Electric power industrial control traffic anomaly detection method and system fusing deep learning and clustering analysis

By integrating deep learning and cluster analysis methods, self-supervised deep neural network and unsupervised cluster analysis model are used to solve the problems of high cost of manual data annotation and poor detection effect in the existing technology, and efficient and widely applicable power industrial control flow abnormality detection is achieved.

CN120074887APending Publication Date: 2025-05-30BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510132473.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing power industrial flow abnormal detection model based on supervised learning requires a large amount of manual data annotation, which increases deployment cost and is difficult to construct a comprehensive black data sample, affecting the detection effect.

Method used

The method of fusion deep learning and cluster analysis is adopted to detect abnormalities of power industrial control flow through self-supervised deep neural network and unsupervised cluster analysis model, and does not rely on manual data annotation, extract the characteristics of the protocol header message to identify abnormal traffic at the session level.

Benefits of technology

It reduces the workload and deployment cost in the early stage of model training, expands the usage scenarios of the model, and can identify abnormal traffic based on single packet and session levels, which is suitable for the detection of various protocol packets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074887A_ABST
    Figure CN120074887A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power industrial control traffic anomaly detection method and system fusing deep learning and clustering analysis. Communication of the power industrial control system is monitored, and power protocol flow data is captured in real time; performing session recombination on the acquired normal flow data, extracting session message data, and sequentially splicing the session message data into a session message sequence; performing iterative training on the self-encoder network structure, solidifying the trained self-encoder network structure, obtaining a middle hidden layer coding feature vector of a normal sample by using the self-encoder network structure, and inputting the middle hidden layer coding feature vector into a clustering model; in the model detection stage, a session message sequence is generated from the power protocol flow data, the extracted session message sequence is input into an auto-encoder network structure, an intermediate hidden layer coding feature vector of the data is obtained, then the intermediate hidden layer coding feature vector is input into a clustering model for outlier analysis, and abnormal flow in the power protocol flow data is identified. According to the invention, the efficiency and accuracy of power industrial control flow anomaly detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of deep learning, and particularly relates to a method and system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis. Background Art

[0002] The abnormal detection scheme for power industrial control traffic messages using a deep learning model generally includes the following stages. In the model inference stage, traffic messages are captured from the power industrial control system, usually by means of network port mirroring packet capture technology, protocol proxy technology, etc. to capture real-time communication traffic; in the model training stage, a large number of qualified training data need to be constructed according to the detection requirements. Usually, a simulated industrial control system environment needs to be built to capture normal traffic by imitating real business interaction behaviors; abnormal traffic is constructed by reproducing malicious behaviors through traceback attack scenarios. This stage consumes a large amount of human resources, and the data quality is directly related to the performance of the detection model. In the feature extraction stage, the messages are deeply parsed to extract key features, such as timestamps, frequencies, message contents, identifiers, etc. Methods such as traffic statistical analysis and state machines can be used to generate a structured feature data set. The extracted features are cleaned, normalized, and encoded to ensure that the data meets the input requirements of the deep learning model. According to the data characteristics, a suitable deep learning model is selected, and then the model is trained using the labeled normal and abnormal data, and appropriate loss functions (such as cross-entropy or mean square error) and optimization functions are used for training. The model needs to learn the feature distribution of normal traffic and identify abnormal behaviors that deviate from this distribution. After training is completed, the trained model is used to infer the real-time traffic and identify and mark abnormal messages.

[0003] However, the current traffic abnormal detection models based on supervised learning require a large amount of manually labeled data, increasing the deployment cost of the models; in addition, it is difficult to construct comprehensive black data samples, and it is difficult to ensure the detection effect of the models; for the detection of abnormal power industrial control traffic, it often relies on the deep packet parsing of protocols. Many statistical features come from the application layer of the protocol, and the performance requirements for the protocol parsing engine are very high, often resulting in packet loss phenomena; the current traffic abnormal models can only detect one protocol, and the generality is very poor; currently, the inputs of many abnormal detection models based on traffic messages are extracted from the single-packet message level. This method can only detect single-packet deformed message abnormalities and cannot detect multi-packet time-series abnormalities based on the session level. Summary of the Invention

[0004] In order to solve the deficiencies existing in the prior art, the present invention provides a method and system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis to improve the efficiency and accuracy of detecting abnormal power industrial control traffic.

[0005] To solve the above technical problems, the present invention adopts the following technical solutions.

[0006] The present invention first discloses a power industrial control traffic anomaly detection method integrating deep learning and clustering analysis, and the method comprises the following steps:

[0007] In a field network management device, monitor the communication of a power industrial control system through a mirror port of a switch, and capture power protocol traffic data to be detected in real time;

[0008] In a model training stage, perform session recombination on the obtained corresponding protocol traffic data in a normal industrial control environment, extract session packet data according to a sliding window size of a predefined number of packets in each session, and sequentially splice the valid packet data in the protocol header of each packet to generate a session packet sequence;

[0009] Iteratively train a predefined autoencoder network structure, set the proportions of a training set, a validation set, and a test set, stop training after the cross-entropy loss of the model validation set is less than a preset value, solidify the trained autoencoder network structure, obtain an intermediate hidden layer coding feature vector of a normal sample by using the autoencoder network structure, and then input it into a predefined clustering model;

[0010] In a model detection stage, change the sliding window step size to the window size, generate a session packet sequence from the power protocol traffic data, input the extracted session packet sequence into the autoencoder network structure, obtain an intermediate hidden layer coding feature vector of the data, and then input it into the clustering model for outlier analysis to identify abnormal traffic in the power protocol traffic data.

[0011] The present invention further includes the following preferred solutions:

[0012] After generating the session packet sequence, further include:

[0013] Map the obtained session packet sequence to positive integers according to byte coding, and then convert it into an input vector of an autoencoding model through one-hot coding as training data of the model.

[0014] The predefined autoencoder network structure is a sparse autoencoder, a denoising autoencoder, or a long short-term memory neural network autoencoder.

[0015] The clustering model is a density-based clustering model, a K-Means clustering model based on distance segmentation, a hierarchical clustering model, a Gaussian mixture model, or a spectral clustering model.

[0016] The present invention also discloses a power industrial control traffic anomaly detection system integrating deep learning and clustering analysis by using the aforementioned power industrial control traffic anomaly detection method integrating deep learning and clustering analysis, including:

[0017] A collection module, which is used to monitor the communication of the power industrial control system through the mirror port of the switch in the on-site network management device, and capture the power protocol traffic data to be detected in real time;

[0018] A feature extraction module, which is used to recombine the session of the corresponding protocol traffic data obtained in the normal industrial control environment during the model training stage, extract the session message data according to the sliding window size of the predefined number of data packets in each session, and sequentially splice the valid message data in the protocol header of each data packet to generate a session message sequence;

[0019] A training module, which is used to iteratively train the predefined autoencoder network structure, set the proportions of the training set, validation set, and test set, stop training after the cross-entropy loss of the model validation set is less than the preset value, solidify the trained autoencoder network structure, obtain the intermediate hidden layer coding feature vector of the normal sample by using the autoencoder network structure, and then input it into the predefined clustering model;

[0020] An anomaly detection module, which is used to change the sliding window step size to the window size during the model detection stage, generate a session message sequence from the power protocol traffic data and input the extracted session message sequence into the autoencoder network structure, obtain the intermediate hidden layer coding feature vector of the data, and then input it into the clustering model for outlier analysis to identify the abnormal traffic in the power protocol traffic data.

[0021] Correspondingly, the present application also discloses a terminal, including a processor and a storage medium;

[0022] The storage medium is used to store instructions;

[0023] The processor is used to operate according to the instructions to execute the steps of the power industrial control traffic anomaly detection method that combines deep learning and clustering analysis as described above.

[0024] Correspondingly, the present application also discloses a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps of the power industrial control traffic anomaly detection method that combines deep learning and clustering analysis as described above.

[0025] The beneficial effects of the present invention are as follows. Compared with the prior art, the present invention provides a method and system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis. By using a self-supervised deep neural network and an unsupervised clustering analysis model, it does not rely on manual data annotation, reducing the workload in the early stage of model training, lowering the model deployment cost, and expanding the usage scenarios of the model. For the detection of abnormal power industrial control traffic, it does not rely on in-depth protocol parsing, only extracts the protocol header messages, avoiding specific features for extracting application layer fields of the protocol, making the model widely applicable to the detection of abnormal messages of various protocols. The model starts from the session level for feature extraction of traffic messages, and can not only identify single-packet malformed message attacks and multi-field combination attacks, but also identify abnormal traffic such as flow-based business logic anomalies, packet out-of-order attacks, and other unknown attack scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a flowchart of the prior art method for detecting abnormal power industrial control traffic.

[0027] Figure 2 is a schematic diagram of the method for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0029] The embodiments described in this application are only a part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0030] Aiming at the deficiencies of the prior art, the present invention proposes a method and system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis. In the deep learning module, feature extraction is performed on the obtained message sequence, and a multi-layer one-dimensional convolutional autoencoder neural network structure is used to gradually extract the coding patterns in the message sequence. To enable the model to be trained only with normal traffic without artificially annotating black sample data, the present invention selects the self-supervised network structure of the deep autoencoder. The autoencoder model is suitable for feature extraction and anomaly detection of time series data. By training the autoencoder, the communication patterns of data messages are learned from normal samples. When the autoencoder reconstructs the data, abnormal data usually shows a large difference in the hidden layer, and then the output of the hidden layer is sent to the clustering model to identify the outliers, which are the abnormal traffic.

[0031] See Figure 2As shown in the figure, the power industrial control traffic anomaly detection method that combines deep learning and clustering analysis disclosed by the present invention includes the following steps:

[0032] Step 1: In the on-site network management device, monitor the communication of the power industrial control system through the mirror port of the switch, and capture the power protocol traffic data to be detected in real time.

[0033] Step 2: In the model training stage, reorganize the corresponding protocol traffic data obtained in the normal industrial control environment into sessions. In each session, extract the session message data according to the sliding window size of the predefined number of data packets. Sequentially splice the valid message data of the protocol headers in each data packet to generate a session message sequence.

[0034] Preferably, the step size of the sliding window is 1 data packet.

[0035] In a preferred embodiment, after generating the session message sequence, it further includes:

[0036] Map the obtained session message sequence to positive integers according to byte encoding, complete data preprocessing, and then convert it into an input vector of the autoencoder model through one-hot encoding as the training data of the model. The data volume is guaranteed to be in the order of millions.

[0037] This application uses a multi-layer one-dimensional convolutional autoencoder neural network structure to gradually extract the coding patterns in the message sequence. Among them, the one-dimensional convolutional autoencoder neural network structure can capture local patterns or features in the sequence data. By sliding on the input sequence, the convolutional kernel can efficiently identify local patterns in the data, such as short-term trends, peaks, and periodic fluctuations of time series; by stacking multiple convolutional layers, the one-dimensional convolutional autoencoder neural network can extract higher-level features layer by layer, from low-level simple patterns (such as local trends) to high-level complex features (such as global patterns or long-term dependencies). This hierarchical feature representation enables the one-dimensional convolutional autoencoder neural network to better capture the complex structure in the sequence data, and can effectively capture the local and global patterns of the data, thereby realizing the pattern extraction of protocol traffic messages.

[0038] The one-dimensional convolutional autoencoder neural network consists of an encoder and a decoder, which are used for feature encoding and data reconstruction respectively. The goal of the encoder is to compress the input data X ∈ R n into a low-dimensional feature vector Z ∈ R m (where m < n). Perform convolutional operations on the input signal through multiple one-dimensional convolutional layers. Each convolutional operation is expressed as:

[0039]

[0040] where x j+i-1represents the (j + i - 1)-th value of the input signal; w i is the weight of the convolutional kernel, with a length of k; b is the bias term; f(.) is the activation function, usually the ReLU function, expressed as:

[0041] f(x) = max(0, x)

[0042] Through one-dimensional convolutional operations, the encoder can extract local patterns of the input data and gradually reduce the dimension of the input, thereby obtaining a compact representation z.

[0043] The model is trained using 3.15 million protocol traffic packets of normal power industrial control services. The training set and test set are divided according to a ratio of 9:1, and sequence data of traffic packets is obtained through the input encoding module.

[0044] The model training parameters include a batch size of 256, a monitoring parameter of monitor val_loss, an optimizer of Adam, a loss function of categorical_crossentropy, a Conv1D kernel_size of 3, a Dropout parameter of 0.3, and an output layer activation function of Softmax.

[0045] The output of the model is the probability of the predicted byte encoding of the packet. Therefore, the softmax layer is selected for the output layer of the model, and the corresponding multi-class cross-entropy loss (Categorical Cross Entropy Loss) is selected for the model loss function:

[0046]

[0047] In the formula, N is the number of samples; M is the number of categories; y ij is the true label (1 or 0) of sample i belonging to category j; p ij is the probability that the model predicts sample i belongs to category j.

[0048] Step 3: Iteratively train the predefined autoencoder network structure, set the ratios of the training set, validation set, and test set, stop training after the cross-entropy loss of the model validation set is less than the preset value, solidify the trained autoencoder network structure, obtain the intermediate hidden layer encoding feature vectors of normal samples using the autoencoder network structure, and then input them into the predefined clustering model to solidify the clustering model of normal samples.

[0049] Furthermore, the autoencoder network structure can be a Sparse Autoencoder, a Denoising Autoencoder, an LSTM Autoencoder, etc.

[0050] Step 4: In the model detection stage, repeat the feature vector extraction operation in Step 2 above, that is, change the sliding window step size to the window size, generate a session message sequence from the power protocol traffic data, and input the extracted session message sequence into the autoencoder network structure to obtain the intermediate hidden layer coding feature vector of the data, and then input it into the clustering model for outlier analysis to identify abnormal traffic in the power protocol traffic data.

[0051] The window size refers to the number of packets in the session message, that is, how many packets of message sequences are spliced into one sample. In the detection stage, ensure that the step size is less than the window size, that is, fully cover all packets in the session.

[0052] In outlier analysis, specifically, the clustering model first clusters the data and checks which data points do not conform to the typical pattern of the cluster in the clustering result, or the distance from their cluster centroid is greater than the preset threshold distance, and thus are considered outliers.

[0053] Furthermore, the clustering model can specifically be a density-based clustering (DBSCAN) model, a K-Means clustering model based on distance segmentation, a hierarchical clustering model, a Gaussian mixture model (GMM), a spectral clustering model, etc.

[0054] The beneficial effects of the present invention are as follows. Compared with the prior art, the present invention provides a method and system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis. Using a self-supervised deep neural network and an unsupervised clustering analysis model, it does not rely on manual data annotation, reduces the workload in the early stage of model training, reduces the deployment cost of the model, and expands the usage scenarios of the model. For the detection of abnormal power industrial control traffic, it does not rely on in-depth protocol parsing, only extracts protocol header messages, avoids specific features for extracting application layer fields of the protocol, and enables the model to be widely used for abnormal detection of various protocol messages. The model starts from the session level for feature extraction of traffic messages, and can not only identify single-packet malformed message attacks and multi-field combination attacks, but also identify abnormal traffic such as flow-based business logic anomalies, packet out-of-order attacks, and other unknown attack scenarios.

[0055] The present invention can be a system, a method, and / or a computer program product. The present invention also discloses a system for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis based on the aforementioned method for detecting abnormal power industrial control traffic by integrating deep learning and clustering analysis, including:

[0056] The acquisition module is used to monitor the communication of the power industrial control system through the mirror port of the switch in the on-site network management device, and capture the power protocol traffic data to be detected in real time;

[0057] The feature extraction module is used to reorganize the session of the corresponding protocol traffic data obtained in the normal industrial control environment during the model training stage, extract the session packet data according to the sliding window size of the predefined number of packets in each session, and sequentially splice the valid packet data in the protocol header of each packet to generate a session packet sequence;

[0058] The training module is used to iteratively train the predefined autoencoder network structure, set the proportions of the training set, validation set, and test set, stop training after the cross-entropy loss of the model validation set is less than the preset value, solidify the trained autoencoder network structure, obtain the intermediate hidden layer coding feature vector of the normal samples using the autoencoder network structure, and then input it into the predefined clustering model;

[0059] The anomaly detection module is used to change the sliding window step size to the window size during the model detection stage, generate a session packet sequence from the power protocol traffic data and input the extracted session packet sequence into the autoencoder network structure, obtain the intermediate hidden layer coding feature vector of the data, and then input it into the clustering model for outlier analysis to identify the abnormal traffic in the power protocol traffic data.

[0060] Based on the spirit of the present invention, those skilled in the art can easily think that a computer program product can be obtained based on the aforementioned power industrial control traffic anomaly detection method that combines deep learning and clustering analysis. The computer program product may include a computer-readable storage medium with computer-readable program instructions for causing a processor to implement various aspects of the present disclosure. That is, the present application also includes a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the power industrial control traffic anomaly detection method that combines deep learning and clustering analysis as described above.

[0061] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example - but not limited to - an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device, such as a punched card or raised structures in grooves storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage medium as used herein is not construed as an instantaneous signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.

[0062] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.

[0063] Computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present disclosure.

[0064] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A method for detecting abnormal flow in power industrial control by integrating deep learning and cluster analysis, characterized in that: The following steps are involved: In the field network management equipment, the communication of the power industrial control system is monitored through the mirror port of the switch, and the power protocol flow data to be detected is captured in real time; In the model training phase, the corresponding protocol traffic data obtained in the normal industrial control environment is reorganized for session, and the session message data is extracted in each session according to the sliding window size of the predefined number of data packets. The valid message data of the protocol header in each data packet is sequentially spliced ​​to generate a session message sequence. Iteratively train the predefined autoencoder network structure, set the ratio of training set, validation set and test set, stop training after the cross entropy loss of the model validation set is less than a preset value, solidify the trained autoencoder network structure, use the autoencoder network structure to obtain the intermediate hidden layer encoding feature vector of the normal sample, and then input it into the predefined clustering model; In the model detection stage, the sliding window step size is changed to the window size, a session message sequence is generated from the power protocol flow data and the extracted session message sequence is input into the autoencoder network structure to obtain the intermediate hidden layer encoding feature vector of the data, which is then input into the clustering model for outlier analysis to identify abnormal flow in the power protocol flow data.

2. The power industrial control flow anomaly detection method integrating deep learning and cluster analysis according to claim 1 is characterized in that: After generating the session message sequence, the method further includes: The obtained session message sequence is mapped into positive integers according to byte encoding, and then converted into the input vector of the autoencoder model through one-hot encoding as the training data of the model.

3. The power industrial control flow anomaly detection method integrating deep learning and cluster analysis according to claim 2 is characterized in that: The predefined autoencoder network structure is a sparse autoencoder, a denoising autoencoder or a long short-term memory neural network autoencoder.

4. The power industrial control flow anomaly detection method integrating deep learning and cluster analysis according to claim 3 is characterized in that: The clustering model is a density-based clustering model, a distance-segmentation-based K-Means clustering model, a hierarchical clustering model, a Gaussian mixture model or a spectral clustering model.

5. A power industrial control flow anomaly detection system integrating deep learning and cluster analysis, characterized in that: include: The acquisition module is used to monitor the communication of the power industrial control system through the mirror port of the switch in the field network management device, and to capture the power protocol flow data to be detected in real time; The feature extraction module is used to reorganize the corresponding protocol traffic data obtained in the normal industrial control environment during the model training phase, extract the session message data in each session according to the sliding window size of the predefined number of data packets, and sequentially splice the valid message data of the protocol header in each data packet to generate a session message sequence; A training module is used to iteratively train a predefined autoencoder network structure, set the ratio of training set, validation set, and test set, stop training after the cross entropy loss of the model validation set is less than a preset value, solidify the trained autoencoder network structure, use the autoencoder network structure to obtain the intermediate hidden layer encoding feature vector of the normal sample, and then input it into the predefined clustering model; The anomaly detection module is used to change the sliding window step size to the window size in the model detection stage, generate a session message sequence from the power protocol flow data and input the extracted session message sequence into the autoencoder network structure, obtain the middle hidden layer encoding feature vector of the data, and then input it into the clustering model for outlier analysis to identify abnormal flow in the power protocol flow data.

6. The power industrial control flow anomaly detection system integrating deep learning and cluster analysis according to claim 5 is characterized in that: The feature extraction module is further used for: After the session message sequence is generated, the obtained session message sequence is mapped to a positive integer according to the byte encoding, and then converted into an input vector of the autoencoder model through one-hot encoding as the training data of the model.

7. The power industrial control flow anomaly detection system integrating deep learning and cluster analysis according to claim 6 is characterized in that: The predefined autoencoder network structure is a sparse autoencoder, a denoising autoencoder or a long short-term memory neural network autoencoder.

8. The power industrial control flow anomaly detection system integrating deep learning and cluster analysis according to claim 7 is characterized in that: The clustering model is a density-based clustering model, a distance-segmentation-based K-Means clustering model, a hierarchical clustering model, a Gaussian mixture model or a spectral clustering model.

9. A terminal comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the power industrial control flow anomaly detection method integrating deep learning and cluster analysis according to any one of claims 1-4.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the power industrial control flow anomaly detection method integrating deep learning and cluster analysis as described in any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Power distribution network district classification method integrating sparse de-noising auto-encoder dimensionality reduction and clustering

    CN110263873A

  • Power data anomaly detection method and system based on LSTM and improved K-means algorithm

    CN113010504A

  • Industrial control intrusion detection system and method considering data packet periodicity

    CN118138344A

  • Substation communication flow anomaly detection method, device, equipment and medium

    CN118631556A