Vulnerability detection method and device of power system, terminal equipment and computer readable storage medium
By identifying key nodes in the power system and using the knowledge graph to generate penetration attack paths, simulating complex attack scenarios, the problem that traditional red team detection mode is difficult to cope with complex security vulnerabilities is solved, and the security protection capability of the power system is improved.
Patent Information
- Application Number
- CN202510143006.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-10
AI Technical Summary
The traditional red team detection model that relies on manual judgment is difficult to effectively deal with complex and changeable security vulnerabilities and weaknesses in the power system.
By obtaining the data transmission throughput of each node of the power system, key nodes are determined, and the knowledge graph is used to generate penetration attack paths, simulate different attack scenarios, and detect vulnerabilities.
It improves the intelligence level of vulnerability detection and the safety protection capabilities of the power system, reduces false alarms, and improves the accuracy and reliability of safety protection.
Smart Images

Figure CN120068056A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system information security, and in particular, to a vulnerability detection method, device, terminal device and computer-readable storage medium for a power system. Background Art
[0002] The security detection work of the power system is mainly based on the security detection experience of the company's red team over the years. The red team conducts in-depth security assessments on the power system by simulating hacker attack means, reveals and repairs potential security hazards and vulnerabilities, thereby providing valuable basis for the optimization and improvement of the system. These rich practical experiences and technical accumulations have laid a solid foundation for the security detection of the power system.
[0003] However, with the increasing expansion of the scale of the power system, its internal equipment and network structure have become increasingly complex and diverse. Coupled with the rapid progress of information technology, new security vulnerabilities and weaknesses emerge in an endless stream, which poses a severe challenge to the traditional red team detection mode that relies on manual judgment. Summary of the Invention
[0004] Embodiments of the present invention provide a vulnerability detection method, device, terminal device and computer-readable storage medium for a power system, which can simulate more complex and changeable attack scenarios, thereby overcoming the limitations of relying on experience in traditional penetration testing.
[0005] An embodiment of the present invention provides a vulnerability detection method for a power system, including:
[0006] Obtain the data transmission throughput of each node of the power system, and determine the key nodes of the power system according to the data transmission throughput of each node;
[0007] Generate a penetration attack path according to the key nodes of the power system, and determine the attack type of the attack data that the penetration attack path can protect according to the preset knowledge graph of the power system;
[0008] Obtain a number of attack data with different tags; the tag is used to indicate the attack type of the attack data;
[0009] Select and combine a number of attack data with different tags according to the attack type of the attack data that the penetration attack path can protect, and generate each attack combination that the penetration attack path can protect;
[0010] Input each attack combination into the corresponding penetration attack path for processing, and after processing, detect whether there is tagged data in the data generated by the key node at the end of the penetration attack path;
[0011] If there is no marked data, it is determined that there is no vulnerability in the penetration attack path under the attack of the attack combination; if there is marked data, it is determined that there is a vulnerability in the penetration attack path under the attack of the attack combination.
[0012] Further, after determining that there is a vulnerability in the penetration attack path under the attack of the attack combination, it further includes:
[0013] Obtain the first evaluation indicators of each key node after the attack combination processes the penetration attack path with vulnerabilities; the first evaluation indicators include: load, amount of working data, working data processing duration, and data retention time;
[0014] Calculate the first delivery retention time of the penetration attack path according to the first evaluation indicators of each key node.
[0015] Compare the first delivery retention time with the second delivery retention time after the same penetration attack path processes normal data without setting an attack combination.
[0016] If the first delivery retention time is within the preset error range of the second delivery retention time, it is determined that there is a first-level rule vulnerability in the corresponding attack combination in the corresponding penetration attack path;
[0017] If the first delivery retention time exceeds the preset error range of the second delivery retention time, it is determined that there is a second-level rule vulnerability in the corresponding attack combination in the corresponding penetration attack path; among them, the severity of the first-level rule vulnerability is greater than that of the second-level rule vulnerability.
[0018] Further, calculating the first delivery retention time of the penetration attack path according to the first evaluation indicators of each key node includes:
[0019] Screen the first evaluation indicators of each key node through principal component analysis to obtain the target evaluation indicators of each key node;
[0020] Determine the data transmission retention time of each key node according to the target evaluation indicators of each key node;
[0021] Determine the first delivery retention time of the penetration attack path according to the data transmission retention time of each key node.
[0022] Further, screening the first evaluation indicators of each key node through principal component analysis to obtain the target evaluation indicators of each key node includes:
[0023] Normalize the first evaluation indicators of each key node to obtain the preprocessed first evaluation indicators of each key node;
[0024] Calculate the covariance of the first evaluation indicators for the preprocessing of each key node to obtain the covariance of each first evaluation indicator of each key node;
[0025] Perform eigen-decomposition on the covariance of each first evaluation indicator of each key node to obtain the eigenvalues of each first evaluation indicator of each key node;
[0026] Calculate the contribution rate of each first evaluation indicator of each key node according to the eigenvalues of each first evaluation indicator of each key node;
[0027] For each key node, compare the contribution rate of each first evaluation indicator with the preset contribution rate threshold respectively, and take the first evaluation indicator corresponding to the one exceeding the preset contribution rate threshold as the target evaluation indicator.
[0028] Furthermore, the second delivery retention time after processing normal data without attack combinations by the same penetration attack path is determined by the following method:
[0029] Obtain the second evaluation indicators of each key node after processing normal data without attack combinations by the same penetration attack path; the second evaluation indicators include: load capacity, amount of working data, working data processing duration, and data retention time;
[0030] Calculate the second delivery retention time of the same penetration attack path according to the second evaluation indicators of each key node.
[0031] Furthermore, determine the key nodes of the power system according to the data transmission throughput of each node, including:
[0032] Calculate the average value of the data transmission throughput of each node to obtain the average data transmission throughput;
[0033] Compare the data transmission throughput of each node with the average data transmission throughput respectively, and take the node corresponding to the data transmission throughput greater than the average data transmission throughput as the key node.
[0034] Furthermore, generate a penetration attack path according to the key nodes of the power system, including:
[0035] Determine the data transmission direction of the key nodes of the power system according to the preset knowledge graph of the power system;
[0036] Arrange and combine the key nodes of the power system according to the data transmission direction to generate a penetration attack path.
[0037] Based on the above method item embodiments, the present invention correspondingly provides device item embodiments, including: a key node determination module, a penetration attack path generation module, an attack data acquisition module, an attack combination generation module, a processing and detection module, and a vulnerability determination module;
[0038] The key node determination module is used to obtain the data transmission throughput of each node in the power system, and determine the key nodes of the power system according to the data transmission throughput of each node;
[0039] The penetration attack path generation module is used to generate a penetration attack path according to the key nodes of the power system, and determine the attack types of the attack data that the penetration attack path can protect according to the preset knowledge graph of the power system;
[0040] The attack data acquisition module is used to acquire a number of attack data with different tags; the tags are used to indicate the attack types of the attack data;
[0041] The attack combination generation module is used to select and combine a number of attack data with different tags according to the attack types of the attack data that the penetration attack path can protect, and generate each attack combination that the penetration attack path can protect;
[0042] The processing and detection module is used to input each attack combination into the corresponding penetration attack path for processing, and detect whether there is tagged data in the data generated by the key node at the end of the penetration attack path after processing;
[0043] The vulnerability determination module is used to determine that there is no vulnerability in the penetration attack path under the attack of the attack combination if there is no tagged data; if there is tagged data, it is determined that there is a vulnerability in the penetration attack path under the attack of the attack combination.
[0044] Based on the above method item embodiments, the present invention correspondingly provides terminal device item embodiments, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the steps of the power system vulnerability detection method as described in the present invention are implemented.
[0045] Based on the above method item embodiments, the present invention correspondingly provides computer-readable storage medium item embodiments, including: a stored computer program, which controls the device where the computer-readable storage medium is located to execute the steps of the power system vulnerability detection method as described in the present invention when the computer program runs.
[0046] Compared with the prior art, the beneficial effects of the embodiments of the present solution are as follows:
[0047] The present invention obtains the data transmission throughput of each node in the power system, determines the key nodes of the power system based on the data transmission throughput of each node, thereby identifying the nodes with large data traffic in the system, generates a penetration attack path based on the key nodes of the power system for simulating the intrusion paths that an attacker may take, and determines the attack types of the attack data that the penetration attack path can protect according to the preset knowledge graph of the power system. Since the knowledge graph of the power system contains the configuration information and connection relationships of each node in the power system, determining the attack types of the attack data that the penetration attack path can protect through the knowledge graph can reduce false alarms and improve the accuracy and reliability of security protection; then, obtains a number of attack data with different tags for simulating various attack behaviors, where the tag is used to indicate the attack type of the attack data, which can help testers distinguish and track the attack results; selects and combines a number of attack data with different tags according to the attack types of the attack data that the penetration attack path can protect to generate each attack combination that the penetration attack path can protect for simulating various attack scenarios; inputs each attack combination into the corresponding penetration attack path for processing, and after processing, detects whether there is tagged data in the data generated by the key node at the end of the penetration attack path; if there is no tagged data, it indicates that the power system has successfully processed the attack, and it is determined that the corresponding attack combination and the corresponding penetration attack path have no vulnerabilities; if there is tagged data, it indicates that the power system has not effectively processed the attack, and it is determined that the corresponding attack combination and the corresponding penetration attack path have vulnerabilities.
[0048] In summary, the present invention uses the knowledge graph for intelligent selection and combination of attack data to simulate more complex and changeable attack scenarios, thereby overcoming the limitations of relying on experience in traditional penetration testing and improving the intelligent level of testing and the security protection ability of the power system. Brief Description of the Drawings
[0049] Figure 1 is a schematic flowchart of a method for detecting vulnerabilities in a power system provided by an embodiment of the present invention;
[0050] Figure 2 is a schematic flowchart of a process for evaluating the severity of vulnerabilities provided by an embodiment of the present invention;
[0051] Figure 3 is a schematic structural diagram of a device for detecting vulnerabilities in a power system provided by an embodiment of the present invention. Detailed Embodiments
[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts belong to the scope of protection of the present invention.
[0053] In the description of the present invention, it should be understood that the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features.
[0054] As Figure 1 shown, an embodiment of the present invention provides a method for detecting vulnerabilities in a power system. The method at least includes the following steps:
[0055] Step S1: Obtain the data transmission throughput of each node in the power system, and determine the key nodes of the power system according to the data transmission throughput of each node;
[0056] In a preferred embodiment, determining the key nodes of the power system according to the data transmission throughput of each node includes:
[0057] Calculate the average value of the data transmission throughput of each node to obtain the average data transmission throughput;
[0058] Compare the data transmission throughput of each node with the average data transmission throughput respectively, and use the nodes corresponding to the data transmission throughput greater than the average data transmission throughput as key nodes.
[0059] For step S1, obtaining the data transmission throughput of each node in the power system, the data transmission throughput is an index to measure the amount of data that a node can process or transmit within a given time, and it reflects the data processing and communication capabilities of the node. It should be noted that the nodes in this embodiment are data processing nodes responsible for data transmission and data processing tasks. In addition, there are also data nodes in the power system, which represent the storage locations of data in the power grid power system and do not directly participate in the data processing or transmission process.
[0060] Next, based on the collected data transmission throughput data, identify which data processing nodes have a significant impact on the data transmission efficiency or stability of the entire system. These nodes are called key nodes. Specifically, aggregate the data transmission throughput of all data processing nodes and calculate their average value. This average value represents the overall level of the data transmission capacity of nodes in the power system. Then, compare the data transmission throughput of each data processing node with the calculated average value, and identify the nodes above the average level as key nodes. These key nodes play the role of "hubs" in data transmission in the power system and are crucial for ensuring the overall stability and efficiency of the system. By screening out key nodes, the processing efficiency of penetration analysis can be improved.
[0061] Step S2: Generate penetration attack paths based on the key nodes of the power system, and determine the attack types of the attack data that can be protected by the penetration attack paths according to the preset knowledge graph of the power system.
[0062] In a preferred embodiment, generating penetration attack paths based on the key nodes of the power system includes:
[0063] Determine the data transmission directions of the key nodes of the power system according to the preset knowledge graph of the power system.
[0064] Arrange and combine the key nodes of the power system according to the data transmission directions to generate penetration attack paths.
[0065] For step S2, through the preset knowledge graph of the power system, this knowledge graph contains information about all nodes (including data processing nodes and data nodes) in the power system and their interconnections, providing a clear view of the data transmission directions and dependencies between nodes. By querying the knowledge graph of the power system, the data transmission direction of each key node can be determined, that is, how data flows from one node to another. Then, sequentially select key nodes as the starting points, and use data nodes and their connected data processing nodes as the ending points. According to the data transmission directions, arrange and combine the key nodes of the power system to automatically generate several connected penetration attack paths. These paths ensure that each node on the path maintains a direct or indirect data transmission relationship, thus simulating the possible action routes that an attacker may take.
[0066] For each generated penetration attack path, analyze the types of data that an attacker may obtain or tamper with at each key node in this penetration attack path according to the information provided in the knowledge graph. For example, if a key node in a certain penetration attack path is a firewall node, then the attack types of the attack data that this node can protect include firewall log attacks, bypass firewall attacks, and session hijacking attacks, etc.
[0067] It should be noted that when it is said that a node or path can handle attacks of type A, it means that the node or path has general protection measures or detection mechanisms against attacks of type A. However, this does not mean that it can handle all specific attack data under type A (such as A1 or A2). Because different attack data may exploit different vulnerabilities or attack vectors, and these vulnerabilities or vectors may not all be within the protection scope of the node or path.
[0068] In addition, generally, when the data processing volume exceeds the processing threshold of a node, the system will adaptively perform data shunting processing. The purpose of penetration testing is to simulate real attack scenarios to evaluate the security of the system. If the test path contains a link that triggers the system's adaptive shunting processing due to excessive data processing volume, then the test results may be affected by the shunting mechanism, and thus cannot accurately reflect the system's performance when facing real attacks. Therefore, to ensure the accuracy of the test, it is necessary to exclude such paths that may interfere with the test results. Specifically, analyze and calculate the data transmission data processing volume of the penetration attack path, analyze parameters such as the data processing volume distribution, data volume size, and data type in the power grid, determine the data processing volume involved in the penetration attack path, and detect whether the penetration attack data processing volume of the penetration attack path exceeds the processing threshold of a single data processing node in the power grid security detection system, so as to preliminarily screen the penetration attack path and exclude the penetration paths with potential security hazards to avoid system crashes.
[0069] Step S3: Obtain a number of attack data with different labels; the labels are used to indicate the attack types of the attack data;
[0070] For step S3, obtain attack data with different labels from multiple sources, and these sources include but are not limited to public data sets, simulated data generated by penetration testing tools, and real attack data captured by honeypots and honeynets. Each piece of attack data will be assigned one or more labels, and these labels can clearly indicate the specific attack type of each piece of attack data, so as to help testers accurately distinguish and identify various attack behaviors.
[0071] It should be noted that the labels are not only used to distinguish different attack types, but can also be used to indicate other key information of each piece of attack data, such as the source, target, timestamp, etc. of the attack.
[0072] Step S4: Select and combine a number of attack data with different labels according to the attack types of the attack data that the penetration attack path can protect, and generate various attack combinations that the penetration attack path can protect;
[0073] For step S4, identify the attack types of the attack data that each penetration attack path can protect through step S2. From the labeled attack data obtained in step S3, select the attack data that matches each attack means in the path. Then, combine these attack data in the order of the attack path to form a series of attack combinations that can reflect the hacker attack process.
[0074] For example, if a key node in a certain penetration attack path can handle type A attacks, and the key node b can handle type B attacks, then it is necessary to select the a1 attack data belonging to type A and the b1 attack data belonging to type B from the attack dataset. After selecting these matching attack data, perform an orderly permutation and combination according to the actual order of the attack path. In this way, a series of attack combinations that can truly and accurately reflect the hacker attack process can be constructed.
[0075] Step S5: Input each attack combination into the corresponding penetration attack path for processing, and after processing, detect whether there is labeled data in the data generated by the key node at the end of the penetration attack path;
[0076] For step S5, during the penetration test, input each attack combination into the corresponding penetration attack path for processing. After the penetration attack path finishes processing all the attack combinations, immediately detect the data generated by the key node at the end of the penetration attack path. These data may include the system's response information, log records, error reports, etc., which can reflect the actual performance of the system when under attack. In particular, check whether there is any data with a specific label in these data. These labels are the labels set in step S3 and can help testers accurately judge whether the attack data has been successfully processed in the penetration attack path.
[0077] Step S6: If there is no labeled data, it is determined that there are no vulnerabilities in the penetration attack path under the attack of the attack combination; if there is labeled data, it is determined that there are vulnerabilities in the penetration attack path under the attack of the attack combination.
[0078] For step S6, after checking all the data, if no data with a specific label is found, then it can be determined that this penetration attack path does not expose any vulnerabilities under the current attack combination. This indicates that our defense strategy is effective and the system can successfully resist this type of attack. In this case, the system shows good security and is not threatened by the current attack combination. However, if information with a specific label is found in the data, it means that there are vulnerabilities in this penetration attack path under the current attack combination. In this case, it is necessary to output the corresponding attack combination with vulnerabilities and the corresponding penetration attack path for further analysis and repair of these system vulnerabilities.
[0079] By identifying vulnerabilities and outputting corresponding information, it can help testers improve the security of the system targeted, repair potential vulnerabilities, and strengthen the system's defense capabilities to ensure that the system can be more robust and secure when facing potential threats.
[0080] After determining that there are vulnerabilities in the penetration attack path, it is crucial to evaluate the severity of the vulnerabilities, as this directly relates to the priority and urgency of subsequent repair measures. As Figure 2 shown, the following are the specific steps for evaluating the severity of vulnerabilities:
[0081] Step S701: Obtain the penetration attack path with vulnerabilities and the first evaluation indicators of each key node after processing the attack combination; the first evaluation indicators include: load volume, working data volume, working data processing duration, and data retention time;
[0082] For step S701, after confirming that there are vulnerabilities in the penetration attack path, in order to more comprehensively understand the impact of the vulnerabilities on the system performance and security, it is necessary to obtain this penetration attack path and collect the first evaluation indicators of each key node after processing the attack combination with vulnerabilities. Among them, the first evaluation indicators include the key node load volume, the real-time working data volume of the key node, the real-time working data processing duration, and the data retention time, etc.
[0083] Step S702: Calculate the first delivery retention time of the penetration attack path according to the first evaluation indicators of each key node;
[0084] In a preferred embodiment, calculating the first delivery retention time of the penetration attack path according to the first evaluation indicators of each key node includes:
[0085] Screen the first evaluation indicators of each key node through principal component analysis to obtain the target evaluation indicators of each key node;
[0086] Determine the data transmission retention time of each key node according to the target evaluation indicators of each key node;
[0087] Determine the first delivery retention time of the penetration attack path according to the data transmission retention time of each key node.
[0088] For step S702, during the penetration testing process, in order to more accurately evaluate the potential risks and system performance of the penetration attack path, it is necessary to calculate the first delivery retention time of the penetration attack path according to the first evaluation indicators of each key node. This time indicator reflects the efficiency of data transmission and processing in the penetration attack path.
[0089] First, using the statistical method of principal component analysis (PCA), the first evaluation indicators of each key node are screened to identify the principal components in the first evaluation indicators, that is, those factors that have the greatest impact on system performance. Through PCA screening, the target evaluation indicators of each key node can be obtained, and these indicators can more accurately reflect the performance changes of the system when facing attacks.
[0090] Preferably, by using principal component analysis to screen the first evaluation indicators of each key node, the target evaluation indicators of each key node are obtained, including:
[0091] Normalize the first evaluation indicators of each key node to obtain the preprocessed first evaluation indicators of each key node;
[0092] Calculate the covariance of the preprocessed first evaluation indicators of each key node to obtain the covariance of each first evaluation indicator of each key node;
[0093] Perform eigen decomposition on the covariance of each first evaluation indicator of each key node to obtain the eigenvalues of each first evaluation indicator of each key node;
[0094] According to the eigenvalues of each first evaluation indicator of each key node, calculate the contribution rate of each first evaluation indicator of each key node;
[0095] For each key node, compare the contribution rate of each first evaluation indicator with the preset contribution rate threshold respectively, and take the first evaluation indicator corresponding to the one exceeding the preset contribution rate threshold as the target evaluation indicator.
[0096] Specifically, according to the first evaluation indicators of each key node, construct the following data matrix:
[0097]
[0098] Among them, X represents the data matrix, m represents the number of key nodes, n represents the number of evaluation indicators, and x mn represents the data of the nth evaluation indicator of the mth key node.
[0099] After constructing the data matrix, it is necessary to normalize the data matrix so that the original data can be in the same order of magnitude after data standardization, thus meeting the comprehensive analysis of each index parameter of the key node.
[0100] Calculate the covariance matrix for the normalized data matrix through the following formula:
[0101]
[0102] Among them, R represents the covariance matrix.
[0103] Perform eigenvalue decomposition on the covariance matrix to obtain eigenvectors and eigenvalues. Calculate the contribution rate of the index parameters based on the eigenvalues. When the calculated contribution rate of the index parameters is greater than the preset contribution threshold, extract the corresponding index parameters as the principal component indexes of the key node, that is, the target evaluation indexes. Assume that after screening the first evaluation indexes of each key node through principal component analysis, p target evaluation indexes are obtained.
[0104] Next, according to the target evaluation indexes of each key node, calculate the data transmission retention time of each key node through the following formula:
[0105]
[0106] where, γ i represents the data transmission retention time of the i-th key node, represents the contribution value of the i-th key node, σ ij represents the weight of the j-th evaluation index of the i-th key node, and p represents the number of target evaluation indexes. represents the contribution value of the k-th target evaluation index of the i-th key node;
[0107] where, the weight is calculated through the following formula:
[0108]
[0109] where, β ij represents the index parameter of the j-th evaluation index of the i-th key node, that is, the representation value of each index, and α ij represents the eigenvalue of the j-th evaluation index of the i-th key node (obtained through the above covariance decomposition).
[0110] It should be noted that by performing principal component analysis on each index of the working state of the key node, the calculation weight of the index parameters with greater influence in the data transmission process on the data transmission configuration can be increased, so as to make the analysis of the data processing performance of the penetration path more accurate.
[0111] Then, according to the data transmission retention time of each key node, calculate the first delivery retention time of the penetration attack path through the following formula:
[0112] Y = γ 1 ω 1 + γ 2 ω 2 + … + γ m ω m
[0113] where, Y represents the first delivery retention time of the penetration attack path, and ω m represents the path node weight of the m-th key node.
[0114] Step S703: Compare the first transport retention time with the second transport retention time after processing normal data without an attack combination on the same penetration attack path;
[0115] For step S703, compare the first transport retention time calculated in step S702 with the second transport retention time. This second transport retention time refers to the total time required for data to start from the starting point, pass through all key nodes, and reach the end point on the same penetration attack path when the system does not set any attack combinations, that is, in the normal state. It reflects the performance of the system in the normal state.
[0116] Preferably, the second transport retention time after processing normal data without an attack combination on the same penetration attack path is determined by the following method:
[0117] Obtain the second evaluation indicators of each key node after processing normal data without an attack combination on the same penetration attack path; the second evaluation indicators include: load, amount of working data, working data processing duration, and data retention time;
[0118] Calculate the second transport retention time of the same penetration attack path according to the second evaluation indicators of each key node.
[0119] It should be noted that the specific calculation method of the second transport retention time after processing normal data without an attack combination on the same penetration attack path is the same as that of the first transport retention time.
[0120] Step S704: If the first transport retention time is within the preset error range of the second transport retention time, it is determined that there is a first-level rule vulnerability in the corresponding attack combination in the corresponding penetration attack path;
[0121] For step S704, if the first transport retention time is within the preset error range of the second transport retention time, that is to say, the transport retention time of the penetration attack path under the attack combination with a vulnerability is similar to the transport retention time of normal data processing, it means that the processing time of the key nodes for the attack data in this penetration attack path is too short, indicating that these nodes do not effectively detect, filter, or process the attack data. Therefore, the vulnerability level is determined to be a first-level rule vulnerability. In this embodiment, it is determined to be a major rule vulnerability.
[0122] Step S705: If the first transport retention time exceeds the preset error range of the second transport retention time, it is determined that there is a second-level rule vulnerability in the corresponding attack combination in the corresponding penetration attack path; where the severity of the first-level rule vulnerability is greater than that of the second-level rule vulnerability.
[0123] For step S705, if the first transport retention time exceeds the preset error range of the second transport retention time, that is to say, the penetration attack path under the attack combination with vulnerabilities has performed a certain processing on the attack data, but this processing is not thorough. In other words, although the system attempts to detect, filter, or process the attack data, these measures have not been able to completely prevent the attack data from abnormally affecting the transport retention time of the data. Therefore, the vulnerability level is determined to be a second-level rule vulnerability. In this embodiment, it is determined to be a minor rule vulnerability.
[0124] By combining the knowledge graph of the power system, the present invention can comprehensively understand the structural characteristics, operation rules, and potential security risk points of the power system, thereby adaptively and automatically generating penetration attack paths, improving the efficiency and accuracy of penetration testing.
[0125] On this basis, the present invention further evaluates the vulnerability level by calculating the transport retention time of the penetration attack path. As a key performance indicator, the transport retention time reflects the transmission and processing efficiency of data on the penetration attack path, as well as the system's response ability to attack data. By comparing the transport retention time in the normal state and the attack state, the present invention can keenly capture the changes in system performance, thereby accurately judging the severity of the vulnerability.
[0126] As Figure 3 shown, based on the above method item embodiment, a corresponding device item embodiment is provided;
[0127] An embodiment of the present invention provides a vulnerability detection device for a power system, including: a key node determination module, a penetration attack path generation module, an attack data acquisition module, an attack combination generation module, a processing detection module, and a vulnerability determination module;
[0128] The key node determination module is used to obtain the data transmission throughput of each node of the power system and determine the key nodes of the power system according to the data transmission throughput of each node;
[0129] The penetration attack path generation module is used to generate a penetration attack path according to the key nodes of the power system and determine the attack types of the attack data that the penetration attack path can protect according to the preset knowledge graph of the power system;
[0130] An attack data acquisition module, configured to acquire a plurality of pieces of attack data with different tags; the tags are used to indicate the attack types of the attack data;
[0131] An attack combination generation module, configured to select and combine a plurality of pieces of attack data with different tags according to the attack types of the attack data that the penetration attack path can defend against, and generate each attack combination that the penetration attack path can defend against;
[0132] A processing detection module, configured to input each attack combination into the corresponding penetration attack path for processing, and after the processing, detect whether there is tagged data in the data generated by the key node at the end of the penetration attack path;
[0133] A vulnerability determination module, configured to determine that there is no vulnerability in the penetration attack path under the attack of the attack combination if there is no tagged data; if there is tagged data, determine that there is a vulnerability in the penetration attack path under the attack of the attack combination.
[0134] It can be understood that the above device item embodiments correspond to the method item embodiments of the present invention, and can implement the vulnerability detection method of the power system provided by any one of the above method item embodiments of the present invention.
[0135] It should be noted that the above-described device embodiments are merely illustrative, and some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement without creative work.
[0136] Based on the above embodiments of the vulnerability detection method of the power system, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the vulnerability detection method of the power system according to any embodiment of the present invention is implemented.
[0137] Exemplarily, in this embodiment, the computer program can be divided into one or more modules, and the one or more modules are stored in the memory and executed by the processor to complete the present invention. The one or more module elements can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.
[0138] The terminal device may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.
[0139] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, and uses various interfaces and lines to connect all parts of the entire terminal device.
[0140] Based on the above method item embodiments, another embodiment is provided: A computer-readable storage medium provided by another embodiment of the present invention includes a stored computer program, wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the vulnerability detection method of the power system described in any one of the above method item embodiments of the present invention.
[0141] Among them, the module / unit integrated in the vulnerability detection device / terminal device of the power system, if implemented in the form of a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above embodiment methods of the present invention, it can also be completed by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a Read-Only Memory (ROM), a Random Access Memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0142] The above are the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A method for detecting a vulnerability in a power system, characterized in that: include: Obtain the data transmission throughput of each node in the power system, and determine the key nodes of the power system according to the data transmission throughput of each node; Generate a penetration attack path according to the key nodes of the power system, and determine the attack type of attack data that can be protected by the penetration attack path according to the preset knowledge graph of the power system; Acquire a plurality of attack data with different tags, wherein the tags are used to indicate the attack type of the attack data; According to the attack type of the attack data that the penetration attack path can protect, several attack data with different tags are selected and combined to generate various attack combinations that the penetration attack path can protect; Input each attack combination into the corresponding penetration attack path for processing, and after processing, detect whether the data generated by the key node at the end point in the penetration attack path has marked data; If there is no marked data, it is determined that the penetration attack path has no vulnerability under the attack of the attack combination; If there is marked data, it is determined that the penetration attack path has a vulnerability under the attack of the attack combination.
2. The method for detecting a vulnerability in a power system according to claim 1, characterized in that: After determining that the penetration attack path has a vulnerability under the attack of the attack combination, it also includes: Obtaining the penetration attack path with vulnerabilities, and evaluating the first evaluation index of each key node after the attack combination is processed; the first evaluation index includes: load, work data volume, work data processing time, and data retention time; Calculate the first transport retention time of the penetration attack path according to the first evaluation index of each key node; Comparing the first transmission retention time with a second transmission retention time after normal data without setting an attack combination is processed by the same penetration attack path; If the first delivery retention time is within the preset error range of the second delivery retention time, it is determined that the corresponding attack combination has a first-level rule vulnerability in the corresponding penetration attack path; If the first transmission retention time exceeds the preset error range of the second transmission retention time, it is determined that the corresponding attack combination has a second-level rule vulnerability in the corresponding penetration attack path; wherein the severity of the first-level rule vulnerability is greater than the severity of the second-level rule vulnerability.
3. The method for detecting a vulnerability in a power system according to claim 2, characterized in that: According to the first evaluation index of each key node, the first transport retention time of the penetration attack path is calculated, including: The first evaluation index of each key node is screened by principal component analysis to obtain the target evaluation index of each key node; According to the target evaluation index of each key node, determine the data transmission retention time of each key node; According to the data transmission retention time of each key node, the first transmission retention time of the penetration attack path is determined.
4. The method for detecting a vulnerability in a power system according to claim 3, characterized in that: The first evaluation index of each key node is screened through principal component analysis to obtain the target evaluation index of each key node, including: Normalizing the first evaluation index of each key node to obtain a pre-processed first evaluation index of each key node; Performing covariance calculation on the first evaluation indicators preprocessed at each key node to obtain the covariance of each first evaluation indicator of each key node; Performing eigendecomposition on the covariance of each first evaluation indicator of each key node to obtain an eigenvalue of each first evaluation indicator of each key node; Calculate the contribution rate of each first evaluation indicator of each key node according to the characteristic value of each first evaluation indicator of each key node; For each key node, the contribution rate of each first evaluation indicator is compared with a preset contribution rate threshold, and the first evaluation indicator corresponding to the first evaluation indicator exceeding the preset contribution rate threshold is used as the target evaluation indicator.
5. The method for detecting a vulnerability in a power system according to claim 4, characterized in that: The second transmission retention time after the same penetration attack path processes the normal data without setting the attack combination is determined by the following method: Obtaining a second evaluation index of each key node after the same penetration attack path processes normal data without setting an attack combination; the second evaluation index includes: load, working data volume, working data processing time, and data retention time; According to the second evaluation index of each key node, the second transport retention time of the same penetration attack path is calculated.
6. The method for detecting a vulnerability in a power system according to claim 1, characterized in that: According to the data transmission throughput of each node, the key nodes of the power system are determined, including: The data transmission throughput of each node is averaged to obtain the average data transmission throughput; The data transmission throughput of each node is compared with the data transmission throughput average value, and the nodes corresponding to which the data transmission throughput is greater than the data transmission throughput average value are taken as key nodes.
7. The method for detecting a vulnerability in a power system according to claim 1, characterized in that: Generate penetration attack paths based on key nodes of the power system, including: According to the preset knowledge graph of the power system, determine the data transmission direction of the key nodes of the power system; According to the data transmission direction, the key nodes of the power system are arranged and combined to generate a penetration attack path.
8. A leakage detection device for a power system, characterized in that: include: Key node determination module, penetration attack path generation module, attack data acquisition module, attack combination generation module, processing detection module and vulnerability determination module; The key node determination module is used to obtain the data transmission throughput of each node of the power system, and determine the key nodes of the power system according to the data transmission throughput of each node; The penetration attack path generation module is used to generate a penetration attack path according to key nodes of the power system, and determine the attack type of attack data that can be protected by the penetration attack path according to a preset knowledge graph of the power system; The attack data acquisition module is used to acquire a number of attack data with different tags; the tags are used to indicate the attack type of the attack data; The attack combination generation module is used to select and combine a number of attack data with different tags according to the attack type of the attack data that the penetration attack path can protect, and generate various attack combinations that the penetration attack path can protect; The processing and detection module is used to input each attack combination into the corresponding penetration attack path for processing, and after processing, detect whether the data generated by the key node at the end point in the penetration attack path has marked data; The vulnerability determination module is used to determine that the penetration attack path has no vulnerability under the attack of the attack combination if there is no marked data; if there is marked data, determine that the penetration attack path has a vulnerability under the attack of the attack combination.
9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the method for detecting a vulnerability in an electric power system as claimed in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: include: A stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the power system vulnerability detection method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for generating attack path in ubiquitous power Internet of Things scene
CN112422665A
Joint utilization method, device and system based on knowledge graph
CN113312627A
Power grid security vulnerability assessment method based on knowledge graph
CN114553534A