Multi-source Heterogeneous Alarm Method, Device and Equipment for Network Security Status of Control System
Through the deep learning model based on the STGCN network, the network security status alarm events of multiple heterogeneous data sources are comprehensively analyzed, and the problems of isolated alarms and high false alarm rates in the power network control system are solved, achieving more accurate alarm triggering and situational awareness.
Patent Information
- Application Number
- CN202510502368.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-22
AI Technical Summary
Existing power network security situation awareness technologies are difficult to effectively correlate network security status alarm events from multiple heterogeneous data sources, resulting in isolation of alarms and high false alarm rates, making it difficult to identify complex attacks.
Using a deep learning model based on STGCN network, a star network is constructed by calculating the correlation coefficients of network security status alarm events of multiple heterogeneous data sources, a multi-frame network security status alarm diagram is generated, and rate-determined verification model is performed to obtain a multi-source association alarm trigger model and output the alarm trigger result.
It improves the accuracy of alarms and the network security situation awareness of control systems, solves the problems of isolation of alarms and high false alarm rates, and is especially suitable for power network control systems.
Smart Images

Figure CN120017427B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power network security situation awareness, and particularly relates to a multi-source heterogeneous alarm method, device and equipment for the network security state of a control system. Background Art
[0002] Many problems have emerged in the practical application of existing power network security situation awareness technologies, making it difficult to meet the safety production requirements of power networks in aspects such as pre-warning monitoring, emergency response during the event, and post-event traceability and defect elimination; specifically, it is manifested as incomplete perception ability, insufficient recognition ability, too slow response speed, and excessive security alarms, etc. In response to the problems existing in the existing power network security situation awareness technologies, the newly released "Regulations on the Security Protection of Power Monitoring Systems" put forward higher requirements on the basis of the structural security principles of "security zoning, network specialization, horizontal isolation, and vertical authentication", that is, "strengthen security immunity, situation awareness, dynamic assessment, and standby emergency measures, and build a continuously developing and improving protection system", and this measure aims to promote the development of the security protection work of power monitoring systems towards a more perfect and efficient direction.
[0003] Currently, in the situation awareness technology of power network control systems, security alarm events may come from multiple heterogeneous data sources, including Huadian Ruilan control system network security monitoring devices, Huadian Ruilan control system private protocol network security monitoring devices, network traffic (especially industrial control protocol traffic) monitoring devices, and various control system log (such as host logs, network security device logs, and industrial device logs, etc.) analysis devices, etc. However, due to the significant differences in these data sources in terms of format, triggering mechanism, and timing characteristics (for example, industrial control protocol traffic alarms are usually triggered based on illegal instructions, communication mode mutations, or traffic anomalies, with a large amount of data and high frequency; system logs cover hosts, network security devices, and industrial devices, etc., and their alarms involve access control, policy changes, and intrusion behaviors, etc., with strong context dependence; Huadian Ruilan control system network security monitoring and Huadian Ruilan control system private protocol network security monitoring reflect control operations at the execution level, such as controller logic anomalies and controller unavailability, etc., with a small amount of data but strong real-time performance), it is difficult for traditional single-alarm analysis methods to effectively associate them, resulting in phenomena such as isolated alarms and high false alarm rates, and it is difficult to accurately identify and trace complex attacks. Therefore, how to comprehensively analyze network security state alarm events from multiple heterogeneous data sources to trigger multi-source associated alarms, thereby improving the accuracy of alarms and the situation awareness ability of the control system network security, is an urgent research topic for those skilled in the art. Summary of the Invention
[0004] The purpose of the present invention is to provide a multi-source heterogeneous alarm method, device, computer equipment, computer-readable storage medium and computer program product for the network security state of a control system, so as to solve the problems of isolated alarms, high false alarm rates and difficulty in identifying complex attacks and giving alarms existing in the existing control system network security situation awareness technology.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] In the first aspect, a multi-source heterogeneous alarm method for the network security state of a control system is provided, including:
[0007] Obtain all historical network security state alarm events triggered for the target control system and coming from multiple heterogeneous data sources, where the network security state alarm events include event types and trigger times;
[0008] Calculate the correlation coefficient between any two event types according to all historical network security state alarm events;
[0009] Obtain the sample data of any event type in the following way: first construct a star network with this any event type as the central node and all other event types as the peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between this any event type and the other event type corresponding to this any peripheral node, then based on all historical network security state alarm events corresponding to this any event type and this other event type respectively, generate multiple frames of network security state alarm diagrams corresponding one by one to multiple consecutive unit time periods in time sequence, and finally use these multiple frames of network security state alarm diagrams as model input items, and use the binary label value of the alarm requirement in the last time period of these multiple unit time periods of this any event type as the model output item to obtain the sample data including this model input item and this model output item;
[0010] For any event type, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated alarm trigger model;
[0011] For any event type, based on all network security state alarm events triggered in the current nearest multiple unit time periods, generate the current nearest multiple frames of network security state alarm diagrams corresponding one by one to the current nearest multiple unit time periods based on the corresponding star network, and import the generation result into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.
[0012] Based on the above invention content, a new solution is provided that can comprehensively analyze network security status alarm events from multiple heterogeneous data sources to trigger multi-source associated alarms. That is, first, according to all historical network security status alarm events triggered for the target control system and coming from multiple heterogeneous data sources, calculate the correlation coefficient between any two event types, and construct sample data for any one event type that comprehensively reflects the network security status of multiple heterogeneous data sources and also reflects the temporal characteristics of these network security statuses. Then, for this any one event type, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated alarm trigger model. Finally, apply this model to immediately output the alarm trigger result for this any one event type. In this way, through multi-source associated alarm triggering based on the STGCN network, the accuracy of alarms and the network security situation awareness ability of the control system can be effectively improved, solving the problems of isolated alarms, high false alarm rates, and difficulty in identifying complex attacks and giving alarms existing in the existing control system network security situation awareness technology. It is particularly suitable for power network control systems and is convenient for practical application and promotion.
[0013] In a possible design, the multiple heterogeneous data sources include a control system network security monitoring device, a control system private protocol network security monitoring device, a control system network traffic monitoring device, and / or a control system log analysis device.
[0014] In a possible design, calculating the correlation coefficient between any two event types according to all historical network security status alarm events includes:
[0015] For each heterogeneous data source among the multiple heterogeneous data sources, generate historical time series data of corresponding various event types according to the event type and trigger time of all corresponding historical network security status alarm events. Among them, the historical time series data contains successive unit time periods in the historical time series and the binary label values of the corresponding event type in each of the unit time periods, where
[0016] represents a positive integer greater than 100, and the binary label value of "1" indicates that an alarm event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that no alarm event of the corresponding event type occurs in the corresponding time period; Perform a normal distribution KS test on the historical time series data corresponding to the first event type among any two event types to calculate the first test statistic value and, for the historical time series data corresponding to the second event type among the any two event types, Perform a normal distribution KS test to calculate the second test statistic value ;
[0017] If the first test statistic value and the second test statistic value are both greater than the preset threshold, then calculate the correlation coefficient of any two event types according to the following formula :
[0018]
[0019] In the formula, represents a positive integer, represents the th label value in represents the th label value in represents mean value of represents mean value of
[0020] In a possible design, according to all historical network security status alarm events corresponding to any one of the event types and the other event type respectively, generate multiple frames of network security status alarm diagrams corresponding one by one to a plurality of consecutive unit time periods in time sequence based on a star network, including:
[0021] Generate the historical time series data of any one of the event types according to the triggering moments of all historical network security status alarm events corresponding to any one of the event types, and generate the historical time series data of the other event type according to the triggering moments of all historical network security status alarm events corresponding to the other event type. Among them, the historical time series data includes consecutive unit time periods in historical time sequence and the binary label values of the corresponding event types in each unit time period of the unit time periods, represents a positive integer greater than 100. The binary label value of "1" indicates that a network security status alarm event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that a network security status alarm event of the corresponding event type does not occur in the corresponding time period;
[0022] Extract the binary label values of consecutive unit time periods in time sequence from the historical time series data of any one of the event types and the other event type respectively, and for the consecutive unit time periods in time sequence For each unit time period in a unit time period, the binarized label value of the obtained extraction and the corresponding time period of any one event type is reflected on the central node in the star network, and the binarized label value of the obtained extraction and the corresponding time period of the other event type is reflected on the peripheral node corresponding to the other event type in the star network, so as to obtain the network security status alarm diagram of the corresponding time period, where represents an integer greater than or equal to 2 and less than .
[0023] In a possible design, for any event type, all corresponding sample data is imported into a deep learning model based on the STGCN network for calibration verification modeling to obtain a corresponding multi-source associated alarm trigger model, including:
[0024] For any event type, all corresponding sample data is imported into a deep learning model based on the STGCN network for calibration verification modeling, and the hyperparameters of the deep learning model are optimized based on an optimization algorithm to obtain the hyperparameters and the optimal search result for minimizing the objective function , where the objective function has the following calculation formula:
[0025]
[0026] In the formula, represents the output error situation index value of the deep learning model, represents the calculation required duration index value of the deep learning model;
[0027] The optimal search result and the model parameters obtained during the optimization process and corresponding to the optimal search result are imported into the deep learning model to obtain a multi-source associated alarm trigger model corresponding to the any event type.
[0028] In a possible design, the optimization algorithm uses a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a grey wolf optimization algorithm, a whale optimization algorithm or a tuna swarm optimization algorithm.
[0029] In a second aspect, a multi-source heterogeneous alarm device for the network security state of a control system is provided, including an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, an associated alarm model training unit and an associated alarm model application unit;
[0030] The alarm event acquisition unit is used to acquire all historical network security state alarm events triggered for the target control system and coming from multiple heterogeneous data sources, where the network security state alarm events include event types and trigger times;
[0031] The correlation coefficient calculation unit is communicatively connected to the alarm event acquisition unit and is configured to calculate the correlation coefficient between any two event types based on all historical network security status alarm events.
[0032] The sample data generation unit is communicatively connected to the alarm event acquisition unit and the correlation coefficient calculation unit respectively, and is configured to obtain the sample data of any one event type in the following manner: First, construct a star network with the any one event type as the central node and all other event types as peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between the any one event type and the other event type corresponding to the any peripheral node. Then, based on all historical network security status alarm events corresponding to the any one event type and the other event type respectively, generate multiple frames of network security status alarm maps corresponding one by one to a plurality of consecutive unit time periods in time sequence. Finally, use the multiple frames of network security status alarm maps as model input items, and use the binary label value of the alarm requirement in the last time period of the any one event type in the plurality of unit time periods as the model output item to obtain the sample data including the model input item and the model output item.
[0033] The associated alarm model training unit is communicatively connected to the sample data generation unit, and is configured to, for any one event type, import all corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated alarm trigger model.
[0034] The associated alarm model application unit is communicatively connected to the associated alarm model training unit, and is configured to, for any one event type, generate the current latest multi-frame network security status alarm maps corresponding one by one to the current latest plurality of unit time periods based on the corresponding star network according to all network security status alarm events triggered in the current latest plurality of unit time periods, and import the generation result into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.
[0035] In a third aspect, the present invention provides a computer device, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the personnel positioning method as described in the first aspect or any possible design in the first aspect.
[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, on which instructions are stored. When the instructions are run on a computer, the personnel positioning method as described in the first aspect or any possible design in the first aspect is executed.
[0037] Fifth aspect, the present invention provides a computer program product, including a computer program or instructions, which, when executed by a computer, implement the personnel positioning method as described in the first aspect or any possible design in the first aspect.
[0038] Beneficial effects of the above solution:
[0039] The present invention provides a new solution capable of comprehensively analyzing network security status warning events from multiple heterogeneous data sources to trigger multi-source associated warnings. That is, first, based on all historical network security status warning events triggered for the target control system and from multiple heterogeneous data sources, calculate the correlation coefficient between any two event types, and construct sample data for any event type that comprehensively reflects the network security status of multiple heterogeneous data sources and also reflects the temporal characteristics of these network security states. Then, for any event type, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated warning trigger model. Finally, apply this model to immediately output the warning trigger result for any event type. In this way, through multi-source associated warning triggering based on the STGCN network, the accuracy of warnings and the network security situation awareness ability of the control system can be effectively improved, and the problems of isolated warnings, high false alarm rates, and difficulty in identifying complex attacks and warning in the existing control system network security situation awareness technology can be solved. It is particularly suitable for power network control systems and is convenient for practical application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0041] Figure 1 It is a schematic flowchart of the multi-source heterogeneous warning method for the network security status of the control system provided in the embodiment of the present application.
[0042] Figure 2 It is an example diagram of the multi-frame network security status warning diagram provided in the embodiment of the present application.
[0043] Figure 3 It is a schematic structural diagram of the multi-source heterogeneous warning device for the network security status of the control system provided in the embodiment of the present application.
[0044] Figure 4 It is a schematic structural diagram of the computer device provided in the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the accompanying drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the accompanying drawings is only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these embodiments. It should be noted here that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation to the present invention.
[0046] It should be understood that although terms such as first and second etc. may be used herein to describe various objects, these objects should not be limited by these terms. These terms are only used to distinguish one object from another. For example, the first object can be called the second object, and similarly the second object can be called the first object, without departing from the scope of the exemplary embodiments of the present invention.
[0047] It should be understood that for the term "and / or" that may appear in this article, it is only a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, B exists alone, or A and B exist simultaneously, etc.; another example, A, B and / or C can represent any one of A, B and C or any combination of them; for the term " / and" that may appear in this article, it is a description of another association object relationship, indicating that two relationships can exist. For example, A / and B can represent: A exists alone or A and B exist simultaneously, etc.; in addition, for the character " / " that may appear in this article, generally it represents that the associated objects before and after are an "or" relationship.
[0048] Embodiment
[0049] As Figure 1 shown, the multi-source heterogeneous alarm method for the network security state of the control system provided in the first aspect of this embodiment can be, but is not limited to, executed by a computer device having certain computing resources and respectively communicatively connected to multiple heterogeneous data sources for triggering network security state alarm events for the target control system. For example, it can be executed by an electronic device such as a cloud server, a personal computer (Personal Computer, PC, referring to a multi-purpose computer suitable for personal use in terms of size, price and performance; desktop computers, laptops, small laptops, tablet computers, and ultrabooks, etc. all belong to personal computers), a smart phone, a personal digital assistant (Personal Digital Assistant, PDA), or a wearable device. As Figure 1 shown, the multi-source heterogeneous alarm method for the network security state of the control system can be, but is not limited to, including the following steps S1 to S5.
[0050] S1. Obtain all historical network security status warning events triggered for the target control system and coming from multiple heterogeneous data sources. Among them, the network security status warning events include, but are not limited to, information such as event types and trigger times.
[0051] In the step S1, the target control system is specifically but not limited to a power network monitoring system such as a coal-fired power plant monitoring system. Specifically, the multiple heterogeneous data sources include, but are not limited to, a control system network security monitoring device (such as Huadian Ruilan control system network security monitoring device), a control system private protocol network security monitoring device (such as Huadian Ruilan control system private protocol network security monitoring device), a control system network traffic monitoring device (such as an industrial control protocol traffic monitoring device), and / or a control system log analysis device (such as a host log analysis device, a network security device log analysis device, and / or an industrial device log analysis device, etc.). These data sources can, based on existing technologies, trigger corresponding network security status warning events for the target control system and routinely transmit them to local devices. For example: The industrial control protocol traffic monitoring device can trigger network security status warning events for the target control system such as those indicating the existence of illegal instructions, abnormal instructions, communication mode mutations, and / or traffic anomalies; the control system log analysis device can trigger network security status warning events for the target control system such as those indicating the existence of access control situations, policy change situations, intrusion behaviors, access behaviors of unknown IPs (abbreviation for Internet Protocol), and / or abnormal device shutdowns. The control system network security monitoring device and / or the control system private protocol network security monitoring device can trigger network security status warning events for the target control system such as those indicating the existence of controller logic anomalies, controller unavailability, and / or unexpected control states, etc. In addition, the event types specifically but not limited to include network security status warning events indicating the existence of illegal instructions, abnormal instructions, communication mode mutations, traffic anomalies, access control situations, policy change situations, intrusion behaviors, access behaviors of unknown IPs, abnormal device shutdowns, controller logic anomalies, controller unavailability, and / or unexpected control states, etc.
[0052] S2. Calculate the correlation coefficients of any two event types based on all the historical network security status warning events.
[0053] In step S2, since multi-source associated alarm triggering will be performed subsequently, and different event types from different heterogeneous sources or the same heterogeneous source will necessarily have different correlations, it is necessary to calculate the correlation coefficient between any two event types first. Specifically, according to all the historical network security status alarm events, the correlation coefficient between any two event types is calculated, including but not limited to the following steps S21 to S23.
[0054] S21. For each heterogeneous data source among the multiple heterogeneous data sources, according to the event type and trigger time of all the corresponding historical network security status alarm events, historical time series data of various event types are generated. Among them, the historical time series data includes but is not limited to consecutive unit time periods in historical time series and the binary label values of the corresponding event type in each of the unit time periods, etc. represents a positive integer greater than 100. The binary label value of "1" indicates that an alarm event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that an alarm event of the corresponding event type does not occur in the corresponding time period.
[0055] In step S21, for example, if the network security monitoring device for the private protocol of the control system can trigger network security status alarm events for indicating controller logic anomalies, controller unavailability, and unexpected control states for the target control system, then according to the event types and trigger times of these historical network security status alarm events, historical time series data of the corresponding three event types (i.e., network security status alarm events for indicating controller logic anomalies, network security status alarm events for indicating controller unavailability, and network security status alarm events for indicating unexpected control states) can be generated for the network security monitoring device for the private protocol of the control system. The unit time period can be but is not limited to examples such as 10 seconds, 30 seconds, or 1 minute, etc.; taking the unit time period as 1 minute as an example, if the network security monitoring device for the private protocol of the control system triggers a network security status alarm event for indicating controller logic anomalies at 10:00:15, 10:05:32, and 10:09:54 respectively, then according to these trigger times, the following historical time series data corresponding to the network security status alarm event for indicating controller logic anomalies can be conventionally generated: {1, 0, 0, 0, 0, 1, 0, 0, 0, 1}; the generation process of the historical time series data of other event types can be deduced by analogy.
[0056] S22. For the historical time series data corresponding to the first event type among any two event types Perform a normal distribution KS test to calculate the first test statistic value , and for the historical time series data corresponding to the second event type among any two event types Perform the normal distribution KS test to calculate the second test statistic value .
[0057] In the step S22, the normal distribution KS test is the Kolmogorov - Smirnov test, which is an existing statistical test method used to determine whether the observed values of a set of data conform to a specific distribution. Therefore, it can be conventionally modified to obtain the first test statistic value and the second test statistic value .
[0058] S23. If the value of the first test statistic value and the value of the second test statistic value are both greater than the preset threshold, then calculate the correlation coefficient of any two event types according to the following formula :
[0059]
[0060] In the formula, represents a positive integer, represents the th label value in , represents the th label value in , represents the mean of ,
[0061] In the step S23, the preset threshold can be exemplified as 0.05
[0062] S3. Obtain the sample data of any event type in the following manner: First, construct a star network with the any event type as the central node and all other event types as peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between the any event type and the other event type corresponding to the any peripheral node. Then, based on the historical network security status alarm events corresponding to the any event type and the other event type respectively, generate multiple frames of network security status alarm diagrams corresponding one by one to multiple consecutive unit time periods in time sequence. Finally, take the multiple frames of network security status alarm diagrams as model input items, and take the binary label value of the alarm requirement in the last time period of the any event type in the multiple unit time periods as the model output item, so as to obtain the sample data including the model input item and the model output item.
[0063] In step S3, for example, if there are a total of nine event types, there will be one central node and eight peripheral nodes in the star network as shown in Figure 2 . The distance from the central node to each peripheral node is negatively correlated with the correlation coefficient of their corresponding event types: the larger the correlation coefficient, the closer the distance; the smaller the correlation coefficient, the farther the distance. Specifically, based on the historical network security status alarm events corresponding to the any event type and the other event type respectively, generate multiple frames of network security status alarm diagrams corresponding one by one to multiple consecutive unit time periods in time sequence, including but not limited to the following steps S31 - S32.
[0064] S31. Generate the historical time series data of the any event type according to the triggering moments of all historical network security status alarm events corresponding to the any event type, and generate the historical time series data of the other event type according to the triggering moments of all historical network security status alarm events corresponding to the other event type. Among them, the historical time series data includes but not limited to consecutive unit time periods in historical time sequence and the binary label values of each unit time period of the corresponding event type in the unit time periods, etc. represents a positive integer greater than 100. The binary label value of "1" indicates that a network security status alarm event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that no network security status alarm event of the corresponding event type occurs in the corresponding time period.
[0065] In step S31, the specific generation details of the historical time series data can refer to the aforementioned step S21, which will not be elaborated here.
[0066] S32. Respectively extract from the historical time series data of the any event type and the other event type the The binary label values for one unit time period, and for each unit time period among the unit time periods, reflect the extracted binary label values of this any event type in the corresponding time period to the central node in the star network, and reflect the extracted binary label values of the other event type in the corresponding time period to the peripheral node in the star network corresponding to the other event type, to obtain the network security status warning map for the corresponding time period, where represents a positive integer greater than or equal to 2 and less than .
[0067] In the step S32, for example, if the unit time period is taken as 1 minute and the value is 4, then four binary label values from 10:00 to 10:03 can be extracted from the historical time series data of this any event type; and four binary label values from 10:00 to 10:03 can be extracted from the historical time series data of the other event type. The specific manner of reflecting the extracted binary label values of this any event type in the respective unit time periods to the central node in the star network may include, but is not limited to, the following: if the extracted binary label value of this any event type in a certain unit time period is "1", then mark the central node in the star network as a solid node, otherwise mark it as a hollow node; the specific manner of reflecting the extracted binary label values of the other event type in the corresponding time period to the peripheral node in the star network corresponding to the other event type may include, but is not limited to, the following: if the extracted binary label value of the other event type in the corresponding time period is "1", then mark the peripheral node in the star network corresponding to the other event type as a solid node, otherwise mark it as a hollow node; the finally obtained four frames of network security status warning maps corresponding to 10:00 to 10:03 are as Figure 2As shown, it not only comprehensively reflects the correlation characteristics of the network security status of multiple heterogeneous data sources, but also reflects the temporal characteristics of these network security statuses, which is conducive to subsequent temporal analysis and causal reasoning. In addition, the binary label value of the alarm requirement is used to reflect whether a network security status alarm event of any of the event types needs to be triggered in the last period. "1" indicates that a network security status alarm event of any of the event types needs to be triggered in the last period, while "0" indicates that a network security status alarm event of any of the event types does not need to be triggered in the last period. It can be specifically obtained by manually checking the triggering situation of the historical network security status alarm events of any of the event types in the last period. For example, if a historical network security status alarm event of any of the event types is triggered in the last period, it is necessary to manually check whether this alarm event is a false alarm. If it is not a false alarm, the binary label value of the alarm requirement of any of the event types in the last period is marked as "1", otherwise it is marked as "0". If no historical network security status alarm event of any of the event types is triggered in the last period, it is necessary to manually check whether the network security status alarm event of any of the event types is missed. If it is missed, the binary label value of the alarm requirement of any of the event types in the last period is marked as "1", otherwise it is marked as "0".
[0068] S4. For any of the event types, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain a corresponding multi-source association alarm trigger model.
[0069] In the step S4, the STGCN (Spatial-Temporal Graph Convolutional Network) network is a deep learning model that combines the Graph Convolutional Network (GCN) and the temporal convolutional network, aiming to process complex data with spatio-temporal correlations. The model models spatial relationships through a graph structure and captures dynamic temporal features through temporal convolution, having the capabilities of temporal analysis and causal reasoning, and is widely used in fields such as action recognition and temporal prediction. Therefore, based on the sample data, a multi-source association triggering model can be trained to output the multi-source association triggering requirements of network security status warning events of any of these event types after inputting multiple frames of network security status warning graphs (using an output of "1" to indicate that a network security status warning event of any of these event types needs to be triggered by multi-source association, and using an output of "0" to indicate that a network security status warning event of any of these event types does not need to be triggered by multi-source association). The specific process of the calibration and verification modeling includes the calibration process and the verification process of the model, that is, first comparing the model simulation results with the measured data, and then adjusting the model parameters according to the comparison results to make the simulation results coincide with the actual situation. Therefore, the multi-source association triggering model can be obtained through conventional training based on the existing technology.
[0070] In the step S4, it is also considered that model hyperparameters refer to the parameters preset in the deep learning model, which cannot be directly learned from the data in the standard model training process but need to be manually set to optimize the performance of the model. For example, for the STGCN network, parameters such as the number of graph convolutional layers, the dimension of the graph convolutional layer, the spatio-temporal convolutional kernel size, the learning rate, the batch size, the selection result of the optimizer, the regularization parameter, and the number of training epochs need to be manually set. In order to achieve the purpose of automatically debugging and obtaining the optimal multi-source association triggering model that can balance the accuracy of warning triggering and the processing speed, preferably, for any of these event types, all the corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling to obtain the corresponding multi-source association triggering model, including but not limited to the following steps S41 to S42.
[0071] S41. For any of these event types, all the corresponding sample data are imported into the deep learning model based on the STGCN network for calibration and verification modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and the optimal search result for minimizing the objective function where the calculation formula of the objective function is as follows:
[0072]
[0073] In the formula, represents the output error situation index value of the deep learning model, represents the index value of the required calculation time for the deep learning model.
[0074] In the step S41, the output error situation index value is used to reflect the accuracy of model alarm triggering. The smaller the value, the higher the accuracy of model alarm triggering. Specifically, it includes but is not limited to the average deviation value, variance, and / or average error rate of the overall samples, etc., and can be obtained through regular statistics during model training and testing. The required calculation time index value is used to reflect the processing speed of the model. The shorter the value, the faster the model processing speed, and it can be obtained through regular timing during model testing. The objective function is used as a comprehensive index that takes into account both the accuracy of alarm triggering and the processing speed. The smaller the result, the better the model obtained by training can comprehensively achieve the optimal performance in the two target dimensions of alarm triggering accuracy and processing speed, so as to optimize and obtain the optimal multi-source associated alarm triggering model that takes into account both alarm triggering accuracy and processing speed. In addition, specifically, the optimization algorithm can be but is not limited to the particle swarm optimization algorithm, Newton optimization algorithm, genetic optimization algorithm, Grey Wolf Algorithm, whale optimization algorithm, or tuna swarm optimization algorithm, etc.
[0075] In the step S41, in order to quickly and accurately obtain the optimal search result, preferably, for any one of the event types, all the corresponding sample data are imported into the deep learning model based on the STGCN network for calibration verification modeling, and the hyperparameters of the deep learning model are optimized based on the optimization algorithm to obtain the hyperparameters and the optimal search result that minimizes the objective function , including but not limited to the following steps S411 to S419.
[0076] S411. Initialize the optimization algorithm parameters including the maximum number of iterations , and randomly generate an initial search value array for the set of parameters to be optimized, and then execute step S412. Among them, the set of parameters to be optimized includes all the hyperparameters of the deep learning model based on the STGCN network, and the initial search value array is expressed as follows:
[0077]
[0078] In the formula, represents a positive integer less than or equal to , represents the total number of parameters in the set of parameters to be optimized, represents the The initial search value corresponding to a parameter, indicating the upper limit of the parameter search space corresponding to the th parameter, indicating the lower limit of the parameter search space corresponding to the th parameter, indicating a fractional random generation function.
[0079] In the step S411, the upper limit of the parameter search space and the lower limit of the parameter search space can be specifically set in advance according to the adjustment requirements.
[0080] S412. Import the initial search value array of the parameter set to be optimized as model hyperparameters into the deep learning model to obtain a first deep learning model. Then, apply all sample data corresponding to any one of the event types to train and test the first deep learning model to obtain a first output error situation index value and a first calculation required duration index value. Finally, import the first output error situation index value and the first calculation required duration index value into the objective function and use the output result as the fitness corresponding to the initial search value array, and then execute step S413, where the objective function has the following calculation formula:
[0081]
[0082] In the formula, represents the output error situation index value of the deep learning model, represents the calculation required duration index value of the deep learning model.
[0083] In the step S412, considering that some hyperparameters need to be integers (such as the number of graph convolutional layers), it is necessary to round the corresponding parameter values before importing the initial position as model hyperparameters into the model. For example, round the number of graph convolutional layers. The aforementioned application of all sample data corresponding to any one of the event types to train and test the first deep learning model is a conventional calibration and verification method, which will not be elaborated here. In addition, when obtaining the first output error situation index value and the first calculation required duration index value, it is also necessary to record the model parameters corresponding to the initial search value array and obtained through model training for use in the subsequent step S42.
[0084] S413. Take the initial search value array of the parameter set to be optimized as the current optimal search value array and initialize the current iteration number , and further initialize the forbidden change countdown value of each parameter set in the parameter set to be optimized to zero, and then execute step S414.
[0085] S414. Based on the current optimal search value array, perform independent increase processing and decrease processing on each parameter in the parameter set to be optimized and with a current forbidden change countdown value of zero, to obtain new search value arrays of the parameter set to be optimized, and then execute step S415, where represents the total number of parameters in the parameter set to be optimized and with a current forbidden change countdown value of zero, and there is .
[0086] In step S414, the increase processing or the decrease processing needs to be carried out within the corresponding parameter search space, and can be a quantitative step-by-step increase / decrease, or an indefinite random increase / decrease. Further, it can first perform quantitative step-by-step increase / decrease on each parameter in the parameter set to be optimized and with a current forbidden change countdown value of zero, and then if it is found that the update of the current optimal search value array is not completed (that is, step S419 is directly executed in subsequent step S418), then perform indefinite random increase / decrease on each parameter in the parameter set to be optimized and with a current forbidden change countdown value of zero, so as to avoid falling into a local optimal solution. For example, if there are the following six parameters in the parameter set to be optimized: parameter A, parameter B, parameter C, parameter D, parameter E, and parameter F, where the current forbidden change countdown values of parameter A, parameter B, parameter E, and parameter F are zero respectively (that is, takes the value of 4), then based on the current optimal search value array, independent increase processing and decrease processing can be performed on parameter A respectively to obtain two different new search value arrays of the parameter set to be optimized (one obtained based on the increase processing and the other obtained based on the decrease processing); based on the current optimal search value array, independent increase processing and decrease processing can be performed on parameter B respectively to obtain two different new search value arrays of the parameter set to be optimized; based on the current optimal search value array, independent increase processing and decrease processing can be performed on parameter E respectively to obtain two different new search value arrays of the parameter set to be optimized; based on the current optimal search value array, independent increase processing and decrease processing can be performed on parameter F respectively to obtain two different new search value arrays of the parameter set to be optimized; and thus 2×4 = 8 new search value arrays can be obtained, and each array represents a neighborhood search direction in the search space.
[0087] S415. For the For each array in the new search value arrays, import the corresponding array as model hyperparameters into the deep learning model to obtain a second deep learning model for the corresponding array. Then, apply all the sample data corresponding to any one of the event types to train and test the second deep learning model to obtain a second output error situation index value and a second calculation required duration index value for the corresponding array. Finally, import the second output error situation index value and the second calculation required duration index value into the objective function , and use the output result as the fitness of the corresponding array, and then execute step S416.
[0088] In step S415, the specific technical details can be obtained by referring to the conventional derivation in the foregoing step S412 and will not be elaborated here. In addition, when obtaining the second output error situation index value and the second calculation required duration index value, it is also necessary to record the corresponding data and the model parameters obtained through model training for use in subsequent step S42.
[0089] S416. For each of the arrays, subtract the fitness of the corresponding array from the fitness of the array corresponding to the current optimal search value array to obtain a fitness difference value for the corresponding array. When the fitness difference value is greater than zero and is the largest fitness difference value in this time, update the forbidden change countdown value of the corresponding unique variable parameter to a positive integer value that is positively correlated with the fitness difference value, and then execute step S417, where the unique variable parameter refers to the parameter in the set of parameters to be optimized that is used to obtain the corresponding array through increase processing or decrease processing.
[0090] In step S416, the fact that the fitness difference value is greater than zero and is the largest fitness difference value in this time means that the best search value array has been obtained in the neighborhood search direction corresponding to the corresponding parameter in this time. Therefore, it is necessary to update the forbidden change countdown value of the corresponding parameter to a positive integer that is positively correlated with the fitness difference value to temporarily lock the search result in this neighborhood search direction. In addition, continuing with the example in step S414 above, among the eight new search value arrays corresponding to parameters A, B, E, and F, if the fitness difference value of a certain new search value array corresponding to parameter F is greater than zero and is the largest fitness difference value in this time (i.e., the largest among the eight fitness difference values in this time), then update the forbidden change countdown value of parameter F from zero to a positive integer value that is positively correlated with the fitness difference value, while the forbidden change countdown values of parameters A, B, and E remain zero.
[0091] S417. Determine whether there is any parameter in the set of parameters to be optimized whose current forbidden change countdown value is zero. If not, decrement the current forbidden change countdown value of each parameter in the set of parameters to be optimized by 1, and then return to execute step S417. Otherwise, execute step S418.
[0092] In step S417, the current forbidden change countdown values of all parameters in the set of parameters to be optimized are not zero, which means that it is impossible to return to execute step S414 subsequently. Therefore, they need to be decremented together until the current forbidden change countdown value of at least one parameter is zero.
[0093] S418. Determine whether there is any fitness difference value greater than zero among the fitness difference values of the respective arrays. If so, update the current optimal search value array to the array in the new search value arrays and corresponding to the minimum fitness, and then execute step S419. Otherwise, directly execute step S419.
[0094] S419. Increment the current iteration count by 1, and determine whether the current iteration count has reached the maximum iteration count . If so, use the current optimal search value array as the hyperparameters of the deep learning model and as the optimal search result for minimizing the objective function . Otherwise, return to execute step S414.
[0095] Thus, by using the aforementioned new heuristic algorithm steps S411 - S419 to optimize the model hyperparameters, it is possible to temporarily lock the search results in different numbers of iterations based on different fitness difference values during the optimization process, which is conducive to quickly searching for the optimal model hyperparameters. Additionally, through the parameter adjustment method of first quantitatively increasing / decreasing the parameters to be adjusted and then randomly increasing / decreasing them in an indefinite amount, it is possible to avoid falling into local optimal solutions and further facilitate quickly and accurately obtaining the optimal search result.
[0096] S42. Import the optimal search result and the model parameters obtained during the optimization process and corresponding to this optimal search result into the deep learning model to obtain a multi-source associated alarm trigger model corresponding to any event type.
[0097] In the step S42, since it is also considered that some hyperparameters need to be integers, it is necessary to round the corresponding parameter values before importing the optimization search result as the model hyperparameters into the model. In addition, the model parameters obtained during the optimization process and corresponding to the optimization search result are the model parameters recorded in the foregoing S412 or S415 and obtained through model training.
[0098] S5. For any one of the event types, based on all the network security status warning events triggered in the current nearest multiple unit time periods, generate a current nearest multi-frame network security status warning map corresponding to the current nearest multiple unit time periods based on the corresponding star network, and import the generation result into the corresponding multi-source associated warning trigger model to output the corresponding warning trigger result.
[0099] In the step S5, all the network security status warning events triggered in the current nearest multiple unit time periods mentioned above come from the multiple heterogeneous data sources. The specific process of generating the current nearest multi-frame network security status warning map based on these warning events can be obtained by the conventional derivation of the foregoing step S3, which will not be elaborated here. In addition, the warning trigger result specifically includes: if it is "1", it means that it is necessary to trigger the network security status warning event of any one of the event types at the current moment, and if it is "0", it means that it is not necessary to trigger the network security status warning event of any one of the event types at the current moment.
[0100] Based on the multi-source heterogeneous warning method for the network security status of the control system described in the foregoing steps S1 to S5, a new solution is provided that can comprehensively analyze the network security status warning events from multiple heterogeneous data sources for multi-source associated warning triggering. That is, first, according to all the historical network security status warning events triggered for the target control system and coming from multiple heterogeneous data sources, calculate the correlation coefficient between any two event types, and construct sample data for any one of the event types that comprehensively reflects the associated characteristics of the network security status of multiple heterogeneous data sources and also reflects the temporal characteristics of these network security statuses. Then, for any one of the event types, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated warning trigger model. Finally, apply this model to immediately output the warning trigger result for any one of the event types. In this way, through multi-source associated warning triggering based on the STGCN network, the accuracy of warning and the network security situation awareness ability of the control system can be effectively improved, and the problems of isolated warning, high false alarm rate, and difficulty in identifying complex attacks and warning existing in the existing network security situation awareness technology of the control system can be solved. It is especially suitable for power network control systems and is convenient for practical application and promotion.
[0101] Such as Figure 3As shown in the figure, in the second aspect of this embodiment, a virtual device for implementing the multi-source heterogeneous alarm method for the network security state of the control system described in the first aspect is provided, including an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, a correlation alarm model training unit, and a correlation alarm model application unit;
[0102] The alarm event acquisition unit is used to acquire all historical network security state alarm events triggered for the target control system and coming from multiple heterogeneous data sources. Among them, the network security state alarm events include event types and trigger times;
[0103] The correlation coefficient calculation unit is communicatively connected to the alarm event acquisition unit and is used to calculate the correlation coefficient between any two event types according to all historical network security state alarm events;
[0104] The sample data generation unit is respectively communicatively connected to the alarm event acquisition unit and the correlation coefficient calculation unit, and is used to obtain the sample data of any event type in the following manner: first, construct a star network with the any event type as the central node and all other event types as the peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between the any event type and the other event type corresponding to the any peripheral node. Then, according to all historical network security state alarm events corresponding to the any event type and the other event type respectively, generate multiple frames of network security state alarm diagrams corresponding to multiple consecutive unit time periods in sequence based on the star network. Finally, take the multiple frames of network security state alarm diagrams as model input items, and take the binary label value of the alarm requirement in the last time period of the multiple unit time periods of the any event type as the model output item to obtain the sample data including the model input item and the model output item;
[0105] The correlation alarm model training unit is communicatively connected to the sample data generation unit and is used to calibrate and verify the modeling of all corresponding sample data into a deep learning model based on the STGCN network for any event type to obtain the corresponding multi-source correlation alarm trigger model;
[0106] The correlation alarm model application unit is communicatively connected to the correlation alarm model training unit and is used to, for any event type, generate the current latest multi-frame network security state alarm diagrams corresponding to the current latest multiple unit time periods based on the corresponding star network according to all network security state alarm events triggered in the current latest multiple unit time periods, and import the generation results into the corresponding multi-source correlation alarm trigger model to output the corresponding alarm trigger result.
[0107] For the working process, working details and technical effects of the aforementioned device provided in the second aspect of this embodiment, reference may be made to the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect, which will not be elaborated here.
[0108] As Figure 4 shown, a computer device for executing the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect is provided in the third aspect of this embodiment, including a memory, a processor and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect. Specifically, by way of example, the memory may include, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a flash memory, a first input first output (FIFO) and / or a first input last output (FILO), etc.; the processor may be, but is not limited to, a microprocessor of the STM32F105 series. In addition, the computer device may also include, but is not limited to, a power module, a display screen and other necessary components.
[0109] For the working process, working details and technical effects of the aforementioned computer device provided in the third aspect of this embodiment, reference may be made to the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect, which will not be elaborated here.
[0110] A computer-readable storage medium storing instructions including the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect is provided in the fourth aspect of this embodiment, that is, instructions are stored on the computer-readable storage medium, and when the instructions are run on a computer, the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect is executed. Among them, the computer-readable storage medium refers to a carrier for storing data, which may include, but is not limited to, a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash drive and / or a memory stick, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices.
[0111] For the working process, working details and technical effects of the aforementioned computer-readable storage medium provided in the fourth aspect of this embodiment, reference may be made to the multi-source heterogeneous warning method for the network security status of the control system described in the first aspect, which will not be elaborated here.
[0112] The fifth aspect of this embodiment provides a computer program product, including a computer program or instructions, and the computer program or the instructions, when executed by a computer, implement the multi-source heterogeneous warning method for the network security state of the control system as described in the first aspect. Among them, the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
[0113] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A multi-source heterogeneous alarm method for the network security status of a control system, characterized in that, Including: Obtain all historical network security status alarm events triggered for the target control system and coming from multiple heterogeneous data sources. Among them, the network security status alarm events include event types and trigger times. Calculate the correlation coefficients between any two event types based on all historical network security status alarm events. Obtain the sample data of any one event type in the following way: First, construct a star network with this one event type as the central node and all other event types as the peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between this one event type and the other event types corresponding to this one peripheral node. Then, based on all historical network security status alarm events corresponding to this one event type and this other event type respectively, generate multiple frames of network security status alarm diagrams corresponding one by one to multiple consecutive unit time periods in time sequence based on the star network. Finally, take these multiple frames of network security status alarm diagrams as model input items, and take the binary label value of the alarm requirement in the last time period of these multiple unit time periods of this one event type as the model output item to obtain the sample data including this model input item and this model output item. For any one event type, import all the corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated alarm trigger model. For any one event type, based on all network security status alarm events triggered in the current recent multiple unit time periods, generate the current recent multiple frames of network security status alarm diagrams corresponding one by one to the current recent multiple unit time periods based on the corresponding star network, and import the generation results into the corresponding multi-source associated alarm trigger model to output the corresponding alarm trigger result.
2. The multi-source heterogeneous alarm method for the network security state of the control system according to claim 1, wherein The multiple heterogeneous data sources include a control system network security monitoring device, a control system private protocol network security monitoring device, a control system network traffic monitoring device, and / or a control system log analysis device.
3. The multi-source heterogeneous alarm method for the network security state of the control system according to claim 1, characterized in that Calculating the correlation coefficients between any two event types based on all historical network security status alarm events includes: For each heterogeneous data source among multiple heterogeneous data sources, according to the event types and trigger times of all historical network security status warning events corresponding thereto, historical time series data of corresponding various event types is generated, wherein the historical time series data includes successive unit time periods in the historical time series and the binary label values of each unit time period of the corresponding event type in the unit time periods, wherein represents a positive integer greater than 100, the binary label value of "1" indicates that a warning event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that a warning event of the corresponding event type does not occur in the corresponding time period; For historical time series data corresponding to a first event type among any two event types perform a normal distribution KS test to calculate a first test statistic value and for historical time series data corresponding to a second event type among the any two event types perform a normal distribution KS test to calculate a second test statistic value ; If the first verification statistic value and the second verification statistic value are both greater than a preset threshold value, then the correlation coefficient of any two of the event types is calculated according to the following formula : Wherein, represents a positive integer, represents the th tag value in represents the th tag value in represents mean value of represents mean value of 4. The multi-source heterogeneous alarm method for the network security status of the control system according to claim 1, wherein Generating multiple frames of network security status alarm diagrams corresponding one by one to multiple consecutive unit time periods in time sequence based on the star network according to all historical network security status alarm events corresponding to this one event type and this other event type respectively includes: Generate historical time series data for any one of the event types based on the triggering times of all historical network security status alert events corresponding to that event type, and generate historical time series data for the other event type based on the triggering times of all historical network security status alert events corresponding to that other event type, where the historical time series data includes successive unit time periods in the historical time series and the binary label values of each unit time period of the corresponding event type in the unit time periods, represents a positive integer greater than 100, the binary label value of "1" indicates that a network security status alert event of the corresponding event type occurs in the corresponding time period, and the binary label value of "0" indicates that a network security status alert event of the corresponding event type does not occur in the corresponding time period; Extract from the historical time-series data of each of the any event type and the other event type to obtain binarized label values that are sequentially continuous in time for unit time periods, and for each unit time period in unit time periods, reflect the extracted binarized label value of the any event type in the corresponding time period to the central node in the star network, and reflect the extracted binarized label value of the other event type in the corresponding time period to the peripheral node corresponding to the other event type in the star network, to obtain a network security status warning diagram for the corresponding time period, where represents a positive integer greater than or equal to 2 and less than .
5. The multi-source heterogeneous alarm method for the network security status of the control system according to claim 1, wherein Importing all the corresponding sample data of any one event type into a deep learning model based on the STGCN network for calibration verification modeling to obtain the corresponding multi-source associated alarm trigger model includes: For any event type, all corresponding sample data are imported into a deep learning model based on the STGCN network for calibration verification modeling, and the hyperparameters of the deep learning model are optimized based on an optimization algorithm to obtain the hyperparameters and use them to make the objective function The optimal search result that minimizes, where the objective function The calculation formula is as follows: Wherein, represents the output error situation index value of the deep learning model, represents the calculation required duration index value of the deep learning model; Import the optimal search result and the model parameters obtained during the optimization process and corresponding to the optimal search result into the deep learning model to obtain the multi-source associated alarm trigger model corresponding to the said one event type.
6. The multi-source heterogeneous alarm method for the network security state of the control system according to claim 5, wherein, The optimization algorithm adopts a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a grey wolf optimization algorithm, a whale optimization algorithm, or a tuna swarm optimization algorithm.
7. A multi-source heterogeneous alarm device for the network security status of a control system, characterized in that, Including an alarm event acquisition unit, a correlation coefficient calculation unit, a sample data generation unit, an associated alarm model training unit, and an associated alarm model application unit; The alarm event acquisition unit is configured to acquire all historical network security status alarm events triggered for the target control system and originating from multiple heterogeneous data sources, where the network security status alarm events include event types and trigger times; The correlation coefficient calculation unit, communicatively connected to the alarm event acquisition unit, is configured to calculate the correlation coefficient between any two event types based on all historical network security status alarm events; The sample data generation unit, communicatively connected to the alarm event acquisition unit and the correlation coefficient calculation unit respectively, is configured to obtain the sample data of any one event type in the following manner: first, construct a star network with this one event type as the central node and all other event types as peripheral nodes respectively, and make the distance from the central node to any peripheral node negatively correlated with the correlation coefficient between this one event type and the other event type corresponding to this one peripheral node. Then, based on all historical network security status alarm events corresponding to this one event type and this other event type respectively, generate multiple frames of network security status alarm diagrams corresponding one-to-one to multiple consecutive unit time periods in time sequence. Finally, use these multiple frames of network security status alarm diagrams as model input items, and use the binary label value of the alarm requirement in the last time period of these multiple unit time periods for this one event type as the model output item, to obtain sample data including this model input item and this model output item; The associated alarm model training unit, communicatively connected to the sample data generation unit, is configured to, for any one event type, import all corresponding sample data into a deep learning model based on the STGCN network for calibration verification modeling, to obtain the corresponding multi-source associated alarm trigger model; The associated alarm model application unit, communicatively connected to the associated alarm model training unit, is configured to, for any one event type, based on all network security status alarm events triggered in the current recent multiple unit time periods, generate the current recent multiple frames of network security status alarm diagrams corresponding one-to-one to the current recent multiple unit time periods based on the corresponding star network, and import the generation result into the corresponding multi-source associated alarm trigger model, and output the corresponding alarm trigger result.
8. A computer device, characterized in that, It includes a memory, a processor, and a transceiver that are communicatively connected in sequence, where the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the multi-source heterogeneous alarm method for the network security status of the control system as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that Instructions are stored on the computer-readable storage medium, and when the instructions run on the computer, they execute the multi-source heterogeneous alarm method for the network security status of the control system as described in any one of claims 1 to 6.
10. A computer program product, comprising a computer program or instructions, characterized in that, The computer program or the instructions, when executed by the computer, implement the multi-source heterogeneous alarm method for the network security status of the control system as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Integration safety prevention analysis alarm system and method thereof
CN105761460A
Internet situation assessment method based on knowledge graph
CN117692198A