Power network defense strategy determination method and device, computer equipment and medium

By extracting the target characteristics and determining the operating status in the operating data of the power network, combining attack and defense entity information to determine the target defense strategy of the power network, the problem that traditional methods are difficult to deal with dynamic attacks and hidden threats is solved, and more efficient and accurate security detection and protection are achieved.

CN120034385APending Publication Date: 2025-05-23ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510204174.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Traditional power network security detection and vulnerability protection methods are difficult to deal with dynamically changing attack patterns and hidden security threats, and there are manual intervention and subjective deviations, which reduces the comprehensiveness and accuracy of detection.

Method used

By obtaining the operating data of the power network, extracting the target operating characteristics based on the feature detection model, determining the operating status of the power network, obtaining attack entity information and defense entity information, and finally determining the target defense strategy based on this information.

Benefits of technology

This method can reduce manual intervention and subjective deviations, is suitable for complex and changeable power network environments, improves the comprehensiveness and accuracy of detection, provides a comprehensive perspective of confrontational analysis, and improves the pertinence and effectiveness of defense measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034385A_ABST
    Figure CN120034385A_ABST
Patent Text Reader

Abstract

The invention relates to a power network defense strategy determination method and device, computer equipment and a medium. The method comprises the following steps: acquiring operation data of a power network in different time periods; for the operation data in each time period, based on a feature detection model, extracting target operation features in the operation data; determining the operation state of the power network according to the target operation characteristics in different time periods; acquiring attack entity information and defense entity information of the power network aiming at the power network of which the operation state is an abnormal state; the attack entity information is the information of an entity which destroys the power network security; the defense entity information is the information of an entity for protecting the security of the power network; and determining a target defense strategy of the power network according to the attack entity information and the defense entity information. By adopting the method, manual intervention and subjective deviation can be reduced, the method is suitable for a complex and changeable operating environment in a power network, and the comprehensiveness and accuracy of overall detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, computer equipment and medium for determining a power network defense strategy. Background Art

[0002] With the rapid development and intelligent advancement of modern power systems, power networks have become an important part of the country's critical infrastructure. The security of power networks is directly related to social stability and economic development, which puts higher requirements on their security detection and vulnerability protection. In recent years, the security threats faced by power networks have continued to increase, and power network security detection and vulnerability protection face complex challenges, including diverse attack methods, high-frequency attack events, and a wide range of attack surfaces. Traditional security detection and protection methods mainly rely on static rules and feature matching, which are difficult to cope with dynamically changing attack patterns and hidden security threats.

[0003] In traditional technologies, security vulnerability protection tools are usually used to protect the security of the power grid, but there are manual intervention and subjective biases, which are not suitable for the complex and changeable operating environment of the power network, reducing the comprehensiveness and accuracy of the overall detection; in addition, the existing power network security detection and vulnerability protection data methods cannot provide a comprehensive adversarial analysis perspective, and have poor flexibility and adaptability, reducing the pertinence and effectiveness of defense measures. Summary of the invention

[0004] Based on this, it is necessary to provide a method, device, computer equipment and medium for determining a power network defense strategy that can accurately and efficiently determine the power network defense strategy in response to the above-mentioned technical problems.

[0005] In a first aspect, the present application provides a method for determining a power network defense strategy, comprising:

[0006] Obtain the operation data of the power network in different periods of time;

[0007] For the operation data in each period, based on the feature detection model, the target operation features in the operation data are extracted;

[0008] Determine the operating status of the power network according to the target operating characteristics in different time periods;

[0009] For a power network in an abnormal operating state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security;

[0010] According to the attack entity information and defense entity information, the target defense strategy of the power network is determined.

[0011] In one embodiment, extracting target operation features from operation data based on a feature detection model includes:

[0012] Inputting the operation data into a feature detection model to obtain at least one-dimensional initial operation features; the feature detection model is constructed based on a decision tree;

[0013] Determine the feature evaluation value of each initial operation feature according to the information gain of each dimension of the initial operation feature;

[0014] The initial operation features are sorted in descending order according to the feature evaluation values ​​to obtain a sorting result;

[0015] The initial running feature with the highest ranking in the preset dimension is selected as the target running feature.

[0016] In one embodiment, determining the operating state of the power network according to target operating characteristics in different time periods includes:

[0017] For each target operating characteristic, determine the Euclidean distance between the target operating characteristics of adjacent time periods;

[0018] According to each Euclidean distance, the minimum cumulative distance of the target operation feature is determined;

[0019] The operating status of the power network is determined based on the relationship between the minimum cumulative distance of different target operating characteristics and the preset score threshold.

[0020] In one embodiment, determining the operation state of the power network according to the relationship between the minimum cumulative distance of different target operation characteristics and a preset score threshold includes:

[0021] For each target operation feature, determine a distance score value of the target operation feature according to the minimum cumulative distance of the target operation feature;

[0022] Determine the sum of the distance scores of each target operation feature as the comprehensive score of the power network;

[0023] When the comprehensive score value is greater than the preset score threshold, it is determined that the operation state of the power network is an abnormal state.

[0024] In one embodiment, determining a target defense strategy of a power network according to attack entity information and defense entity information includes:

[0025] Determining at least one initial attack strategy based on the attack entity information; and determining at least one initial defense strategy based on the defense entity information;

[0026] Generate at least one initial combination strategy; wherein the initial combination strategy includes an initial attack strategy and an initial defense strategy;

[0027] Determine the comprehensive resources in the corresponding initial combination strategy according to the attack resources of the initial attack strategy and the defense resources in the initial defense strategy in different initial combination strategies;

[0028] According to the comprehensive resources of different initial combination strategies, the target defense strategy of the power network is determined.

[0029] In one embodiment, a target defense strategy for a power network is determined based on comprehensive resources of different initial combination strategies, including:

[0030] Sequentially select the initial combination strategy with the largest preset number of comprehensive resources as the first combination strategy, and construct a first combination strategy set;

[0031] For each iteration, crossover mutation is performed on each first combination strategy in the first combination strategy set to obtain a second combination strategy;

[0032] According to the comprehensive resources of each first combination strategy and the comprehensive resources of the second combination strategy, a combination strategy with the largest preset number of comprehensive resources is selected to update the first combination strategy set until the number of iterations reaches a preset number threshold;

[0033] The defense strategy in the first combination strategy with the largest comprehensive resource in the first combination strategy set obtained by the last update is used as the target defense strategy of the power network.

[0034] In a second aspect, the present application also provides a device for determining a power network defense strategy, comprising:

[0035] A data acquisition module, which acquires the operation data of the power network in different time periods;

[0036] A feature extraction module is used to extract target operation features from the operation data in each time period based on a feature detection model;

[0037] A state determination module is used to determine the operation state of the power network according to the target operation characteristics in different time periods;

[0038] The entity acquisition module is used to acquire the attack entity information and defense entity information of the power network for the power network in an abnormal operation state; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security;

[0039] The strategy determination module is used to determine the target defense strategy of the power network according to the attack entity information and the defense entity information.

[0040] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0041] Obtain the operation data of the power network in different periods of time;

[0042] For the operation data in each period, based on the feature detection model, the target operation features in the operation data are extracted;

[0043] Determine the operating status of the power network according to the target operating characteristics in different time periods;

[0044] For a power network in an abnormal operating state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security;

[0045] According to the attack entity information and defense entity information, the target defense strategy of the power network is determined.

[0046] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0047] Obtain the operation data of the power network in different periods of time;

[0048] For the operation data in each period, based on the feature detection model, the target operation features in the operation data are extracted;

[0049] Determine the operating status of the power network according to the target operating characteristics in different time periods;

[0050] For a power network in an abnormal operating state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security;

[0051] According to the attack entity information and defense entity information, the target defense strategy of the power network is determined.

[0052] In a fifth aspect, the present application further provides a computer program product, including a computer program, which implements the following steps when executed by a processor:

[0053] Obtain the operation data of the power network in different periods of time;

[0054] For the operation data in each period, based on the feature detection model, the target operation features in the operation data are extracted;

[0055] Determine the operating status of the power network according to the target operating characteristics in different time periods;

[0056] For a power network in an abnormal operating state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security;

[0057] According to the attack entity information and defense entity information, the target defense strategy of the power network is determined.

[0058] The above-mentioned power network defense strategy determination method, device, computer equipment and medium obtain the operation data of the power network in different time periods; for the operation data in each time period, based on the feature detection model, extract the target operation characteristics in the operation data; determine the operation status of the power network according to the target operation characteristics in different time periods; for the power network with an abnormal operation status, obtain the attack entity information and defense entity information of the power network; the attack entity information is the information of the entity that destroys the power network; the defense entity information is the information of the entity that protects the security of the power network; according to the attack entity information and the defense entity information, determine the target defense strategy of the power network. This embodiment can reduce manual intervention and subjective bias, is suitable for the complex and changeable operating environment in the power network, improves the comprehensiveness and accuracy of the overall detection, and helps to quickly identify and respond to abnormal events in the power network. At the same time, it can provide a comprehensive confrontation analysis perspective, has a high degree of flexibility and adaptability, improves the pertinence and effectiveness of defense measures, and achieves a balance between maximizing protection effects and minimizing resource costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0060] Figure 1 An application environment diagram of a method for determining a power network defense strategy provided in this embodiment;

[0061] Figure 2 A schematic diagram of a flow chart of a first method for determining a power network defense strategy provided in this embodiment;

[0062] Figure 3A schematic diagram of a flow chart of steps for determining the operating status of a power network provided in this embodiment;

[0063] Figure 4 A structural block diagram of a power network defense strategy determination device provided in this embodiment;

[0064] Figure 5 An internal structure diagram of a first computer device provided in this embodiment;

[0065] Figure 6 This is a diagram of the internal structure of the second computer device provided in this embodiment. DETAILED DESCRIPTION

[0066] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0067] The power network defense strategy determination method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The computer device obtains the operation data of the power network in different time periods; for the operation data in each time period, based on the feature detection model, the target operation characteristics in the operation data are extracted; according to the target operation characteristics in different time periods, the operation state of the power network is determined; for the power network with an abnormal operation state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network security; the defense entity information is the information of the entity that protects the power network security; according to the attack entity information and the defense entity information, the target defense strategy of the power network is determined. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented with an independent server or a server cluster consisting of multiple servers.

[0068] In an exemplary embodiment, Figure 2 As shown in the figure, a method for determining a power network defense strategy is provided. Figure 1 The computer device in the example is used to illustrate, including the following steps 201 to 205. Among them:

[0069] Step 201, obtaining operation data of the power network in different time periods.

[0070] The operation data may include voltage, current, power, frequency, network traffic data, system logs and other data.

[0071] Step 202 : for the operation data in each time period, based on the feature detection model, extract the target operation features in the operation data.

[0072] One optional implementation method may be: inputting the operation data into a feature detection model to obtain at least one-dimensional initial operation feature; the feature detection model is constructed based on a decision tree; determining the feature evaluation value of each initial operation feature according to the information gain of each dimension of the initial operation feature; sorting the initial operation features in descending order of the feature evaluation value to obtain a sorting result; and selecting the initial operation feature with a preset dimension ranking first as the target operation feature.

[0073] Another optional implementation method may be to input the operating data in each time period into a feature detection model, and the feature detection model extracts the gain of each feature when it is split in each group of decision trees of the feature detection model, and accumulates or averages the feature importance of all trees to obtain the final feature importance, and then sorts the features according to the feature importance scores, and extracts the target operating features with corresponding high scores according to user needs.

[0074] It should be noted that the feature detection model can be trained in the following way: collect various operating data from the power network, remove noise and outliers from each operating data, fill in missing values ​​in the data, and then standardize the operating data of different dimensions to a unified scale range, and build a feature detection model based on the gradient boosting tree model, select initial features from the preprocessed data, and initialize a decision tree and prediction value. The feature detection model then calculates the initial residual of each data point through the prediction value. The initial decision tree calculates the gain of each feature for splitting the data at different splitting points, and selects the feature and splitting point with the largest gain as the splitting criterion for the current node. According to the selected features and splitting points, The data is split into left and right child nodes, and the above process is repeated recursively on the child nodes until the preset tree depth is reached or the number of data points contained in the leaf node is less than the preset threshold. The predicted value of each data point is updated according to the output of the split decision tree, and the new residual is calculated based on the updated predicted value. The new decision tree is trained to select the split point according to the feature data, fit the current residual, and then add the new decision tree to the feature detection model. After each round of training, the feature detection model is verified using the cross-validation method. If the reduction in the model error relative to the previous iteration is lower than the preset threshold, the training is stopped. Otherwise, the feature detection model parameters are adjusted and the iterative training is repeated until the preset number of training times is reached.

[0075] Step 203, determining the operation status of the power network according to the target operation characteristics in different time periods.

[0076] Specifically, the target operation characteristics in different time periods are input into the network status detection model to obtain the operation status of the power network.

[0077] Step 204, for the power network whose operating state is abnormal, acquiring attack entity information and defense entity information of the power network.

[0078] The attack entity information is the information of the entity that destroys the security of the power network; the defense entity information is the information of the entity that protects the security of the power network.

[0079] Specifically, we collect information about entities that damage or illegally conduct power networks, as well as information about entities responsible for protecting the security of power networks, and determine the main targets of attackers and defenders respectively. Then, we construct an attacker strategy set based on the different attack strategies and defense strategies selected. With the defender strategy collection .

[0080] Step 205: determining a target defense strategy for the power network according to the attack entity information and the defense entity information.

[0081] Specifically, the attack entity information and the defense entity information are input into the target defense strategy model, and the target defense strategy model analyzes the attack entity information and the defense entity information to obtain the target defense strategy of the power network.

[0082] It should be noted that the present embodiment can also collect and analyze power network data in real time and take corresponding vulnerability protection measures; evaluate and summarize the detection and protection results to optimize the detection and protection algorithms; conduct network security drills and training regularly and establish a collaborative protection mechanism.

[0083] The above-mentioned method for determining the power network defense strategy obtains the operation data of the power network in different time periods; for the operation data in each time period, based on the feature detection model, the target operation features in the operation data are extracted; according to the target operation features in different time periods, the operation state of the power network is determined; for the power network with an abnormal operation state, the attack entity information and defense entity information of the power network are obtained; the attack entity information is the information of the entity that destroys the power network; the defense entity information is the information of the entity that protects the security of the power network; according to the attack entity information and the defense entity information, the target defense strategy of the power network is determined. This embodiment can reduce manual intervention and subjective bias, is suitable for the complex and changeable operating environment in the power network, improves the comprehensiveness and accuracy of the overall detection, and helps to quickly identify and respond to abnormal events in the power network. At the same time, it can provide a comprehensive perspective of confrontation analysis, has a high degree of flexibility and adaptability, improves the pertinence and effectiveness of defense measures, and achieves a balance between maximizing protection effects and minimizing resource costs.

[0084] In one embodiment, Figure 3 As shown, a flow chart of the steps of determining the operation status of the power network is provided, and the operation status of the power network is determined according to the characteristic data of each target operation characteristic in different time periods, including:

[0085] Step 301 : for each target operation feature, determine the Euclidean distance between the target operation features in adjacent time periods.

[0086] Step 302: Determine the minimum cumulative distance of the target running feature according to each Euclidean distance.

[0087] Specifically, the time series data in each group of feature data extracted by the feature extraction model are collected, the time series are divided into windows of equal length, and the Euclidean distance between each pair of points in the time series is calculated, and the cumulative distance matrix is ​​constructed based on the Euclidean distance calculation results.

[0088] Step 303 : determining the operation state of the power network according to the relationship between the minimum cumulative distances of different target operation characteristics and the preset score thresholds.

[0089] In one embodiment, the operating state of the power network is determined based on the size relationship between the minimum cumulative distance of different target operating characteristics and a preset score threshold, including: for each target operating characteristic, determining the distance score value of the target operating characteristic based on the minimum cumulative distance of the target operating characteristic; determining the sum of the distance score values ​​of each target operating characteristic as the comprehensive score value of the power network; and determining that the operating state of the power network is an abnormal state when the comprehensive score value is greater than the preset score threshold.

[0090] Specifically, each data information in the cumulative distance matrix is ​​calculated recursively, and starting from the lower right corner of the cumulative distance matrix, backtracking is performed along the direction of the minimum cumulative distance to find the optimal alignment path, and a group of alignment points representing two groups of sequences in each step of the path are collected; according to the distance of each group of alignment points in the optimal alignment path, the total anomaly score is calculated, and an anomaly threshold is set. When the distance of the alignment points exceeds the threshold, these points are considered to be abnormal and are marked as abnormal.

[0091] For example, the specific calculation formula of the cumulative distance matrix is ​​as follows (1-1):

[0092] (1-1)

[0093] In the formula, D(i,j) represents the distance from the start of the sequence to X i and Y j The minimum cumulative distance; d(X i ,Y j ) represents the data point X i With data point Y j The Euclidean distance between i represents the i-th data point in the time series data X; Y j Represents the jth data point in the time series data Y; Represents the minimum cumulative distance in previous paths.

[0094] It should be further explained that the time series data points marked as abnormal are extracted, and the features of the abnormal points are extracted, including the time point, amplitude and feature parameters. The radius of the neighborhood of a data point and the minimum number of neighbors MinPts required for a data point to be considered a core point are initialized. Then, for each point in the data set, the number of neighbors within the radius is calculated. If the number of neighbors is greater than or equal to MinPts, it is marked as a core point. Starting from the core point, all points in its neighborhood are recursively added to the same cluster, and the neighborhood of these points continues to be expanded until no new points can be added. Any point that does not belong to any cluster is marked as a noise point. Each data point is marked and classified according to the cluster to which it belongs. Then, each cluster is analyzed to identify similar abnormal patterns and behaviors, and a scatter plot is used to display the clustering results in real time.

[0095] In this embodiment, various operation data are collected and preprocessed from the power network, and a feature detection model is constructed based on a gradient boosting tree model. Initial features are selected from the preprocessed data, and a decision tree and a prediction value are initialized. Then, the feature detection model calculates the initial residual of each data point through the prediction value, fits the initial residual through the initial decision tree, and calculates a new residual based on the updated prediction value. Then, a new decision tree is constructed, and iterative training is repeated until a preset number of training times is reached. The gain brought by each feature when splitting in each group of decision trees in the feature detection model is extracted, and the feature importance of all trees is accumulated or averaged to obtain the final feature importance. Then, the features are sorted according to the feature importance score, and the feature data with the top corresponding scores are extracted. The feature data is divided into windows of equal length, and the Euclidean distance between each pair of points is calculated to construct a cumulative distance matrix. The data information in the cumulative distance matrix is ​​calculated recursively, and starting from the lower right corner of the cumulative distance matrix, backtracking is performed along the direction of the minimum cumulative distance to find the optimal alignment path, and a group of alignment points representing two groups of sequences in each step of the path are collected. According to the distance of each group of alignment points in the optimal alignment path, the total anomaly score is calculated, and an anomaly threshold is set. When the distance of the alignment points exceeds the threshold, these points are considered to be abnormal and marked as abnormal. This can reduce manual intervention and subjective bias, is suitable for the complex and changeable operating environment in the power network, improves the comprehensiveness and accuracy of the overall detection, and helps to quickly identify and respond to abnormal events in the power network.

[0096] In one embodiment, a target defense strategy of a power network is determined based on attack entity information and defense entity information, including: determining at least one initial attack strategy based on the attack entity information; and determining at least one initial defense strategy based on the defense entity information; generating at least one initial combination strategy; wherein the initial combination strategy includes an initial attack strategy and an initial defense strategy; determining comprehensive resources in corresponding initial combination strategies based on attack resources of the initial attack strategies and defense resources in the initial defense strategies in different initial combination strategies; and determining a target defense strategy of the power network based on the comprehensive resources of different initial combination strategies.

[0097] In one embodiment, a target defense strategy of the power network is determined based on the comprehensive resources of different initial combination strategies, including: selecting the initial combination strategies with the largest preset number of comprehensive resources in turn as the first combination strategy, and constructing a first combination strategy set; for each iteration, performing cross-mutation on each first combination strategy in the first combination strategy set to obtain a second combination strategy; based on the comprehensive resources of each first combination strategy and the comprehensive resources of the second combination strategy, selecting the combination strategy with the largest preset number of comprehensive resources to update the first combination strategy set until the number of iterations reaches a preset number threshold; and using the defense strategy in the first combination strategy with the largest comprehensive resources in the first combination strategy set obtained by the last update as the target defense strategy of the power network.

[0098] Specifically, we extract attacker resource indicators and defender resource indicators from the existing protection database, and test attacker selection strategies in a simulated environment based on the collected data. The defender chooses a strategy , the actual resources of the attacker and the defender, organize the resource values ​​under different strategy combinations into a resource matrix, calculate the expected resources of the attacker and the defender, find the marked positions in the resource matrix of the attacker and the defender, and use them as Nash equilibrium points, and determine whether each marked position is a maximized strategy. If it is a maximized strategy, list all strategy combinations that meet the conditions and record the corresponding resources. Generate a corresponding strategy space based on each group of defense strategies, then initialize a group of defense populations, and initialize the position vectors of each individual in the population, and then obtain the resources of the defense strategy corresponding to each group of individual position vectors in the game, identify the top three groups of individuals with the best resources, and update the positions of other individuals based on the position vector information of the top three groups of individuals, recalculate the resources, update the information of the top three groups of individuals, and then re-update the positions of other individuals, iterate repeatedly, update the positions of all individuals in each iteration, recalculate the resources, and update the positions of the top three groups of individuals, stop when the resources reach the set threshold or reach the set maximum number of iterations, take the defense strategy corresponding to the position with the highest resources as the optimal defense strategy, calculate and output the comprehensive resources of the optimal defense strategy, and conduct risk and cost assessment on the defense strategy, and feedback to the user for review.

[0099] For example, the specific calculation formula of comprehensive resources is shown in the following formula (1-2):

[0100] (1-2)

[0101] In the formula, Represents the probability of the attack strategy appearing; Represents the defender's benefits under attack and defense strategies.

[0102] This embodiment collects entity information on those who damage or conduct illegal acts against the power grid, as well as entity information on those responsible for protecting the security of the power grid, and respectively determines the main objectives of attackers and defenders. After that, according to the selected different attack strategies and defense strategies, an attacker strategy set and a defender strategy set are constructed. The benefit values under different strategy combinations are sorted into a benefit matrix, and the expected benefits of attackers and defenders are calculated. In the benefit matrices of attackers and defenders, find the positions that are marked simultaneously, and use them as Nash equilibrium points at the same time. Then determine whether each marked position is a maximizing strategy. If it is a maximizing strategy, list all strategy combinations that meet the conditions and record the corresponding benefits. Generate the corresponding strategy space according to each group of defense strategies. Then initialize a group of defense populations and initialize the position vectors of each individual in the population. Then obtain the benefits of the defense strategies corresponding to each group of individual position vectors in the game, identify the top three groups of individuals with the best benefits, and update the positions of other individuals according to the information of the position vectors of the top three groups. Recalculate the benefits to update the information of the top three groups of individuals, and then update the positions of other individuals again. Iterate repeatedly. In each iteration, update the positions of all individuals, recalculate the benefits, and update the positions of the top three groups of individuals. Stop when the benefit reaches the set threshold or the set maximum number of iterations. Take the defense strategy corresponding to the position with the highest benefit as the optimal defense strategy, calculate and output the comprehensive benefit of the optimal defense strategy, and conduct risk and cost assessments on this defense strategy and feedback it to the user for viewing. It can provide a comprehensive perspective on adversarial analysis, has high flexibility and adaptability, enhances the pertinence and effectiveness of defense measures, and achieves the balance between maximizing the protection effect and minimizing the resource cost.

[0103] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indication of the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0104] Based on the same inventive concept, the embodiment of the present application also provides a power network defense strategy determination device for implementing the power network defense strategy determination method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more power network defense strategy determination device embodiments provided below can refer to the limitations of the power network defense strategy determination method above, and will not be repeated here.

[0105] In an exemplary embodiment, Figure 4 As shown, a power network defense strategy determination device is provided, comprising: a data acquisition module 10, a feature extraction module 11, a state determination module 12, an entity acquisition module 13 and a strategy determination module 14, wherein:

[0106] The data acquisition module 10 acquires the operation data of the power network in different time periods;

[0107] The feature extraction module 11 is used to extract target operation features from the operation data in each time period based on the feature detection model;

[0108] A state determination module 12, for determining the operation state of the power network according to target operation characteristics in different time periods;

[0109] The entity acquisition module 13 is used to acquire the attack entity information and defense entity information of the power network for the power network in an abnormal operation state; the attack entity information is the information of the entity that destroys the power network; the defense entity information is the information of the entity that protects the security of the power network;

[0110] The strategy determination module 14 is used to determine the target defense strategy of the power network according to the attack entity information and the defense entity information.

[0111] In one embodiment, the feature extraction module 11 is also used to input the operation data into the feature detection model to obtain at least one-dimensional initial operation feature; the feature detection model is constructed based on a decision tree; the feature evaluation value of each initial operation feature is determined according to the information gain of each dimension of the initial operation feature; the initial operation features are sorted in descending order according to the feature evaluation value to obtain a sorting result; and the initial operation feature with a preset dimension ranking first is selected as the target operation feature.

[0112] In one embodiment, the state determination module 12 is also used to determine, for each target operating feature, the Euclidean distance between the target operating features of adjacent time periods; determine the minimum cumulative distance of the target operating features based on each Euclidean distance; and determine the operating state of the power network based on the relationship between the minimum cumulative distance of different target operating features and a preset score threshold.

[0113] In one embodiment, the state determination module 12 is also used to determine the distance score value of the target operation feature for each target operation feature according to the minimum cumulative distance of the target operation feature; determine the sum of the distance score values ​​of each target operation feature as the comprehensive score value of the power network; when the comprehensive score value is greater than a preset score threshold, determine that the operation state of the power network is an abnormal state.

[0114] In one embodiment, the strategy determination module 14 is also used to determine at least one initial attack strategy based on the attack entity information; and, based on the defense entity information, determine at least one initial defense strategy; generate at least one initial combination strategy; wherein the initial combination strategy includes an initial attack strategy and an initial defense strategy; determine the comprehensive resources in the corresponding initial combination strategy based on the attack resources of the initial attack strategy in different initial combination strategies and the defense resources in the initial defense strategy; determine the target defense strategy of the power network based on the comprehensive resources of different initial combination strategies.

[0115] In one embodiment, the strategy determination module 14 is also used to sequentially select the initial combination strategy with the largest preset number of comprehensive resources as the first combination strategy, and construct a first combination strategy set; for each iteration, cross-mutate each first combination strategy in the first combination strategy set to obtain a second combination strategy; based on the comprehensive resources of each first combination strategy and the comprehensive resources of the second combination strategy, select the combination strategy with the largest preset number of comprehensive resources to update the first combination strategy set until the number of iterations reaches a preset number threshold; use the defense strategy in the first combination strategy with the largest comprehensive resources in the first combination strategy set obtained by the last update as the target defense strategy of the power network.

[0116] Each module in the above-mentioned power network defense strategy determination device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0117] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 5As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for determining a power network defense strategy is implemented.

[0118] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be realized through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for determining a power network defense strategy is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse.

[0119] Those skilled in the art will understand that Figure 5 and Figure 6The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0120] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the above steps are implemented when the processor executes the computer program.

[0121] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the above steps are implemented.

[0122] In one embodiment, a computer program product is provided, comprising a computer program, which implements the above steps when executed by a processor.

[0123] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0124] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0125] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0126] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for determining a power network defense strategy, characterized in that: The method comprises: Obtain the operation data of the power network in different periods of time; For the operation data in each time period, based on the feature detection model, extract the target operation features in the operation data; Determining the operating state of the power network according to target operating characteristics in different time periods; For a power network whose operation state is abnormal, acquiring attack entity information and defense entity information of the power network; the attack entity information is information of an entity that destroys the power network; the defense entity information is information of an entity that protects the security of the power network; A target defense strategy for the power network is determined according to the attack entity information and the defense entity information.

2. The method according to claim 1, characterized in that The extracting target operation features from the operation data based on the feature detection model includes: Inputting the operation data into the feature detection model to obtain at least one-dimensional initial operation feature; the feature detection model is constructed based on a decision tree; Determining a feature evaluation value of each of the initial operating features according to the information gain of the initial operating features of each dimension; The initial operation features are sorted in descending order according to the feature evaluation values ​​to obtain a sorting result; The initial running feature with the highest ranking in the preset dimension is selected as the target running feature.

3. The method according to claim 1, characterized in that Determining the operating state of the power network according to target operating characteristics in different time periods includes: For each target operating characteristic, determine the Euclidean distance between the target operating characteristics of adjacent time periods; Determining the minimum cumulative distance of the target operation feature according to each of the Euclidean distances; The operating state of the power network is determined according to the size relationship between the minimum cumulative distances of different target operating characteristics and the preset score thresholds.

4. The method according to claim 3, characterized in that Determining the operating state of the power network according to the size relationship between the minimum cumulative distances of different target operating characteristics and preset score thresholds includes: For each target operation feature, determining a distance score value of the target operation feature according to the minimum cumulative distance of the target operation feature; Determine the sum of the distance scores of the target operation characteristics as the comprehensive score of the power network; When the comprehensive score value is greater than a preset score threshold, it is determined that the operation state of the power network is an abnormal state.

5. The method according to claim 1, characterized in that Determining a target defense strategy of the power network according to the attack entity information and the defense entity information includes: Determining at least one initial attack strategy based on the attack entity information; and determining at least one initial defense strategy based on the defense entity information; Generate at least one initial combination strategy; wherein the initial combination strategy includes an initial attack strategy and an initial defense strategy; Determine the comprehensive resources in the corresponding initial combination strategy according to the attack resources of the initial attack strategy and the defense resources in the initial defense strategy in different initial combination strategies; According to the comprehensive resources of different initial combination strategies, the target defense strategy of the power network is determined.

6. The method according to claim 5, characterized in that Determining the target defense strategy of the power network according to the comprehensive resources of different initial combination strategies includes: Sequentially select the initial combination strategy with the largest preset number of comprehensive resources as the first combination strategy, and construct a first combination strategy set; For each iteration, crossover mutation is performed on each first combination strategy in the first combination strategy set to obtain a second combination strategy; According to the comprehensive resources of each first combination strategy and the comprehensive resources of the second combination strategy, a combination strategy with the largest preset number of comprehensive resources is selected to update the first combination strategy set until the number of iterations reaches a preset number threshold; The defense strategy in the first combination strategy with the largest comprehensive resource in the first combination strategy set obtained by the last update is used as the target defense strategy of the power network.

7. A device for determining a power network defense strategy, characterized in that: The device comprises: A data acquisition module, which acquires the operation data of the power network in different time periods; A feature extraction module, for extracting target operation features from the operation data in each time period based on a feature detection model; A state determination module, used to determine the operation state of the power network according to target operation characteristics in different time periods; An entity acquisition module is used to acquire, for a power network in an abnormal operating state, attack entity information and defense entity information of the power network; the attack entity information is information about an entity that destroys the power network; the defense entity information is information about an entity that protects the power network security; The strategy determination module is used to determine the target defense strategy of the power network according to the attack entity information and the defense entity information.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • Power network state identification method and system based on data feature analysis

    CN120566456A

  • Alternating current optimal defense resource allocation method based on two-stage hybrid optimization

    CN120768593A