Construction method of attack and defense model of electric power system

By conducting structural topology modeling and historical intrusion data analysis on the power system, combining offensive and defense simulation and game analysis, identifying and repairing weaknesses, the problem of existing power system defense models independent of the attack model is solved, and the dynamicity and comprehensive security of defense are improved.

CN120050103AInactive Publication Date: 2025-05-27JIAN JIZHOU DISTRICT HEXING TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510212546.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing power system defense model is independent of the attack model, lacks attack and defense interaction analysis, and has unidentified weaknesses or vulnerabilities, resulting in defects in defense strategies and system vulnerability.

Method used

By obtaining power system structure data for topological modeling, identifying attack surfaces and vulnerabilities, combining historical intrusion data for attack path analysis and simulation, generating offensive and defense strategy game data, and performing weakness identification and vulnerability repair, and dynamically adjusting defense measures.

Benefits of technology

It improves the accuracy of offensive and defensive modeling and the dynamic nature of defense, enhances the understanding of the power system structure and offensive and defensive preparation, and improves the attack response capabilities and the comprehensive security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050103A_ABST
    Figure CN120050103A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of model construction, in particular to a construction method of an attack and defense model of a power system. The method comprises the following steps: acquiring structural data of a power system; performing structure topology modeling on the power system structure data to generate power system topology structure modeling data; carrying out attack surface identification on the modeling data of the topological structure of the power system to generate attack point data of the structure of the power system; performing power system network security modeling based on the power system structure attack point data and the power system topological structure modeling data to generate power system network security modeling data; acquiring historical intrusion data of the power system; and performing attack path analysis on the historical intrusion data of the power system to generate attack type path data of the power system. According to the method, through combination of electric power system structure modeling, historical intrusion data analysis, attack simulation, game analysis and vulnerability repair, the accuracy of attack and defense modeling and the dynamic performance of defense are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of model construction, and particularly to a method for constructing an attack and defense model of a power system. Background Art

[0002] In the early days, power systems mainly relied on physical security measures. However, with the wide application of information technology, power systems began to adopt intelligent means such as automation, remote monitoring, and data transmission, which also introduced new network attack risks. With the rapid development of computer technology and communication networks, the control systems of power systems have gradually been networked, forming a smart grid based on SCADA (Supervisory Control and Data Acquisition) and EMS (Energy Management System). At this time, the security of power systems mainly focused on the prevention of physical attacks, ignoring the attack threats in the information network. Power systems have gradually moved towards full digitization and have begun to be affected by threats such as network attacks and information leakage. Research on attack and defense of power systems has gradually emerged, especially the monitoring and protection of information flow and control flow in power networks. Scholars have proposed methods based on game theory, complex network analysis, attack-defense models, etc. to simulate and evaluate the security of power systems and attack and defense strategies. However, currently, traditional power system defense models are usually independent of attack models, lacking interactive analysis of attack and defense. At the same time, attack and defense models often have unrecognized weaknesses or vulnerabilities, resulting in defects in defense strategies and vulnerabilities of the system. Summary of the Invention

[0003] Based on this, it is necessary to provide a method for constructing an attack and defense model of a power system to solve at least one of the above technical problems.

[0004] To achieve the above object, a method for constructing an attack and defense model of a power system, the method includes the following steps:

[0005] Step S1: Obtain power system structure data; perform structural topology modeling on the power system structure data to generate power system topology structure modeling data; perform attack surface identification on the power system topology structure modeling data to generate power system structure attack point data; perform power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate power system network security modeling data;

[0006] Step S2: Obtain power system historical intrusion data; perform attack path analysis on the power system historical intrusion data to generate power system attack type path data; perform attack intensity and strategy simulation on the power system network security modeling data through the power system attack type path data to generate power system attack simulation data; perform model encapsulation on the power system attack simulation data to generate a power system attack simulation model;

[0007] Step S3: Based on the historical attack type data of the power system, perform attack fault tolerance on the key attack nodes in the power system attack type path data to generate a power system defense simulation model; conduct game analysis on the power system defense simulation model and the power system attack simulation model to generate power system attack and defense strategy game data;

[0008] Step S4: Identify attack and defense weaknesses in the power system attack and defense strategy game data to obtain attack and defense weakness identification data; based on the attack and defense weakness identification data, repair attack and defense vulnerabilities in the power system attack simulation model and the power system defense simulation model to generate a power system attack and defense evolution model.

[0009] Through obtaining the power system structure data and performing topological modeling, the present invention can clearly display the network structure of the power system, identify potential attack surfaces and vulnerable points. The key to this step lies in generating the security modeling data of the power system, providing accurate basic information for subsequent attack analysis and defense strategy design, and fundamentally enhancing the understanding of the power system structure and attack and defense preparations. Analyzing the attack paths using the historical intrusion data of the power system can reveal the attacker's behavior patterns and attack methods, providing a prediction basis for future attacks. Through the simulation based on the attack paths, the attack intensity and strategies can be accurately simulated, the attack response ability can be improved, potential threats can be identified in advance and targeted defense deployments can be made. This process enhances the realism of the attack simulation and the system emergency response ability. By performing fault tolerance on the key attack nodes based on the historical attack type data, the fault tolerance ability of the system can be improved and the vulnerability of the key nodes can be reduced. At the same time, generating a defense simulation model and conducting game analysis with the attack simulation model can evaluate the effectiveness of the attack and defense strategies in real time, ensuring the adaptability and flexibility of the defense measures in the face of different attack scenarios, thereby improving the comprehensive security of the power system in the dynamic attack and defense environment. Identifying weaknesses in the attack and defense strategy game data can reveal potential weak links in the defense system, providing a basis for further security enhancement. By repairing vulnerabilities based on the weakness identification data, the defense measures can be dynamically adjusted to ensure the resilience of the power system in the face of constantly changing attack means. The generation of the attack and defense evolution model promotes the continuous self-optimization and evolution of the system, thereby improving the long-term defense ability and enabling the power system to cope with new attack threats. Therefore, the present invention improves the accuracy of the attack and defense modeling and the dynamics of the defense by combining power system structure modeling, historical intrusion data analysis, attack simulation, game analysis and vulnerability repair.

[0010] Preferably, step S1 includes the following steps:

[0011] Step S11: Obtain the power system structure data;

[0012] Step S12: Perform topological structure analysis on the power system structure data to generate power system structure topology data;

[0013] Step S13: Perform structural topology modeling on the power system according to the power system structure topology data to generate power system topology structure modeling data; identify the attack surface of the power system topology structure modeling data to generate power system structure attack point data;

[0014] Step S14: Perform power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate power system network security modeling data.

[0015] The present invention obtains the power system structure data and performs topology analysis to ensure that the overall architecture of the power system is clearly presented, facilitating subsequent analysis and processing. Through power system topology structure modeling and attack surface identification, potential attack points in the system can be identified, which is a key step in improving the security of the power system. Combining the attack point data and topology structure modeling to construct the network security model of the power system helps to strengthen the defense measures targeted, thereby reducing the risk of the power system being attacked. The power system network security modeling data can provide accurate basis for security policies, enhancing the system's response ability and adaptability to emergencies.

[0016] Preferably, the attack surface identification of the power system topology structure modeling data includes:

[0017] Extract node data from the power system topology structure data to obtain node data;

[0018] Extract edge connection information from the power system topology structure modeling data according to the node data to obtain edge connection data;

[0019] Construct the power system line through the edge connection data and the node data to obtain the power system line data;

[0020] Identify the attack surface according to the power system line data, identify potential attack paths, and thus generate power system potential attack path data;

[0021] Identify the structural attack points in the power system according to the power system potential attack path data to the power system line data, and thus obtain the power system structure attack point data.

[0022] Through node data extraction and edge connection information extraction, the present invention can comprehensively understand the topological structure of the power system, providing a complete view for subsequent attack surface identification and protection measures, which ensures a profound analysis of the structure of the power network from all levels of the system. By constructing the power system lines and combining node data and edge connection data, potential attack paths in the power system can be accurately identified, which helps to discover attack surfaces from multiple perspectives and avoid overlooking any attack routes. According to the identified potential attack paths, the system can further identify existing structural attack points, and this process enhances the security defense and early warning capabilities of the power system. After identifying the attack points, targeted protection measures can be enhanced to reduce the risk of being attacked. By clearly identifying the potential attack paths and structural attack points in the power system, accurate data support can be provided for the network security emergency response of the power system, which enables the system to be protected and restored more quickly and effectively when attacked. After identifying the attack paths and attack points, it can help optimize the allocation of security resources in the power system, concentrate efforts on protecting the most vulnerable links, and thus improve the overall security.

[0023] Preferably, step S2 includes the following steps:

[0024] Step S21: Obtain the historical intrusion data of the power system;

[0025] Step S22: Classify the historical intrusion data of the power system by attack type to generate the historical attack type data of the power system;

[0026] Step S23: Analyze the attack paths of the historical intrusion data of the power system according to the historical attack type data of the power system to generate the attack type path data of the power system;

[0027] Step S24: Simulate the attack intensity and strategy on the network security modeling data of the power system through the attack type path data of the power system to generate the attack simulation data of the power system; encapsulate the attack simulation data of the power system to generate the attack simulation model of the power system.

[0028] By acquiring and classifying historical intrusion data of the power system, the present invention can clearly understand past attack types and patterns, providing valuable reference data for subsequent attack path analysis and protection strategies. This classification helps identify various types of attack behaviors and enhances the system's ability to identify different types of attacks. By performing attack path analysis on the historical attack type data of the power system, it is possible to comprehensively display the attacker's action route and the process of the attack, revealing potential system vulnerabilities. This provides a basis for subsequent defense measures and strategy formulation, and helps to identify and repair vulnerabilities in advance. Based on the attack path data, performing attack intensity and strategy simulation enables the power system to comprehensively evaluate the risks and impacts under different attack scenarios. This simulation provides a scientific basis for defense decisions and helps to formulate reasonable emergency response and protection strategies. By generating an attack simulation model for the power system, it is possible to combine the attack path, attack type, and protection strategy in a system model, facilitating long-term tracking and application. These simulation models can be used for future intrusion detection, attack and defense drills, and dynamic adjustment of network security strategies. Through the attack simulation data and models, it is possible to further analyze the vulnerable points of the power system when facing different attacks, and then optimize the existing defense strategies. This data-driven optimization greatly improves the protection ability of the power system and can effectively respond to new types of attacks. By encapsulating the attack simulation model, it can be applied to the real-time monitoring and warning system of the power system. The model can quickly respond to potential threats, detect abnormal behaviors in advance, and trigger corresponding defense measures.

[0029] Preferably, the attack intensity and strategy simulation of the power system network security modeling data based on the power system attack type path data includes:

[0030] Performing feature extraction on the power system attack type path data to generate attack feature data; based on the attack feature data, performing attack path topology analysis on the power system attack type path data to generate attack path topology data;

[0031] Performing vulnerability assessment on the attack path topology data, and based on the assessment results, performing attack impact range analysis on the attack path topology data to generate attack range impact data; based on the attack range impact data, performing key node identification on the power system attack type path data to generate key attack node data;

[0032] Calculating the attack intensity of the key attack node data to generate node attack intensity data; based on the node attack intensity data, performing cascading failure simulation on the power system attack type path data to generate path failure simulation data; performing dynamic analysis of the system response on the path failure simulation data to generate power system response data;

[0033] Performing protection strategy evaluation on the power system response data to generate power system attack simulation data.

[0034] Through feature extraction of attack type path data, the present invention can identify the key features of attack behaviors, providing basic data support for subsequent path analysis, vulnerability assessment, and formulation of protection strategies. This process ensures that the nature and objectives of attacks can be fully understood at the system level. The attack path topology analysis based on attack feature data can accurately restore the attack route and network structure. Through detailed analysis of the attack path, weak links in the system can be identified, providing an important basis for formulating more targeted defense strategies. Vulnerability assessment helps confirm which parts of the system are most vulnerable to attacks, and the impact range of the attack scope on data generation provides the scope of influence caused by these weak links, enabling the power system to identify high-risk areas in advance and take effective defense measures. By identifying key nodes from attack path data, the "key points" in the system can be clarified, and the failure of these nodes will trigger major system failures. Attack intensity calculation provides a quantitative indicator for identifying the potential damage caused by attacks to the system, helping to improve the accuracy and timeliness of responses. Conducting cascading failure simulations can simulate the chain reactions caused by different attack paths, helping to discover multi-level failures triggered by attacks. Through dynamic analysis of system responses, the performance of the system when encountering attacks can be evaluated in real time, providing data support for formulating emergency response and repair measures. Through protection strategy assessment, existing security defense strategies can be optimized based on attack simulation data. The simulation results provide a complete security protection framework for the power system, enabling the defense system to more precisely adapt to various attack situations. System response data can show the recovery ability of the power system after encountering attacks. By analyzing the weaknesses in the recovery process, the redundancy design and recovery mechanism of the system can be further strengthened to ensure that it can quickly resume normal operation after an attack. Through comprehensive simulation of the entire attack path, the power system can identify potential risks globally, layout protection measures in advance, thereby enhancing the overall security and response ability of the system.

[0035] Preferably, the formula for calculating the attack intensity of critical attack node data is specifically as follows:

[0036]

[0037] In the formula, I attack (t,X) represents the calculation result of the attack intensity at the Xth critical node in the system at time t, α i represents the weighting coefficient for the importance of node i, P i (t) represents the load or power demand of node i at time t, β i represents the intensity coefficient of the attack type faced by node i, γ j represents the weighting coefficient for the recovery ability of node j, D j(t) represents the degree of loss of node j, C j represents the recovery ability coefficient of node j, t 0 represents the lower limit of time integration, t 1 represents the upper limit of time integration. n represents the number of parameters related to the attack point intensity, and m represents the number of parameters related to the system recovery ability and loss degree.

[0038] The present invention analyzes and integrates an attack intensity calculation formula, which is designed to quantitatively calculate the attack intensity when a certain key node is attacked within a certain time range (from t 0 to t 1 ). The attack intensity is not only affected by the attack itself, but also by the interaction of factors such as node load, attack type, and node recovery ability. Through integral calculation, the formula takes into account the gradual cumulative effect of the attack in the time dimension, enabling the real-time evaluation of the responses of different nodes to the attack during the attack duration (such as load changes, loss degrees, recovery times, etc.). Among them, the coefficient α i in the formula is used to reflect the importance of different nodes in the power system. For nodes that are crucial to the system (such as key substations or generators), this coefficient is larger, indicating that its impact on system stability is more significant. The introduction of this coefficient enables the system to assign different attack intensity weights to different nodes according to the criticality of the nodes, thereby preferentially protecting more important nodes and improving the anti-attack ability of the system. P i (t) reflects the workload or power demand of the node at a specific moment. The larger the node load, the heavier the power load it undertakes, usually meaning that the node plays a more important role in power transmission. The introduction of the load enables the system to consider the current working pressure of the node when evaluating the attack intensity, and thus identify those nodes that are particularly vulnerable under high load, so as to optimize the protection measures. β i represents the intensity or nature of the attack suffered by the node. Different types of attacks (such as information tampering, physical damage, network intrusion, etc.) have different impacts on the system, and the intensity coefficient is used to quantitatively describe the destructiveness of the attack. Through the quantitative evaluation of different attack types, the defense system can more specifically identify and respond to specific attack patterns, thereby reducing the potential losses caused by the attack. γ j represents the recovery ability of the node, that is, the ability of the node to return to the normal working state after the attack. Nodes with stronger recovery ability have shorter recovery times, and vice versa. The introduction of the recovery ability coefficient helps to distinguish between nodes that recover quickly and those that recover slowly after the attack. By enhancing the protection of nodes with weaker recovery ability, the overall disaster tolerance ability and system recovery speed of the system can be improved. D j(t) represents the degree of loss caused by an attack on a node at a certain moment. The loss can include power supply interruption, data loss, etc. By quantifying the degree of loss, the actual impact of the attack on each node can be clearly identified, thus helping to evaluate the vulnerability of the system and giving priority to those nodes with greater losses when designing defense strategies. C j represents the ease of node recovery. Nodes with stronger recovery capabilities have shorter recovery times, while nodes with poor recovery capabilities require longer recovery times. Through this coefficient, the system can quantify the recovery capabilities of nodes, so as to reasonably allocate resources in defense to ensure that nodes with weaker recovery capabilities receive priority attention and support. Integral term represents the cumulative attack intensity during the attack period (from t 0 to t 1 ). The attack persists over time and gradually affects the states of each node. The integral term can accurately capture this dynamic change. The integration enables the model to consider the cumulative effect of time on the attack intensity, evaluate the comprehensive impact of a long-term attack on nodes, avoid the limitation of only considering a single moment, and make the calculation of attack intensity more comprehensive and accurate. The above formula accurately quantifies the attack intensity of each key node in the power system by comprehensively considering various factors such as the importance of the node, load demand, attack type, recovery ability, and degree of loss. By adjusting the weights of each parameter, the most vulnerable parts of the system can be effectively identified, and then targeted defense measures can be taken to enhance the anti-pressure ability and recovery ability of the power system in the face of complex attacks. This multi-dimensional and dynamic analysis method not only improves the security of the system but also enables real-time adjustment and optimization in practical applications.

[0039] Preferably, step S3 includes the following steps:

[0040] Step S31: Construct a defense strategy based on the historical attack type data of the power system to generate a power system defense strategy; perform key component redundancy design on the key attack nodes in the power system attack type path data according to the power system defense strategy to obtain key component redundancy data;

[0041] Step S32: Use the key component redundancy data to perform attack fault tolerance on the key attack nodes in the power system attack type path data to generate a key node fault tolerance mechanism; encapsulate the power system historical attack type data through the key node fault tolerance mechanism to generate a power system defense simulation model;

[0042] Step S33: Conduct offense-defense simulation on the power system defense simulation model and the power system attack simulation model, and perform power system offense-defense performance evaluation on the results of the offense-defense simulation to generate power system offense-defense performance evaluation data;

[0043] Step S34: Perform a game analysis on the power system defense simulation model and the power system attack simulation model using the power system attack and defense performance evaluation data to generate the power system attack and defense strategy game data.

[0044] The present invention constructs a defense strategy for the power system based on historical attack type data, which can effectively cope with known attack patterns. This strategy is established on the basis of a profound analysis of past attack events, thus ensuring the pertinence and effectiveness of the defense measures. By designing key component redundancy for key attack nodes, it is ensured that when under attack, the key system components can automatically switch to the backup or redundant system, thereby improving the fault tolerance of the system and avoiding the paralysis of the entire system caused by a single point of failure. The design of attack fault tolerance for key nodes can effectively slow down the damage of the attack to the power system. This mechanism ensures that even if some components are attacked, other parts of the system can still operate normally, thus guaranteeing the continuity and stability of power supply. By encapsulating the historical attack type data of the power system through a model and generating a defense simulation model, the defense effect under different attack scenarios can be simulated, which provides reliable basic data for subsequent attack and defense simulations and helps to accurately evaluate the effectiveness of defense measures. Through the attack and defense simulation of the power system defense simulation model and the attack simulation model, the performance of the defense strategy in actual attacks can be comprehensively evaluated. This simulation evaluation helps to discover the weaknesses of the defense strategy and provides a basis for further optimization. Through the game analysis of the attack and defense simulation results, the mutual game between the power system defense and attack can be further analyzed, and the optimal attack and defense strategy combination can be identified. The game analysis not only reveals the reaction of the system under various attack modes but also provides a basis for formulating flexible countermeasures. Through the attack and defense performance evaluation and game analysis, the power system can dynamically adjust the defense strategy according to the simulation results, improving the system's adaptability to new attacks. This flexibility enables the power system to maintain efficient operation in the face of constantly changing attack threats. Through the generated attack and defense strategy game data, the allocation of security resources can be further optimized to ensure that the defense resources are fully utilized in key areas and reduce the overall risk of the system.

[0045] Preferably, the attack fault tolerance for the key attack nodes in the power system attack type path data using the key component redundancy data includes:

[0046] Performing a redundant resource evaluation on the key attack nodes in the power system attack type path data using the key component redundancy data to generate redundant resource evaluation data; calculating the node fault tolerance ability for the redundant resource evaluation data to generate node resource fault tolerance data;

[0047] Optimize the resource allocation for the key attack nodes in the power system attack type path data through the node resource fault tolerance of data pairs, and generate the optimized resource allocation data; design the fault switching strategy for the optimized resource allocation data to generate the node resource fault switching data;

[0048] Balance the node resource load for the node resource fault switching data to generate the node resource balance data; plan the recovery time sequence for the node resource fault switching data according to the node resource balance data to generate the node resource recovery time sequence data; design the emergency response mechanism for the node resource recovery time sequence data, thereby generating the key node fault tolerance mechanism.

[0049] By evaluating the redundant resources of the key components' redundant data, the present invention can assess the redundant resource status of each key node in the system, ensure timely switching to the backup system or component in case of an attack or failure, and avoid single-point failures in the system. This assessment helps to identify and enhance the redundant protection of key nodes in advance, improving the overall reliability of the system. Through the calculation of the node fault tolerance ability, the node resource fault tolerance data is generated, thus providing a quantitative fault tolerance ability assessment for the power system. This data ensures that the system can rely on redundant resources to maintain normal operation under different attack and failure conditions, guaranteeing the continuity and stability of the power system. Based on the node fault tolerance ability, by optimizing the resource allocation, the reasonable configuration of redundant resources among key nodes can be ensured, improving the resource utilization efficiency. This optimization helps to reduce resource waste in case of a failure and ensures that the system can resume normal operation in the shortest time. By designing the fault switching strategy, the switching process under different fault scenarios can be set in advance. This strategy can ensure that the system quickly switches to the backup resources or alternative paths in case of a node failure, minimizing the impact of attacks or failures on the power system and improving the flexibility and response ability of the system. After the node resource fault switching, by performing node resource load balancing, the load is evenly distributed among each node, avoiding a certain node becoming a new weak link due to overload. The load balancing optimization can enhance the stability of the system, enabling the power system to effectively cope with various attack or failure scenarios. Through the node resource recovery timing planning, an efficient recovery sequence can be designed to ensure that the faulty nodes can be recovered according to the priority, thus reducing the time required for the power system to recover. This planning helps to quickly resume normal operation in case of an attack or system failure and reduce the losses during the recovery process. By designing the emergency response mechanism for the recovery timing data, the preset emergency response process can be quickly initiated when an attack occurs, maximizing the shortening of the response time and enhancing the emergency response ability. This mechanism ensures that effective measures can be quickly taken to deal with the situation when the power system is attacked, reducing losses and guaranteeing the stable operation of key areas. Through the effective implementation of the above multiple steps, the finally generated key node fault tolerance mechanism provides multiple guarantees for the power system, enabling the power system to quickly adjust in case of emergencies such as attacks and failures and maintain efficient operation. The optimization of the overall fault tolerance mechanism enhances the resilience of the power system in the face of complex situations and improves the long-term sustainable operation ability of the system.

[0050] Preferably, step S34 includes the following steps:

[0051] Step S341: Confirm the attack time delay of the power system attack simulation model to obtain the attack time delay data; perform the actual attack timeliness analysis on the power system attack simulation model through the attack time delay data to generate the actual attack timeliness data;

[0052] Step S342: Analyze the defense time of the power system defense simulation model to generate defense time data; calculate the attack prevention rate of the power system defense simulation model based on the defense time data to obtain the attack prevention rate data;

[0053] Step S343: Solve the Nash equilibrium according to the actual attack timeliness data and the attack prevention rate data to generate the attack and defense Nash equilibrium data; analyze the bias of the equilibrium point of the attack and defense Nash equilibrium data to generate the power system attack and defense strategy game data.

[0054] Through the identification of attack and defense weaknesses in the power system attack and defense strategy game data, the present invention can timely discover potential security vulnerabilities and weak links in the system. This process helps to accurately locate the deficiencies in the defense strategy and provides key data for subsequent vulnerability repair, thereby enhancing the system's protection ability. Based on the attack and defense weakness identification data, dynamic repair is performed on the power system attack simulation model and the defense simulation model. This repair process ensures that the system can self-adjust according to the changing attack means and defense requirements, avoids the long-term impact of attacks on the power system, and enhances the system's adaptability and resilience in the face of new attacks. Through the repair and optimization of attack and defense vulnerabilities, the attack simulation model and the defense simulation model can be effectively integrated. This integration not only improves the accuracy and comprehensive performance of the model, but also ensures the efficient operation of the power system attack and defense strategy in practical applications, enabling the defense strategy to better cope with different attack scenarios. The power system attack and defense evolution model generated through model integration provides a basis for continuous optimization of the long-term security of the power system. This model can adapt to the evolving attack environment and defense requirements of the power system, help the power system conduct continuous security assessment and optimization, and ensure that the system can still maintain a high level of security and stability under different attack scenarios. The attack and defense evolution model can dynamically adjust and optimize the defense strategy according to the changes in the system security environment, improving the system's reaction speed and adaptability in the face of unknown or new attacks. Through continuous evolution, the system can reduce its dependence on fixed defense strategies and enhance its ability to cope with complex attack and defense situations. Through the dynamic repair of attack and defense vulnerabilities and the integration of the attack and defense evolution model, the security protection ability of the power system is continuously enhanced. This long-term self-optimization mechanism ensures that the power system can always maintain stable and reliable operation in the evolving attack environment, thereby enhancing the long-term sustainability of the power system.

[0055] Preferably, step S4 includes the following steps:

[0056] Step S41: Identify the attack and defense weaknesses in the power system attack and defense strategy game data to obtain the attack and defense weakness identification data; perform attack and defense vulnerability repair on the power system attack simulation model and the power system defense simulation model based on the attack and defense weakness identification data to generate the attack and defense vulnerability dynamic repair data;

[0057] Step S42: Integrate the power system attack simulation model and the power system defense simulation model according to the dynamic repair data of attack and defense vulnerabilities to generate a power system attack and defense evolution model.

[0058] Through the identification of attack and defense weaknesses in the game data of power system attack and defense strategies, the present invention can timely discover potential security vulnerabilities and weak links in the system. This process helps to accurately locate the deficiencies in the defense strategy and provides key data for subsequent vulnerability repair, thereby enhancing the system's protection ability. Based on the data of attack and defense weakness identification, the attack simulation model and the defense simulation model of the power system are dynamically repaired. This repair process ensures that the system can self-adjust according to the changing attack means and defense requirements, avoids the long-term impact of attacks on the power system, and enhances the system's adaptability and resilience in the face of new attacks. Through the repair and optimization of attack and defense vulnerabilities, the attack simulation model and the defense simulation model can be effectively integrated. This integration not only improves the accuracy and comprehensive performance of the models, but also ensures the efficient operation of the power system attack and defense strategies in practical applications, enabling the defense strategy to better cope with different attack scenarios. The power system attack and defense evolution model generated through model integration provides a basis for continuous optimization of the long-term security of the power system. This model can adapt to the evolving attack environment and defense requirements of the power system, help the power system conduct continuous security assessment and optimization, and ensure that the system can still maintain a high level of security and stability under different attack scenarios. The attack and defense evolution model can dynamically adjust and optimize the defense strategy according to the changes in the system security environment, improving the system's response speed and adaptability in the face of unknown or new attacks. Through continuous evolution, the system can reduce its dependence on fixed defense strategies and enhance its ability to cope with complex attack and defense situations. Through the dynamic repair of attack and defense vulnerabilities and the integration of the attack and defense evolution model, the security protection ability of the power system is continuously enhanced. This long-term self-optimization mechanism ensures that the power system can always operate stably and reliably in the evolving attack environment, thereby enhancing the long-term sustainability of the power system. Model integration and attack and defense vulnerability repair can provide more accurate data analysis and prediction support, providing a scientific basis for the resource allocation and decision-making of the power system. Through the refined optimization of attack and defense strategies, the system can efficiently utilize limited security resources, minimize the attack risk, and ensure the safe operation of the power system. Brief Description of the Drawings

[0059] Figure 1 It is a schematic flow chart of the steps of a method for constructing a power system attack and defense model;

[0060] Figure 2 It is Figure 1 a schematic detailed implementation step flow chart of step S2 in

[0061] Figure 3 For Figure 1 a schematic diagram of the detailed implementation steps of step S3 in

[0062] The realization, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. Specific embodiments

[0063] The technical method of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0064] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.

[0065] It should be understood that although the terms "first", "second", etc. may be used here to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit can be called the second unit, and similarly the second unit can be called the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed associated items.

[0066] To achieve the above object, please refer to Figures 1 to 3 , a method for constructing an attack and defense model of a power system, the method comprising the following steps:

[0067] Step S1: Obtain power system structure data; perform structural topology modeling on the power system structure data to generate power system topology structure modeling data; perform attack surface identification on the power system topology structure modeling data to generate power system structure attack point data; perform power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate power system network security modeling data;

[0068] Step S2: Obtain the historical intrusion data of the power system; conduct an attack path analysis on the historical intrusion data of the power system to generate power system attack type path data; perform an attack intensity and strategy simulation on the power system network security modeling data through the power system attack type path data to generate power system attack simulation data; perform model encapsulation on the power system attack simulation data to generate a power system attack simulation model;

[0069] Step S3: Perform attack fault tolerance on the key attack nodes in the power system attack type path data based on the historical power system attack type data to generate a power system defense simulation model; conduct a game analysis on the power system defense simulation model and the power system attack simulation model to generate power system attack and defense strategy game data;

[0070] Step S4: Identify the attack and defense weaknesses in the power system attack and defense strategy game data to obtain attack and defense weakness identification data; repair the attack and defense vulnerabilities of the power system attack simulation model and the power system defense simulation model based on the attack and defense weakness identification data to generate a power system attack and defense evolution model.

[0071] By obtaining the power system structure data and performing topological modeling, the present invention can clearly display the network structure of the power system, identify potential attack surfaces and vulnerabilities. The key to this step lies in generating the security modeling data of the power system, providing accurate basic information for subsequent attack analysis and defense strategy design, and fundamentally enhancing the understanding of the power system structure and the preparation for offense and defense. Using the historical intrusion data of the power system for attack path analysis can reveal the behavior patterns and attack methods of attackers, providing a prediction basis for future attacks. Through the simulation based on the attack path, the attack intensity and strategy can be accurately simulated, the attack response ability can be improved, potential threats can be identified in advance and targeted defense deployments can be carried out. This process enhances the realism of the attack simulation and the system emergency response ability. By tolerating key attack nodes based on historical attack type data, the fault tolerance ability of the system can be improved and the vulnerability of key nodes can be reduced. At the same time, by generating a defense simulation model and performing game analysis with the attack simulation model, the effectiveness of the offense and defense strategies can be evaluated in real time, ensuring the adaptability and flexibility of the defense measures in the face of different attack scenarios, thereby improving the overall security of the power system in a dynamic offense and defense environment. Identifying weaknesses in the game data of the offense and defense strategies can reveal potential weak links in the defense system, providing a basis for further security enhancement. By repairing vulnerabilities based on the weakness identification data, the defense measures can be dynamically adjusted to ensure the resilience of the power system in the face of constantly changing attack means. The generation of the offense and defense evolution model prompts the system to continuously self-optimize and evolve, thereby improving the long-term defense ability and enabling the power system to cope with new attack threats. Therefore, the present invention improves the accuracy of the offense and defense modeling and the dynamics of the defense by combining power system structure modeling, historical intrusion data analysis, attack simulation, game analysis and vulnerability repair.

[0072] In an embodiment of the present invention, with reference to Figure 1 As shown, it is a schematic flow chart of the steps of a method for constructing an offense and defense model of a power system according to the present invention. In this example, the method for constructing an offense and defense model of a power system includes the following steps:

[0073] Step S1: Obtain the power system structure data; perform structural topology modeling on the power system structure data to generate power system topology structure modeling data; perform attack surface identification on the power system topology structure modeling data to generate power system structure attack point data; perform power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate power system network security modeling data;

[0074] In the embodiments of the present invention, data is extracted from the monitoring systems (such as SCADA, EMS) of the power system, including the positions, operating states, current and voltage data, etc. of various power equipment (transformers, switches, lines, generators, etc.). A data acquisition interface (such as protocols like OPC, Modbus, etc.) is used to connect to the power system data source, and tools such as Python and SQL are utilized to obtain structured data. Graph theory algorithms are used to model the various devices and their connection relationships in the power system to generate a topology graph. Each device serves as a node in the graph, and the lines serve as the edges between the nodes. Considering the connectivity, load balance, and importance of the nodes in the network, further optimization modeling is carried out. NetworkX (a Python library) is used for topology modeling; for complex power systems, tools such as Simulink and SimPowerSystems in MATLAB can also be used for simulation modeling. Through network security analysis techniques, such as attack graph and attack tree methods, potential attack surfaces in the power system are identified, which can be achieved by conducting security assessments on device interfaces, communication protocols, etc. The ATT&CK framework and attack graph analysis tools are used to construct an attack surface graph of the power system; machine learning classification is combined with Scikit-learn in Python to identify attack points. Based on the topology modeling data and attack point data, a security model is constructed, and protection levels and response mechanisms are defined. For example, security measures such as firewalls, intrusion detection systems (IDS), and access control lists (ACL) are defined. MATLAB, Opnet, or QualNet is used for network security modeling to simulate the impact of network traffic and security attacks on the power system.

[0075] Step S2: Obtain the historical intrusion data of the power system; conduct an attack path analysis on the historical intrusion data of the power system to generate power system attack type path data; perform an attack intensity and strategy simulation on the power system network security modeling data through the power system attack type path data to generate power system attack simulation data; perform model encapsulation on the power system attack simulation data to generate a power system attack simulation model;

[0076] In the embodiments of the present invention, intrusion data is extracted from the historical logs of the power system, intrusion detection systems (IDS), and SIEM (Security Information and Event Management system). The data includes attack types, attack paths, attack sources, and attack time periods, etc. SIEM tools (such as Splunk, Elastic Stack) and intrusion detection systems (such as Snort, Suricata) are used to collect intrusion data. Path analysis is performed on the historical attack data, and data mining techniques (such as clustering, association rule analysis, etc.) are adopted to identify the attack paths and behavior patterns of attackers. Clustering analysis is carried out using Scikit-learn in Python, or the arules package in the R language is used to analyze the attack paths. Based on the results of the attack path analysis, various attack scenarios (such as DDoS attacks, phishing attacks, etc.) are simulated to analyze how attackers invade from the attack point and spread to other systems, and the effects of different attack strategies are simulated. Network simulation tools such as MATLAB, OpNET, and NS3 are used for attack simulation. A virtual environment can be constructed to observe the reactions of the power system by simulating attack behaviors. The attack simulation data is encapsulated into a modular attack simulation model, which can be reused in different scenarios. Each attack simulation model should include parameters such as attack sources, propagation paths, and attack intensities. The Simulink and model encapsulation functions of MATLAB are used to encapsulate the simulation data into executable simulation modules.

[0077] Step S3: Perform attack fault tolerance on the key attack nodes in the power system attack type path data based on the historical attack type data of the power system to generate a power system defense simulation model; perform game analysis on the power system defense simulation model and the power system attack simulation model to generate power system attack and defense strategy game data;

[0078] In the embodiments of the present invention, a fault tolerance mechanism is designed by applying fault tolerance technologies (such as redundant nodes, backup communication lines) according to the historical attack type data of the power system. The impact of attacks is reduced by reconfiguring the redundant lines of the power network, backup generating units, load dispatching, etc. MATLAB / Simulink is used for redundant design to simulate the response and recovery capabilities of redundant components during attacks. A defense simulation model is constructed according to the fault tolerance mechanism of the power system. The settings and configurations of defense devices (such as firewalls, IDS, DDoS protection systems, etc.) are simulated through the model to evaluate the response effects of different defense measures against attacks. Network simulation tools such as QualNet and OpNET are used to establish defense models and system recovery models. The Nash equilibrium model in game theory is adopted to perform game analysis on the strategies between attackers and defenders. The probabilities of the defenders adopting the best strategies and the reaction strategies of the attackers are calculated under different attack situations. Game analysis is carried out using the game theory toolbox in MATLAB or specialized game theory analysis software (such as Gambit).

[0079] Step S4: Identify the offensive and defensive weaknesses in the power system offensive and defensive strategy game data to obtain the offensive and defensive weakness identification data; repair the offensive and defensive vulnerabilities in the power system attack simulation model and the power system defense simulation model based on the offensive and defensive weakness identification data, and generate the power system offensive and defensive evolution model.

[0080] In the embodiment of the present invention, the weak links in the system are identified by using the game analysis results. Security vulnerabilities existing in the power system are identified through vulnerability scanning tools, such as unauthorized access, configuration errors, etc. Use Nessus and OpenVAS to scan the system for vulnerabilities, and combine with Wireshark for network traffic analysis. For the identified vulnerabilities, repair and reinforcement are carried out, which includes upgrading system patches, modifying access permissions, strengthening network firewalls, increasing the sensitivity of IDS, etc. Use automated operation and maintenance tools such as Ansible and Chef to perform batch security patch updates. Enhance the protection strategy through manual configuration or automated scripts. According to the results of vulnerability repair and weakness identification, dynamically adjust the defense model to generate a continuously optimized offensive and defensive evolution model, simulate the continuous repair and evolution of the system in multiple attacks, and improve the ability to respond to new attacks. Use the dynamic simulation functions of MATLAB and Simulink to build a simulation model of system evolution and continuously optimize it.

[0081] Preferably, step S1 includes the following steps:

[0082] Step S11: Obtain the power system structure data;

[0083] Step S12: Conduct a topological structure analysis on the power system structure data to generate the power system structure topology data;

[0084] Step S13: Perform a structural topology modeling on the power system according to the power system structure topology data to generate the power system topology structure modeling data; identify the attack surface of the power system topology structure modeling data to generate the power system structure attack point data;

[0085] Step S14: Perform a power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate the power system network security modeling data.

[0086] In an embodiment of the present invention, structural data is obtained from the actual operating environment or data acquisition system of the power system, and these data include but are not limited to information of components such as generators, substations, transmission lines, and load points. The data source can be a power dispatching center, a real-time monitoring system, an equipment management system, etc. Once the basic data of the power system is obtained, it is necessary to perform a topological structure analysis on it. This analysis will generate a topological diagram of the system based on the connection relationship between power equipment (such as the connectivity of power lines, the mutual dependence between substations, etc.), and this topological structure data can be a graphical representation, such as generating a matrix representation of power grid nodes and edges, or a connectivity analysis result constructed by a graph theory algorithm. Using the topological data analyzed in step S12, the power system is subjected to structural topological modeling. The modeling process uses mathematical tools (such as graph theory, matrix representation, network flow analysis, etc.) to construct an accurate power system topological model, which can reflect the power flow, transmission constraints, and fault recovery mechanisms between power system components. On this basis, further attack surface identification is performed to identify attack points (such as key nodes, weak links, etc.) in the power system. According to the topological structure modeling data and attack point data in step S13, a network security model of the power system is established. This model will consider the security of each device and network path in the system, including vulnerability analysis of potential attacks (such as cyber attacks, physical attacks, etc.). By simulating different attack scenarios, the response and recovery capabilities of the power system when attacked are evaluated, and finally the network security modeling data of the power system is generated to guide the implementation of safety protection measures.

[0087] Preferably, identifying the attack surface of the power system topology modeling data includes:

[0088] Extract node data from the power system topology data to obtain node data;

[0089] Extract edge connection information from the power system topology structure modeling data according to the node data, thereby obtaining edge connection data;

[0090] The power system line is constructed by edge connection data and node data, thereby obtaining the power system line data;

[0091] Attack surface identification is performed based on power system line data to identify potential attack paths, thereby generating power system potential attack path data;

[0092] According to the potential attack path data of the power system, the structural attack points of the power system line data are identified, and the structural attack points in the power system are identified, so as to obtain the structural attack point data of the power system.

[0093] In the embodiments of the present invention, all nodes (such as substations, generators, load points, etc.) are extracted from the power system topology structure data. Node data is the basic information representing each component in the power system, such as node numbers, node types, equipment connected to the nodes, etc. The process of extracting node data can utilize data parsing methods, such as parsing power grid graphic data files (such as CSV, JSON formats) to extract the detailed information of each node. Specifically, the attributes of each node are read from the power system topology structure data file, and using the node representation method in graph theory, these nodes are stored as a data structure (such as a dictionary or a list) for subsequent processing. After extracting the node data, the next step is to identify the connection relationships (i.e., edges) between these nodes. An edge is formed between every two connected nodes. The edge connection data includes information such as the starting node, ending node, connection method, transmission capacity, etc. of the edge, and these information are crucial for understanding the power flow and its attack paths in the power system. Based on the node data, analyze the connection relationships between the nodes to generate edge connection information. Each edge usually includes a starting point, an ending point, and other attributes of the edge (such as transmission capacity, working status, etc.). Use the edge representation method in the graph structure (such as a matrix, a list, etc.) to store the edge connection data. Once the edge connection data and node data are obtained, the line information of the power system can be constructed according to these data. The power system line refers to the specific path for transmitting power in the power network, which includes the lines connecting the nodes and the related power transmission characteristics (such as voltage, current, impedance, etc.). The line data is the key data for identifying the attack surface and potential risks. According to the edge connection information between the nodes, construct the line topology model of the power system. Each line is composed of the connected nodes, the attributes of the edges, and their corresponding power transmission characteristics. Store the line data, including the starting and ending nodes of the line, the electrical characteristics of the line (such as impedance, load capacity, etc.), and other transmission-related information. After constructing the power system line data, the potential attack paths in the system can be identified according to the topology structure and attributes of the lines. The attack surface identification process aims to identify the vulnerable components in the system, such as critical lines, vulnerable nodes, etc., which may cause the collapse or large-scale failure of the entire system when attacked. Adopt network security analysis methods, and use the power system line data to analyze potential attack paths, including the lines starting from critical nodes, single fault points, etc. For each line, its vulnerability (such as load, redundancy, etc.) can be calculated to evaluate the possibility of it becoming an attack target. Use the attack surface identification algorithm to simulate various attack scenarios (such as DDoS attacks, physical attacks, network attacks, etc.) to identify which lines are most likely to become attack targets. After identifying the potential attack paths, further analyze the structural attack points of the power system. The structural attack points refer to the key components or paths that will affect the normal operation of the system, cause large-scale power outages or network paralysis when attacked, and these attack points are usually located in the core parts of the power system, such as critical nodes, important substations, important transmission lines, etc.Based on the potential attack path data identified in step 4, further analyze each line and node of the power system to identify those structural attack points that will have a serious impact on the system once attacked. For each line and node, calculate its influence in the system, such as the load-carrying capacity of the line and the redundancy backup capacity of the node, so as to evaluate whether it is a key attack point in the attack surface.

[0094] As an example of the present invention, refer to Figure 2 As shown, in this example, step S2 includes:

[0095] Step S21: Obtain the historical intrusion data of the power system;

[0096] Step S22: Classify the historical intrusion data of the power system by attack type to generate the historical attack type data of the power system;

[0097] Step S23: Analyze the attack path of the historical intrusion data of the power system according to the historical attack type data of the power system to generate the attack type path data of the power system;

[0098] Step S24: Simulate the attack intensity and strategy on the power system network security modeling data through the attack type path data of the power system to generate the attack simulation data of the power system; encapsulate the attack simulation data of the power system to generate the attack simulation model of the power system.

[0099] In the embodiments of the present invention, relevant data is obtained from the historical intrusion records of the power system. This data generally includes various network intrusions, physical attacks, malicious behaviors, or fault events suffered by the power system in the past. The data sources can include: power system security monitoring logs (such as the logs of intrusion detection systems and network monitoring systems), fault and anomaly reports of power dispatching centers, accident analysis reports, or event investigation results, and historical attack case databases. Data mining algorithms (such as K-means clustering, decision trees, support vector machines, etc.) are used to classify the historical intrusion data. The classification process considers the multi-dimensional features of the attack types, such as the attack source, attack target, attack method, etc. "Power system historical attack type data" is generated according to the classification results, and each piece of data indicates the attack type and related information. Based on the historical attack data, an attack path graph is constructed, where each path represents the attack steps taken by the attacker. Graph theory algorithms (such as the shortest path algorithm, depth-first search, etc.) are used to analyze the path of the attacker from the intrusion point to the target node, identify the critical path of the attack, and generate "power system attack type path data", including the attack path, attack source, attack time series, and its impact. Combining the topological structure of the power system, historical attack path data, and various attack strategies, simulation tools (such as simulation models, artificial intelligence algorithms, etc.) are used to simulate the performance of the system under different attack scenarios. The intensity of each attack path is evaluated, considering the impact of the attack on aspects such as the interruption, transmission capacity, and recovery ability of the power network. Based on the simulation results, appropriate network security strategies (such as firewall rules, intrusion detection, network isolation, etc.) are proposed, and the effectiveness of these strategies is evaluated to generate "power system attack simulation data", which contains information such as the attack path, attack intensity, attack strategy, and system response time. The simulation data is combined with the physical model, topological model, and network security model of the power system to form a comprehensive attack simulation system. The attack simulation model is encapsulated as a modular simulation tool, which can be called in different power system security analysis scenarios. The model should have scalability, be able to handle new attack types and paths, and update and optimize the protection strategies.

[0100] Preferably, the attack intensity and strategy simulation of the power system network security modeling data through the power system attack type path data includes:

[0101] Feature extraction is performed on the power system attack type path data to generate attack feature data; based on the attack feature data, attack path topology analysis is performed on the power system attack type path data to generate attack path topology data;

[0102] Vulnerability assessment is carried out on the attack path topology data, and based on the assessment results, the attack impact scope analysis is performed on the attack path topology data to generate attack scope impact data; based on the attack scope impact data, key node identification is carried out on the power system attack type path data to generate key attack node data;

[0103] Attack intensity calculation is carried out on the key attack node data to generate node attack intensity data; based on the node attack intensity data, cascade fault simulation is performed on the power system attack type path data to generate path fault simulation data; dynamic analysis of system response is carried out on the path fault simulation data to generate power system response data;

[0104] Protection strategy assessment is carried out on the power system response data to generate power system attack simulation data.

[0105] In the embodiments of the present invention, by extracting the basic features of each attack path, including the attack source, attack target, attack method, devices passed by the path, connection relationships between nodes, attack time, etc. Use data mining techniques (such as clustering analysis, principal component analysis, etc.) to integrate these features to generate "attack feature data". Extract the topological structure features of the path, such as the importance of nodes, path stability, etc. Conduct topological analysis on the attack path through graph theory methods to construct a topological graph of the attack path. In the topological graph, each node represents a device or system component in the power system, and each edge represents the connection between them. Based on the features of nodes and edges (such as bandwidth, load, physical access points, etc.), generate "attack path topology data" to describe the path and method of attack propagation. Based on topological analysis, calculate the vulnerability of each node and edge in the path, considering the security and vulnerability levels of different nodes. Use vulnerability assessment methods (such as network connectivity analysis, shortest path algorithm, etc.) to evaluate the weaknesses of each node and edge in the path and generate "vulnerability assessment data". According to the vulnerability assessment results, determine the part of the path or key devices under attack. Based on the vulnerability assessment results, simulate the area of attack propagation, analyze the influence range from the attack source to the target, and generate "attack range impact data", including the propagation path of the attack, specific fault points, device damage degree, etc. Consider the mutual dependence between devices, analyze the chain reaction and fault spread caused by the attack. Combine with the influence range analysis to identify the key nodes in the attack path, such as core power equipment, key control nodes, network routers, etc. Use methods such as centrality analysis and node importance analysis to identify the nodes that play key roles in the attack path and generate "key attack node data". Mark the key nodes that cause the complete paralysis of the system during the attack process. Calculate the attack intensity for each key node, considering factors such as the type of attack (such as physical attack, network attack, etc.), node security, available protection measures, etc. Calculate the impact of the node failure caused by the attacker on the system stability and generate "node attack intensity data". The intensity calculation can be based on historical attack data, existing network topology, and physical-level attack models. Use a fault simulation tool or system simulation platform to input the node attack intensity data and simulate the impact of the attack on the power system. According to the attack intensity, predict the cascading failures that occur, including power outages, device damage, system failures, etc., and generate "path fault simulation data", including the fault propagation process, affected system parts, repair time, etc. Based on the path fault simulation data, analyze the response time, fault repair process, and recovery effect of the power system. Use dynamic system analysis methods (such as discrete event simulation, dynamic network analysis, etc.) to model the emergency response of the power system and generate "power system response data", including information such as the system recovery time, loss assessment, recoverable devices, etc.Compare the response data of the power system with existing protection strategies (such as intrusion detection, firewalls, anti-tampering technologies, etc.) to evaluate the effectiveness of the protection strategies. Based on the response data, evaluate whether the system can quickly recover after an attack or whether certain protection measures need to be enhanced, and generate "power system attack simulation data", including the evaluation results of the protection measures and the recommended adjustment of the protection strategy.

[0106] Preferably, the formula for calculating the attack intensity of critical attack node data is specifically as follows:

[0107]

[0108] In the formula, I attack (t,X) represents the calculation result of the attack intensity at the Xth critical node in the system at time t, and α i represents the weighting coefficient of the importance of node i, and P i (t) represents the load or power demand of node i at time t, and β i represents the intensity coefficient of the attack type faced by node i, and γ j represents the weighting coefficient of the recovery ability of node j, and D j (t) represents the degree of loss of node j, and C j represents the recovery ability coefficient of node j, t 0 represents the lower limit of time integration, and t 1 represents the upper limit of time integration, n represents the number of parameters related to the intensity of the attack point, and m represents the number of parameters related to the system recovery ability and the degree of loss.

[0109] The present invention analyzes and integrates an attack intensity calculation formula, which is designed to quantitatively calculate the attack intensity when a certain critical node is attacked within a certain time range (from t 0 to t 1 ). The attack intensity is not only affected by the attack itself, but also by the interaction of factors such as node load, attack type, and node recovery ability. Through integral calculation, the formula takes into account the gradual cumulative effect of the attack in the time dimension, enabling the real-time evaluation of the responses of different nodes to the attack during the attack duration (such as load changes, degree of loss, recovery time, etc.). Among them, the coefficient α i in the formula is used to reflect the importance of different nodes in the power system. For nodes that are crucial to the system (such as key substations or generators), this coefficient is relatively large, indicating that its impact on the system stability is more significant. The introduction of this coefficient enables the system to assign different attack intensity weights to different nodes according to the criticality of the nodes, thereby giving priority to protecting more important nodes and improving the anti-attack ability of the system. P i(t) reflects the workload or power demand of a node at a specific moment. The greater the node load, the heavier the power load it undertakes, which usually means the more important role of this node in power transmission. The introduction of load enables the system to consider the current working pressure of the node when evaluating the attack intensity, and then identify those nodes that are particularly vulnerable under high load, so as to optimize the protection measures. β i represents the intensity or nature of the attack suffered by the node. Different types of attacks (such as information tampering, physical damage, network intrusion, etc.) have different impacts on the system, and the intensity coefficient is used to quantitatively describe the destructiveness of the attack. Through the quantitative evaluation of different attack types, the defense system can more specifically identify and respond to specific attack patterns, thereby reducing the potential losses caused by attacks. γ j represents the recovery ability of the node, that is, the ability of the node to return to the normal working state after an attack. Nodes with stronger recovery ability have shorter recovery times, while those with weaker recovery ability have longer recovery times. The introduction of the recovery ability coefficient helps to distinguish between nodes that recover quickly and those that recover slowly after an attack. By enhancing the protection of nodes with weaker recovery ability, the disaster tolerance and system recovery speed of the overall system can be improved. D j (t) represents the degree of loss caused by an attack to a node at a certain moment. The losses can include power supply interruption, data loss, etc. By quantifying the degree of loss, the actual impact of the attack on each node can be clearly identified, which helps to evaluate the vulnerability of the system and prioritize those nodes with larger losses when designing defense strategies. C j represents the difficulty of node recovery. Nodes with stronger recovery ability have shorter recovery times, while nodes with poor recovery ability require longer recovery times. Through this coefficient, the system can quantify the recovery ability of nodes, so as to reasonably allocate resources in the defense and ensure that nodes with weaker recovery ability are given priority attention and support. Integral term represents the cumulative attack intensity during the attack period (from t 0 to t 1 ). The attack persists over time and gradually affects the state of each node. The integral term can accurately capture this dynamic change. The integral enables the model to consider the cumulative effect of time on the attack intensity, evaluate the comprehensive impact of a long-term attack on nodes, avoid the limitation of only considering a single moment, and make the calculation of attack intensity more comprehensive and accurate. The above formula accurately quantifies the attack intensity of each key node in the power system by comprehensively considering various factors such as the importance of the node, load demand, attack type, recovery ability, and degree of loss. By adjusting the weights of each parameter, the most vulnerable parts of the system can be effectively identified, and then targeted defense measures can be taken to enhance the anti-pressure ability and recovery ability of the power system in the face of complex attacks. This multi-dimensional and dynamic analysis method not only improves the security of the system but also can be adjusted and optimized in real time in practical applications.

[0110] As an example of the present invention, with reference to Figure 3 as shown, in this example, step S3 includes:

[0111] Step S31: Construct a defense strategy based on the historical attack type data of the power system to generate a power system defense strategy; perform redundant design of key components for the key attack nodes in the power system attack type path data according to the power system defense strategy to obtain key component redundant data;

[0112] Step S32: Use the key component redundant data to perform attack fault tolerance on the key attack nodes in the power system attack type path data to generate a key node fault tolerance mechanism; encapsulate the historical attack type data of the power system through the key node fault tolerance mechanism to generate a power system defense simulation model;

[0113] Step S33: Perform offensive and defensive simulations on the power system defense simulation model and the power system attack simulation model, and evaluate the offensive and defensive performance of the power system on the basis of the offensive and defensive simulation results to generate power system offensive and defensive performance evaluation data;

[0114] Step S34: Perform game analysis on the power system defense simulation model and the power system attack simulation model through the power system offensive and defensive performance evaluation data to generate power system offensive and defensive strategy game data.

[0115] In the embodiments of the present invention, common attack methods, attack paths, and attack types are identified through historical intrusion records. Based on the analysis of attack type data, corresponding defense strategies are formulated. Common strategies include: isolating critical devices and networks to prevent the spread of attacks, setting up effective network firewalls and intrusion detection systems to prevent external attacks, and physically redundant designing critical facilities to improve the attack resistance of the system. Integrating the above defense measures to generate defense strategy data for specific attack types. According to the attack path analysis and vulnerability assessment, key nodes in the system are identified, such as critical power equipment, control system nodes, etc. Redundant design for each key node can include: redundantly configuring critical devices to ensure that the standby device can quickly take over when the main device fails, designing redundant communication links to ensure that when communication is interrupted, it can switch to the standby link, and generating "critical component redundancy data" according to the redundant design plan, recording information such as redundant devices, communication paths, backup nodes, etc. Based on the critical component redundancy data, a fault tolerance mechanism is established for each key node. The fault tolerance mechanism should include: automatically switching to the standby device or path when a key node is attacked or fails. Deploying a real-time monitoring system to detect the operating status of key nodes and ensure that the redundant system is started in a timely manner. According to the fault tolerance design, generating "critical node fault tolerance mechanism" data, recording the fault tolerance strategy and the corresponding redundant system. Combining historical attack data, critical component redundant design, and critical node fault tolerance mechanism to construct a power system defense simulation model. Using power system simulation tools (such as PowerWorld, DIgSILENT PowerFactory, etc.) for model encapsulation to ensure that the model can run in actual attack scenarios. Through model encapsulation, generating the "defense simulation model" of the power system for further attack and defense simulation and evaluation. Designing simulation scenarios to simulate different types of attacks (such as denial of service, physical attacks, network intrusions, etc.) and the defense responses of the power system. Conducting attack and defense simulations through simulation software to simulate the performance of the system and the reaction of the defense system when an attack occurs. Collecting relevant data during the simulation process, including the success rate of attacks, the effectiveness of defenses, the system recovery time, etc., to generate "power system attack and defense performance evaluation data". According to the attack and defense performance evaluation data, establishing an attack and defense game model, where the two players in the game model are the attacker (the attacker) and the defender (the power system defense system). In the game model, methods such as Nash equilibrium and optimal strategy in game theory are used to analyze the strategy choices of both sides and their impacts. Based on the game analysis results, generating "power system attack and defense strategy game data", including recommended defense strategies, attack countermeasures, etc.

[0116] Preferably, using the critical component redundancy data to perform attack fault tolerance on the critical attack nodes in the power system attack type path data includes:

[0117] Utilize redundant data of key components to evaluate redundant resources for key attack nodes in the power system attack type path data, generating redundant resource evaluation data; calculate the node fault tolerance ability for the redundant resource evaluation data, generating node resource fault tolerance data;

[0118] Optimize resource allocation for key attack nodes in the power system attack type path data through the node resource fault tolerance data, generating resource allocation optimization data; design a fault switching strategy for the resource allocation optimization data, generating node resource fault switching data;

[0119] Perform node resource load balancing on the node resource fault switching data, generating node resource balance data; plan the recovery time sequence for the node resource fault switching data based on the node resource balance data, generating node resource recovery time sequence data; design an emergency response mechanism for the node resource recovery time sequence data, thereby generating a key node fault tolerance mechanism.

[0120] The present invention identifies critical nodes in the power system through attack path data, which are specifically power supply links, substations, control centers, etc. Evaluate the redundant resources of these critical nodes according to the redundancy design scheme (such as equipment redundancy, communication redundancy, backup power sources, etc.). Focus on evaluating the coverage, response speed, and availability of redundant resources. Record the redundant resource situation of each critical node, including standby equipment, standby paths, standby communication, etc. Design a fault-tolerant computing model based on the redundant resource configuration of the nodes. The fault tolerance can be evaluated from the following aspects: the quantity and quality of redundant resources, the time required for recovery after enabling redundant resources, and whether the redundant resources can support the existing load. Based on the calculation results, record the fault tolerance of each critical node, including recovery time, resource load situation, etc. Design a resource allocation optimization model, considering factors such as the allocation of redundant resources, the importance of nodes, and the load of resources. Use optimization algorithms (such as linear programming, genetic algorithms, etc.) for optimization. Through the optimization model, generate a reasonable resource allocation plan to ensure that critical nodes can be effectively supported quickly when an attack occurs. Based on the resource allocation optimization results, design a failover strategy for each critical node, which includes: when a node fails, the system automatically enables standby equipment or paths to ensure that the delay during the switching process is minimized to reduce service interruption. Record the failover strategy, including the switching mechanism, switching priority, delay control, etc. Use load balancing algorithms (such as weighted round-robin, least connections method, etc.) to ensure that the resources after switching are reasonably allocated. Record the load balancing situation of each critical node after resource switching to ensure that redundant resources can effectively support the load of the system. According to the importance, load situation, and availability of redundant resources of critical nodes, formulate a recovery timing plan. The recovery timing plan should minimize the system recovery time and give priority to recovering nodes with greater impact. Record the recovery timing plan, including the recovery order and time window of each node. Design emergency response measures for each node, including fault detection, recovery priority, emergency switching mechanism, etc. Integrate data such as redundant resource evaluation, fault tolerance, load balancing, and recovery timing to form a complete "critical node fault tolerance mechanism" to ensure effective fault tolerance and rapid recovery when the power system is attacked or fails.

[0121] Preferably, step S34 includes the following steps:

[0122] Step S341: Confirm the attack time delay of the power system attack simulation model to obtain attack time delay data; perform actual attack timeliness analysis on the power system attack simulation model through the attack time delay data to generate actual attack timeliness data;

[0123] Step S342: Analyze the defense time of the power system defense simulation model to generate defense time data; calculate the attack prevention rate of the power system defense simulation model based on the defense time data to obtain attack prevention rate data;

[0124] Step S343: Solve the Nash equilibrium based on the actual attack timeliness data and attack prevention rate data to generate attack-defense Nash equilibrium data; perform equilibrium point bias analysis on the attack-defense Nash equilibrium data, thereby generating power system attack-defense strategy game data.

[0125] In the embodiment of the present invention, time delay analysis is performed on each attack path in the attack simulation model to evaluate the time difference between attack execution and system response. By detecting the response delays of each link, such as time factors such as attack initiation, transmission, and diffusion to the defense system. During the attack simulation process, record the time delay of each stage to form attack time delay data. This data should include the specific delay values of each attack stage and be refined to specific attack paths and attack methods. Based on the attack time delay data, further evaluate the timeliness of the attack in the real environment, which includes analyzing the time period from the start of the attack to the final impact, considering the influence of factors such as the network, hardware, and resources in the actual environment. Through timeliness analysis, obtain the actual attack timeliness data, which will reveal whether the attack can be completed before the system defense response and its potential harmfulness. Conduct a comprehensive defense response time analysis on the power system defense simulation model. Whenever an attack path is triggered, analyze the response time required by the defense system, including the network level, monitoring system response, intrusion detection and repair time. Generate defense time data according to the response speed and actual defense effect of the defense system, and these data will show the time required for the defense mechanism when encountering an attack. According to the defense time data, calculate the prevention rate of the system defense against different attack paths. The prevention rate depends on the timeliness and effectiveness of the defense system response. The prevention rate is usually obtained by comparing the defense response time with the attack arrival time. Through multiple simulations and analyses, obtain the attack prevention rate data for different attack modes to evaluate the actual prevention effect of the defense system. Use the concept of Nash equilibrium to construct an attack-defense game model and input the actual attack timeliness data and attack prevention rate data. By solving the strategies of both sides of the game (the attacker and the defender), find an equilibrium point that can balance the interests of both sides. The Nash equilibrium point in the attack-defense game can be solved through simulation algorithms (such as backward induction method, genetic algorithm, etc.), that is, under the given conditions, the optimal decisions of the attacker and the defender in strategy selection. According to the solution process, obtain the attack-defense Nash equilibrium data, which contains key information such as the strategies selected by each party at the equilibrium point and the game results of maximizing interests. Perform bias analysis on the attack-defense Nash equilibrium data, that is, analyze whether the equilibrium point is biased towards the defense side or the attack side. This analysis helps to reveal which party's strategy is dominant under different attack and defense conditions and whether there is a strategy advantage of a certain party in the game. Through bias analysis, obtain the final power system attack-defense strategy game data, which comprehensively reflects the game results of attack-defense strategies under different conditions for decision-makers' reference.

[0126] Preferably, step S4 includes the following steps:

[0127] Step S41: Identify attack and defense weaknesses in the power system attack and defense strategy game data to obtain attack and defense weakness identification data; repair attack and defense vulnerabilities in the power system attack simulation model and the power system defense simulation model based on the attack and defense weakness identification data to generate dynamic attack and defense vulnerability repair data;

[0128] Step S42: Integrate the power system attack simulation model and the power system defense simulation model according to the dynamic attack and defense vulnerability repair data to generate a power system attack and defense evolution model.

[0129] In the embodiment of the present invention, preferably, step S4 includes the following steps:

[0130] Step S41: Identify attack and defense weaknesses in the power system attack and defense strategy game data to obtain attack and defense weakness identification data; repair attack and defense vulnerabilities in the power system attack simulation model and the power system defense simulation model based on the attack and defense weakness identification data to generate dynamic attack and defense vulnerability repair data;

[0131] Step S42: Integrate the power system attack simulation model and the power system defense simulation model according to the dynamic attack and defense vulnerability repair data to generate a power system attack and defense evolution model.

[0132] In the embodiments of the present invention, methods such as game theory and game tree analysis are used to model attack and defense strategies, automatically identify attack paths and weak defense points in the system. Historical data and attack simulation results can be combined to dynamically evaluate potential weaknesses. Through this process, identification data of power system attack and defense weaknesses is generated, covering the types of weaknesses, the scope of influence, the attack paths where vulnerabilities are located, etc. According to the identified attack and defense weaknesses, targeted vulnerability repair measures are designed. For example, for the identified attack path weaknesses, additional defense layers are added; for the weak points in the defense mechanism, the defense capabilities are enhanced. Multiple methods can be used to repair attack and defense vulnerabilities, including but not limited to: for example, adding redundancy, implementing a depth defense strategy, enhancing access control, etc. For example, attack paths are blocked through technical means, and intrusion detection and response capabilities are strengthened. By optimizing the response process and enhancing the emergency repair capabilities, the risks brought by vulnerabilities are reduced. According to the implementation of the repair plan, dynamic repair data of attack and defense vulnerabilities is generated, recording the impacts after each vulnerability is repaired to ensure that the repair effects of the model and strategies are verified. According to the dynamic repair data of attack and defense vulnerabilities, a model integration framework is designed to ensure that the repaired attack simulation and defense simulation can be effectively integrated. For example, the response capabilities of the model can be improved by integrating the repaired defense strategies and the simulation results of new attack paths. Attack and defense simulations are carried out to verify the effectiveness of the newly integrated attack and defense evolution model, ensuring that the repaired system can better cope with future attacks. For example, new attack scenarios are simulated, the defense capabilities after repair are tested, and the performance of new defense mechanisms is evaluated. The integrated model should take into account historical attack patterns, repair strategies, and the effectiveness of defense strategies to form a complete attack and defense evolution model, which should be able to dynamically adapt to new attack patterns and system requirements.

[0133] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the application documents are intended to be encompassed within the present invention.

[0134] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. A method for constructing an attack and defense model of a power system, characterized in that: The following steps are involved: Step S1: Acquire power system structure data; perform structural topology modeling on the power system structure data to generate power system topology structure modeling data; Identify the attack surface of the power system topology modeling data and generate power system structure attack point data; Conduct power system network security modeling based on power system structure attack point data and power system topology structure modeling data to generate power system network security modeling data; Step S2: Obtaining historical intrusion data of the power system; Perform attack path analysis on the historical intrusion data of the power system to generate power system attack type path data; simulate the attack intensity and strategy of the power system network security modeling data through the power system attack type path data to generate power system attack simulation data; Model encapsulation is performed on the power system attack simulation data to generate a power system attack simulation model; Step S3: Based on the historical attack type data of the power system, attack fault tolerance is performed on the key attack nodes in the attack type path data of the power system to generate a power system defense simulation model; game analysis is performed on the power system defense simulation model and the power system attack simulation model to generate power system attack and defense strategy game data; Step S4: identifying attack and defense weaknesses of the power system attack and defense strategy game data to obtain attack and defense weakness identification data; Based on the attack and defense weakness identification data, the attack and defense vulnerabilities of the power system attack simulation model and the power system defense simulation model are repaired to generate a power system attack and defense evolution model.

2. The method for constructing an attack and defense model of a power system according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: acquiring power system structure data; Step S12: performing topological structure analysis on the power system structure data to generate power system structure topological data; Step S13: Perform structural topology modeling of the power system according to the power system structural topology data to generate power system topology structure modeling data; perform attack surface identification on the power system topology structure modeling data to generate power system structural attack point data; Step S14: Perform power system network security modeling based on the power system structure attack point data and the power system topology structure modeling data to generate power system network security modeling data.

3. The method for constructing an attack and defense model of a power system according to claim 2, characterized in that: Attack surface identification of power system topology modeling data includes: Extract node data from the power system topology data to obtain node data; Extract edge connection information from the power system topology structure modeling data according to the node data, thereby obtaining edge connection data; The power system line is constructed by edge connection data and node data, thereby obtaining the power system line data; Attack surface identification is performed based on power system line data to identify potential attack paths, thereby generating power system potential attack path data; According to the potential attack path data of the power system, the structural attack points of the power system line data are identified, and the structural attack points in the power system are identified, so as to obtain the structural attack point data of the power system.

4. The method for constructing an attack and defense model of a power system according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Acquire historical intrusion data of the power system; Step S22: classifying the attack types of the historical intrusion data of the power system to generate historical attack type data of the power system; Step S23: performing attack path analysis on the historical intrusion data of the power system according to the historical attack type data of the power system, and generating the attack type path data of the power system; Step S24: Simulate the attack intensity and strategy of the power system network security modeling data through the power system attack type path data to generate power system attack simulation data; perform model encapsulation on the power system attack simulation data to generate a power system attack simulation model.

5. The method for constructing an attack and defense model of a power system according to claim 4, characterized in that: The attack intensity and strategy simulation of power system network security modeling data through power system attack type path data includes: Extract features of the power system attack type path data to generate attack feature data; perform attack path topology analysis on the power system attack type path data based on the attack feature data to generate attack path topology data; Conduct vulnerability assessment on attack path topology data, and analyze the attack impact range of attack path topology data based on the assessment results to generate attack range impact data; identify key nodes of power system attack type path data based on attack range impact data to generate key attack node data; Calculate the attack intensity of key attack node data to generate node attack intensity data; simulate cascading failures on power system attack type path data based on node attack intensity data to generate path failure simulation data; perform system response dynamic analysis on path failure simulation data to generate power system response data; Evaluate the protection strategy of the power system response data and generate power system attack simulation data.

6. The method for constructing an attack and defense model of a power system according to claim 5, characterized in that: The formula for calculating the attack intensity of key attack node data is as follows: In the formula, I attack (t,X) represents the calculation result of the attack intensity at the Xth key node in the system at time t, α i It is expressed as the weighted coefficient of the importance of node i, P i (t) represents the load or power demand of node i at time t, β i It is expressed as the intensity coefficient of the attack type faced by node i, γ j It is expressed as the weighted coefficient of node j’s recovery capability, D j (t) represents the loss degree of node j, C j It is represented as the recovery capacity coefficient of node j, t0 is represented as the lower limit of time integration, t1 is represented as the upper limit of time integration, n is represented as the number of parameters related to the intensity of attack point, and m is represented as the number of parameters related to the system recovery capacity and loss degree.

7. The method for constructing an attack and defense model of a power system according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: constructing a defense strategy based on the historical attack type data of the power system to generate a power system defense strategy; performing a key component redundancy design on key attack nodes in the power system attack type path data according to the power system defense strategy to obtain key component redundancy data; Step S32: using the redundant data of key components to perform attack fault tolerance on key attack nodes in the attack type path data of the power system, and generating a key node fault tolerance mechanism; using the key node fault tolerance mechanism to perform model encapsulation on the historical attack type data of the power system, and generating a power system defense simulation model; Step S33: performing attack and defense simulation on the power system defense simulation model and the power system attack simulation model, and performing power system attack and defense performance evaluation on the attack and defense simulation results to generate power system attack and defense performance evaluation data; Step S34: Perform game analysis on the power system defense simulation model and the power system attack simulation model through the power system attack and defense performance evaluation data to generate power system attack and defense strategy game data.

8. The method for constructing an attack and defense model of a power system according to claim 7, characterized in that: Using redundant data of key components to perform attack fault tolerance on key attack nodes in the attack type path data of the power system includes: Using the redundant data of key components, redundant resource evaluation is performed on the key attack nodes in the power system attack type path data to generate redundant resource evaluation data; node fault tolerance capacity is calculated on the redundant resource evaluation data to generate node resource fault tolerance data; Optimize resource allocation for key attack nodes in the power system attack type path data through node resource fault tolerance data to generate resource allocation optimization data; design a fault switching strategy for the resource allocation optimization data to generate node resource fault switching data; Perform node resource load balancing on the node resource fault switching data to generate node resource balancing data; perform recovery timing planning on the node resource fault switching data based on the node resource balancing data to generate node resource recovery timing data; design an emergency response mechanism for the node resource recovery timing data to generate a key node fault tolerance mechanism.

9. The method for constructing an attack and defense model of a power system according to claim 7, characterized in that: Step S34 includes the following steps: Step S341: confirming the attack time delay of the power system attack simulation model to obtain attack time delay data; performing actual attack time effectiveness analysis on the power system attack simulation model through the attack time delay data to generate actual attack time effectiveness data; Step S342: performing defense time analysis on the power system defense simulation model to generate defense time data; performing attack blocking rate calculation on the power system defense simulation model based on the defense time data to obtain attack blocking rate data; Step S343: Solve the Nash equilibrium according to the actual attack time data and the attack prevention rate data to generate attack and defense Nash equilibrium data; perform equilibrium point bias analysis on the attack and defense Nash equilibrium data to generate power system attack and defense strategy game data.

10. The method for constructing an attack and defense model of a power system according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: identifying attack and defense weaknesses of the power system attack and defense strategy game data to obtain attack and defense weakness identification data; repairing attack and defense vulnerabilities of the power system attack simulation model and the power system defense simulation model based on the attack and defense weakness identification data to generate attack and defense vulnerability dynamic repair data; Step S42: Integrate the power system attack simulation model and the power system defense simulation model according to the attack and defense vulnerability dynamic repair data to generate a power system attack and defense evolution model.

Citation Information

Cited By

  • Network attack simulation method and system based on distributed power generation

    CN120528712A