Information physical cooperative attack influence path analysis method and system
By constructing a three-layer Internet network model and chain failure evolution model of the power information physics system, combined with the weight comprehensive central indicators, the shortcomings of the vulnerability analysis of the power information physics system and the assessment of the impact path of the information physics collaborative attack in the existing technology are solved, and accurate identification of the vulnerability of the key nodes of the system is achieved and the accurate assessment of the impact path of the attack is achieved.
Patent Information
- Application Number
- CN202510188959.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art is difficult to realize the analysis of the vulnerability of global interconnected systems caused by the impact of local system failure in new power information physics systems, and it is unable to effectively evaluate the impact path of information physics collaborative attacks.
A method for a path analysis of the impact of information physics synergistic attacks is proposed. By constructing a three-layer Internet network model of power physics, information and business control systems, analyzing the state transition relationship of dependent nodes, establishing a chain failure evolution model, and proposing a weight comprehensive central indicator to evaluate the vulnerability of key nodes.
It realizes accurate identification and evaluation of the paths affecting information physics synergistic attacks in the power information physics system, identify the most vulnerable key nodes in the system, and improves the security and controllability of the system.
Smart Images

Figure CN120050082A_ABST
Abstract
Description
Technical Field
[0001] The present invention is directed to the technical field of network security analysis and defense for power cyber-physical systems, and proposes a method and system for analyzing the impact path of cyber-physical collaborative attacks. Background Art
[0002] With the deep integration of digital and intelligent devices, traditional power systems have gradually evolved into modern new power systems with data explosion and complex structures. At the same time, the continuously expanding power monitoring business extremely relies on the effective information support provided by power information systems to complete the scheduling and control of power physical systems, greatly intensifying the deep interconnection between the power physical side and the information side. Traditional power systems further tend to be new power cyber-physical systems with complex structures and large scales. The new power cyber-physical system relies on digital technology to improve the real-time performance and controllability of the system, but due to the nature of its interconnected systems, it is more vulnerable than previous single systems and faces more severe challenges of network attacks and cascading accident risks.
[0003] Currently, research on network attacks against power cyber-physical systems usually focuses on a single type of network attack in specific monitoring business scenarios of power cyber-physical systems, and fails to realize the vulnerability analysis of the global interconnected system caused by the failure of local systems in power cyber-physical systems. To achieve global system vulnerability analysis, it is necessary to study and establish a unified power system model considering the multi-layer network interconnection of power cyber-physical systems, and propose a method for analyzing the impact path of cyber-physical attacks based on the vulnerability assessment of key links. Summary of the Invention
[0004] In order to solve technical problems such as the security risk analysis of key node vulnerability links and the system stable operation control of new power cyber-physical systems, the present invention discloses a method and system for analyzing the impact path of cyber-physical collaborative attacks. The specific technical solutions are as follows:
[0005] A method for analyzing the impact path of cyber-physical collaborative attacks, comprising:
[0006] Analyze the source of physical system security events caused by information system security threats, summarize cyber-physical collaborative attack types according to the source, and establish corresponding typical attack models for the cyber-physical collaborative attack types;
[0007] Establish the respective single-sided node network layers of the power physical system, the power information system, and the power service control system, describe the interaction relationships of different single-sided node network layers according to the generalized incidence matrix in the power system, and construct a three-layer interconnected network model using the structure of physical node - dependent connection edge - information node; wherein, the single-sided nodes include physical nodes and information nodes, and a physical node and an information node in the three-layer interconnected network model form a pair of dependent nodes;
[0008] Analyze the relationship of the normal-failure state transition of dependent nodes in the three-layer interconnected network model, analyze the impact of single-sided node failure on the operation of the power grid, and based on the relationship of the state transition and the impact on the operation of the power grid, establish an evolutionary model of cascading failure of dependent nodes;
[0009] Propose a weighted comprehensive centrality index that comprehensively considers the importance of key nodes in the primary physical system and the secondary information system of power, and estimate the vulnerability of key nodes in the power system according to the weighted comprehensive centrality index;
[0010] Based on the evolutionary model of cascading failure of power system nodes and the vulnerability analysis of key nodes in the power system, construct the impact path of cyber-physical collaborative attack, and conduct simulation verification for the impact path of cyber-physical collaborative attack.
[0011] Furthermore, the typical attack model includes a data attack type model and a network attack type model, and the typical attack model records the impact analysis on the power system under different cyber-physical collaborative attacks.
[0012] Furthermore, in the single-sided node network layer, the physical nodes on the layer follow the energy flow, and the information nodes follow the information flow, including the topological structure and node attributes of the system.
[0013] Furthermore, the single-sided node network layer constructs a three-layer interconnected network model of the power cyber-physical system according to the generalized incidence matrix in the power cyber-physical system. The specific steps are as follows:
[0014] (1) In a power cyber-physical system containing n nodes, the set of power physical nodes is denoted as V p = {1, 2, …, n}, E p represents the physical connection edges, and G p = (V p , E p ) represents a connected graph. The incidence matrix A p represents the topological relationship between different nodes:
[0015]
[0016] In the formula, a ij is a matrix element. When there is a stable connection relationship between nodes i and j, then a ij = 1; otherwise, take the element a ij = 0;
[0017] (2) Based on the one-to-one node dependence framework, the set of information nodes V c = {1, 2, …, n} includes source information nodes Vc-s and central information nodes Vc-c, that is, Vc =(V c-s ,V c-c ); Different from the physical connection edge relationship that conforms to the power flow distribution among power physical nodes, the information connection edge E among information nodes c adopts a scale-free network connection and is represented by the incidence matrix A c as follows:
[0018]
[0019] In the formula, b ij is the matrix element. When there is a stable connection relationship between nodes i and j, then b ij =1; otherwise, the element b ij =0;
[0020] (3) For a power system with n cyber-physical nodes, which follows the one-to-one node model framework, the failure of any one-side node will cause the failure of its dependent node, and its stable connection relationship will turn into a disconnection relationship. After abstracting and processing the above model, the connection state between cyber-physical nodes is obtained, and the physical-information incidence matrix A p-c can be expressed as:
[0021]
[0022] In the formula, A p-c represents an incidence matrix based on the connection relationship between the information network layer and the physical network layer, reflecting the most basic connectivity relationship between cyber-physical nodes. When nodes i and j are connected, the element c ij =1; otherwise c ij =0;
[0023] (4) The network adjacency matrix of the power physical system, the network adjacency matrix of the power information system, and the multi-layer network adjacency matrix are spliced to form the topological mathematical model of the power information-physical system, which is represented by the topological adjacency matrix A:
[0024]
[0025] In the formula, the matrices A p and A c are the physical layer adjacency matrix and the information layer adjacency matrix respectively; A p-c is the adjacency matrix established between the power grid and the information network based on the deep integration of the primary system and the secondary system.
[0026] Furthermore, by analyzing the relationship framework of the mutual conversion of dependent nodes between the normal and failure states, the impact of the failure of one-side nodes on the operation of the power grid is analyzed, and an evolutionary model of the impact of cascading failures of dependent nodes is established.
[0027] Furthermore, a weighted comprehensive centrality index that comprehensively considers the vulnerability of key nodes in the primary power physical system and the secondary information system is proposed. Calculate the comprehensive centrality index of each node and form an ordered list to identify the most vulnerable key nodes in the power cyber-physical system and estimate the node vulnerability of the power cyber-physical system.
[0028] Furthermore, the weighted comprehensive centrality index is obtained according to the power flow characteristic parameters of the power physical system nodes and the network topology characteristic parameters of the information system. The specific calculation steps are as follows:
[0029] (1) Calculate the degree centrality index of node weights:
[0030]
[0031] In the formula, is the degree centrality of information node i; η i is the degree importance of information node i; p i is the adjustable power flow characteristic parameter of the power physical node dependent on information node i; I D (i) is the node weight degree centrality index;
[0032] (2) Calculate the betweenness centrality index of node weights:
[0033]
[0034] I B (i) = μ i ·p i
[0035] In the formula, is the betweenness center line of information node i; μ i is the betweenness importance of information node i; I B (i) is the node weight betweenness centrality index;
[0036] (3) Normalization processing:
[0037]
[0038] In the formula, I D.max and I D.min are the maximum and minimum values of the node weight degree centrality index among all nodes respectively; I B.max and I B.min are the maximum and minimum values of the node weight betweenness centrality index among all nodes respectively; and are the normalized weight degrees and weight betweenness respectively;
[0039] Combining the above two weight indicators, the comprehensive centrality index of the node weights of the three-layer interconnected network model of the power cyber-physical system is defined as:
[0040]
[0041] In the formula, α represents the importance weight coefficient of the system-dependent nodes; I B-D (i) is the comprehensive centrality index of the weights of the dependent nodes.
[0042] Furthermore, the simulation verification is carried out by building an IEEE 57-node system through MATLAB software, simulating different cyber-physical collaborative attack strategies and the simulation node cascading failure model, and analyzing the node survival rate performance index of the system when suffering continuous attacks or failures.
[0043] Furthermore, the different cyber-physical collaborative attack strategies include:
[0044] (1) A random attack strategy based on the random node path;
[0045] (2) A deliberate attack strategy based on the attack influence path of the nodes with high comprehensive index weights.
[0046] In the second aspect, the present invention also discloses an analysis system for the influence path of cyber-physical collaborative attacks, including a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the steps of the foregoing method.
[0047] In the third aspect, the present invention also discloses a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, all the steps of the foregoing method are implemented.
[0048] The present invention provides a method for analyzing the influence path of cyber-physical collaborative attacks based on the vulnerability of system critical nodes. By constructing a three-layer interconnected network model of power physics, information, and business control systems, and proposing a node dependence framework and a cascading failure evolution model, it is possible to accurately identify the influence path of cyber-physical collaborative attacks and the propagation law of critical node failures, and solve the problems of inaccurate evaluation of the influence of cyber-physical collaborative attacks and insufficient identification of the vulnerability of critical nodes in the prior art. Description of the Drawings
[0049] Figure 1 It is a flowchart of a method for analyzing the influence path of a cyber-physical collaborative attack according to an embodiment of the present invention;
[0050] Figure 2 It is a schematic diagram of the three-layer interconnected network model according to an embodiment of the present invention;
[0051] Figure 3Schematic diagram for analyzing vulnerable links of the power cyber-physical system according to an embodiment of the present invention;
[0052] Figure 4 IEEE 57-node system diagram according to an embodiment of the present invention;
[0053] Figure 5 IEEE 57-scale-free information network topology structure (m = 1) system diagram according to an embodiment of the present invention;
[0054] Figure 6 Flowchart for analyzing vulnerability of attack impact path under different attack strategies according to an embodiment of the present invention;
[0055] Figure 7 Relationship curve diagram of survival rate of key nodes under different attack strategies according to an embodiment of the present invention. Detailed implementation manners
[0056] The present invention will be further clarified below in conjunction with the accompanying drawings and specific implementation manners. It should be understood that the following specific implementation manners are only used to illustrate the present invention and not to limit the scope of the present invention. After reading the present invention, various equivalent modifications of the present invention by those skilled in the art fall within the scope defined by the appended claims of the present invention.
[0057] As Figure 1 shown is a flowchart of a specific embodiment of an information-physical collaborative attack impact path analysis method for node vulnerability in a power system according to the present invention. This embodiment includes the following steps:
[0058] Step S101: Analyze the sources of physical system security incidents caused by information system security threats, summarize information-physical collaborative attack types, and establish a typical attack model;
[0059] Step S102: Establish a single-sided node network layer for each of the power physical system, power information system, and power service control system. Describe the interaction relationship between different single-sided node network layers according to the generalized incidence matrix in the power system. Construct a three-layer interconnected network model using the structure of "physical node - dependent connection edge - information node". Among them, the single-sided nodes include physical nodes and information nodes. A physical node and an information node in the three-layer interconnected network model form a pair of dependent nodes;
[0060] Step S103: Analyze the relationship of the "normal - failure" state transition of dependent nodes, analyze the impact of single-sided node failure on power grid operation, and establish a dependent node cascading failure evolution model;
[0061] Step S104: Propose a weighted comprehensive centrality index that comprehensively considers the importance of key nodes in the primary power physical system and the secondary information system, and estimate the vulnerability of key nodes in the power system;
[0062] Step S105: Based on the power system node cascading failure evolution model and the vulnerability analysis of key nodes in the power system, perform simulations through the IEEE 57-node system to verify the accuracy of the foregoing steps in identifying the impact path of cyber-physical coordinated attacks.
[0063] The following will explain each specific step.
[0064] Step S101 analyzes the sources of physical system security incidents caused by information system security threats, summarizes the types of cyber-physical coordinated attacks in the power system, and establishes two typical attack scenarios; summarizes the types of cyber-physical coordinated attacks faced by the power cyber-physical system, and constructs corresponding models for the internal mechanisms of these attacks. The two typical attack scenarios include:
[0065] 1) Data attack type model:
[0066] The control center in the power cyber-physical system can implement security and stability control functions such as state estimation, load frequency control, and voltage control, and issue control commands to physical nodes in the power physical network through the information-side network, such as adjusting the power output of generators and regulating the tap positions of transformers, so as to complete the corresponding control strategies. Among them, a large amount of multi-source heterogeneous power privacy data, including measurement data and control instructions, is vulnerable to data network attacks. Common data type attacks include False Data Injection Attack (FDIA), which targets electrical privacy data such as voltage / current and power flow, and affects the output of state estimation by manipulating system measurement data, thereby misleading the dispatching control center's judgment of the power physical system and prompting it to issue incorrect operation instructions.
[0067] The AC power flow model of the N-node power system is:
[0068] z = h(x) + e, e ∼ Ν(0, R)
[0069] In the formula, x is the state vector composed of the selected state variable values; z is the measurement vector; e is the measurement noise obeying the Gaussian distribution; h(x) is the measurement function reflecting the system structure and parameters.
[0070] Based on the Weighted Least Squares (WLS) for estimation:
[0071]
[0072] In the formula, h i (x) is the measurement variable z i and the state variable x iThe corresponding measurement function; ω i For the measured variable z i The weight coefficient; W is the weight matrix composed of weight coefficients; Is the estimated value of the corresponding state variable.
[0073] For the power cyber-physical system in which modern physical systems and information systems are highly integrated, professional attackers study the blind area of the traditional Largest Normalized Residual (LNR) detection method, establish a specific attack vector based on the AC power flow measurement equation, and implement a coordinated attack strategy by simultaneously tampering with the measurement vector and the state vector to achieve the injection of false data. Suppose there is a false data vector b designed by a professional attacker. Then, the mathematical model of the false data injection attack (FDIA) against this vector can be expressed as follows:
[0074]
[0075] z a = z + a
[0076] In the formula, and respectively represent the state estimation vectors before and after being attacked by the false data vector b in the system; a represents a specific attack vector based on the tampered state estimation vector and the system measurement equation; z and z a are the measurement vectors before and after being attacked by the attack vector a in the system, respectively.
[0077] Detect the above attack through the LNR detection method, and the result can be expressed as:
[0078]
[0079] In the formula, r and r a are the residuals before and after the FDIA attack, respectively; τ is the LNR detection threshold.
[0080] It can be seen from the above formula that the residual r of the measured equation after being attacked a is within the allowable range of the threshold, indicating that the new FDIA can avoid the traditional LNR detection. The new FDIA attack is both flexible and stealthy. When the power cyber-physical system is stable, it can induce the system to deviate from the normal stable operating state. If an attack is carried out on the automatic generation control system, causing its frequency to drop sharply below the preset safety threshold, it may cause the system to fall into an unstable state due to unnecessary load shedding and other operations.
[0081] 2) Network attack type model:
[0082] For the power cyber-physical system, its stable operation and fast control extremely rely on accurate and highly time-sensitive data support. This requires the power information network to transmit and process a large amount of data collected by power physical devices and operation instructions. Therefore, in addition to the above-mentioned direct tampering with power privacy data or control instructions, professional attackers can also carry out denial-of-service (DoS) attacks by means such as clogging and damaging communication channels. This kind of attack poses an extremely significant risk to the stability of the power physical system. Among common network attack means, there is a kind of DoS attack targeting the transport layer of the information network. Its main attack focus usually concentrates on key components of the power system operation, such as remote terminal units (RTUs) and intelligent electronic devices (IEDs). The attacker causes the device to stop responding and thus unable to work properly by blocking the transmission of measurement information and control instructions in the control system or state equation.
[0083] Compared with the new type of FDIA attack that requires a lot of professional electrical knowledge, has a high implementation difficulty, and has a clear direction, launching a DoS attack does not require strictly designing an attack vector that can avoid bad data detection. Taking the DoS network attack on system sensors as an example, its general continuous-time domain model can be expressed as:
[0084]
[0085] y(t) = Cx(t) + v(t) + a(t)y(t)
[0086] In the formula, x(t) and u(t) respectively represent the system state variables and control inputs; w(t) is the process noise obeying the Gaussian distribution with zero mean; matrix Α is the state transition matrix; Β is the input matrix; y(t) is the measurement data vector provided by the sensor received by the system; matrix C is the observation matrix; v(t) respectively represents the measurement noise, usually assumed to obey the Gaussian distribution with zero mean; when a(t) = 0, it means the system is not under a DoS attack; when a(t) = -1, the system cannot receive the measurement data provided by the sensor, and the control center has to estimate the missing real-time measurement data through historical data and state equations to estimate the true state of the system. When the power cyber-physical system is operating normally, general DoS is difficult to cause obvious damage. However, when the system itself is in other data attack or failure states, the DoS attack may lead to a greater control error, weaken the control effect, and then may cause a new chain failure reaction, resulting in large-scale system stability damage.
[0087] In the embodiment of the present invention, the construction of the three - layer interconnected network model described in step S102 is based on complex network theory. Unilateral node network layers are established for the power physical system, the power information system, and the power service control system respectively. Physical nodes follow the energy flow, and information nodes follow the information flow, forming three relatively independent unilateral node network layers. The unilateral node network layer includes the topological structures (one - to - one node dependence framework), node attributes (information flow and energy flow), etc. of the power information system, the power physical system, and the power service system. The topological structures of the three systems are the same and conform to the one - to - one node dependence framework, including the number of nodes, node position topology, etc.; the attributes of physical nodes are to follow the energy flow law and conform to the power flow constraint; the attributes of information nodes are to follow the information flow constraint and conform to the minimum path constraint; the nodes of the power service system rely on the central information nodes and thus have the same attributes as information nodes. The general incidence matrix in the power CPS is used to characterize the interaction characteristics of different network layers, and a three - layer interconnected network model with a one - to - one node dependence relationship is constructed, as Figure 2 shown, to accurately describe the structural characteristics of the power information - physical system, abstractly simplify and describe the interaction relationships between various nodes in the system, and conduct model validity analysis in combination with complex distributed power CPS scenarios.
[0088] To further simplify the interaction process of the power information - physical system, the three - layer interconnected network model in the present invention adopts a one - to - one node dependence framework of "physical node - dependent connection edge - information node". The connection relationship of power physical nodes is connected according to the actual system situation, and its topological energy flow transmission obeys the power flow distribution. At the same time, each physical node supplies energy to one information node, and the information node can complete the functions of real - time monitoring and remote control of the physical node; the connection between information nodes is a scale - free network connection method. Different from the energy flow of the power physical system, the information flow of the information system propagates through the shortest simplified path; the functions of the power monitoring system are modularly designed and constructed into a network architecture, directly interfacing with the dispatching center node in the information layer, and constructing a unilateral node network model covering the power physical layer, the information layer, and the control layer. Using the incidence matrix theory, the dependence relationship connection edge is used to depict the dynamic process of physical nodes transmitting collected data to information nodes and information nodes sending control instructions to physical nodes.
[0089] The mathematical modeling of the three - layer interconnected network model is based on complex network theory. In a power information - physical system containing n nodes, the power physical node set V p ={1, 2, …, n} is composed of nodes with different functional characteristics such as power generation, power transformation, and load. The line set in the power system is represented by the physical connection edge E p , and the formed connected graph G p =(V p , E p) can describe the topology of the power physical layer. Taking the incidence matrix A p to represent the topological relationship between different nodes:
[0090]
[0091] where a ij is the matrix element. Without considering the characteristics and properties of the lines between different levels, the lines in the same direction are merged and simplified, only reflecting the most basic connection relationship - that is, whether there is a connection. When there is a stable connection relationship between nodes i and j, then a ij = 1; otherwise, take the element a ij = 0.
[0092] Based on the one-to-one node dependence framework, the information node set V c = {1, 2,..., n} includes the source information node Vc-s and the central information node Vc-c, that is, V c = (V c-s , V c-c ); Different from the physical connection edge relationship that conforms to the power flow distribution between power physical nodes, the information connection edge E c between information nodes adopts a scale-free network connection, represented by the incidence matrix A c :
[0093]
[0094] where b ij is the matrix element. When there is a stable connection relationship between nodes i and j, then b ij = 1; otherwise, take the element b ij = 0.
[0095] For a power system with n information-physical nodes, which follows the one-to-one node model framework, the failure of any one-side node will cause the failure of its dependent node, and its stable connection relationship will turn into a disconnection relationship. After abstracting and processing the above model, the connection state between information-physical nodes is obtained, and it can be represented by the physical-information incidence matrix A p-c as:
[0096]
[0097] where A p-c represents an incidence matrix based on the connection relationship between the information network layer and the physical network layer, reflecting the most basic connection relationship between information-physical nodes. When nodes i and j are connected, the element c ij = 1; otherwise c ij = 0.
[0098] The network adjacency matrix of the power physical system, the network adjacency matrix of the power information system, and the multi-layer network adjacency matrix are spliced to form a topological mathematical model of the power information-physical system, which is represented by the topological adjacency matrix A:
[0099]
[0100] In the formula, matrix A p and A c are the adjacency matrix of the physical layer and the adjacency matrix of the information layer respectively; A p-c is the adjacency matrix established between the power grid and the information network based on the deep integration of the primary system and the secondary system.
[0101] In the embodiment of the present invention, step S103 analyzes the relationship of the "normal-failure" state transition of the dependent nodes. In the three-layer interconnected network model of the power information-physical system, both the information nodes and the physical nodes have two states: normal and failure, as Figure 3 shown. The information nodes and the physical nodes have the ability to transition between the normal state and the failure state, and the state change of the physical nodes is restricted by the state of the information nodes. In particular, the failure state of the information nodes may induce related physical nodes to enter the failure state.
[0102] When an accidental fault occurs in the power physical system, such as when the branch power flow exceeds the limit, it is likely to cause:
[0103] 1) If the information node fails, communication between its adjacent information nodes is impossible, and the information connection edge fails E c ; when the information node fails, it will be unable to execute the established control function, and as a result, the physical nodes directly related to the information node will also lose their effectiveness.
[0104] 2) If the physical node fails, the dependent information node loses its function and cannot complete subsequent operations, such as adjusting the generator output or shedding load, etc. This may lead to cascading failure events in the system, and in severe cases, it may even cause the collapse of the entire system.
[0105] In step S104 of this embodiment, by extracting the power flow characteristic parameters of the power physical system nodes and the topological characteristic parameters of the information system network, a weighted comprehensive centrality index that comprehensively considers the vulnerability of the key nodes of the primary power physical system and the secondary information system is proposed. The comprehensive centrality index of each node is calculated and a sequence list is formed to identify the most vulnerable key nodes in the power information-physical system, so as to evaluate the vulnerability of the key links of the system.
[0106] Professional attackers usually design attack vectors with the aim of maximizing the disruption of the stability of the power cyber-physical system. Therefore, their attack impact paths are often based on high-vulnerability nodes in the power cyber-physical system. To quantify the importance of critical nodes in the system, the present invention extracts the power flow characteristic parameters of nodes in the power physical system and the network topology characteristic parameters of the information system, and combines the node weight degree centrality index and the weight betweenness centrality index to propose a weight comprehensive centrality index to evaluate the vulnerability of the power cyber-physical system.
[0107] The degree of a node is defined as the number of edges directly connected to that node:
[0108]
[0109] In the formula, deg(i) is the degree of node i; N is the scale of the complex network; N - 1 represents the maximum possible degree in this network. C D (i) is the degree centrality of node i, which reflects the local importance of the node in a single-side network but cannot reflect its global importance in a multi-layer system.
[0110] In the cascading failure modeling of the power cyber-physical system (CPS), the failure of high-degree information nodes will trigger the failure of more information connection edges, thus causing a major impact on the integrity of the network topology. However, based on the power information system network and the power physical system network topology structures characterized by different node connection methods, the connection edge situations of the same node in different single-side networks are different. Considering that in the three-layer interconnected network model of the power cyber-physical system, power information nodes play a control role for power physical nodes during failure, by adjusting the power flow characteristic parameters of physical nodes, such as the output power p G and the load level p L , the stable and secure operation of the power physical system can be ensured. Therefore, the importance of power physical nodes can be determined by their adjustable power flow characteristic parameters.
[0111] The mathematical expression of the node weight degree centrality index is specifically as follows:
[0112]
[0113] I D (i) = η i p i
[0114] In the formula, is the degree centrality of information node i; η i is the degree importance of information node i; p i is the adjustable power flow characteristic parameter of the power physical node dependent on information node i; I D(i) is the node weight degree centrality index.
[0115] To characterize the global criticality of nodes, the betweenness is defined as follows:
[0116]
[0117] In the formula, δst is the number of all paths between nodes s and t; δ st (i) is the number of nodes passed from node s to t through node i; C B (i) is the betweenness centrality of node i.
[0118] In the three-layer interconnected network model of the power cyber-physical system proposed in the present invention, since the transmission between information nodes follows the shortest path principle, the betweenness can better reflect the criticality of information nodes in the information network topology. Combining with the adjustable power flow characteristic parameters of the related power physical nodes, a betweenness centrality index of node weight is constructed:
[0119]
[0120] In the formula, is the betweenness center line of information node i; μ i is the betweenness importance of information node i; I B (i) is the node weight betweenness centrality index.
[0121] For convenient analysis and comparison, first, the above node weight degree centrality index I D (i) and the node weight betweenness centrality index I B (i) are normalized:
[0122]
[0123] In the formula, I D.max and I D.min are the maximum and minimum values of the weight degree centrality index among all nodes respectively; I B.max and I B.min are the maximum and minimum values of the weight betweenness centrality index among all nodes respectively; and are the normalized weight degrees and weight betweenness respectively.
[0124] Combining the above two weight indexes, the node weight comprehensive centrality index of the three-layer interconnected network model of the power cyber-physical system is defined as:
[0125]
[0126] In the formula, α represents the importance weight coefficient of the system-dependent nodes; I B-D(i) is the comprehensive centrality index of dependent node weights.
[0127] The comprehensive centrality index of dependent node weights aims to characterize the criticality and vulnerability characteristics of different nodes in the influence path of cyber-physical collaborative attacks in the power system. This index is based on the importance evaluation of nodes in the primary physical system and the secondary information system, and combines the dependence relationship between the two for weighted comprehensive calculation, so as to quantify the criticality and vulnerability of nodes in the evolution process of system cascading failures. Through this index, the status of key nodes in the influence path and their failure propagation characteristics can be clarified, and then the structural and directional characteristics of the attack influence path can be revealed, providing a scientific basis for analyzing the propagation mechanism and scope of cyber-physical collaborative attacks, and providing theoretical support for the optimization design of subsequent defense strategies.
[0128] In this embodiment, step S105 is based on the power cyber-physical system node cascading failure influence evolution model and the power system node vulnerability analysis, and is simulated through the IEEE 57-node system, as Figure 4 shown, where the numbers 1-57 respectively represent the node numbers in the IEEE 57-node system, and the nodes connected to the symbol representing the generator are power generation nodes, to verify the accuracy of the proposed method in identifying the influence path of cyber-physical collaborative attacks, realize the accurate identification and evaluation of cyber-physical collaborative attacks in the power cyber-physical system, and effectively improve the security and controllability of the system. In a specific embodiment, the cyber-physical collaborative attack influence path analysis method of the present invention is verified on the IEEE 57-node system, as Figure 5 shown, and the specific process is as follows.
[0129] Select MATLAB as the simulation environment, establish a primary-side power network model based on the IEEE 57-node system, construct a one-to-one dependence relationship between information nodes and power nodes based on the three-layer interconnected network model of the power cyber-physical system proposed by the present invention, and generate a scale-free network with m = 1 as the secondary-side information network, as Figure 6 shown, where m = 1 is the number of edges of each newly added node, and its node label is the same as Figure 4 that, representing the information node with the same label as the physical node, which conforms to the one-to-one dependent node framework. Based on the system key node vulnerability evaluation model, calculate three key indicators of weighted degree, weighted betweenness, and weighted synthesis respectively as the evaluation results of the system node vulnerability links, and use the information node with the largest weighted degree as the information system dispatching control center, and its functional modules constitute the power monitoring service control layer.
[0130] To further study the vulnerability of the cyber-physical power system under cyber-physical power attacks and the impact path of cascading failures caused by the failure of critical nodes, the present invention selects the node survival rate as a performance index to measure the network's performance when under attack or failure. The node survival rate reflects the time it takes for the network to recover from the failure state to the normal state. Generally, when the cyber-physical power system is attacked, the corresponding nodes and connecting edges completely fail, and the probability of large-scale cascading failure accidents occurring in the network decreases as the remaining topological structure conditions improve.
[0131] The present invention verifies the accuracy of the collaborative attack impact path analysis method based on the vulnerability of critical nodes in the cyber-physical power system by simulating the attacks of different attackers on the vulnerable links of critical nodes in the cyber-physical power system and the selection of impact paths. The specific process is as Figure 7 shown. To simulate the possible cyber-physical collaborative attacks in reality, a collaborative attack strategy is first formulated, including: (1) a random attack strategy based on random node paths, and (2) a deliberate attack strategy based on the attack impact path of nodes with high-weight comprehensive indicators. Among them, the random attack strategy randomly makes a certain number of system nodes fail, and the deliberate attack strategy with high-weight comprehensive indicators sorts the system nodes according to the corresponding indicators and then removes the same number of system nodes with high indicators. Since the attack protection levels for power balance nodes (corresponding to node number 1) and dispatching center nodes (corresponding to node number 12) in the cyber-physical power system are relatively high, and general cyber-physical collaborative attacks cannot easily directly damage them, these two nodes are not attacked in the above attack strategies.
[0132] Based on the comprehensive experimental results, the following conclusions can be drawn: From Figure 7 it can be seen that as the number of attacks continuously increases, the node survival rates of the cyber-physical power system under different attack impact paths all continuously decrease. Among them, the node survival rate under the deliberate attack impact strategy decreases from 94.83% in the first time to 63.79% in the tenth time. Under the deliberate attack impact strategy, that is, under the attack node path sorted according to the weight comprehensive centrality index proposed in the present invention, the node survival rate rapidly drops from 93.10% in the first time to 58.62% in the tenth time. After the last attack, the impact of network vulnerability caused by the deliberate attack impact strategy is 11.89% higher than that of the deliberate attack impact strategy. Under the same attack, the maximum difference in the node survival rate under the deliberate attack impact strategy compared to the deliberate attack impact strategy can reach 10.35%.
[0133] In summary, the weight comprehensive centrality index proposed in the present invention can accurately identify the vulnerability of system critical nodes. If the node security protection on the attack impact path of high-weight comprehensive indicators is emphasized in reality, it will help improve the security and stability of the cyber-physical power system and avoid large-scale system cascading failures caused by cyber-physical collaborative attacks.
Claims
1. A method for analyzing the impact path of cyber-physical coordinated attacks, characterized in that: include: Analyze the sources of physical system security incidents caused by information system security threats, summarize the types of information-physical coordinated attacks based on the sources, and establish corresponding typical attack models for the types of information-physical coordinated attacks; Establish the unilateral node network layers of the power physical system, power information system and power business control system respectively, describe the interactive relationship of different unilateral node network layers according to the universal association matrix in the power system, and construct a three-layer Internet network model using the structure of physical node-dependent connection edge-information node; among which, the unilateral nodes include physical nodes and information nodes, and a physical node and an information node in the three-layer Internet network model constitute a pair of dependent nodes; Analyze the relationship between normal and failure state transitions of dependent nodes in the three-layer interconnected network model, analyze the impact of single-side node failure on power grid operation, and establish a dependent node cascading failure evolution model based on the relationship between state transitions and the impact on power grid operation; A weighted comprehensive centrality index that comprehensively considers the importance of key nodes of the primary physical system and secondary information system of the power system is proposed, and the vulnerability of key nodes of the power system is estimated based on the weighted comprehensive centrality index; Based on the cascading failure evolution model of power system nodes and the vulnerability analysis of key nodes in the power system, an impact path of cyber-physical collaborative attack is constructed, and simulation verification is carried out on the impact path of cyber-physical collaborative attack.
2. The impact path analysis method according to claim 1, characterized in that: The typical attack model includes a data attack type model and a network attack type model. The typical attack model records the impact analysis on the power system under different information-physical collaborative attacks.
3. The impact path analysis method according to claim 2, characterized in that: The single-sided node network layer includes a structure and node attributes. Physical nodes on the single-sided node network layer follow energy flow, and information nodes follow information flow.
4. The impact path analysis method according to claim 3, characterized in that: The single-side node network layer constructs a three-layer interconnected network model of the power cyber-physical system based on the universal association matrix in the power cyber-physical system. The specific steps include: (1) In a power cyber-physical system containing n nodes, the set of power physical nodes is represented by V p ={1,2,…,n},E p represents the physical connection edge, G p =(V p ,E p ) represents the connected graph, with the incidence matrix A p Represents the topological relationship between different nodes: In the formula, a ij is a matrix element. When there is a stable connection between nodes i and j, then a ij =1; otherwise, take element a ij =0; (2) Based on the one-to-one node dependency framework, the information node set V c ={1,2,…,n} including source information node V c-s and the central information node V c-c , that is, V c =(V c-s ,V c-c ); Different from the physical connection edge relationship between power physical nodes that conforms to the power flow distribution, the information connection edge E between information nodes c Using scale-free network connections, the correlation matrix A c express: Where b ij is a matrix element; when there is a stable connection between nodes i and j, then b ij =1; otherwise, take element b ij =0; (3) For a power system with n cyber-physical nodes, it follows a one-to-one node model framework. The failure of a node on either side will cause the failure of its dependent node, and its stable connection relationship will be converted into a disconnected relationship. After abstracting the above model, the connection status between cyber-physical nodes is obtained, and the physical-information association matrix A is used. p-c It can be expressed as: In the formula, A p-c Represents an association matrix based on the connection relationship between the information network layer and the physical network layer, reflecting the most basic information physical node connection relationship. When nodes i and j are connected, element c ij =1; otherwise c ij =0; (4) The network adjacency matrix of the power physical system, the network adjacency matrix of the power information system, and the multi-layer network adjacency matrix are spliced together to form the topological mathematical model of the power information physical system, which is represented by the topological adjacency matrix A: In the formula, the matrix A p and A c are the physical layer adjacency matrix and the information layer adjacency matrix respectively; A p-c It is an adjacency matrix established between the power grid and the information network based on the deep integration of the primary system and the secondary system.
5. The impact path analysis method according to claim 4, characterized in that: By analyzing the relationship framework of the mutual conversion between normal and failure states of dependent nodes, the impact of unilateral node failure on power grid operation is analyzed, and a dependent node chain failure impact evolution model is established based on the impact of unilateral node failure on power grid operation.
6. The impact path analysis method according to claim 5, characterized in that: A weighted comprehensive centrality index that comprehensively considers the vulnerability of key nodes in the primary physical system and secondary information system of the power system is proposed. The comprehensive centrality index of each node is calculated and a sequential list is formed to identify the most vulnerable key nodes in the power information-physical system. The node vulnerability of the power information-physical system is estimated based on the weighted comprehensive centrality index.
7. The impact path analysis method according to claim 6, characterized in that: The weighted comprehensive centrality index is obtained based on the power physical system node flow characteristic parameters and the information system network topology characteristic parameters. The specific calculation steps include: (1) Calculate the degree centrality index of node weight: I D (i)=η i p i In the formula, is the degree centrality of information node i; η i is the degree importance of information node i; p i I is the adjustable power flow characteristic parameter of the information node i that depends on the power physical node; D (i) is the node weight degree centrality index; (2) Calculate the betweenness centrality index of node weight: I B (i)=μ i ·p i In the formula, is the betweenness centerline of information node i; μ i is the betweenness importance of information node i; I B (i) is the node weight betweenness centrality index; (3) Normalization processing: In the formula, I D.max and I D.min are the maximum and minimum values of the weight degree centrality index among all nodes respectively; I B.max and I B.min are the maximum and minimum values of the weighted betweenness centrality index among all nodes respectively; and are the normalized weight degree and weight betweenness respectively; Combining the above two weight indicators, the node weight comprehensive centrality index of the three-layer interconnected network model of the power information-physical system is defined as: In the formula, α represents the importance weight coefficient of the system dependent nodes; I B-D (i) is the comprehensive centrality index of dependent node weights.
8. The impact path analysis method according to claim 7, characterized in that: The simulation verification uses MATLAB software to build an IEEE 57-node system, simulates different cyber-physical collaborative attack strategies and simulates node chain failure models, and analyzes the node survival rate performance indicators of the system when it is subjected to continuous attacks or failures.
9. The impact path analysis method according to claim 8, characterized in that: The different cyber-physical coordinated attack strategies include: (1) Random attack strategy based on random node paths; (2) Deliberate attack strategy based on the attack impact path of high-weight comprehensive indicator nodes.
10. An impact path analysis system for cyber-physical coordinated attacks, characterized in that: include: Typical attack models are used to analyze the sources of physical system security incidents caused by cyber system security threats, and to summarize the types of cyber-physical coordinated attacks based on the sources; The single-side node network layer includes structure and node attributes. Physical nodes on the single-side node network layer follow energy flow, and information nodes follow information flow. Single-side nodes include physical nodes and information nodes, which are used to build a three-layer Internet model. The three-layer interconnected network model describes the interactive relationship between different single-side nodes in the network layer based on the universal association matrix in the power system, and adopts the structure of physical node-dependent connection edge-information node. In the three-layer interconnected network model, a physical node and an information node form a pair of dependent nodes. The dependent node cascading failure evolution model is used to analyze the relationship between the normal-failure state transition of dependent nodes in the three-layer interconnected network model, and analyze the impact of unilateral node failure on the operation of the power grid based on the relationship; A key node vulnerability assessment module is used to propose a weighted comprehensive centrality index that comprehensively considers the importance of key nodes of the primary physical system and secondary information system of the power system, and analyze the vulnerability of key nodes of the power system based on the weighted comprehensive centrality index; The simulation verification module constructs a physical-information collaborative attack for simulation verification based on the power system node cascading failure evolution model and the vulnerability analysis of key nodes in the power system.
11. The impact path analysis system according to claim 10, characterized in that: The typical attack model includes a data attack type model and a network attack type model. The typical attack model records the impact analysis on the power system under different information-physical collaborative attacks.
12. The impact path analysis system according to claim 11, characterized in that: The single-side node network layer constructs a three-layer interconnected network model of the power information-physical system according to the universal association matrix in the power information-physical system. The specific steps include: (1) In a power cyber-physical system containing n nodes, the set of power physical nodes is represented by V p ={1,2,…,n},E p represents the physical connection edge, G p =(V p ,E p ) represents the connected graph, with the incidence matrix A p Represents the topological relationship between different nodes: In the formula, a ij is a matrix element. When there is a stable connection between nodes i and j, then a ij =1; otherwise, take element a ij =0; (2) Based on the one-to-one node dependency framework, the information node set V c ={1,2,…,n} including source information node V c-s and the central information node V c-c , that is, V c =(V c-s ,V c-c ); Different from the physical connection edge relationship between power physical nodes that conforms to the power flow distribution, the information connection edge E between information nodes c Using scale-free network connections, the correlation matrix A c express: Where b ij is a matrix element; when there is a stable connection between nodes i and j, then b ij =1; otherwise, take element b ij =0; (3) For a power system with n cyber-physical nodes, it follows a one-to-one node model framework. The failure of a node on either side will cause the failure of its dependent node, and its stable connection relationship will be converted into a disconnected relationship. After abstracting the above model, the connection status between cyber-physical nodes is obtained, and the physical-information association matrix A is used. p-c It can be expressed as: In the formula, A p-c Represents an association matrix based on the connection relationship between the information network layer and the physical network layer, reflecting the most basic information physical node connection relationship. When nodes i and j are connected, element c ij =1; otherwise c ij =0; (4) The network adjacency matrix of the power physical system, the network adjacency matrix of the power information system, and the multi-layer network adjacency matrix are spliced together to form the topological mathematical model of the power information physical system, which is represented by the topological adjacency matrix A: In the formula, the matrix A p and A c are the physical layer adjacency matrix and the information layer adjacency matrix respectively; A p-c It is an adjacency matrix established between the power grid and the information network based on the deep integration of the primary system and the secondary system.
13. The impact path analysis system according to claim 12, characterized in that: In the key node vulnerability assessment module, the weighted comprehensive centrality index is obtained according to the power physical system node flow characteristic parameters and the information system network topology characteristic parameters. The specific calculation steps include: (1) Calculate the degree centrality index of node weight: I D (i)=η i p i In the formula, is the degree centrality of information node i; η i is the degree importance of information node i; p i I is the adjustable power flow characteristic parameter of the information node i that depends on the power physical node; D (i) is the node weight degree centrality index; (2) Calculate the betweenness centrality index of node weight: I B (i)=μ i ·p i In the formula, is the betweenness centerline of information node i; μ i is the betweenness importance of information node i; I B (i) is the node weight betweenness centrality index; (3) Normalization processing: In the formula, I D.max and I D.min are the maximum and minimum values of the weight degree centrality index among all nodes respectively; I B.max and I B.min are the maximum and minimum values of the weighted betweenness centrality index among all nodes respectively; and are the normalized weight degree and weight betweenness respectively; Combining the above two weight indicators, the node weight comprehensive centrality index of the three-layer interconnected network model of the power information-physical system is defined as: In the formula, α represents the importance weight coefficient of the system dependent nodes; I B-D (i) is the comprehensive centrality index of dependent node weights.
14. The impact path analysis system according to claim 13, characterized in that: The simulation verification module builds the IEEE 57 node system through MATLAB software, simulates different cyber-physical coordinated attack strategies and simulates node chain failure models, and analyzes the node survival rate performance indicators of the system when it is subjected to continuous attacks or failures.
15. The impact path analysis system according to claim 14, characterized in that: The different cyber-physical coordinated attack strategies include: (1) Random attack strategy based on random node paths; (2) Deliberate attack strategy based on the attack impact path of high-weight comprehensive indicator nodes.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to claims 1 to 9 are implemented.
Citation Information
Patent Citations
Power system resilience evaluation method considering network attack
CN114662328A
Electric power information physical system vulnerability analysis method and device and storage medium
CN115587721A
Method, device and equipment for calculating vulnerability of combat network
CN117217598A
Information physical system key node identification method for coping with network attack
CN117729058A
Cited By
System reliability evaluation method based on time sequence multilayer complex network
CN120911118A