APT tracing method and device based on power grid information physical coupling

By adopting the APT traceability method based on physical coupling of grid information in the smart grid, and using technical means such as LSTM model and overload correlation diagram, the cross-layer attack traceability problem faced by the smart grid is solved, and high-accurate attack traceability and security protection are achieved.

CN120030535AActive Publication Date: 2025-05-23QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Patent Information

Application Number
CN202510481176.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-23
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

Smart grids face the complexity of cross-layer attacks, and existing technologies are difficult to effectively trace the source and locate the attack source, resulting in insufficient security protection capabilities.

Method used

The APT traceability method based on physical coupling of power grid information is adopted, and the audit log data is obtained by simulating APT behavior, reconstructing it into a causal relationship diagram, and training is used to identify APT behavior. At the same time, an overload correlation graph and an overload dependency library are constructed, and the fragility and destructive influences are evaluated in combination with frequency and destructive indicators, suspicious branch sequences are determined and attack paths are restored.

Benefits of technology

It significantly improves the accuracy of attack tracing, can accurately recover attack paths, reduce false alarms, and enhances the security protection capabilities of the smart grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030535A_ABST
    Figure CN120030535A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of intelligent power grid data security protection, and particularly relates to an APT traceability method and device based on power grid information physical coupling, and the method comprises the steps: obtaining audit log data, reconstructing the audit log data into a causal relationship graph, and constructing a training sample set based on the causal relationship graph to train an LSTM model; constructing an overload association graph based on the overload condition of the physical layer topology and the physical layer bus node, and performing vulnerability evaluation on each branch; based on the real overload condition of each branch, binary classification is carried out, an overload dependency relationship library is constructed, and the destructive influence associated with the overload of each branch is evaluated; and determining a suspicious branch sequence based on the two evaluation results, narrowing a suspicious log range according to an information-physical topological relation and a time attribute to obtain a to-be-identified log, reconstructing the to-be-identified log into a target causal relation graph, and identifying the to-be-identified log by using a trained LSTM model to discriminate an attack entity and restore an attack path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of smart grid data security protection, and specifically relates to an APT (advanced persistent threat) tracing method and device based on grid information-physical coupling, which is particularly suitable for attack identification, attack source location and attack path reconstruction in a smart grid environment. Background Art

[0002] With the continuous growth of electricity demand and the rapid development of information and communication technology, smart grids have achieved a more stable and sustainable power supply with their advanced management and control capabilities. However, the high dependence of smart grids on cyberspace has also brought severe security challenges, exposing them to cyber attacks such as malicious data tampering.

[0003] At the level of power information systems, APTs (advanced persistent threats) usually adopt long-term and multi-step attack strategies to gradually obtain host permissions, making it easier for attackers to launch FDIA (false data injection attacks) at the physical layer. By tampering with state estimation results, FDIA can have a serious impact on power physical systems, leading to wrong decisions and even system instability. At the physical system level, the propagation and evolution mechanism of security threats is extremely complex, and the nodes that ultimately show failures are often not the nodes directly affected by the attack, which makes tracing analysis more difficult. Therefore, smart grids are in urgent need of a comprehensive tracing method that can deal with cross-layer attacks to improve their security protection capabilities.

[0004] Traditional APT tracing methods at the network information layer mainly include methods based on logging, packet marking technology, and active data perception. These methods rely on network attack models to achieve step-by-step reverse tracing. However, they face many challenges in practical applications, such as the need to store and process massive amounts of data, and the tracing process is susceptible to interruptions in the middle, resulting in reduced tracing reliability.

[0005] FDIA traceability methods are mainly divided into two categories: model-based methods and data-driven methods. Model-based methods rely on the accuracy and completeness of the power grid model, which is easily restricted when facing complex environments and dynamic changes, and it is difficult to guarantee the traceability effect. In contrast, data-driven methods use machine learning technology to analyze large amounts of data to achieve more efficient attack location, improve traceability accuracy, and have stronger adaptability and robustness.

[0006] Chinese patent document CN116760604A discloses an APT online detection method based on system logs and deep learning, including: 1) preprocessing system logs and iteratively training word vector models; 2) converting each group of log sequences into vector data sets through the trained word vector model; 3) building a Transformer model and iteratively training it using the vector data set; 4) obtaining the log index sequence and performing lagging expansion; 5) building a BiLSTM model and iteratively training it using the expanded data set; 6) using the two trained models to detect and predict APT attacks online.

[0007] Chinese patent document CN116846631A discloses an APT attack detection method based on threat intelligence and traffic features, including: A: obtaining an original attack sequence set and marking it; B: obtaining an attack sequence set after data cleaning and a corresponding network traffic feature set; C: constructing a local threat intelligence library and obtaining threat intelligence features of each original traffic; D: building a sample message feature library and obtaining message features of the sequence set; E: using the obtained network traffic feature set, threat intelligence features and message features to train a multi-fusion detection model based on an LSTM recurrent neural network and obtain a trained multi-fusion detection model; F: using the trained multi-fusion detection model to perform APT attack detection on an unknown traffic sequence to determine whether an APT attack exists.

[0008] However, there is currently a lack of a traceability strategy in the power system that can integrate the methods of the network information layer and the physical layer to form a complete bottom-up traceability system and realize the full-link traceability process from discovering physical faults to accurately locating network attackers. Summary of the invention

[0009] The present invention aims to fill the gap in the prior art and provide an APT tracing method based on physical coupling of power grid information to effectively analyze the sources and attack paths of potential security threats to the power system.

[0010] The invention also discloses a device loaded with an APT tracing method based on physical coupling of power grid information.

[0011] The existing technology is prone to false alarms when processing massive data at the network information layer, and has a low accuracy rate when processing complex faults at the physical layer. However, the present invention provides a complete information-physical cross-layer collaborative tracing process through an innovative model architecture and novel tracing strategies and methods, which can accurately restore the attack path and significantly improve the accuracy of attack tracing.

[0012] The detailed technical scheme of the present invention is as follows: An APT tracing method based on physical coupling of power grid information, the method comprising: S1. Based on simulating APT behavior in a real scenario, obtaining audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; S2. constructing a training sample set based on the causal relationship graph, and using the training sample set to train the LSTM model so that the LSTM model acquires the ability to identify potential APT behaviors; S3. Based on the physical layer topology and the overload condition of the physical layer bus node, construct an overload association graph, and calculate the vulnerability of the path in the overload association graph to perform a vulnerability assessment on each branch to obtain a first assessment result; S4. Based on the actual overload situation of each branch, all branches are classified into two categories, an overload dependency library is constructed, and a data-driven method is combined with frequency indicators. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; S5. Determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the scope of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified; S6. Reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify the attack entity and restore the attack path.

[0013] Preferably, in S1, reconstructing the audit log data into a causal relationship graph specifically includes: Extracting a directed cyclic causal relationship graph from the audit log data, wherein the causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions; Among them, the information nodes representing the subject and the object include processes, files, IP addresses, and domain names, the edges representing actions include read and execute, and the edge points from a subject to an object; Furthermore, the complexity of the causal relationship graph is reduced by three optimization methods: removing information nodes and edges that cannot be reached by the attacking node, deleting duplicate edges, and merging similar events.

[0014] Preferably, according to the present invention, in S2, constructing a training sample set based on the causal relationship graph specifically includes: Sequence extraction, i.e. extracting attack sequences and non-attack sequences from the constructed causal relationship graph; Lemma restoration, i.e. converting the extracted attack sequence and non-attack sequence into text sequences respectively based on natural language processing (NLP); Selective sampling includes: selecting an undersampling strategy for the non-attack sequence, that is, first calculating the Levenshtein distance between sequences, and then filtering the sequences by setting a threshold; selecting an oversampling strategy based on mutation for the attack sequence, that is, randomly mutating a certain word in the sequence into another word of the same type; The sequence data obtained by selective sampling is constructed as a training sample set.

[0015] Preferably, in S3, based on the physical layer topology and the overload condition of the physical layer bus node, an overload association graph is constructed, which specifically includes: Calculate the pre-overload set of all branches in the physical layer topology, where the pre-overload set is defined as: Overload, and check the overload of other branches in the physical layer topology network. If other branches are overloaded due to LR attack, it indicates that there is a problem in the branch. Before reaching its capacity, other branches are already overloaded and more vulnerable to LR attacks, marking these other branches as branches Pre-overload collection of; The model of the LR attack is: (1); (2); (3); In formulas (1)-(3): A vector representing error data added to the branch power measurement; represents the power transmission distribution coefficient of the power grid; represents the false data vector added to the bus node power measurement; Indicates the identification of the busbar node; Indicates the threshold coefficient of bus node load; Indicates the load of the bus node; Indicates the total number of busbar nodes; In order to overload each branch, the constraints set are: (4); In formula (4): represents the power flow on the branch; Indicates the maximum capacity of the branch; Definition represents the vulnerability relationship between two branches : (5); In formula (5): the symbol ‘→’ indicates that there is a vulnerability relationship between the two branches, that is, the overload of the latter is caused by the former; Indicates branch With branch The vulnerability relationship between the Included in branch Pre-overload collection of; Based on formula (5), the cascade mode of branch overload is obtained as follows: (6); In formula (6): The number of branches that have a transitive relationship, and the overload of the latter is caused by any of the former, that is, the branch The overload is caused by the branch { } caused by any branch in it; Based on the pre-overload set of all branches, and combined with the directed association and transitivity between branches, an overload association graph is constructed. ,in, is the vertex set representing each branch, is the edge set representing the relationship between branches; And, in S3, the vulnerability metric is defined as for: (7); (8); In formula (7)-(8): Represents a vertex set The number of vertices; and Represents a vertex set The and Vertices, Represents a vertex and vertices The distance between the vertices and vertices If there is a path between is 1, otherwise, is 0.

[0016] Preferably, in S4, all branches are classified into two categories based on the actual overload conditions of each branch, specifically including: For an initially normal branch, its power satisfies: (9); In formula (9): Indicates the load of the normal branch; After the branch is attacked, its forged branch power measurement value satisfy: (10); in ; The power flow actually allocated to the branch satisfy: (11); Based on the above conditions, it is judged whether the branch is actually overloaded, so as to classify all branches and use Represents a false overload set, using Represents the real overload set, namely: (12); (13); In formula (12)-(13): Indicates branch Initial normal load; Indicates adding to a branch Incorrect data from power measurements; Indicates branch The load threshold; Indicates branch The real load; Indicates branch The load threshold.

[0017] According to the preferred embodiment of the present invention, in S4, the frequency index is defined and destructive indicators They are: (14); (15); In formula (14)-(15): Indicates branch and branch roads Frequency index of Indicates branch and branch roads Destructive indicators; Represents a false overload set The number of branches in ; Represents the real overload set The number of branches in ; Indicates and The set of fake overloads associated with each overload dependency; Indicates and The set of real overloads associated with each overload dependency; Indicates the number of all overload dependencies; if there are two branches ∈ and ∈ ,but is 1, indicating that there is a two branches of an overload dependency, otherwise is 0.

[0018] Preferably, according to the present invention, S5 specifically includes: The geometric distance between the first evaluation result and the second evaluation result is used to represent the importance of the overload association, and a comprehensive index is defined. for: (16); Based on the ranking of the calculation results of formula (16), the suspicious branch sequence is determined; Based on the time points of known failures And the time point when the information layer attacks the physical layer , from the time node Start positioning forward a time node , so that , to determine the time frame of the APT attack.

[0019] In another aspect of the present invention, a device for implementing an APT source tracing method based on physical coupling of power grid information is provided, the device comprising: A training data acquisition module, for simulating APT behaviors in real scenarios, acquiring audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; A model building module, used to build a training sample set based on the causal relationship graph, and use the training sample set to train the LSTM model so that the LSTM model can acquire the ability to identify potential APT behaviors; A first evaluation module is used to construct an overload association diagram based on the physical layer topology and the overload condition of the physical layer bus node, and calculate the vulnerability of the path in the overload association diagram to perform vulnerability evaluation on each branch to obtain a first evaluation result; The second evaluation module is used to classify all branches based on the actual overload conditions of each branch, build an overload dependency library, and combine frequency indicators based on a data-driven approach. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and to narrow down the scope of suspicious logs according to the information-physical topology relationship and the time attribute, so as to obtain logs to be identified; The attack identification module is used to reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to distinguish the attack entity and restore the attack path.

[0020] In another aspect of the present invention, there is also provided an electronic device, comprising: at least one processor; and A memory storing instructions, which, when executed by the at least one processor, enables the at least one processor to execute the APT tracing method based on physical coupling of power grid information as described above.

[0021] In another aspect of the present invention, a machine-readable storage medium is provided, which stores executable instructions, and when the instructions are executed, the machine executes the APT tracing method based on physical coupling of power grid information as described above.

[0022] Compared with the prior art, the present invention has the following beneficial effects: (1) The sequence-based model of the present invention combines the semantic enhancement capabilities of NLP, can accurately reveal a variety of APT behaviors, and has a high ability to identify potential APT threats. Compared with existing traditional APT tracing methods, this model is better at dealing with massive data logs, reducing false positives, and can restore attack paths with higher accuracy.

[0023] (2) The model-data joint driven method used by the present invention in locating the physical layer attack source not only takes into account the characteristics of the physical device itself, but also analyzes the failure mechanism under special attack scenarios, combines the dependencies between failures, and uses multiple indicators as evaluation criteria, thereby significantly improving the accuracy of tracing the source of false data injection attacks. Compared with existing traditional attack location methods, this method can reduce deviations and improve overall generalization capabilities and prediction accuracy.

[0024] (3) The present invention fills the gap in the complete traceability strategy from physical device failure to APT network intrusion in CPPS. Existing methods often only consider the traceability method within a single layer or simple information-physical data fusion, while the present invention systematically combines the specific methods of the two layers to construct a complete bottom-up traceability mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a flow chart of the APT tracing method based on physical coupling of power grid information described in the present invention.

[0026] Figure 2 is the comprehensive evaluation index of each branch in Example 1 of the present invention . DETAILED DESCRIPTION

[0027] The present disclosure is further described below in conjunction with the accompanying drawings and embodiments.

[0028] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present disclosure belongs.

[0029] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, it indicates the presence of features, steps, operations, devices, components and / or combinations thereof.

[0030] In the absence of conflict, the embodiments in the present disclosure and the features in the embodiments may be combined with each other.

[0031] The existing technology is prone to false alarms when processing massive data at the network information layer, and has a low accuracy rate when processing complex faults at the physical layer. However, the present invention provides a complete information-physical cross-layer collaborative tracing process through an innovative model architecture and novel tracing strategies and methods, which can accurately restore the attack path and significantly improve the accuracy of attack tracing.

[0032] The method of the present invention comprises: firstly, obtaining original log data by simulating APT behavior, preprocessing the data by using the semantic enhancement capability of NLP (natural language processing), extracting attack and non-attack sequences, and inputting them into a sequence-based LSTM (long short-term memory network) model for training, so as to obtain a model with good recognition capability for potential APT behavior.

[0033] Secondly, the physical layer topology and the physical characteristics of the physical layer bus nodes are modeled, and an overload correlation diagram is constructed to evaluate the cascading impact of physical system vulnerabilities and security threats. Thirdly, a dependency library of fault correlation between branches is constructed, and a data-driven approach is used to evaluate the destructive impact of correlated faults in each branch. Then, the physical layer starting attack node is located based on the evaluation results, and then the suspicious log information of the information layer is determined based on the information-physical topology relationship and time attributes.

[0034] Finally, the trained LSTM model is used to infer suspicious log data, identify attack nodes, and restore the complete attack path.

[0035] The APT tracing method and device based on physical coupling of power grid information of the present invention are further described below in conjunction with specific embodiments.

[0036] Embodiment 1, Ginseng Figure 1 This embodiment provides an APT source tracing method based on physical coupling of power grid information, the method comprising: S1. Based on simulating APT behavior in a real scenario, audit log data including normal activity records are obtained, and the audit log data is reconstructed into a causal relationship graph.

[0037] At the network information layer, in order to accurately identify APT behavior, it is necessary to simulate and generate log data containing various attack behaviors.

[0038] Specifically, this embodiment can implement various attacks based on public information of real APT behaviors, including single-host attacks and multi-host attacks, and generate audit logs in a controlled test environment (i.e., multiple hosts that are ensured not to be threatened by other network attacks).

[0039] During each attack execution, the normal behavior data of the administrator is simulated on the same experimental platform as much as possible, including browsing different websites, executing different applications, such as SCADA data collection, attachment download and transmission, and connecting to other hosts. These attacks include different malware strategies, such as phishing links, email attachments, intermediate processes, and lateral movement between hosts, such as leaking sensitive data.

[0040] In addition, in order to accurately identify data related to multi-step attacks from massive audit logs and reduce false positives and time overhead, the acquired log data needs to be preprocessed to reconstruct it into a causal relationship graph.

[0041] Specifically, after obtaining the audit log data, a graph construction method is used to extract a directed cyclic causal relationship graph from the data. The causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions. The information nodes representing subjects and objects can be processes, files, IP addresses, domain names, etc.; the edges representing actions can be read, execute, etc., and the edges point from a subject to an object.

[0042] In order to improve the learning efficiency of subsequent models, this embodiment adopts three optimization methods to reduce the complexity of the causal relationship graph, including removing information nodes and edges that cannot be reached by attacking nodes, deleting duplicate edges, and merging similar events.

[0043] Based on the above, the massive audit log data can be abstracted and reconstructed into a low-complexity causal relationship graph.

[0044] S2. Construct a training sample set based on the causal relationship graph, and use the training sample set to train the LSTM model so that the LSTM model can acquire the ability to identify potential APT behaviors.

[0045] Most APTs usually adopt similar attack strategies as multi-step attacks, and a specific attack can be abstractly represented by a time-based sequence, while the semantics expressed by a text sequence with a timestamp can well reveal the key patterns of attack and non-attack. This embodiment combines the advantages of NLP (natural language processing) and LSTM (long short-term memory network), and the sequence-based model can efficiently identify data with potential threat behaviors.

[0046] Specifically, this step first constructs a training sample set for training the LSTM model based on the causal relationship graph. The construction process includes sequence extraction, word form restoration, and selective sampling of model training data.

[0047] The sequence extraction is to first extract the attack and non-attack sequences from the constructed causal relationship graph.

[0048] After constructing the optimized causal relationship graph, if the source node (i.e., the starting node of the causal relationship graph) or the target node (i.e., the ending node of the causal relationship graph) is an attack node, the attack sequence sorted by timestamp is extracted from the adjacency graph of the node to represent the attack event; for non-attack nodes, because their number is exponential compared to attack nodes, in order to accurately learn the boundary between the two, first determine the non-attack nodes adjacent to the attack nodes, and then extract the non-attack sequence sorted by timestamp from the adjacency graph of the node to represent the non-attack event.

[0049] The word form restoration is to convert the extracted attack and non-attack sequences into text sequences by using word form restoration.

[0050] In order to mine attack and non-attack behavior patterns, these two sequences are subjected to NLP-based lemmatization. First, a vocabulary is defined to divide the semantics into four different types: process, file, network, and operation. Each type contains multiple words, which are sufficient to capture the contextual semantics and grammatical similarity in the causal graph. Then, each sequence is parsed and mapped to the corresponding position in the vocabulary so that it contains the full semantics of the generalized sequence pattern, thereby converting the original sequence into a time-based text sequence.

[0051] The model training data is selectively sampled, that is, balanced sampling is performed on attacking and non-attacking text sequences respectively to obtain training samples.

[0052] In actual network systems, the number of attack nodes is usually much smaller than that of non-attack nodes, which results in an imbalance in the number of attack sequences and non-attack sequences constructed previously. Using such extremely unbalanced data for training will cause the model to be biased towards the majority (non-attack) class or unable to learn the minority (attack) class.

[0053] In order to balance the training data, an undersampling strategy is selected for non-attack sequences, that is, after calculating the Levenshtein distance between sequences, the sequences are filtered by setting a threshold; for attack sequences, a mutation-based oversampling strategy is selected, that is, a certain word in the sequence is randomly mutated to another word of the same type, which increases the number of similar sequences that are not triggered in the attack used for model training, thereby including more types of attack sequences in the training data.

[0054] Finally, the LSTM network is used to implement sequence-based model training, that is, the obtained training samples are input into the LSTM network for training so that it can acquire the ability to identify potential APT behaviors.

[0055] S3. Based on the physical layer topology and the overload conditions of the physical layer bus nodes, an overload association diagram is constructed, and the vulnerability of the paths in the overload association diagram is calculated to perform a vulnerability assessment on each branch to obtain a first assessment result.

[0056] At the physical layer, in the face of LR (load redistribution) attacks caused by APT intrusion at the information layer, the method of this embodiment first considers the physical characteristics of the physical equipment and the line itself, and constructs an overload association graph, i.e., a relational directed graph, based on the analysis of topological connections and the load capacity of each bus node. By calculating the vulnerability of the path in the association graph, the vulnerability of each branch is evaluated to determine the physical node most likely to be attacked.

[0057] The above-mentioned LR attack is a special FDIA (false data injection attack) whose purpose is to distort the results of safety-constrained economic dispatch by injecting false data into the bus node power and branch flow measurement, causing the system to enter a non-optimal or even unsafe operating state. It has assumptions and constraints that are more biased towards actual scenarios, that is, the generator output is not modified and the total load is kept unchanged to ensure the balance between power supply and demand, making traditional bad data detection (BDD) unable to effectively identify certain data anomalies.

[0058] The model of LR attack is as follows: (1); (2); (3); In formulas (1)-(3): A vector representing error data added to the branch power measurement; represents the power transmission distribution coefficient of the power grid; represents the false data vector added to the bus node power measurement; Indicates the identification of the busbar node; Indicates the threshold coefficient of bus node load; Indicates the load of the bus node; Indicates the total number of busbar nodes.

[0059] The above equations (2) and (3) represent the constraint relationship. Constraint (2) ensures that the injection into the busbar node The error measurement of the actual load measurement does not exceed the load upper limit; constraint (3) ensures that the sum of the dummy load measurements added to the actual load measurement of each bus node is equal to zero, so that the total system load remains unchanged after the dummy load data injection.

[0060] By investigating the vulnerability correlation between branches, the physical vulnerability characteristics of the entire physical layer topology network can be obtained, and the most vulnerable branch can be determined on this basis.

[0061] In order to ensure that each branch can be overloaded, the minimum attack cost is first determined to ensure that the following constraint (4) holds: (4); In formula (4): represents the power flow on the branch; Indicates the maximum capacity of the branch.

[0062] Secondly, make a branch If other branches are overloaded due to LR attacks, this indicates that the branch Before reaching its capacity, there are other branches that are overloaded and more vulnerable to LR attacks, so they are marked as branches. A pre-overload collection.

[0063] The vulnerability relationship between two branches is expressed as follows: : (5); In formula (5): the symbol ‘→’ indicates that there is a vulnerability relationship between the two branches, that is, the overload of the latter is caused by the former; Indicates branch With branch The vulnerability relationship between the Included in branch A pre-overload collection.

[0064] In addition, there is also transitivity between pre-overload sets, so that the cascade mode of branch overload is obtained, which can be expressed as: (6); In formula (6): The number of branches that have a transitive relationship, and the overload of the latter is caused by any of the former, that is, the branch The overload is caused by the branch { } caused by any branch in it.

[0065] After finding the pre-overload set of all branches, the overload association graph is constructed based on the directed association and transitivity between branches. ,in, is the vertex set representing each branch, It is the edge set that represents the relationship between branches.

[0066] After building the overload association graph After that, the vulnerability measure is calculated for each vertex in the graph as the starting vertex, and finally the ranking of vulnerable branches is obtained according to the calculation results.

[0067] Vulnerability Metrics It is expressed as follows: (7); (8); In formula (7)-(8): Represents a vertex set The number of vertices; and Represents a vertex set The and Vertices, Represents a vertex and vertices The distance between the vertices and vertices If there is a path between is 1, otherwise, is 0.

[0068] Based on the above vulnerability assessment calculation, a first assessment result is obtained, and the vulnerability ranking of the branches is determined according to the result.

[0069] S4. Based on the actual overload situation of each branch, all branches are classified into two categories, an overload dependency library is constructed, and a data-driven method is combined with frequency indicators. and destructive indicators The destructive impact of the overload association of each branch is evaluated to obtain a second evaluation result.

[0070] Due to the particularity of LR attacks, the presence of injected false data causes the control center to mistakenly believe that there is an unexpected situation in the system that requires rescheduling the SCED, which will cause the normal branches to be mistakenly considered to be overloaded (i.e., false overload). After the scheduling allocation is completed, the actual overloaded branches are not discovered (i.e., real overload), resulting in serious consequences.

[0071] To solve this problem, the method of this embodiment classifies all branches according to the above two types of branch overload characteristics, that is, whether they are truly overloaded, and generates an overload dependency library, and then uses a data-driven method to evaluate the potential fault correlation risks between physical devices.

[0072] First, classify the overloaded branches.

[0073] For an initially normal branch, its power satisfies: (9); In formula (9): Indicates the load of the normal branch.

[0074] Ensure forged branch power measurements after attack satisfy: (10); in .

[0075] After the decision correction and redistribution by the control center, the system believes that the overload problem has been solved, but there are some branches that are actually allocated power flows. Still satisfied: (11).

[0076] According to the above conditions, it is judged whether the branch is really overloaded, so as to classify all branches. Represents a false overload set, using Represents a real overload set. The definition can be described as follows: (12); (13); In formula (12)-(13): Indicates branch Initial normal load; Indicates adding to a branch Incorrect data for power measurements; Indicates branch The load threshold; Indicates branch The real load; Indicates branch The load threshold.

[0077] Then the overload dependencies between the two types of branches, false and real, are investigated.

[0078] Obviously, there is an overload dependency between the two types of branches, that is, false overload often leads to real overload. If there is such a dependency between two branches, then by using constraints (10) and (11), it is possible to solve the problem of satisfying both the fake measurement and the actual line. Overload condition.

[0079] By making The power of each branch in the set reaches the maximum, and the worst overload condition of each branch is solved in turn to investigate all overload dependencies, generate an overload dependency library, and reveal the overload mechanism of the system under LR attack.

[0080] Finally, failure-associated risks and disruptive impacts are evaluated.

[0081] That is, based on the constructed overload dependency library, using a data-driven approach and frequency indicators and destructive indicators Two indicators are used to identify key branches in the network. The definitions of the two indicators are as follows: (14); (15); In formula (14)-(15): Indicates branch and branch roads Frequency index of Indicates branch and branch roads Destructive indicators; Represents a false overload set The number of branches in ; Represents a real overload set The number of branches in ; Indicates and The set of fake overloads associated with each overload dependency; Indicates and The set of real overloads associated with each overload dependency; Indicates the number of all overload dependencies; if there are two branches ∈ and ∈ ,but is 1, indicating that there is a two branches of an overload dependency, otherwise is 0.

[0082] The above frequency index and destructive indicators The higher the values ​​of the two indicators, the greater the possibility and destructiveness of this overload association.

[0083] Based on the calculation of the destructive impact of the overload association of each branch, a second evaluation result is obtained. According to the actual fault, and with reference to the evaluation result, the key branch ranking based on the overload association is determined.

[0084] S5. Determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the scope of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified.

[0085] After the above two steps S3 and S4, the attack source tracing for physical characteristics and fault correlation of the physical layer is completed, that is, the initial location of the information layer network intrusion attacking the physical layer is found. This step S5 determines the suspicious log data containing potential APT behavior through the actual information-physical topology relationship and time-state range constraints.

[0086] First, combine the vulnerability measurement , frequency index and destructive indicators , perform comprehensive branch sorting on the physical layer tracing results.

[0087] Among them, the vulnerability metric Consider the physical characteristics of the physical layer itself; frequency-based indicators and destructive-based indicators Consider the possibility of overload-related failures and their destructiveness. However, experimental results show that overload associations with a greater probability of occurrence are often less destructive, while overload associations with a lower probability of occurrence are often more destructive. In order to balance the relationship between the two, the method in this embodiment chooses to use the geometric distance between the two to represent the importance of a certain overload association, so as to avoid a deviation in the final result caused by an excessively large indicator. Comprehensive indicators defined It is expressed as follows: (16).

[0088] Finally, the final branch sequence for physical layer attack tracing is obtained based on the ranking of the calculation results.

[0089] After obtaining the final branch sequence of physical layer attack tracing, data alignment based on time-topology is performed.

[0090] Assume that the time node when a known fault occurs in the physical layer is recorded as , the time point when the information layer attacks the physical layer is recorded as ,but Should be Before, that is , indicating that the time node of the information layer attacking the physical layer is much shorter than the time node of the known fault. According to the general latency time of general APT behavior, The time node starts to locate one time node forward ,make sure , indicating that the time node when the information layer attacks the physical layer is much longer than the time node of forward positioning, and much shorter than the time node of the known fault, thus determining the time range of the APT attack.

[0091] Then, based on the actual information - physical topology, we can find the single or multiple hosts that directly or indirectly send instructions to the physical layer during this time period. Finally, we determine the suspicious log data based on the host name and time tag, that is, the log to be identified.

[0092] S6. Reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify the attack entity and restore the attack path.

[0093] Based on the above steps, the trained LSTM model and the log data to be identified are obtained respectively.

[0094] Then, based on the method in S1, the log to be identified is first reconstructed into a target causal relationship graph, and then the target causal relationship graph is input into the trained LSTM model to identify potential attack sequences and infer the attack entity; then all nodes and paths associated with the attack node are found from the target causal relationship graph, the attack story is reconstructed, and finally the specific APT attack behavior is restored.

[0095] The following is a combination of specific examples and related experiments to verify the effectiveness of this method.

[0096] The example includes the following steps: S1. Log data acquisition and preprocessing: This method takes the power grid cyber-physical system as the application scenario. The information layer corresponds to the supervision layer composed of multiple PC terminals and databases in the industrial control system, and the physical layer corresponds to the field control and physical equipment layer.

[0097] Firstly, the normal activities of PC operators are simulated in a real environment, and potential APT attacks are carried out. The generated log data is preprocessed, that is, reconstructed into the form of a causal relationship graph, and three optimization methods are used to reduce the complexity. The three methods include removing nodes and edges that cannot be reached by the attacking node, deleting duplicate edges, and merging similar events.

[0098] S2. Construct sequence and lemma conversion: Extract attack and non-attack sequences from the constructed optimized relationship graph, define a vocabulary to divide semantics into four different types: process, file, network, and actions, which are used to lemmatize information nodes and edges, thereby converting the sequence into a text sequence based on timestamps. Then, undersample the attack sequence and oversample the non-attack sequence. Finally, input the training samples into the LSTM model for sequence-based training and learning.

[0099] S3. Vulnerability assessment for physical properties: The power of each branch is maximized, the pre-overload set of each branch is obtained, and then the overload association graph is constructed according to the transitivity between the sets. Then, the vulnerability measures of all paths of each vertex in the graph as the starting vertex are calculated in turn. Finally, the vulnerability ranking of each branch is obtained according to the calculation results.

[0100] S4. Risk assessment of fault correlation between branches: According to whether the branch is actually overloaded, each branch is classified into two categories to obtain a set of false overloaded branches. and the real overload branch set According to the dependency between the two sets, increase The load values ​​of the branches in the set are used to solve the worst case of overload association of each branch, and to build an overload dependency library, and then use data-driven methods and frequency indicators , destructive indicators These two evaluation indicators identify the critical branches in the network, and then determine the branch ranking based on overload association according to the actual faults.

[0101] S5. Determination of suspicious logs based on information-physical coupling: Combining three evaluation indicators of the physical layer, namely vulnerability measurement, frequency index , destructive indicators , using the comprehensive evaluation criteria to fuse the two branch sequences of the physical layer. Then, based on the time-topology constraint, the log range is narrowed. The time constraint of this embodiment is about two months, that is: .

[0102] S6. Model reasoning and restoration of attack paths: The two months of unidentified logs are reconstructed into a suspicious causal relationship graph using the S1 method, and then the sequence-based model trained by S2 is used to identify the potential attack sequence in the relationship graph, and the attack node is identified based on the identified attack sequence. Finally, the attack event is reconstructed by combining the nodes associated with the attack node, thereby restoring the specific and complete attack path.

[0103] experiment: The following are some basic settings for the experiment.

[0104] The simulation results are performed on the IEEE 39-node power grid model, and the simulation environment is set up using MATPOWER. This experiment uses log data generated in a controlled test environment, which includes normal activities of host users, and 6 APT attacks, including 3 single-host attacks (S1-S3) and 3 multi-host attacks (M1-M3). The average size of the log data generated containing one attack is "725.9KB". The experiment was conducted on a system equipped with an NVIDIA GeForce RTX 4060 graphics card.

[0105] In the experimental part, the model's APT identification performance in the network information layer and physical layer attack location were comprehensively evaluated. The experiment is mainly divided into three parts: model prediction accuracy evaluation, physical vulnerability evaluation, and overload correlation evaluation between branches.

[0106] In the model prediction accuracy evaluation part, the generated log data was used for training, and the inference prediction was performed on the logs containing 6 APT attacks. The model's recognition performance of attack nodes and attack events was evaluated respectively, and the evaluation indicators included Precision, Recall, and F1-score. The results are shown in Table 1: Table 1: Evaluation results of the model’s recognition performance on attack nodes and attack events

[0107] In the physical vulnerability assessment and overload correlation assessment between branches, Table 2 shows the top 5 results of the three evaluation indicators for each branch: Table 2: Physical vulnerability assessment results of each branch and overload correlation assessment results between branches

[0108] and Figure 2 A comparison chart of the comprehensive indicators of each branch is shown. The top five branches finally determined at the physical layer are ranked as 27, 26, 3, 7, and 25.

[0109] Embodiment 2, This embodiment provides a device for implementing an APT source tracing method based on physical coupling of power grid information, the device comprising: A training data acquisition module, for simulating APT behaviors in real scenarios, acquiring audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; A model building module, used to build a training sample set based on the causal relationship graph, and use the training sample set to train the LSTM model so that the LSTM model can acquire the ability to identify potential APT behaviors; A first evaluation module is used to construct an overload association diagram based on the physical layer topology and the overload condition of the physical layer bus node, and calculate the vulnerability of the path in the overload association diagram to perform vulnerability evaluation on each branch to obtain a first evaluation result; The second evaluation module is used to classify all branches based on the actual overload conditions of each branch, build an overload dependency library, and combine frequency indicators based on a data-driven approach. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and to narrow down the scope of suspicious logs according to the information-physical topology relationship and the time attribute, so as to obtain logs to be identified; The attack identification module is used to reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to distinguish the attack entity and restore the attack path.

[0110] Embodiment 3, This embodiment also provides an electronic device, including: At least one processor; and a memory, wherein the memory stores instructions, and when the instructions are executed by the at least one processor, the at least one processor executes the APT tracing method based on physical coupling of power grid information as described above.

[0111] In this embodiment, the electronic device may include, but is not limited to: personal computers, server computers, workstations, desktop computers, laptop computers, notebook computers, mobile computing devices, smart phones, tablet computers, cellular phones, personal digital assistants (PDAs), handheld devices, messaging devices, wearable computing devices, consumer electronic devices, and the like.

[0112] Embodiment 4, This embodiment also provides a machine-readable storage medium storing executable instructions, which, when executed, enable the machine to execute the APT tracing method based on physical coupling of power grid information as described above.

[0113] Specifically, a system or device equipped with a readable storage medium can be provided, on which software program codes that implement the functions of any of the above-mentioned embodiments are stored, and a computer or processor of the system or device can read and execute instructions stored in the readable storage medium.

[0114] In this case, the program code itself read from the machine-readable medium can realize the function of any one of the above embodiments, and thus the machine-readable code and the machine-readable storage medium storing the machine-readable code constitute part of this specification.

[0115] Examples of readable storage media include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD-RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code may be downloaded from a server computer or a cloud via a communication network.

[0116] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0117] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0118] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0119] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0120] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solution of the present invention, and are not intended to limit the specific implementation methods of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the claims of the present invention shall be included in the protection scope of the claims of the present invention.

Claims

1. An APT tracing method based on physical coupling of power grid information, characterized in that: The method comprises: S1. Based on simulating APT behavior in a real scenario, obtaining audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; S2. constructing a training sample set based on the causal relationship graph, and using the training sample set to train the LSTM model so that the LSTM model acquires the ability to identify potential APT behaviors; S3. Based on the physical layer topology and the overload condition of the physical layer bus node, construct an overload association graph, and calculate the vulnerability of the path in the overload association graph to perform a vulnerability assessment on each branch to obtain a first assessment result; S4. Based on the actual overload situation of each branch, all branches are classified into two categories, an overload dependency library is constructed, and a data-driven method is combined with frequency indicators. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; S5. Determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the scope of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified; S6. Reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify the attack entity and restore the attack path.

2. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S1, the audit log data is reconstructed into a causal relationship graph, specifically including: Extracting a directed cyclic causal relationship graph from the audit log data, wherein the causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions; Among them, the information nodes representing the subject and the object include processes, files, IP addresses, and domain names, the edges representing actions include read and execute, and the edge points from a subject to an object; Furthermore, the complexity of the causal relationship graph is reduced by three optimization methods: removing information nodes and edges that cannot be reached by the attacking node, deleting duplicate edges, and merging similar events.

3. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S2, constructing a training sample set based on the causal relationship graph specifically includes: Sequence extraction, i.e. extracting attack sequences and non-attack sequences from the constructed causal relationship graph; Lemma restoration, i.e. converting the extracted attack sequence and non-attack sequence into text sequences respectively based on natural language processing (NLP); Selective sampling includes: selecting an undersampling strategy for the non-attack sequence, that is, first calculating the Levenshtein distance between sequences, and then filtering the sequences by setting a threshold; selecting an oversampling strategy based on mutation for the attack sequence, that is, randomly mutating a certain word in the sequence into another word of the same type; The sequence data obtained by selective sampling is constructed as a training sample set.

4. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S3, based on the physical layer topology and the overload condition of the physical layer bus node, an overload association diagram is constructed, which specifically includes: Calculate the pre-overload set of all branches in the physical layer topology, where the pre-overload set is defined as: Overload, and check the overload of other branches in the physical layer topology network. If other branches are overloaded due to LR attack, it indicates that there is a problem in the branch. Before reaching its capacity, other branches are already overloaded and more vulnerable to LR attacks, marking these other branches as branches Pre-overload collection of; The model of the LR attack is: (1); (2); (3); In formulas (1)-(3): A vector representing error data added to the branch power measurement; represents the power transmission distribution coefficient of the power grid; represents the false data vector added to the bus node power measurement; Indicates the identification of the busbar node; Indicates the threshold coefficient of bus node load; Indicates the load of the bus node; Indicates the total number of busbar nodes; In order to overload each branch, the constraints set are: (4); In formula (4): represents the power flow on the branch; Indicates the maximum capacity of the branch; Definition represents the vulnerability relationship between two branches : (5); In formula (5): the symbol ‘→’ indicates that there is a vulnerability relationship between the two branches, that is, the overload of the latter is caused by the former; Indicates branch With branch The vulnerability relationship between the Included in branch Pre-overload collection of; Based on formula (5), the cascade mode of branch overload is obtained as follows: (6); In formula (6): The number of branches that have a transitive relationship, and the overload of the latter is caused by any of the former, that is, the branch The overload is caused by the branch { } caused by any branch in it; Based on the pre-overload set of all branches, and combined with the directed association and transitivity between branches, an overload association graph is constructed. ,in, is the vertex set representing each branch, is the edge set representing the relationship between branches; And, in S3, the vulnerability metric is defined for: (7); (8); In formula (7)-(8): Represents a vertex set The number of vertices; and Represents a vertex set The and Vertices, Represents a vertex and vertices The distance between the vertices and vertices If there is a path between is 1, otherwise, is 0.

5. The APT tracing method based on physical coupling of power grid information according to claim 4 is characterized in that: In S4, based on the actual overload conditions of each branch, all branches are classified into two categories, specifically including: For an initially normal branch, its power satisfies: (9); In formula (9): Indicates the load of the normal branch; After the branch is attacked, its forged branch power measurement value satisfy: (10); in ; The power flow actually allocated to the branch satisfy: (11); Based on the above conditions, it is judged whether the branch is actually overloaded, so as to classify all branches and use Represents a false overload set, using Represents the real overload set, namely: (12); (13); In formula (12)-(13): Indicates branch Initial normal load; Indicates adding to a branch Incorrect data for power measurements; Indicates branch The load threshold; Indicates branch The real load; Indicates branch The load threshold.

6. The APT tracing method based on physical coupling of power grid information according to claim 5 is characterized in that: In S4, the frequency index is defined and destructive indicators They are: (14); (15); In formula (14)-(15): Indicates branch and branch roads Frequency index of Indicates branch and branch roads Destructive indicators; Represents a false overload set The number of branches in ; Represents the real overload set The number of branches in ; Indicates and The set of fake overloads associated with each overload dependency; Indicates and The set of real overloads associated with each overload dependency; Indicates the number of all overload dependencies; if there are two branches ∈ and ∈ ,but is 1, indicating that there is a two branches of an overload dependency, otherwise is 0.

7. The APT tracing method based on grid information physical coupling according to claim 6 is characterized in that: The S5 specifically includes: The geometric distance between the first evaluation result and the second evaluation result is used to represent the importance of the overload association, and a comprehensive index is defined. for: (16); Based on the ranking of the calculation results of formula (16), the suspicious branch sequence is determined; Based on the time points of known failures And the time point when the information layer attacks the physical layer , from the time node Start positioning forward a time node , so that , to determine the time frame of the APT attack.

8. A device for implementing an APT tracing method based on physical coupling of power grid information, characterized in that: The device comprises: A training data acquisition module, for simulating APT behaviors in real scenarios, acquiring audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; A model building module, used to build a training sample set based on the causal relationship graph, and use the training sample set to train the LSTM model so that the LSTM model can acquire the ability to identify potential APT behaviors; A first evaluation module is used to construct an overload association diagram based on the physical layer topology and the overload condition of the physical layer bus node, and calculate the vulnerability of the path in the overload association diagram to perform vulnerability evaluation on each branch to obtain a first evaluation result; The second evaluation module is used to classify all branches based on the actual overload conditions of each branch, build an overload dependency library, and combine frequency indicators based on a data-driven approach. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and to narrow down the scope of suspicious logs according to the information-physical topology relationship and the time attribute, so as to obtain logs to be identified; The attack identification module is used to reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to distinguish the attack entity and restore the attack path.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and A memory storing instructions, which, when executed by the at least one processor, enables the at least one processor to execute the APT tracing method based on physical coupling of power grid information as described in any one of claims 1 to 7.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores executable instructions, and when the instructions are executed, the machine executes the APT tracing method based on physical coupling of power grid information as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • APT online detection method based on system log and deep learning

    CN116760604A

  • APT attack detection method based on threat intelligence and traffic characteristics

    CN116846631A

  • APT attack traceability analysis method based on bidirectional long and short time memory network

    CN115567306A

  • Network attack reconstruction method, model training method and related device

    CN116886379A

  • APT attack tracing method fusing sequence learning and causal analysis

    CN118898071A

Cited By

  • Traceability analysis method and device for APT attack detection, equipment and medium

    CN121508992A