm triggering model, and finally apply the model to instantly output the alarm triggering result of any event type, so that the accuracy of the alarm and the network security situation awareness capability of the control system can be effectively improved through the multi-source associated alarm triggering based on the STGCN network, and the problems of isolated alarms, high false alarm rate, and difficulty in identifying complex attacks and alarms in the existing control system network security situation awareness technology are solved. The invention is particularly suitable for power network control systems and is convenient for practical application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0020] Figure 1 A flowchart of a multi-source heterogeneous alarm method for the network security status of a control system provided in an embodiment of the present application.

[0021] Figure 2 This is an example diagram of a multi-frame network security status alarm diagram provided in an embodiment of the present application.

[0022] Figure 3 A schematic diagram of the structure of a multi-source heterogeneous alarm device for the network security status of a control system provided in an embodiment of the present application.

[0023] Figure 4 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structures of the drawings is only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can be obtained based on these embodiments without creative work. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.

[0025] It should be understood that although the terms first and second, etc. may be used herein to describe various objects, these objects should not be limited by these terms. These terms are only used to distinguish one object from another object. For example, a first object can be referred to as a second object, and similarly, a second object can be referred to as a first object without departing from the scope of the exemplary embodiments of the present invention.

[0026] It should be understood that the term "and / or" that may appear in this document is merely a description of the association relationship between associated objects, indicating that there may be three relationships. For example, A and / or B can indicate three situations: A exists alone, B exists alone, or A and B exist at the same time. For another example, A, B and / or C can indicate the existence of any one of A, B and C or any combination of them. The term " / and" that may appear in this document describes another type of association object relationship, indicating that there may be two relationships. For example, A / and B can indicate two situations: A exists alone or A and B exist at the same time. In addition, the character " / " that may appear in this document generally indicates that the previous and next associated objects are in an "or" relationship.

[0027] Example like Figure 1 As shown, the control system network security status multi-source heterogeneous alarm method provided in the first aspect of this embodiment can be executed by, but is not limited to, a computer device having certain computing resources and communicating with multiple heterogeneous data sources for triggering network security status alarm events for the target control system, such as a cloud server, a personal computer (PC, a multi-purpose computer with a size, price and performance suitable for personal use; desktops, laptops, small laptops, tablets and ultrabooks are all personal computers), smart phones, personal digital assistants (PDA) or wearable devices and other electronic devices. Figure 1 As shown, the control system network security status multi-source heterogeneous alarm method may include but is not limited to the following steps S1 to S5.

[0028] S1. Acquire all historical network security status alarm events triggered for a target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes but is not limited to information such as event type and triggering time.

[0029] In the step S1, the target control system is specifically but not limited to an electric power network monitoring system such as a coal-fired power plant monitoring system. Specifically, the multiple heterogeneous data sources include but are not limited to a control system network security monitoring device (such as a Huadian Ruilan control system network security monitoring device), a control system private protocol network security monitoring device (such as a Huadian Ruilan control system private protocol network security monitoring device), a control system network flow monitoring device (such as an industrial control protocol flow monitoring device) and / or a control system log analysis device (such as a host log analysis device, a network security device log analysis device and / or an industrial equipment log analysis device, etc.). These data sources can trigger corresponding network security status alarm events for the target control system based on existing technologies and transmit them to local devices in a conventional manner; for example: the industrial control protocol flow monitoring device can trigger network security status alarm events such as those used to indicate the presence of illegal instructions, abnormal instructions, communication mode mutations and / or traffic abnormalities for the target control system; the control system log analysis device can trigger network security status alarm events such as those used to indicate the presence of access control conditions, policy changes, intrusion behaviors, unknown IP (Internet Protocol, Internet The control system network security monitoring device and / or the control system private protocol network security monitoring device can trigger network security status alarm events such as those used to indicate the existence of controller logic abnormalities, controller unavailability, and / or unexpected control states for the target control system, etc. In addition, the event types specifically but not limited to include network security status alarm events used to indicate the existence of illegal instructions, abnormal instructions, communication mode mutations, traffic abnormalities, access control conditions, policy changes, intrusion behaviors, unknown IP access behaviors, abnormal equipment shutdowns, controller logic abnormalities, controller unavailability, and / or unexpected control states.

[0030] S2. Based on all the historical network security status alarm events, calculate the correlation coefficient between any two event types.

[0031] In step S2, since multi-source correlation alarm triggering is to be performed later, and different event types from different heterogeneous sources or the same heterogeneous source must have different correlations, it is necessary to first calculate the correlation coefficient of any two event types. Specifically, according to all the historical network security status alarm events, the correlation coefficient of any two event types is calculated, including but not limited to the following steps S21 to S23.

[0032] S21. For each heterogeneous data source in the plurality of heterogeneous data sources, generate corresponding historical time series data of various event types according to the event type and trigger time of all the corresponding historical network security status alarm events, wherein the historical time series data includes but is not limited to the historical time series of consecutive events. The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, etc. represents a positive integer greater than 100, the binary label value "1" indicates that an alarm event of the corresponding event type occurs in the corresponding time period, and the binary label value "0" indicates that an alarm event of the corresponding event type does not occur in the corresponding time period.

[0033] In the step S21, for example, if the control system private protocol network security monitoring device can trigger a network security status alarm event for the target control system to indicate the existence of controller logic abnormalities, controller unavailability, and unexpected control states, then according to the event types and triggering times of these network security status alarm events triggered historically, the control system private protocol network security monitoring device can generate the corresponding historical time series data of three event types (i.e., network security status alarm events for indicating the existence of controller logic abnormalities, network security status alarm events for indicating the existence of controller unavailability, and network security status alarm events for indicating the existence of unexpected control states). The unit time period can be, but is not limited to, 10 seconds, 30 seconds or 1 minute, etc.; taking 1 minute as an example, if the control system private protocol network security monitoring device triggers a network security status alarm event indicating the existence of a controller logic abnormality at 10:00:15, 10:05:32 and 10:09:54 respectively, then based on these triggering times, the following historical time series data corresponding to the network security status alarm event indicating the existence of a controller logic abnormality can be conventionally generated: {1,0,0,0,0,1,0,0,0,1}; the generation process of the historical time series data of other event types is similar.

[0034] S22. For the historical time series data corresponding to the first event type in any two event types Perform a normal distribution KS test to calculate the first test statistic value , and the historical time series data corresponding to the second event type in the arbitrary two event types Perform the normal distribution KS check to calculate the second check statistic value .

[0035] In step S22, the normal distribution KS test is the Kolmogorov-Smirnov test, which is an existing statistical test method used to determine whether the observed values ​​of a set of data conform to a specific distribution. Therefore, it can be conventionally used to obtain the first test statistic. value and the second check statistic value .

[0036] S23. If the first check statistic value and the second check statistic value If both are greater than the preset threshold, the correlation coefficient of any two event types is calculated according to the following formula :

[0037] In the formula, represents a positive integer, Indicated in The tag value, Indicated in The tag value, express The mean of express The mean of .

[0038] In the step S23, the preset threshold may be 0.05, for example.

[0039] S3. Obtain sample data of any event type in the following manner: first construct a star network with the any event type as the central node and all other event types as peripheral nodes, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types respectively, generate a multi-frame network security status alarm graph corresponding to a plurality of unit time periods consecutively in time sequence based on the star network; finally, use the multi-frame network security status alarm graph as a model input item, and use the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods as a model output item, to obtain sample data including the model input item and the model output item.

[0040] In step S3, for example, if there are nine event types in total, Figure 2 The star network shown has one central node and eight peripheral nodes, and the distance from the central node to each peripheral node is negatively correlated with the correlation coefficient of their corresponding event types: the larger the correlation coefficient, the closer the distance; the smaller the correlation coefficient, the farther the distance. Specifically, according to all historical network security status alarm events corresponding to any event type and the other event types, a multi-frame network security status alarm diagram corresponding to multiple unit time periods that are sequentially continuous in time sequence is generated based on the star network, including but not limited to the following steps S31 to S32.

[0041] S31. Generate historical time series data of any event type according to the triggering time of all historical network security status alarm events corresponding to any event type, and generate historical time series data of other event types according to the triggering time of all historical network security status alarm events corresponding to other event types, wherein the historical time series data includes but is not limited to the historical time series data that are consecutive in sequence. The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, etc. It represents a positive integer greater than 100. The binary label value "1" indicates that a network security status alarm event of the corresponding event type occurs in the corresponding time period. The binary label value "0" indicates that a network security status alarm event of the corresponding event type does not occur in the corresponding time period.

[0042] In the step S31, the specific generation details of the historical time series data can be found in the aforementioned step S21, which will not be repeated here.

[0043] S32. Extract the time series data of the event type and the other event type respectively. Binarized label values ​​for unit time periods, and for the For each unit time period in the unit time period, the binary label value of any event type extracted in the corresponding time period is reflected on the central node in the star network, and the binary label value of the other event type extracted in the corresponding time period is reflected on the peripheral nodes corresponding to the other event type in the star network, and the network security status alarm diagram of the corresponding time period is obtained, wherein, Indicates greater than or equal to 2 and less than A positive integer.

[0044] In step S32, for example, if the unit time period is 1 minute and If the value is 4, four binary label values ​​from 10:00 to 10:03 can be extracted from the historical time series data of any event type; and four binary label values ​​from 10:00 to 10:03 can be extracted from the historical time series data of the other event type. The specific manner in which the extracted binary label value of any event type in each unit time period is reflected on the central node in the star network may include but is not limited to the following: if the extracted binary label value of any event type in a certain unit time period is "1", the central node in the star network is marked as a solid node, otherwise it is marked as a hollow node; the specific manner in which the extracted binary label value of the other event type in the corresponding time period is reflected on the peripheral nodes in the star network corresponding to the other event type may include but is not limited to the following: if the extracted binary label value of the other event type in the corresponding time period is "1", the peripheral nodes in the star network corresponding to the other event type are marked as solid nodes, otherwise they are marked as hollow nodes; the final four-frame network security status alarm diagram corresponding to 10:00 to 10:03 is as shown in FIG. Figure 2As shown, it not only comprehensively reflects the correlation characteristics of the network security status of multiple heterogeneous data sources, but also reflects the time series characteristics of these network security status, which is conducive to subsequent time series analysis and causal reasoning. In addition, the alarm requirement binary label value is used to reflect whether it is necessary to trigger the network security status alarm event of any event type in the last period, and "1" is used to indicate that the network security status alarm event of any event type needs to be triggered in the last period, while "0" is used to indicate that the network security status alarm event of any event type does not need to be triggered in the last period. It can be specifically obtained by manually checking the triggering situation of the historical network security status alarm event in the last period and for any event type. For example, if a historical network security status alarm event of any event type is triggered in the last period, it is necessary to manually check whether the alarm event is a false alarm. If not, the alarm requirement binary label value of any event type in the last period is marked as "1", otherwise it is marked as "0". If the historical network security status alarm event of any event type is not triggered in the last period, it is necessary to manually check whether the network security status alarm event of any event type is missed. If missed, the alarm requirement binary label value of any event type in the last period is marked as "1", otherwise it is marked as "0".

[0045] S4. For any of the event types, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source correlation alarm trigger model.

[0046] In the step S4, the STGCN (Spatial-Temporal Graph Convolutional Network) network is a deep learning model that combines a graph convolutional network (GCN) and a temporal convolutional network, and is designed to process complex data with spatiotemporal correlation; the model models spatial relationships through a graph structure and captures dynamic timing features through temporal convolution. It has timing analysis and causal reasoning capabilities and is widely used in fields such as action recognition and timing prediction. Therefore, it is possible to train based on the sample data to obtain the multi-source association triggering requirement for a network security status alarm event of any event type after inputting multiple frames of network security status alarm graphs (i.e., outputting "1" to indicate that a network security status alarm event of any event type needs to be triggered by multiple sources, and outputting "0" to indicate that a network security status alarm event of any event type does not need to be triggered by multiple sources). The multi-source association alarm triggering model The specific process of the calibration and verification modeling includes a calibration process and a verification process of the model, that is, first comparing the model simulation results with the measured data, and then adjusting the model parameters according to the comparison results to make the simulation results consistent with the actual process. Therefore, the multi-source correlation alarm trigger model can be obtained based on conventional training of the existing technology.

[0047] In the step S4, it is also considered that model hyperparameters refer to parameters pre-set in the deep learning model. These parameters cannot be directly learned from the data in the standard model training process, but need to be manually set to optimize the performance of the model. For example, for the STGCN network, it is necessary to manually set parameters such as the number of graph convolution layers, the dimension of the graph convolution layer, the size of the spatiotemporal convolution kernel, the learning rate, the batch size, the optimizer selection result, the regularization parameter and the number of training rounds. In order to achieve the purpose of automatically debugging to obtain the optimal multi-source correlation alarm trigger model that can take into account both alarm trigger accuracy and processing speed, preferably, for any of the event types, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source correlation alarm trigger model, including but not limited to the following steps S41 to S42.

[0048] S41. For any of the event types, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and use them to make the objective function Minimize the optimization search results, where the objective function The calculation formula is as follows:

[0049] In the formula, Indicates the output error indicator value of the deep learning model. Indicates the time required for deep learning model calculation.

[0050] In step S41, the output error condition index value is used to reflect the accuracy of the model alarm triggering. The smaller the value, the higher the accuracy of the model alarm triggering. It specifically includes but is not limited to the average deviation value, variance and / or average error rate of the overall sample, and can be obtained by conventional statistics during the model training and testing process. The calculation time required index value is used to reflect the model processing speed. The shorter the value, the faster the model processing speed. It can be obtained by conventional timing during the model testing process. The objective function It is used as a comprehensive indicator that takes into account both the accuracy of alarm triggering and the processing speed. The smaller the result, the better the trained model can achieve the best in terms of the two target dimensions of alarm triggering accuracy and processing speed, so that the optimal multi-source associated alarm triggering model that takes into account both the accuracy of alarm triggering and the processing speed can be optimized in the future. In addition, the optimization algorithm can be, but is not limited to, a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a Grey Wolf Algorithm, a whale optimization algorithm, or a tuna school optimization algorithm.

[0051] In step S41, in order to quickly and accurately obtain the optimized search results, it is also preferred that, for any event type, all corresponding sample data are imported into a deep learning model based on the STGCN network for calibration verification modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and use them to make the objective function The minimized optimized search results include but are not limited to the following steps S411 to S419.

[0052] S411. Initialization includes the maximum number of iterations The optimization algorithm parameters are randomly generated, and an initial search value array of the parameter set to be optimized is then executed, wherein the parameter set to be optimized includes all hyperparameters of the deep learning model based on the STGCN network, and the initial search value array of the parameter set to be optimized is It is expressed as follows:

[0053] In the formula, Indicates less than or equal to A positive integer, represents the total number of parameters in the parameter set to be optimized, Indicates the first The initial search value corresponding to the parameter, Indicates that The upper limit of the parameter search space corresponding to the parameters, Indicates that The lower limit of the parameter search space corresponding to the parameters, Represents a purely decimal random generator.

[0054] In the step S411, the parameter search space upper limit and the parameter search space lower limit may be specifically set in advance according to adjustment requirements.

[0055] S412. Import the initial search value array of the parameter set to be optimized as a model hyperparameter into the deep learning model to obtain a first deep learning model, then apply all sample data corresponding to any event type to perform model training and testing on the first deep learning model to obtain a first output error situation index value and a first calculation required time index value, and finally import the first output error situation index value and the first calculation required time index value into the objective function , and the output result is used as the fitness corresponding to the initial search value array, and then step S413 is executed, wherein the objective function The calculation formula is as follows:

[0056] In the formula, Indicates the output error indicator value of the deep learning model. Indicates the time required for deep learning model calculation.

[0057] In the step S412, considering that some hyperparameters need to be integers (such as the number of graph convolution layers), it is necessary to round the corresponding parameter values ​​before importing the initial position into the model as a model hyperparameter, such as rounding the number of graph convolution layers. The aforementioned application uses all sample data corresponding to any of the event types to train and test the first deep learning model, which is an existing conventional calibration verification method and will not be repeated here. In addition, when obtaining the first output error condition index value and the first calculation time required index value, it is also necessary to record the model parameters corresponding to the initial search value array and obtained through model training, so as to use them in the subsequent step S42.

[0058] S413. Use the initial search value array of the parameter set to be optimized as the current optimal search value array, and initialize the current number of iterations , and also initialize the prohibited change countdown value of each parameter in the parameter set to be optimized to zero, and then execute step S414.

[0059] S414. Based on the current optimal search value array, each parameter in the parameter set to be optimized and whose current forbidden change countdown value is zero is independently increased and decreased to obtain the parameter set to be optimized. A new search value array is generated, and then step S415 is executed, wherein: represents the total number of parameters in the set of parameters to be optimized whose current forbidden change countdown value is zero, and .

[0060] In the step S414, the increase processing or the decrease processing needs to be performed in the corresponding parameter search space, and can be a quantitative step increase / decrease, or an indefinite random increase / decrease, and it is also possible to first perform a quantitative step increase / decrease on each parameter in the parameter set to be optimized and whose current prohibited change countdown value is zero, and then if it is found that the update of the current optimal search value array has not been completed (that is, step S419 is directly executed in the subsequent step S418), then perform an indefinite random increase / decrease on each parameter in the parameter set to be optimized and whose current prohibited change countdown value is zero, so as to avoid falling into a local optimal solution. For example, if there are the following six parameters in the parameter set to be optimized: parameter A, parameter B, parameter C, parameter D, parameter E and parameter F, wherein the current prohibited change countdown values ​​of parameter A, parameter B, parameter E and parameter F are zero (that is, The value is 4), then based on the current optimal search value array, parameter A is independently increased and decreased respectively, to obtain two different new search value arrays of the parameter set to be optimized (one of which is obtained based on the increase process, and the other is obtained based on the decrease process); based on the current optimal search value array, parameter B is independently increased and decreased respectively, to obtain two different new search value arrays of the parameter set to be optimized; based on the current optimal search value array, parameter E is independently increased and decreased respectively, to obtain two different new search value arrays of the parameter set to be optimized; based on the current optimal search value array, parameter F is independently increased and decreased respectively, to obtain two different new search value arrays of the parameter set to be optimized; and further 2×4=8 new search value arrays can be obtained, each of which represents a neighborhood search direction in the search space.

[0061] S415. For the For each array in the new search value array, the corresponding array is imported into the deep learning model as a model hyperparameter to obtain a second deep learning model of the corresponding array, and then all sample data corresponding to any event type are applied to perform model training and testing on the second deep learning model to obtain a second output error situation index value and a second calculation required time index value of the corresponding array, and finally the second output error situation index value and the second calculation required time index value are imported into the objective function , and use the output result as the fitness of the corresponding array, and then execute step S416.

[0062] In the step S415, the specific technical details can be obtained by referring to the conventional derivation of the aforementioned step S412, which will not be repeated here. In addition, when obtaining the second output error condition index value and the second calculation required time index value, it is also necessary to record the corresponding data and the model parameters obtained through model training so as to be used in the subsequent step S42.

[0063] S416. For each array, subtract the fitness of the corresponding array from the fitness corresponding to the current optimal search value array to obtain the fitness difference value of the corresponding array, and when the fitness difference value is greater than zero and is the largest fitness difference value this time, update the prohibited change countdown value of the corresponding unique variable parameter to a positive integer value positively correlated with the fitness difference value, and then execute step S417, wherein the unique variable parameter refers to the parameter in the parameter set to be optimized and is used to obtain the parameter of the corresponding array by increasing or decreasing the processing.

[0064] In step S416, the fitness difference value is greater than zero and is the largest fitness difference value this time, which means that the best search value array is obtained in the neighborhood search direction corresponding to the corresponding parameter this time, so it is necessary to temporarily lock the search results in this neighborhood search direction by updating the forbidden change countdown value of the corresponding parameter to a positive integer positively correlated with the fitness difference value. In addition, based on the example in step S414 above, among the eight new search value arrays corresponding to parameters A, B, E and F, if the fitness difference value of a new search value array corresponding to parameter F is greater than zero and is the largest fitness difference value this time (i.e., the largest among the eight fitness difference values ​​this time), then the forbidden change countdown value of parameter F is updated from zero to a positive integer value positively correlated with the fitness difference value, while the forbidden change countdown values ​​of parameters A, B and E remain zero.

[0065] S417. Determine whether there is any parameter in the parameter set to be optimized whose current prohibited change countdown value is zero. If not, decrement the current prohibited change countdown value of each parameter in the parameter set to be optimized by 1, and then return to execute step S417, otherwise execute step S418.

[0066] In step S417, if the current prohibited change countdown values ​​of all parameters in the parameter set to be optimized are not zero, it means that it is impossible to return to execute step S414 subsequently, so they need to be decremented together until the current prohibited change countdown value of at least one parameter is zero.

[0067] S418. Determine whether there is any fitness difference value greater than zero in the fitness difference values ​​of each array. If so, update the current optimal search value array to the value in the array. If an array in the new search value array and corresponding to the minimum fitness is found, then step S419 is executed; otherwise, step S419 is directly executed.

[0068] S419. Make the current number of iterations Add 1 to the current number of iterations. Whether the maximum number of iterations has been reached If so, the current optimal search value array is used as the hyperparameter of the deep learning model and used to make the objective function Minimize the optimized search results, otherwise return to execute step S414.

[0069] Therefore, the model hyperparameters are optimized through the aforementioned new heuristic algorithm steps S411 to S419. During the optimization process, the search results in each optimal neighborhood search direction can be temporarily locked for different numbers of iterations based on different fitness difference values, which is conducive to quickly searching for the optimal model hyperparameters. By first quantitatively increasing / decreasing the parameters to be adjusted in steps and then randomly increasing / decreasing the parameters in an unquantified manner, it is also possible to avoid falling into a local optimal solution, which is further conducive to quickly and accurately obtaining the optimal search results.

[0070] S42. Import the optimized search results and the model parameters obtained during the optimization process and corresponding to the optimized search results into the deep learning model to obtain a multi-source correlation alarm triggering model corresponding to any of the event types.

[0071] In step S42, it is also considered that some hyperparameters need to be integers, so before the optimization search result is imported into the model as a model hyperparameter, it is necessary to round the corresponding parameter value. In addition, the model parameters obtained in the optimization process and corresponding to the optimization search result are the model parameters recorded in the aforementioned S412 or S415 and obtained after model training.

[0072] S5. For any of the event types, according to all network security status alarm events triggered in the current multiple unit time periods, a current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods is generated based on the corresponding star network, and the generated result is imported into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

[0073] In the step S5, all the network security status alarm events triggered in the current multiple unit time periods are from the multiple heterogeneous data sources. The specific process of generating the current multiple frames of network security status alarm graph based on these alarm events can be obtained by referring to the conventional derivation of the step S3, which will not be repeated here. In addition, the alarm trigger result specifically includes: if it is "1", it means that the network security status alarm event of any event type needs to be triggered at the current moment, and if it is "0", it means that the network security status alarm event of any event type does not need to be triggered at the current moment.

[0074] Therefore, based on the multi-source heterogeneous alarm method for the network security status of the control system described in the aforementioned steps S1 to S5, a new solution is provided that can comprehensively analyze the network security status alarm events from multiple heterogeneous data sources to perform multi-source associated alarm triggering, that is, first, based on all historical network security status alarm events triggered for the target control system and from multiple heterogeneous data sources, the correlation coefficient of any two event types is calculated, and sample data of any event type that comprehensively reflects both the associated characteristics of the network security status of multiple heterogeneous data sources and the temporal characteristics of these network security states is constructed, and then for any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source associated alarm triggering model, and finally the model is applied to instantly output the alarm triggering result of any event type, so that the accuracy of the alarm and the network security situation awareness capability of the control system can be effectively improved through the multi-source associated alarm triggering based on the STGCN network, and the problems of isolated alarms, high false alarm rate and difficulty in identifying complex attacks and alarming in the existing control system network security situation awareness technology are solved. It is particularly suitable for power network control systems and is convenient for practical application and promotion.

[0075] like Figure 3As shown, the second aspect of this embodiment provides a virtual device for implementing the multi-source heterogeneous alarm method for the network security status of the control system described in the first aspect, including an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, an associated alarm model training unit and an associated alarm model application unit; The alarm event acquisition unit is used to acquire all historical network security status alarm events triggered for the target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes an event type and a triggering time; The correlation coefficient calculation unit is communicatively connected to the alarm event acquisition unit and is used to calculate the correlation coefficient of any two event types based on all historical network security status alarm events; The sample data generating unit is respectively connected to the alarm event acquiring unit and the correlation coefficient calculating unit in communication, and is used to obtain sample data of any event type in the following manner: first, a star network is constructed with the any event type as a central node and all other event types as peripheral nodes, and the distance from the central node to any peripheral node is negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods that are consecutive in time sequence is generated based on the star network; finally, the multi-frame network security status alarm diagram is used as a model input item, and the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods is used as a model output item, so as to obtain sample data including the model input item and the model output item; The associated alarm model training unit is communicatively connected to the sample data generating unit, and is used to import all corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling for any event type, so as to obtain a corresponding multi-source associated alarm triggering model; The associated alarm model application unit is communicatively connected to the associated alarm model training unit, and is used to generate, for any event type, a current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods based on a corresponding star network according to all network security status alarm events triggered in the current multiple unit time periods, and import the generated result into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

[0076] The working process, working details and technical effects of the aforementioned device provided in the second aspect of this embodiment can be referred to the multi-source heterogeneous alarm method for the network security status of the control system described in the first aspect, and will not be described in detail here.

[0077] like Figure 4As shown, the third aspect of this embodiment provides a computer device for executing the multi-source heterogeneous alarm method for the network security status of the control system as described in the first aspect, including a memory, a processor and a transceiver that are sequentially connected in communication, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the multi-source heterogeneous alarm method for the network security status of the control system as described in the first aspect. For example, the memory may include, but is not limited to, a random access memory (Random-Access Memory, RAM), a read-only memory (Read-Only Memory, ROM), a flash memory (Flash Memory), a first-input first output memory (First Input First Output, FIFO) and / or a first-input last output memory (First Input Last Output, FILO), etc.; the processor may include, but is not limited to, a microprocessor of the STM32F105 series. In addition, the computer device may also include, but is not limited to, a power module, a display screen and other necessary components.

[0078] The working process, working details and technical effects of the aforementioned computer device provided in the third aspect of this embodiment can be referred to the multi-source heterogeneous alarm method for the network security status of the control system described in the first aspect, and will not be repeated here.

[0079] In a fourth aspect of this embodiment, there is provided a computer-readable storage medium storing instructions including the method for multi-source heterogeneous alarm of network security status of a control system as described in the first aspect, that is, the computer-readable storage medium stores instructions, and when the instructions are executed on a computer, the method for multi-source heterogeneous alarm of network security status of a control system as described in the first aspect is executed. The computer-readable storage medium refers to a carrier for storing data, which may include but is not limited to computer-readable storage media such as floppy disks, optical disks, hard disks, flash memories, USB flash drives, and / or memory sticks, and the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0080] The working process, working details and technical effects of the aforementioned computer-readable storage medium provided in the fourth aspect of this embodiment can be referred to the multi-source heterogeneous alarm method for the network security status of the control system as described in the first aspect, and will not be repeated here.

[0081] A fifth aspect of this embodiment provides a computer program product, including a computer program or an instruction, which, when executed by a computer, implements the multi-source heterogeneous alarm method for the network security status of a control system as described in the first aspect. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0082] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A multi-source heterogeneous alarm method for control system network security status, characterized in that: include: Acquire all historical network security status alarm events triggered for a target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes an event type and a triggering time; Based on all historical network security status alarm events, the correlation coefficient between any two event types is calculated; The sample data of any event type is obtained in the following manner: first, a star network is constructed with the any event type as a central node and all other event types as peripheral nodes, and the distance from the central node to any peripheral node is negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods that are consecutive in time sequence is generated based on the star network; finally, the multi-frame network security status alarm diagram is used as a model input item, and the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods is used as a model output item, so as to obtain sample data including the model input item and the model output item; For any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source correlation alarm trigger model; For any event type, according to all network security status alarm events triggered in the current multiple unit time periods, the current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods is generated based on the corresponding star network, and the generated result is imported into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

2. The multi-source heterogeneous alarm method for control system network security status according to claim 1 is characterized in that: The multiple heterogeneous data sources include a control system network security monitoring device, a control system private protocol network security monitoring device, a control system network traffic monitoring device and / or a control system log analysis device.

3. The multi-source heterogeneous alarm method for control system network security status according to claim 1 is characterized in that: Based on all historical network security status alarm events, the correlation coefficient of any two event types is calculated, including: For each heterogeneous data source among the multiple heterogeneous data sources, according to the event type and trigger time of all corresponding historical network security status alarm events, the corresponding historical time series data of various event types are generated, wherein the historical time series data contains the The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, Represents a positive integer greater than 100. A binary label value of "1" indicates that an alarm event of the corresponding event type occurs in the corresponding period, and a binary label value of "0" indicates that an alarm event of the corresponding event type does not occur in the corresponding period; For the historical time series data corresponding to the first event type in any two event types Perform a normal distribution KS test to calculate the first test statistic value , and the historical time series data corresponding to the second event type in the arbitrary two event types Perform a normal distribution KS test to calculate the second test statistic value ; If the first check statistic value and the second check statistic value If both are greater than the preset threshold, the correlation coefficient of any two event types is calculated according to the following formula : In the formula, represents a positive integer, Indicated in The tag value, Indicated in The tag value, express The mean of express The mean of .

4. The multi-source heterogeneous alarm method for control system network security status according to claim 1 is characterized in that: According to all historical network security status alarm events corresponding to the any event type and the other event type, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods sequentially in time sequence is generated based on a star network, including: Generate historical time series data of any event type according to the triggering time of all historical network security status alarm events corresponding to the any event type, and generate historical time series data of the other event type according to the triggering time of all historical network security status alarm events corresponding to the other event type, wherein the historical time series data contains the The unit time periods and corresponding event types are described in The binary label value of each unit time period in the unit time period, It represents a positive integer greater than 100. A binary label value of "1" indicates that a network security status alarm event of the corresponding event type occurs in the corresponding period. A binary label value of "0" indicates that a network security status alarm event of the corresponding event type does not occur in the corresponding period. Extract the time series data of the event type and the other event type respectively to obtain the time series data. Binarized label values ​​for unit time periods, and for For each unit time period in the unit time period, the binary label value of any event type extracted in the corresponding time period is reflected on the central node in the star network, and the binary label value of the other event type extracted in the corresponding time period is reflected on the peripheral nodes corresponding to the other event type in the star network, and the network security status alarm diagram of the corresponding time period is obtained, wherein, Indicates greater than or equal to 2 and less than A positive integer.

5. The multi-source heterogeneous alarm method for control system network security status according to claim 1 is characterized in that: For any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source correlation alarm trigger model, including: For any event type, all corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and validation modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and use them to make the objective function Minimize the optimization search results, where the objective function The calculation formula is as follows: In the formula, Indicates the output error indicator value of the deep learning model. Indicates the time required for calculation of the deep learning model; The optimized search results and the model parameters obtained during the optimization process and corresponding to the optimized search results are imported into the deep learning model to obtain a multi-source correlation alarm triggering model corresponding to any of the event types.

6. The multi-source heterogeneous alarm method for control system network security status according to claim 5 is characterized in that: The optimization algorithm adopts a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a gray wolf optimization algorithm, a whale optimization algorithm or a tuna swarm optimization algorithm.

7. A multi-source heterogeneous alarm device for control system network security status, characterized in that: It includes an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, a correlation alarm model training unit and a correlation alarm model application unit; The alarm event acquisition unit is used to acquire all historical network security status alarm events triggered for the target control system and from multiple heterogeneous data sources, wherein the network security status alarm event includes an event type and a triggering time; The correlation coefficient calculation unit is communicatively connected to the alarm event acquisition unit and is used to calculate the correlation coefficient of any two event types based on all historical network security status alarm events; The sample data generating unit is respectively connected to the alarm event acquiring unit and the correlation coefficient calculating unit in communication, and is used to obtain sample data of any event type in the following manner: first, a star network is constructed with the any event type as a central node and all other event types as peripheral nodes, and the distance from the central node to any peripheral node is negatively correlated with the correlation coefficient of the any event type and other event types corresponding to the any peripheral node; then, according to all historical network security status alarm events corresponding to the any event type and the other event types, a multi-frame network security status alarm diagram corresponding to a plurality of unit time periods that are consecutive in time sequence is generated based on the star network; finally, the multi-frame network security status alarm diagram is used as a model input item, and the alarm demand binary label value of the last time period of the any event type in the plurality of unit time periods is used as a model output item, so as to obtain sample data including the model input item and the model output item; The associated alarm model training unit is communicatively connected to the sample data generating unit, and is used to import all corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling for any event type, so as to obtain a corresponding multi-source associated alarm triggering model; The associated alarm model application unit is communicatively connected to the associated alarm model training unit, and is used to generate, for any event type, a current multiple-frame network security status alarm graph corresponding to the current multiple unit time periods based on a corresponding star network according to all network security status alarm events triggered in the current multiple unit time periods, and import the generated result into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.

8. A computer device, characterized in that: It includes a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the multi-source heterogeneous alarm method for the network security status of a control system as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on the computer, the multi-source heterogeneous alarm method for the network security status of the control system as described in any one of claims 1 to 6 is executed.

10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or the instruction is executed by a computer, the method for multi-source heterogeneous alarm of the network security status of a control system as claimed in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Integration safety prevention analysis alarm system and method thereof

    CN105761460A

  • Internet situation assessment method based on knowledge graph

    CN117692198A

  • Utilizing topology-centric monitoring to model a system and correlate low level system anomalies and high level system impacts

    US20230161661A1