APT Tracing Method and Device Based on Cyber-Physical Coupling of Power Grid

By adopting a method based on physical coupling of grid information in the smart grid, reconstructing the causal relationship diagram, building an LSTM model and evaluating the fragility of the physical layer, the problem of APT traceability difficulties in smart grids is solved, and high-accurate attack path restoration and traceability are achieved.

CN120030535BActive Publication Date: 2025-06-24QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510481176.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-06-24
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

When facing advanced persistent threats (APTs), smart grids lack effective cross-layer traceability methods, which leads to difficulties in attack identification, attack source location and attack path reconstruction.

Method used

APT traceability method based on physical coupling of power grid information is adopted, audit log data is obtained by simulating APT behavior, causal relationship diagram is reconstructed, and LSTM model is constructed to identify potential APT behavior. Combining the physical layer topology and overload situation, overload association diagram and dependency database are constructed, vulnerability and destructive impact are evaluated, and suspicious branch sequences and attack paths are finally determined.

Benefits of technology

It significantly improves the accuracy of attack tracing, can accurately recover attack paths, reduce false alarms, and enhances the identification and traceability of APT threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030535B_ABST
    Figure CN120030535B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of data security protection for smart grids, and particularly relates to an APT traceability method and device based on cyber-physical coupling of power grids. The method includes: acquiring audit log data and reconstructing it into a causal relationship graph, training an LSTM model based on the causal relationship graph by constructing a training sample set; constructing an overload association graph based on the physical layer topology and the overload conditions of physical layer bus nodes, and performing vulnerability assessment on each branch therein; performing binary classification on each branch based on its actual overload condition, constructing an overload dependency relationship library, and evaluating the destructive impact of each branch's overload association; determining a suspicious branch sequence based on the above two evaluation results, narrowing down the range of suspicious logs according to the information-physical topology relationship and time attributes to obtain the logs to be identified, reconstructing the logs to be identified into a target causal relationship graph, and using the trained LSTM model to identify it to identify the attack entity and restore the attack path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security protection for smart grids, and particularly relates to an APT (Advanced Persistent Threat) tracing method and device based on the cyber-physical coupling of power grids, which are particularly suitable for attack identification, attack source location, and attack path reconstruction in a smart grid environment. Background Art

[0002] With the continuous growth of power demand and the rapid development of information and communication technologies, smart grids, with their advanced management and control capabilities, have achieved a more stable and sustainable power supply. However, the high dependence of smart grids on cyberspace also brings severe security challenges, making them face threats of cyber attacks such as malicious data tampering.

[0003] At the power information system level, APT (Advanced Persistent Threat) usually adopts a long-term and multi-step attack strategy to gradually obtain host permissions, facilitating the attacker to launch FDIA (False Data Injection Attack) at the physical layer. By tampering with the state estimation results, FDIA can have a serious impact on the power physical system, leading to incorrect decisions and even system instability. At the physical system level, the propagation and evolution mechanism of security threats is extremely complex, and the nodes that ultimately exhibit faults are often not the nodes directly affected by the attack, making the tracing analysis more difficult. Therefore, there is an urgent need for a comprehensive tracing method for smart grids that can handle cross-layer attacks to enhance their security protection capabilities.

[0004] Traditional APT tracing methods in the network information layer mainly include methods based on log records, packet marking techniques, and actively sensed data. These methods rely on network attack models to achieve step-by-step backward tracing. However, they face many challenges in practical applications, such as the need to store and process massive amounts of data, and being easily affected by interruptions in intermediate links during the tracing process, resulting in a reduction in tracing reliability.

[0005] FDIA tracing methods are mainly divided into two categories: model-based methods and data-driven methods. Model-based methods rely on the accuracy and integrity of the power grid model and are easily restricted in the face of complex environments and dynamic changes, making it difficult to ensure the tracing effect. In contrast, data-driven methods use machine learning techniques to analyze a large amount of data to achieve more efficient attack location, improve tracing accuracy, and have stronger adaptability and robustness.

[0006] Chinese Patent Document CN116760604A discloses an APT online detection method based on system logs and deep learning, including: 1) preprocessing system logs and iteratively training a word vector model; 2) converting each group of log sequences into a vector data set through the trained word vector model; 3) constructing a Transformer model and iteratively training it using the vector data set; 4) obtaining a log index sequence and performing lag expansion; 5) building a BiLSTM model and iteratively training it using the expanded data set; 6) using the two trained models to perform online detection and prediction of APT attacks.

[0007] Chinese Patent Document CN116846631A discloses an APT attack detection method based on threat intelligence and traffic characteristics, including: A: obtaining an original attack sequence set and performing marking; B: obtaining an attack sequence set after data cleaning and the corresponding network traffic characteristic set; C: constructing a local threat intelligence library and obtaining the threat intelligence characteristics of each original traffic; D: constructing a sample message feature library and obtaining the message features of the sequence set; E: using the obtained network traffic characteristic set, threat intelligence characteristics and message features to train a multi-fusion detection model based on an LSTM recurrent neural network and obtaining the trained multi-fusion detection model; F: using the trained multi-fusion detection model to perform APT attack detection on unknown traffic sequences to determine whether there is an APT attack.

[0008] However, currently in the power system, there is still a lack of a tracing strategy that can integrate the methods of the network information layer and the physical layer, form a complete bottom-up tracing system, and realize the full-link tracing process from discovering physical faults to accurately locating network attackers. Summary of the Invention

[0009] The present invention aims to fill the gaps in the existing technology and provides an APT tracing method based on the cyber-physical coupling of the power grid, which can effectively analyze the sources and attack paths of potential security threats in the power system.

[0010] The present invention also discloses a device loaded with the APT tracing method based on the cyber-physical coupling of the power grid.

[0011] When the existing technology processes massive data in the network information layer, false alarms are likely to occur, and when dealing with complex faults in the physical layer, the accuracy rate is relatively low. The present invention provides a complete cross-layer collaborative tracing process of information-physics through an innovative model architecture and novel tracing strategies and methods, which can accurately restore the attack path and significantly improve the accuracy rate of attack tracing at the same time.

[0012] The detailed technical solution of the present invention is as follows:

[0013] An APT tracing method based on the cyber-physical coupling of the power grid, the method includes:

[0014] S1. Simulate APT behavior in a real scenario, obtain audit log data including normal activity records, and reconstruct the audit log data into a causal relationship graph;

[0015] S2. Construct a training sample set based on the causal relationship graph, and use the training sample set to train an LSTM model so that the LSTM model obtains the ability to identify potential APT behavior;

[0016] S3. Construct an overload association graph based on the physical layer topology and the overload situation of physical layer bus nodes, and calculate the vulnerability of the paths in the overload association graph to perform vulnerability assessment on each branch to obtain a first assessment result;

[0017] S4. Perform binary classification on all branches based on the actual overload situation of each branch, construct an overload dependency relationship library, and combine frequency metrics based on a data-driven method and destructive metrics to evaluate the destructive impact of the overload association of each branch to obtain a second assessment result;

[0018] S5. Determine a suspicious branch sequence based on the first assessment result and the second assessment result, and narrow the range of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified;

[0019] S6. Reconstruct the logs to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify the attack entity and restore the attack path.

[0020] Preferably according to the present invention, in S1, reconstructing the audit log data into a causal relationship graph specifically includes:

[0021] Extract a causal relationship graph with directed cycles from the audit log data, where the causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions;

[0022] Among them, the information nodes representing subjects and objects include processes, files, IP addresses, and domain names, and the edges representing actions include reading and executing, and the edges point from one subject to one object;

[0023] And reduce the complexity of the causal relationship graph through three optimization methods: removing information nodes and edges that cannot be reached by attack nodes, deleting duplicate edges, and merging similar events.

[0024] Preferably according to the present invention, in S2, constructing a training sample set based on the causal relationship graph specifically includes:

[0025] Sequence extraction, that is, extracting attack sequences and non-attack sequences from the constructed causal relationship graph;

[0026] Lemmatization, that is, based on natural language processing (NLP), converting the extracted attack sequences and non-attack sequences into text sequences respectively;

[0027] Selective sampling, including: selecting an undersampling strategy for the non-attack sequences, that is, first calculating the Levenshtein distance between sequences, and then filtering the sequences by setting a threshold; selecting a mutation-based oversampling strategy for the attack sequences, that is, randomly mutating a certain vocabulary in the sequence into another vocabulary of the same type;

[0028] Construct the sequence data obtained by selective sampling into a training sample set.

[0029] According to the preference of the present invention, in S3, based on the physical layer topology and the overload situation of the physical layer bus nodes, construct an overload association graph, specifically including:

[0030] Calculate the pre-overload set of all branches in the physical layer topology, and the pre-overload set is defined as: by setting constraint conditions to overload a certain branch and check the overload situation of other branches in the physical layer topology network. If there are other branches overloaded due to LR attacks, it indicates that there are other branches overloaded before the branch reaches its capacity and is more vulnerable to LR attacks. Mark these other branches as the pre-overload set of the branch ;

[0031] Among them, the model of the LR attack is:

[0032] (1);

[0033] (2);

[0034] (3);

[0035] In formulas (1)-(3): represents the vector of false data added to the branch power measurement; represents the power transfer distribution coefficient of the power grid; represents the false data vector added to the bus node power measurement; represents the identifier of the bus node; represents the threshold coefficient of the bus node load; represents the load of the bus node; represents the total number of bus nodes;

[0036] The constraint condition set to overload each branch is:

[0037] (4);

[0038] In formula (4): represents the power flow on the branch; represents the maximum capacity on the branch;

[0039] defines to represent the vulnerability relationship between two branches :

[0040] (5);

[0041] In formula (5): The symbol '→' indicates that there is a vulnerability relationship between two branches, that is, the overload of the latter is caused by the former; represents branch and branch the vulnerability relationship between them, and branch is included in the pre-overload set of branch ;

[0042] Based on formula (5), the cascading mode of branch overload is:

[0043] (6);

[0044] In formula (6): represents the number of branches with a transitive relationship, and the overload of the latter is caused by any of the former, that is, the overload of branch is caused by any branch in the set { };

[0045] Based on the pre-overload sets of all branches, combined with the directed association and transitivity between branches, an overload association graph is constructed , where is the vertex set representing each branch, is the edge set representing the relationship between branches;

[0046] Also, in the said S3, the vulnerability metric is defined as:

[0047] (7);

[0048] (8);

[0049] In formulas (7)-(8): represents the number of vertices in the vertex set ; and represent the in the vertex set th and the vertices, representing vertices and vertices the distance between; if there is a path between vertex and vertex , then is 1, otherwise, is 0.

[0050] Preferably according to the present invention, in S4, based on the true overload conditions of each branch, all branches are classified into two categories, specifically including:

[0051] For the initially normal branches, their power satisfies:

[0052] (9);

[0053] In formula (9): represents the load of the normal branch;

[0054] After the branch is attacked, its forged branch power measurement value satisfies:

[0055] (10);

[0056] where ;

[0057] The power flow actually allocated to the branch satisfies:

[0058] (11);

[0059] Based on the above conditions, it is judged whether the branch is truly overloaded to classify all branches, and is used to represent the false overload set, and is used to represent the true overload set, that is:

[0060] (12);

[0061] (13);

[0062] In formulas (12)-(13): represents the initial normal load of branch ; represents the error data added to the power measurement of branch ; represents the load threshold of branch ; represents the true load of branch ; represents branch The load threshold.

[0063] Preferably according to the present invention, in S4, the frequency index and the destructive index are respectively:

[0064] (14);

[0065] (15);

[0066] In formulas (14)-(15): represents the frequency index of branch and branch ; represents the destructive index of branch and branch ; represents the number of branches in the false overload set ; represents the number of branches in the true overload set ; represents the false overload set associated with the th overload dependency; represents the true overload set associated with the th overload dependency; represents the number of all overload dependencies; if there are two branches ∈ and ∈ , then is 1, indicating that there are two branches with the th overload dependency, otherwise is 0.

[0067] Preferably according to the present invention, S5 specifically includes:

[0068] Using the geometric distance between the first evaluation result and the second evaluation result to represent the importance degree of the overload association, defining the comprehensive index as:

[0069] (16);

[0070] Determining the suspicious branch sequence based on the ranking of the calculation result of the above formula (16);

[0071] Based on the time node of the known fault and the time node when the information layer attacks the physical layer , starting from the time node to locate a time node forward , such that , to determine the time range of the APT attack.

[0072] In another aspect of the present invention, there is provided an apparatus for implementing an APT traceability method based on the cyber-physical coupling of the power grid, the apparatus comprising:

[0073] A training data acquisition module, configured to obtain audit log data including normal activity records based on simulating APT behavior in a real scenario, and reconstruct the audit log data into a causal relationship graph;

[0074] A model construction module, configured to construct a training sample set based on the causal relationship graph, and use the training sample set to train an LSTM model, so that the LSTM model obtains the ability to identify potential APT behavior;

[0075] A first evaluation module, configured to construct an overload association graph based on the physical layer topology and the overload condition of the physical layer bus nodes, and calculate the vulnerability of the paths in the overload association graph to perform a vulnerability evaluation on each branch to obtain a first evaluation result;

[0076] A second evaluation module, configured to perform binary classification on all branches based on the actual overload condition of each branch, construct an overload dependency library, and combine frequency metrics based on a data-driven method and a destructive index to evaluate the destructive impact of the overload association of each branch to obtain a second evaluation result;

[0077] A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the range of suspicious logs according to the cyber-physical topology relationship and time attributes to obtain logs to be identified;

[0078] An attack recognition module, configured to reconstruct the logs to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify attack entities and restore the attack path.

[0079] In another aspect of the present invention, there is also provided an electronic device, comprising:

[0080] At least one processor; and

[0081] A memory, the memory stores instructions, when the instructions are executed by the at least one processor, the at least one processor executes the APT traceability method based on the cyber-physical coupling of the power grid as described above.

[0082] In another aspect of the present invention, there is also provided a machine-readable storage medium storing executable instructions, which when executed cause the machine to perform the APT traceability method based on the cyber-physical coupling of the power grid as described above.

[0083] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0084] (1) The sequence-based model of the present invention combines the semantic enhancement ability of NLP, can accurately reveal various APT behaviors, and has a high recognition ability for potential APT threats. Compared with the existing traditional APT traceability methods, this model is better at dealing with massive data logs, reducing false alarms, and can restore the attack path with a high degree of accuracy.

[0085] (2) The model-data joint-driven method applied by the present invention in physical layer attack source location not only considers the characteristics of physical devices themselves, but also combines the dependency relationships between faults and various indicators as evaluation criteria by analyzing the fault mechanisms in special attack scenarios, thereby significantly improving the traceability accuracy of false data injection attacks. Compared with the existing traditional attack location methods, this method can reduce deviations and improve the overall generalization ability and prediction accuracy.

[0086] (3) The present invention fills the gap in the complete traceability strategy from physical device failures to APT network intrusions in CPPS. Existing methods often only consider traceability methods within a single layer or simple cyber-physical data fusion, while the present invention systematically combines the specific methods of the two layers to construct a complete bottom-up traceability mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0087] Figure 1 is a flowchart of the APT traceability method based on the cyber-physical coupling of the power grid according to the present invention.

[0088] Figure 2 is a comparison chart of the comprehensive evaluation indexes of each branch in Embodiment 1 of the present invention of. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0089] The present disclosure will be further described below in conjunction with the drawings and embodiments.

[0090] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.

[0091] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they specify the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0092] In the case of no conflict, the embodiments in the present disclosure and the features in the embodiments may be combined with each other.

[0093] In the prior art, false alarms are likely to occur when processing massive data at the network information layer, and when dealing with complex faults at the physical layer, there is a problem of low accuracy. The present invention provides a complete information - physical cross - layer collaborative traceability process through an innovative model architecture and novel traceability strategies and methods, which can accurately restore the attack path and significantly improve the accuracy of attack traceability.

[0094] The method of the present invention includes: First, obtain the original log data by simulating APT behavior, pre - process the data using the semantic enhancement ability of NLP (Natural Language Processing), extract attack and non - attack sequences, and input them into a sequence - based LSTM (Long Short - Term Memory) model for training to obtain a model with good recognition ability for potential APT behavior.

[0095] Secondly, model the physical layer topology and the physical characteristics of the physical layer bus nodes, construct an overload correlation graph to evaluate the cascading impact of physical system vulnerabilities and security threats. Thirdly, construct a dependency library for the fault correlation between branches, and use a data - driven method to evaluate the destructive impact of associated faults occurring in each branch. Then, locate the starting attack node at the physical layer based on the evaluation results, and then determine the suspicious log information at the information layer according to the information - physical topology relationship and time attributes.

[0096] Finally, use the trained LSTM model to infer the suspicious log data, identify the attack nodes, and restore the complete attack path.

[0097] The following further describes the APT traceability method and device based on the power grid information - physical coupling of the present invention in combination with specific embodiments.

[0098] Embodiment 1

[0099] Refer Figure 1 , this embodiment provides an APT traceability method based on the power grid information - physical coupling, and the method includes:

[0100] S1. Based on simulating APT behavior in a real scenario, obtain audit log data including normal activity records, and reconstruct the audit log data into a causal relationship graph.

[0101] In the network information layer, in order to accurately identify APT behavior, it is necessary to simulate and generate log data containing various attack behaviors.

[0102] Specifically, in this embodiment, various attacks can be implemented according to the public information of real APT behavior, including single-host attacks and multi-host attacks, and audit logs are generated in a controlled test environment (i.e., multiple hosts ensuring no threat from other network attacks).

[0103] During each attack execution, as much as possible, various normal behavior data of administrators are simulated and generated on the same experimental platform, including browsing different websites, executing different applications, such as SCADA data collection, attachment download and transmission programs, and connecting to other hosts, etc. These implemented attacks include different malware strategies, such as phishing links, email attachments, intermediate processes, and lateral movement between hosts, such as leaking sensitive data.

[0104] In addition, in order to accurately identify data related to multi-step attacks from a large amount of audit logs, and reduce false positives and time overhead, it is necessary to preprocess the obtained log data to reconstruct it into a causal relationship graph.

[0105] Specifically, after obtaining the audit log data, a graph construction method is used to extract a directed cyclic causal relationship graph from the data. The causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions. Among them, the information nodes representing subjects and objects can be processes, files, IP addresses, domain names, etc.; the edges representing actions can be read, execute, etc., and the edges point from one subject to one object.

[0106] In order to improve the learning efficiency of the subsequent model, this embodiment adopts three optimization methods to reduce the complexity of the causal relationship graph, including removing information nodes and edges that cannot be reached by attack nodes, deleting duplicate edges, and merging similar events.

[0107] Based on the above, the abstraction and reconstruction of a large amount of audit log data into a form of a causal relationship graph with low complexity are realized.

[0108] S2. Based on the causal relationship graph, construct a training sample set, and use the training sample set to train the LSTM model so that the LSTM model obtains the ability to identify potential APT behavior.

[0109] Most APTs, as multi-step attacks, usually adopt similar attack strategies, and a specific attack can be abstractly represented by a time-based sequence. The semantics expressed by the timestamped text sequence can well reveal the key patterns of attacks and non-attacks. This embodiment combines the advantages of NLP (Natural Language Processing) and LSTM (Long Short-Term Memory Network). The sequence-based model can efficiently identify data with potentially threatening behaviors.

[0110] Specifically, this step first constructs a training sample set for training the LSTM model based on the causal relationship graph. The construction process includes sequence extraction, lemmatization, and selective sampling of model training data.

[0111] The so-called sequence extraction means first extracting attack and non-attack sequences from the constructed causal relationship graph.

[0112] After constructing the optimized causal relationship graph, if the source node (i.e., the starting node of the causal relationship graph) or the target node (i.e., the ending node of the causal relationship graph) is an attack node, then extract the attack sequence sorted by timestamp from the adjacent graph of this node to represent the attack event; for non-attack nodes, because compared with attack nodes, their quantity is exponential, so in order to accurately learn the boundary between the two, first determine the non-attack nodes adjacent to the attack nodes, and then extract the non-attack sequence sorted by timestamp from the adjacent graph of this node to represent the non-attack event.

[0113] The so-called lemmatization means using lemmatization to convert the extracted attack and non-attack sequences into text sequences.

[0114] To mine the attack and non-attack behavior patterns, perform lemmatization based on NLP on these two sequences. First, define the vocabulary, divide the semantics into four different types: process, file, network, and operation. Each type contains multiple words, and these word types are sufficient to capture the context semantics and syntactic similarities in the causal relationship graph. Then parse each sequence and map them to the corresponding positions in the vocabulary to make them contain all the semantics of the generalized sequence pattern, thereby converting the original sequence into a time-based text sequence.

[0115] The so-called selective sampling of model training data means performing balanced sampling on the attack and non-attack text sequences respectively to obtain training samples.

[0116] In an actual network system, the information nodes representing attacks are usually much smaller than non-attack nodes, which will result in unequal numbers of the previously constructed attack sequences and non-attack sequences. Using this extremely unbalanced data for training will make the model biased towards the majority (non-attack) class or unable to learn the minority (attack) class.

[0117] To balance the training data, an undersampling strategy is selected for non - attack sequences, that is, after calculating the Levenshtein distance between sequences, the sequences are filtered by setting a threshold; for attack sequences, an oversampling strategy based on mutation is selected, that is, a certain word in the sequence is randomly mutated into another word of the same type, which increases the number of similar sequences that are not triggered in the attacks used for model training, so that more types of attack sequences are included in the training data.

[0118] Finally, an LSTM network is used to implement sequence - based model training, that is, the obtained training samples are input into the LSTM network for training to enable it to acquire the ability to recognize potential APT behaviors.

[0119] S3. Based on the physical layer topology and the overload situation of physical layer bus nodes, an overload association graph is constructed, and the vulnerability of the paths in the overload association graph is calculated to evaluate the vulnerability of each branch, obtaining the first evaluation result.

[0120] At the physical layer, in the face of LR (Load Redistribution) attacks caused by APT intrusions in the information layer, the method of this embodiment first considers the physical characteristics of physical devices and lines themselves. According to the analysis of topological connections and the load - bearing capacity of each bus node, an overload association graph, that is, a relational directed graph, is constructed. By calculating the vulnerability of the paths in the association graph, the vulnerability of each branch is evaluated, thereby determining the physical nodes most likely to be attacked.

[0121] The above - mentioned LR attack, as a special type of FDIA (False Data Injection Attack), aims to distort the results of security - constrained economic dispatch by injecting false data into the power measurements of bus nodes and branch power flows, causing the system to enter a non - optimal or even unsafe operating state. It has more practical - scenario - oriented assumptions and constraints, that is, it does not modify the generator output and keeps the total load unchanged to ensure the balance between power supply and demand, making traditional Bad Data Detection (BDD) unable to effectively identify certain data anomalies.

[0122] The model of the LR attack is as follows:

[0123] (1);

[0124] (2);

[0125] (3);

[0126] In formulas (1)-(3): represents the vector of error data added to the branch power measurement; represents the power transfer distribution factor of the power grid; represents the vector of false data added to the bus node power measurement; The identifier indicating the bus node; The threshold coefficient indicating the load of the bus node; The load indicating the bus node; The total number indicating the bus nodes.

[0127] The above equations (2) and (3) represent the constraint relationships. Constraint (2) ensures that the error measurement of the actual load measurement injected into the bus node does not exceed the load upper limit; Constraint (3) ensures that the sum of the false load measurements added to the actual load measurement of each bus node is equal to zero, so that the total system load remains unchanged after the false load data injection.

[0128] By investigating the vulnerability correlation between branches, the overall physical vulnerability characteristics of the physical layer topology network can be obtained, and on this basis, the most vulnerable branches can be determined.

[0129] To ensure that each branch can be overloaded, first determine the minimum attack cost to ensure that the following constraint (4) holds:

[0130] (4);

[0131] In equation (4): represents the power flow on the branch; represents the maximum capacity on the branch.

[0132] Secondly, overload a certain branch and check the overload conditions of other branches in the network. If other branches are overloaded due to the LR attack, it means that before the branch reaches its capacity, other branches have been overloaded and are more vulnerable to the LR attack. Therefore, mark them as the pre-overload set of the branch .

[0133] The vulnerability relationship between two branches is represented by the following definition :

[0134] (5);

[0135] In equation (5): The symbol '→' indicates that there is a vulnerability relationship between two branches, that is, the overload of the latter is caused by the former; represents the branch and the branch the vulnerability relationship between them, and the branch is included in the pre-overload set of the branch .

[0136] In addition, there is also transitivity between the pre-overload sets, so as to obtain the cascading mode of branch overload, which can be expressed as:

[0137] (6);

[0138] In formula (6): represents the number of branches with a transitive relationship, and the overload of the latter is caused by any of the former, that is, the overload of branch is caused by any branch in the branch set { }.

[0139] After obtaining the pre-overload sets of all branches, an overload association graph is constructed according to the directed association and transitivity between branches , where is the vertex set representing each branch, is the edge set representing the relationship between branches.

[0140] After constructing the overload association graph , the vulnerability metric is calculated for the paths starting from each vertex in the graph in turn, and finally the vulnerability branch ranking is obtained according to the calculation results.

[0141] Vulnerability metric is expressed by the following formula:

[0142] (7);

[0143] (8);

[0144] In formulas (7)-(8): represents the number of vertices in the vertex set ; and represent the -th and -th vertices in the vertex set , represents the distance between vertex and vertex ; if there is a path between vertex and vertex , then is 1, otherwise is 0.

[0145] Based on the above vulnerability assessment calculation, a first assessment result is obtained, and the vulnerability ranking of the branches is determined according to this result.

[0146] S4. Based on the actual overload situation of each branch, all branches are classified into two categories, an overload dependence relationship library is constructed, and the destructive impact of the overload association of each branch is evaluated based on a data-driven method combined with a frequency index and a destructive index to obtain a second assessment result.

[0147] Due to the special nature of the LR attack, there is false data injected, causing the control center to mistakenly believe that there is an unexpected situation in the system that requires re-scheduling SCED. As a result, normal branches are mistakenly considered overloaded (i.e., false overload), and after the scheduling assignment is completed, the actually overloaded branches are not discovered (i.e., true overload), thus causing serious consequences.

[0148] To solve this problem, the method of this embodiment classifies all branches according to the above two types of branch overload characteristics, i.e., whether it is truly overloaded, and generates an overload dependency library, and then uses a data-driven method to evaluate the potential fault association risk between physical devices.

[0149] First, classify the overloaded branches.

[0150] For branches that are initially normal, their power satisfies:

[0151] (9);

[0152] In formula (9): represents the load of a normal branch.

[0153] After being attacked, ensure that the forged branch power measurement value satisfies:

[0154] (10);

[0155] Where .

[0156] After the decision correction and reallocation by the control center, the system believes that the discovered overload problem has been solved, but there are some branches where the actually allocated power flow still satisfies:

[0157] (11).

[0158] Judge whether the branch is truly overloaded according to the above conditions to classify all branches, use to represent the set of false overloads, and use to represent the set of true overloads. The definition can be described in the following form:

[0159] (12);

[0160] (13);

[0161] In formulas (12)-(13): represents the initial normal load of branch ; Indicates addition to a branch Erroneous data for power measurement; Indicates a branch Load threshold of; Indicates a branch True load of; Indicates a branch Load threshold of.

[0162] Then investigate the overload dependence relationship between the two types of false and true branches.

[0163] Obviously, there is an overload dependence relationship between the two types of branches, that is, false overload often leads to true overload. If there is such a dependence between two branches, then through constraints (10) and (11), the conditions that satisfy both forged measurement and actual line

[0164] Overload can be solved.

[0165] By making The power of each branch in the set reaches the maximum, and the worst overload conditions of each branch are solved in turn to investigate all overload dependence relationships, generate an overload dependence relationship library, and reveal the overload mechanism of the system under LR attack.

[0166] Finally, evaluate the fault correlation risk and destructive impact.

[0167] That is, based on the constructed overload dependence relationship library, use data-driven methods and frequency metrics And destructive metrics Two metrics to identify key branches in the network. The definitions of the two metrics are as follows:

[0168] (14);

[0169] (15);

[0170] In equations (14)-(15): Indicates a branch And branch Frequency metric of; Indicates a branch And branch Destructive metric of; Indicates the set of false overloads Number of branches in; Indicates the set of true overloads Number of branches in; Indicates the set of false overloads associated with the th overload dependence; Indicates the A set of true overloads associated with overload dependencies; Represents the number of all overload dependencies; if there are two branches ∈ and ∈ , then is 1, indicating that there are two branches with the th overload dependency, otherwise is 0.

[0171] The above frequency index and the destructive index The higher the values of these two indices, the greater the likelihood and destructiveness of this overload association.

[0172] Based on the calculation of the destructive impact of the above overload associations for each branch, a second evaluation result is obtained. According to the actual faults that occur and referring to the evaluation results, the critical branch ranking based on overload associations is determined.

[0173] S5. Determine the suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the range of suspicious logs according to the information - physical topology relationship and time attributes to obtain the logs to be identified.

[0174] After the above two steps S3 and S4, the attack tracing for the physical layer regarding physical characteristics and fault correlation is completed, that is, the initial position of the information - layer network intrusion on the physical layer is found. This step S5 determines the suspicious log data containing potential APT behavior through the actual information - physical topology relationship and time - state range constraints.

[0175] First, combine the vulnerability metric , the frequency index and the destructive index to perform a comprehensive branch ranking on the physical layer tracing results.

[0176] Among them, the vulnerability metric considers the physical characteristics of the physical layer itself; while the frequency - based index and the destructiveness - based index consider the likelihood and destructiveness of the occurrence of overload - related faults. However, through experimental results, it is found that the more likely an overload association occurs, the smaller its destructiveness tends to be, and the less likely an overload association occurs, the greater its destructiveness tends to be. To balance the relationship between the two, the method of this embodiment selects the geometric distance between the two to represent the importance of an overload association, avoiding deviation in the final result caused by an overly large value of a certain index. The defined comprehensive index is represented by the following formula:

[0177] (16).

[0178] Finally, rank according to the calculation results to obtain the final branch sequence for physical layer attack traceability.

[0179] After obtaining the final branch sequence for physical layer attack traceability, perform time-topology based data alignment.

[0180] Assume that the time node when a known fault occurs in the physical layer is denoted as , and the time node when the information layer attacks the physical layer is denoted as , then should be before , that is , indicating that the time node when the information layer attacks the physical layer is much smaller than the time node of the known fault. According to the approximate latency time of general APT behavior, locate a time node forward from the time node to ensure , indicating that the time node when the information layer attacks the physical layer is much larger than the forward located time node and much smaller than the time node of the known fault, thereby determining the time range of the APT attack.

[0181] Then, according to the actual information-physical topology, one or more hosts that directly or indirectly send instructions to the physical layer during this time period can be found. Finally, determine the suspicious log data based on the host name and time tag, which is used as the log to be recognized.

[0182] S6. Reconstruct the log to be recognized into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to discriminate the attack entity and restore the attack path.

[0183] Based on the above steps, a trained LSTM model and log data to be recognized are obtained respectively.

[0184] Then, first reconstruct the log to be recognized into a target causal relationship graph based on the method in S1, and then input the target causal relationship graph into the trained LSTM model to identify the potential attack sequence, infer the attack entity; then find all the nodes and paths associated with the attack node from the target causal relationship graph, reconstruct the attack story, and finally restore the specific APT attack behavior.

[0185] The effectiveness of the proposed method is verified by the following specific examples and related experiments.

[0186] Examples include the following steps:

[0187] S1. Log data acquisition and preprocessing:

[0188] This method takes the cyber - physical system of the power grid as the application scenario. The information layer corresponds to the supervision layer composed of multiple PC terminals and databases in the industrial control system, and the physical layer corresponds to the field control and physical equipment layer.

[0189] First, simulate the normal activities of PC - terminal operators in the real environment and implement potential APT attacks. Pre - process the generated log data, that is, reconstruct it into the form of a causal relationship graph, and use three optimization methods to reduce the complexity. These three methods include removing the nodes and edges that cannot be reached by the attack nodes, deleting duplicate edges, and merging similar events.

[0190] S2. Construction of sequences and lemmatization transformation:

[0191] Extract attack and non - attack sequences from the constructed optimized relationship graph. Define a vocabulary to divide the semantics into four different types: process (process), file (file), network (network), and actions (operations) for lemmatizing information nodes and edges, so as to transform the sequences into text sequences based on timestamps. Then, undersample the attack sequences and oversample the non - attack sequences. Finally, input the training samples into the LSTM model for sequence - based training and learning.

[0192] S3. Vulnerability assessment for physical characteristics:

[0193] Maximize the power of each branch, obtain the pre - overload set of each branch, and then construct an overload association graph according to the transitivity between sets. Then, calculate the vulnerability measure of all paths starting from each vertex in the graph in turn. Finally, obtain the vulnerability ranking of each branch according to the calculation results.

[0194] S4. Risk assessment for fault correlation between branches:

[0195] Perform binary classification on each branch according to whether the branch is truly overloaded to obtain the set of falsely overloaded branches and the set of truly overloaded branches . According to the dependence relationship between the two sets, increase the load value of the branches in the set to solve the worst - case scenario of overload correlation between branches, and construct an overload dependence relationship library. Then, use data - driven methods and frequency metrics , destructive metrics these two evaluation metrics to identify the key branches in the network, and then determine the branch ranking based on overload association according to the actual faults.

[0196] S5. Determination of suspicious logs based on information - physical coupling:

[0197] Combine three evaluation metrics in the physical layer, namely vulnerability measure, frequency metric , Destructive indicators , fuse the two branch sequences in the physical layer with the comprehensive evaluation criteria. Then, according to the time-topology constraints, narrow down the log scope. The time constraint in this embodiment is about two months, that is: .

[0198] S6. Model inference and restoration of the attack path:

[0199] Reconstruct the logs to be identified in two months into a suspicious causal relationship graph using the method of S1, and then use the sequence-based model trained by S2 to identify the potential attack sequences in the relationship graph, and judge the attack nodes according to the identified attack sequences. Finally, combine the nodes associated with the attack nodes to reconstruct the attack events, so as to restore the specific and complete attack path.

[0200] Experiment:

[0201] The following are some basic settings for the experiment.

[0202] The simulation results were executed on the IEEE 39-bus power grid model, and the simulation environment was set using MATPOWER. The log data used in this experiment was generated in a controlled test environment, which included the normal activities of host users and 6 APT attacks, including 3 single-host attacks (S1-S3) and 3 multi-host attacks (M1-M3). The average size of the log data containing one attack was "725.9KB". The experiment was conducted on a system equipped with an NVIDIA GeForce RTX 4060 graphics card.

[0203] In the experimental part, the APT recognition performance of the model in the network information layer and the physical layer attack positioning were comprehensively evaluated. The experiment was mainly divided into three parts: model prediction accuracy evaluation, physical vulnerability evaluation, and branch overload correlation evaluation.

[0204] In the model prediction accuracy evaluation part, the generated log data was used for training, and the logs containing 6 APT attacks were respectively used for inference prediction. And the recognition performance of the model for attack nodes and the recognition performance for attack events were respectively evaluated, and the evaluation indicators included Precision, Recall, and F1-score. The results are shown in Table 1:

[0205] Table 1: Evaluation results of the model's recognition performance for attack nodes and attack events

[0206]

[0207] In the physical vulnerability evaluation and branch overload correlation evaluation parts, Table 2 shows the top 5 results of the three evaluation indicators for each branch:

[0208] Table 2: Physical vulnerability assessment of each branch and assessment results of overload correlation between branches

[0209]

[0210] And Figure 2 It shows a comparison chart of comprehensive indexes of each branch. The top 5 branches finally determined at the physical layer are ranked as 27, 26, 3, 7, and 25.

[0211] Example 2

[0212] This embodiment provides a device for implementing an APT traceability method based on cyber-physical coupling of a power grid. The device includes:

[0213] A training data acquisition module, configured to obtain audit log data including normal activity records based on simulating APT behavior in a real scenario, and reconstruct the audit log data into a causal relationship graph;

[0214] A model construction module, configured to construct a training sample set based on the causal relationship graph, and use the training sample set to train an LSTM model, so that the LSTM model obtains the ability to identify potential APT behavior;

[0215] A first evaluation module, configured to construct an overload correlation graph based on the physical layer topology and the overload conditions of physical layer bus nodes, and calculate the vulnerability of paths in the overload correlation graph to perform vulnerability assessment on each branch and obtain a first evaluation result;

[0216] A second evaluation module, configured to perform binary classification on all branches based on the actual overload conditions of each branch, construct an overload dependency library, and combine frequency metrics based on a data-driven method and destructive metrics to evaluate the destructive impact of overload correlation of each branch and obtain a second evaluation result;

[0217] A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the range of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified;

[0218] An attack identification module, configured to reconstruct the logs to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify attack entities and restore the attack path.

[0219] Example 3

[0220] This embodiment further provides an electronic device, including:

[0221] At least one processor; and a memory that stores instructions which, when executed by the at least one processor, cause the at least one processor to perform the APT tracing method based on cyber-physical coupling of the power grid as described above.

[0222] In this embodiment, the electronic device may include but is not limited to: personal computers, server computers, workstations, desktop computers, laptop computers, notebook computers, mobile computing devices, smart phones, tablet computers, cellular phones, personal digital assistants (PDAs), handheld devices, messaging devices, wearable computing devices, consumer electronic devices, and so on.

[0223] Embodiment 4

[0224] This embodiment also provides a machine-readable storage medium storing executable instructions which, when executed, cause the machine to perform the APT tracing method based on cyber-physical coupling of the power grid as described above.

[0225] Specifically, a system or device equipped with a readable storage medium may be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer or processor of the system or device reads and executes the instructions stored in the readable storage medium.

[0226] In this case, the program code read from the readable medium itself can implement the functions of any one of the above embodiments, so the machine-readable code and the readable storage medium storing the machine-readable code constitute a part of this specification.

[0227] Examples of readable storage media include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD-RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code may be downloaded from a server computer or a cloud via a communication network.

[0228] Those skilled in the art should understand that the embodiments of the present invention may be provided as a method, a system, or a computer program product. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0229] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0230] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0231] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0232] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the claims of the present invention shall be included in the protection scope of the claims of the present invention.

Claims

1. An APT tracing method based on physical coupling of power grid information, characterized in that: The method comprises: S1. Based on simulating APT behavior in a real scenario, obtaining audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; S2. constructing a training sample set based on the causal relationship graph, and using the training sample set to train the LSTM model so that the LSTM model acquires the ability to identify potential APT behaviors; S3. Based on the physical layer topology and the overload condition of the physical layer bus node, construct an overload association graph, and calculate the vulnerability of the path in the overload association graph to perform a vulnerability assessment on each branch to obtain a first assessment result; S4. Based on the actual overload situation of each branch, all branches are classified into two categories, an overload dependency library is constructed, and a data-driven method is combined with frequency indicators. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; S5. Determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and narrow the scope of suspicious logs according to the information-physical topology relationship and time attributes to obtain logs to be identified; S6. Reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to identify the attack entity and restore the attack path.

2. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S1, the audit log data is reconstructed into a causal relationship graph, specifically including: Extracting a directed cyclic causal relationship graph from the audit log data, wherein the causal relationship graph is composed of information nodes representing subjects and objects and edges representing actions; Among them, the information nodes representing the subject and the object include processes, files, IP addresses, and domain names, the edges representing actions include read and execute, and the edge points from a subject to an object; Furthermore, the complexity of the causal relationship graph is reduced by three optimization methods: removing information nodes and edges that cannot be reached by the attacking node, deleting duplicate edges, and merging similar events.

3. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S2, constructing a training sample set based on the causal relationship graph specifically includes: Sequence extraction, i.e. extracting attack sequences and non-attack sequences from the constructed causal relationship graph; Lemma restoration, i.e. converting the extracted attack sequence and non-attack sequence into text sequences respectively based on natural language processing (NLP); Selective sampling includes: selecting an undersampling strategy for the non-attack sequence, that is, first calculating the Levenshtein distance between sequences, and then filtering the sequences by setting a threshold; selecting an oversampling strategy based on mutation for the attack sequence, that is, randomly mutating a certain word in the sequence into another word of the same type; The sequence data obtained by selective sampling is constructed as a training sample set.

4. The APT tracing method based on physical coupling of power grid information according to claim 1 is characterized in that: In S3, based on the physical layer topology and the overload condition of the physical layer bus node, an overload association diagram is constructed, which specifically includes: Calculate the pre-overload set of all branches in the physical layer topology, where the pre-overload set is defined as: Overload, and check the overload of other branches in the physical layer topology network. If other branches are overloaded due to LR attack, it indicates that there is a problem in the branch. Before reaching its capacity, other branches are already overloaded and more vulnerable to LR attacks, marking these other branches as branches Pre-overload collection of; The model of the LR attack is: (1); (2); (3); In formulas (1)-(3): A vector representing error data added to the branch power measurement; represents the power transmission distribution coefficient of the power grid; represents the false data vector added to the bus node power measurement; Indicates the identification of the busbar node; Indicates the threshold coefficient of bus node load; Indicates the load of the bus node; Indicates the total number of busbar nodes; In order to overload each branch, the constraints set are: (4); In formula (4): represents the power flow on the branch; Indicates the maximum capacity of the branch; Definition represents the vulnerability relationship between two branches : (5); In formula (5): the symbol ‘→’ indicates that there is a vulnerability relationship between the two branches, that is, the overload of the latter is caused by the former; Indicates branch With branch The vulnerability relationship between the Included in branch Pre-overload collection of; Based on formula (5), the cascade mode of branch overload is: (6); In formula (6): The number of branches that have a transitive relationship, and the overload of the latter is caused by any of the former, that is, the branch The overload is caused by the branch { } caused by any branch in it; Based on the pre-overload set of all branches, and combined with the directed association and transitivity between branches, an overload association graph is constructed. ,in, is the vertex set representing each branch, is the edge set representing the relationship between branches; And, in S3, the vulnerability metric is defined for: (7); (8); In formula (7)-(8): Represents a vertex set The number of vertices; and Represents a vertex set The and Vertices, Represents a vertex and vertices The distance between the vertices and vertices If there is a path between is 1, otherwise, is 0.

5. The APT tracing method based on physical coupling of power grid information according to claim 4 is characterized in that: In S4, based on the actual overload conditions of each branch, all branches are classified into two categories, specifically including: For an initially normal branch, its power satisfies: (9); In formula (9): Indicates the load of the normal branch; After the branch is attacked, its forged branch power measurement value satisfy: (10); in ; The power flow actually allocated to the branch satisfy: (11); Based on the above conditions, it is judged whether the branch is actually overloaded, so as to classify all branches and use Represents a false overload set, using Represents the real overload set, namely: (12); (13); In formula (12)-(13): Indicates branch Initial normal load; Indicates adding to a branch Incorrect data for power measurements; Indicates branch The load threshold; Indicates branch The real load; Indicates branch The load threshold.

6. The APT tracing method based on grid information physical coupling according to claim 5 is characterized in that: In S4, the frequency index is defined and destructive indicators They are: (14); (15); In formula (14)-(15): Indicates branch and branch roads Frequency index of Indicates branch and branch roads Destructive indicators; Represents a false overload set The number of branches in ; Represents a real overload set The number of branches in ; Indicates and The set of fake overloads associated with each overload dependency; Indicates and The set of real overloads associated with each overload dependency; Indicates the number of all overload dependencies; if there are two branches ∈ and ∈ ,but is 1, indicating that there is a two branches of an overload dependency, otherwise is 0.

7. The APT tracing method based on grid information physical coupling according to claim 6 is characterized in that: The S5 specifically includes: The geometric distance between the first evaluation result and the second evaluation result is used to represent the importance of the overload association, and a comprehensive index is defined. for: (16); Based on the ranking of the calculation results of formula (16), the suspicious branch sequence is determined; Based on the time points of known failures And the time point when the information layer attacks the physical layer , from the time node Start positioning forward one time node , so that , to determine the time frame of the APT attack.

8. A device for implementing an APT tracing method based on physical coupling of power grid information, characterized in that: The device comprises: A training data acquisition module, for simulating APT behaviors in real scenarios, acquiring audit log data including normal activity records, and reconstructing the audit log data into a causal relationship graph; A model building module, used to build a training sample set based on the causal relationship graph, and use the training sample set to train the LSTM model so that the LSTM model can acquire the ability to identify potential APT behaviors; A first evaluation module is used to construct an overload association diagram based on the physical layer topology and the overload condition of the physical layer bus node, and calculate the vulnerability of the path in the overload association diagram to perform vulnerability evaluation on each branch to obtain a first evaluation result; The second evaluation module is used to classify all branches based on the actual overload conditions of each branch, build an overload dependency library, and combine frequency indicators based on a data-driven approach. and destructive indicators evaluating the destructive impact of overload association of each branch to obtain a second evaluation result; A suspicious data determination module, configured to determine a suspicious branch sequence based on the first evaluation result and the second evaluation result, and to narrow down the scope of suspicious logs according to the information-physical topology relationship and the time attribute, so as to obtain logs to be identified; The attack identification module is used to reconstruct the log to be identified into a target causal relationship graph, and use the trained LSTM model to identify the target causal relationship graph to distinguish the attack entity and restore the attack path.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and A memory storing instructions, which, when executed by the at least one processor, enables the at least one processor to execute the APT tracing method based on physical coupling of power grid information as described in any one of claims 1 to 7.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores executable instructions, and when the instructions are executed, the machine executes the APT tracing method based on physical coupling of power grid information as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • APT online detection method based on system log and deep learning

    CN116760604A

  • APT attack detection method based on threat intelligence and traffic characteristics

    CN116846631A

  • Network attack reconstruction method, model training method and related device

    CN116886379A

  • Apt detection method and system based on continuous-time dynamic heterogeneous graph network

    US20250063058A1