Intelligent substation intrusion detection method based on hidden Markov model
By adopting an intrusion detection method based on the hidden Markov model in intelligent substations, combined with multi-dimensional feature extraction and modeling, the problem that traditional detection methods are difficult to identify complex attack behaviors is solved, and the intrusion detection effect with high accuracy and robustness is achieved.
Patent Information
- Application Number
- CN202510198371.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-22
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-22
AI Technical Summary
Smart substations face complex information security threats, traditional intrusion detection methods are difficult to effectively identify distributed attacks, and there are problems with high false alarm rates and missed rates.
The intelligent substation intrusion detection method based on the hidden Markov model is adopted. By extracting and modeling network traffic in a multi-dimensional feature, combining the ARIMA model and traceless Kalman filtering method, multiple protocol compliance detection rules are established, and packet compliance is calculated using Hamming distance to achieve real-time detection of multiple attack behaviors.
This method can effectively identify various attacks including distributed denial of service attacks, abnormal data injection and message tampering, reduce false alarms and missed reports, improve detection accuracy and robustness, and adapt to the information security needs of smart substations in complex scenarios.
Smart Images

Figure CN120074902A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of industrial control security, and in particular relates to an intelligent substation intrusion detection method based on a hidden Markov model. Background Art
[0002] Smart substations are the core infrastructure of smart grid power transmission and distribution systems. Smart substations are based on interactive data transmission networking and sharing standardization. They use embedded devices with computing capabilities to autonomously complete conventional substation tasks such as control, protection, and information measurement of power equipment. With the extensive application of advanced information technology in smart substations, the number of smart device connections has increased significantly, and there are more and more information security vulnerabilities and potential intrusion points. Smart substations are facing many potential information security threats. At the same time, smart substations involve system integration at multiple levels of power equipment, communication networks, and data analysis. This complexity gives attackers the opportunity to attack at different levels after intrusion, affecting all aspects of the power system, inducing power system instability or power outages, and causing serious impacts on political stability and social economy. Therefore, it is necessary to build a standard and effective intrusion detection system to accurately identify attack behaviors through real-time monitoring, abnormal data analysis and other technologies to cope with the increasing information security threats.
[0003] Intrusion detection systems can effectively identify a variety of common network attacks such as false data attacks and denial of service attacks. In recent years, intrusion detection technology has been widely used in the information security protection of smart substations. It is responsible for real-time monitoring of network traffic and identification of abnormal data. Through the coordination with security modules such as identity authentication, access control and log analysis, intrusion detection technology has significantly improved the overall security protection capabilities of smart substations. The IEC 61850 standard defines a variety of dedicated communication messages with different functions such as GOOSE and SV, but its design complexity and real-time requirements have brought new challenges to the intrusion detection system. Due to the diversity of nodes and the complexity of scenarios under the IEC 61850 standard, traditional intrusion detection methods are often limited to single-node or single-dimensional detection modes, and it is difficult to capture the full picture of distributed attack behaviors. Some intrusion detection systems have the problem of isolated and single deployment and lack of coordination and interaction. The detection method has problems such as difficulty in balancing the false alarm rate and false alarm rate. For the comprehensive coverage of network attacks, it is necessary to comprehensively consider multi-dimensional features such as network traffic changes and abnormal message features, and design a more adaptable intrusion detection algorithm to improve the ability to judge complex attack behaviors. Summary of the invention
[0004] Aiming at the problems of small detection coverage of complex attack behaviors by a single detection method and high false alarm rate in high-real-time scenarios, the present invention provides an intrusion detection method for intelligent substations based on the hidden Markov model. This method can fully consider the multi-dimensional communication characteristics of intelligent substations and identify various attack behaviors including distributed denial of service attacks, abnormal data injection, and message tampering.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] An intrusion detection method for intelligent substations based on the hidden Markov model, comprising the following steps:
[0007] S1: Segment and cut the continuous network traffic according to the time scale, extract the message identifier, the measured data transmitted by the message, and the message throughput size that can characterize the message protocol compliance within the same time window, and construct a complete intrusion detection data set;
[0008] S2: Extract the measured data of the node, based on the unscented Kalman filter method, calculate the difference between the state variable and the measured value, and establish a state model that can calculate the attack detection index reflecting the deviation degree of the variable;
[0009] S3: Regard the real-time message traffic as time series data and model it through the ARIMA model. Based on the traffic change law, screen the traffic model with the best fitting effect in the traffic models after multiple fittings, and determine the detection confidence interval based on the screening rules, and establish a time series model that can calculate the traffic throughput;
[0010] S4: According to the IEC 61850 protocol specification, establish multiple protocol compliance detection rules, and based on the Hamming distance calculation method, establish a specification detection model that can judge whether the message conforms to the communication protocol specification;
[0011] S5: Real-time detect the network traffic of the intelligent substation, calculate the data integrity detection vector, the traffic throughput detection vector, and the protocol compliance detection vector respectively according to the models established in S2, S3, and S4. After normalization, use them as the input variables of the hidden Markov model, and combine the observed sequence data to comprehensively analyze the abnormal characteristics of the system and achieve the final discrimination.
[0012] Compared with the prior art, the beneficial effects of the present invention are:
[0013] In view of various potential attack patterns existing in the communication network of intelligent substations, the present invention designs a fusion intrusion detection method that combines traffic characteristics, measurement data, and protocol specifications. Compared with traditional intrusion detection methods based on a single dimension or a single model, the present invention fully integrates multi-dimensional features, which can effectively avoid the problems of missed reports or false reports of complex attack behaviors by a single detection method. In addition, through the Hidden Markov Model (HMM) to fuse and classify the states of multi-dimensional detection results, compared with single-dimensional detection methods, the present invention is optimized for the complexity characteristics of intelligent substation protocols, can effectively identify attack behaviors during detection, while reducing false reports and missed reports in complex scenarios, showing higher robustness and accuracy, and reducing the dependence on a single rule or expert knowledge. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 FIG. is the overall flowchart of an intrusion detection method for intelligent substations based on the Hidden Markov Model;
[0015] Figure 2 FIG. is the detailed flowchart of an intrusion detection method for intelligent substations based on the Hidden Markov Model. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] The following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings and embodiments. Obviously, the described embodiments are only a part of the embodiments of the invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENT 1:
[0018] The present invention provides an intrusion detection method for intelligent substations based on the Hidden Markov Model, as Figure 1 shown, the method includes the following steps:
[0019] S1: Statistically analyze the historical network traffic of the intelligent substation, classify different packets, select an appropriate time window considering the detection accuracy and real-time data volume of the intelligent substation, divide the packets on a time scale, and extract the protocol field information, time characteristics, and traffic characteristic data of the historical packets.
[0020] S2: Model the key electrical parameters of the observable intelligent substation, and establish a voltage amplitude state equation, a voltage phase angle state equation, and a node current state equation.
[0021] S3: Discretize the three state equations to obtain the state equation of a single node, where F is the state transition matrix, indicating the evolution relationship of the system state over time.
[0022] S4: Establish the observation equation Z k= HX k + V s , where Z k is the observation vector, H is the observation matrix, and V s is the measurement noise, and X k is the state vector, are the sensor measurement values of voltage, phase angle, and current respectively.
[0023] S5: Set the initial state vector estimate X 0 , the initial state covariance matrix P 0 , the process noise covariance matrix Q, and the measurement noise covariance matrix R; establish the UKF model, and the state prediction equation: X k|k-1 = f(X k-1 ) + ω k , and the measurement prediction equation: Z k|k-1 = h(X k|k-1 ) + v k , where f(·) is the data state equation, h(·) is the measurement nonlinear equation, and ω k , v k are the noises of the normal distribution respectively.
[0024] S6: Establish the intelligent substation traffic model, divide the original message data according to the selected time window size, perform stationarity detection through the ADF test, and if it is not stationary, perform differencing operations until the ADF check is passed.
[0025] S7: Establish the ARIMA model for predicting traffic throughput changes, estimate the model parameters based on the Akaike information criterion, select the optimal model parameters, and train the model based on historical traffic data.
[0026] S8: Generate the model multiple times based on historical data, set rules to screen the model, generate detection thresholds based on the models generated multiple times, and the screening rules are as follows:
[0027]
[0028] where y max represents the maximum observed value in the historical data, represents the jth observed value predicted by the model, represents the mean of all predicted values, and X t represents the true value of the historical observed data,
[0029] According to determine the confidence interval for model detection, where P is the confidence level and S inside is the number of sequences within the traffic threshold interval, and S totalThe total number of sequences for simulation prediction; establish a time series model capable of calculating traffic throughput.
[0030] S9: Analyze the field characteristics and communication rules of the GOOSE and SV message protocols defined in the IEC-61850 standard to generate a protocol specification detection rule library.
[0031] S10: Generate a message specification detection vector Y n = [y 1 ,..., y n ; Perform protocol compliance detection on different fields of the message. Output 1 if the detection passes the setting, and 0 if it fails; establish a protocol compliance detection model: where P H is the protocol compliance of the message, y i is the i-th element in Y n , and y 0 is the standard message protocol specification detection vector.
[0032] S11: Combine the feature vectors obtained from the above models in the same time window to establish a hidden Markov model, and continue to train according to the feature vectors of historical data to calculate the model parameters λ = (π, A, B); where π is the initial state probability distribution, A is the state transition probability matrix, and B is the observation probability matrix.
[0033] S12: Capture network traffic from switches in the process layer and bay layer, perform preliminary classification on different messages, determine the message traffic size, select an appropriate time window size, and divide the messages.
[0034] S13: Extract the feature of each field of the message. For the measurement message, extract the voltage amplitude V k , voltage phase angle θ k and the current amplitude I k flowing through this node to generate a state vector X k = [V k , θ k , I k ;
[0035] S14: Predict the state vector and the error covariance matrix P k+1|k at the current time k + 1 according to the UKF model established in S5; Calculate the Kalman gain K k based on the observed data and the predicted value, and update the state estimation vector and the covariance matrix P k+1|k+1 ; According to the optimal estimated value and the actual measured value Z k+1, calculate the differences between the state variables and the measured values, and between the predicted values and the measured values, and further calculate the attack detection index to generate a data integrity detection vector ADI = [r 1 ,... r n for multiple nodes within a fixed time period.
[0036] S15: Based on the aggregated packet traffic data, predict the current packet traffic, calculate the difference between the measured packet traffic value and the detection threshold, and generate a traffic throughput detection vector TDV = [Δf 1 ,..., Δf n .
[0037] S16: Calculate the Hamming distance value between each packet and the standard packet, and generate a packet protocol compliance detection vector PNV = [d 1 ,..., d n according to the time aggregation scale per unit time.
[0038] S17: Obtain the detection vectors ADI, TDV, and PNV in the aforementioned detection stage, and construct a packet feature sequence O = [o 1 , o 2 ,..., o n .
[0039] S18: Use the forward algorithm to calculate the packet sequence probability where P(O|λ) is the probability that the observed sequence O appears under the model parameter λ, N represents the total number of hidden states, and α T (i) represents the probability of being in state i at time T; set the detection threshold T p , if P(O|λ) < T p , then determine that the current packet sequence is abnormal and there is an attack behavior. If P(O|λ) ≥ T p , then determine that the current packet sequence is normal.
[0040] Example 1:
[0041] As Figure 2 shown, the specific implementation steps of an intrusion detection method for intelligent substations based on the hidden Markov model in this example are as follows:
[0042] S1: Statistically analyze the historical network traffic of the intelligent substation, classify different packets, select an appropriate time window considering the detection accuracy and real-time data volume of the intelligent substation, divide the time scale of the packets, and extract the protocol field information, time characteristics, and traffic feature data of the historical packets.
[0043] S2: Model the electrical observables of the intelligent substation, and establish a voltage amplitude state equation, a voltage phase angle state equation, and a node current state equation.
[0044] In this embodiment, the voltage amplitude state equation is V k+1 = V k - aV k Δt + bI k Δt + W V,s , and the voltage phase angle state equation is The node current state equation is I k+1 = GV k cosθ k + BV k sinθ k + W I,s .
[0045] Where W V,s is the voltage amplitude process noise, W θ,s is the phase angle measurement process noise, W I,s is the current measurement process noise, P k indicates the active power injected at the node, Δt is the time step, a = 0.95, b = 0.02,
[0046] W V,s ~N(0, 0.01), c = 0.9, W θ,s ~N(0, 0.01), W I ,s~N(0, 0.01), G = 0.01, B = 0.05.
[0047] S3: Discretize the three state equations to obtain the state equation of a single node, where F is the state transition matrix, indicating the evolution relationship of the system state over time.
[0048] In this embodiment, the state equation of a single node is X k+1 = FX k + W k , X k represents the state vector, W k represents the process noise, and the state transition matrix F is:[[]]
[0049]
[0050] S4: Establish the observation equation Z k = HX k + V s , where H is the observation matrix, V s is the measurement noise, are the sensor measurement values of voltage, phase angle, and current respectively.
[0051] In this embodiment, the observation matrix The measurement noise V s ~N(0, R k), where R k represents the covariance matrix of the observation noise, and the diagonal elements of the matrix represent the variances of the measurement noises of different observation variables respectively.
[0052] S5: Set the initial state vector estimate X 0 , the initial state covariance matrix P 0 , the process noise covariance matrix Q, and the measurement noise covariance matrix R. Establish a UKF model, and the state prediction equation: X k|k-1 = f(X k-1 ) + ω k , and the measurement prediction equation: Z k|k-1 = h(X k|k-1 ) + v k , where f(·) is the data state equation, h(·) is the measurement nonlinear equation, ω k , v k are the noises of the normal distribution respectively;
[0053] In this embodiment, the initial state vector estimate X 0 is set as the first group of measurement values received, and the initial covariance matrix P 0 = diag(0.01, 0.1, 0.2), the process noise covariance matrix Q is calculated from historical data, Q = diag(0.0023, 0.0012, 0.0073), and the observation noise covariance matrix R = diag(0.0017, 0.00027, 0.093).
[0054] S6: Establish an intelligent substation traffic model, select the time window size according to the substation traffic characteristics, divide the original message data according to the time window, and perform a stationarity detection through the ADF test. If it is not stationary, perform a differencing operation until it passes the ADF verification.
[0055] In this embodiment, after the historical traffic data is differenced by the first order, the ADF verification result p = 0.0000183 < 0.05, indicating that the data can pass the time series stationarity verification after being differenced by the first order.
[0056] S7: Establish an ARIMA model for predicting the change of traffic throughput, estimate the model parameters according to the Akaike information criterion, select the optimal model parameters, and train the model based on the historical traffic data.
[0057] In this embodiment, after aggregating the historical traffic data on a time scale of 1 s, the traffic data model is:
[0058] Among them,
[0059] y t-i represents the traffic data of the previous i time steps, εt Represents random noise.
[0060] S8: Generate models multiple times based on historical data, set rules to screen the models, generate detection thresholds based on the models generated multiple times, and determine the confidence interval for model detection according to ; Establish a time series model capable of calculating traffic throughput.
[0061] In this embodiment, the screening rules are as follows:
[0062]
[0063] The method for generating the detection threshold is as follows:
[0064]
[0065] where y max represents the maximum observed value in the historical data, represents the j-th observed value predicted by the model, represents the mean of all predicted values, X t represents the true value of the historical observed data, Y j represents the predicted value for the j-th observation, and k represents the total number of time steps.
[0066] In 1000 model generation experiments, sequences meeting the requirements were screened out through the screening rules, accounting for 97.32%. Based on this ratio, a 95% confidence interval was set, and this threshold can cover the vast majority of normal traffic fluctuations.
[0067] S9: Statistically analyze the protocol specifications of multiple IEC-61850 messages, generate multiple protocol detection rules, and establish a message protocol specification detection rule library.
[0068] In this embodiment, 37 detection rules were generated based on the IEC-61850 protocol: e.g., (#R1) The first four bytes of the MAC address of the message must be 01-0c-cd-01 or 01-0c-cd-04 (#R2) The value of the TPID field of the message must be 0x8100.
[0069] S10: Generate a message specification detection vector Y n = [y 1 ,..., y n according to the detection results of a single message for multiple rules; perform legality detection on different fields of the message, output 1 if the detection passes the setting, and output 0 if it fails.
[0070] In this embodiment, taking the 6th message in 30 seconds as an example, this message violates #R27, #R53, #R54, and the rule detection vector is Y n= [0,..., y 27 ,..., 0,..., y 53 , y 54 ,..., 0]。
[0071] Establish a protocol compliance detection model: where P H is the protocol compliance of the message, y i is the i-th element in Y n , and y 0 is the standard message protocol specification detection vector.
[0072] S11: Combine the feature vectors obtained from the above model under the same time window, establish a Hidden Markov Model, continue to train according to the feature vectors of historical data, and calculate the model parameters.
[0073] In this embodiment, the model parameters are π = [0.8973, 0.0619, 0.0253, 0.0155],
[0074]
[0075] S12: Capture network traffic from switches in the process layer and the bay layer, perform a preliminary classification on different messages, determine the message traffic size, select an appropriate time window size, and divide the messages.
[0076] S13: Extract the feature of each field of the message. For the measurement message, extract the voltage amplitude V k , the voltage phase angle θ k , and the current amplitude I k flowing through this node, and generate the state vector X k = [V k , θ k , I k ;
[0077] S14: Predict the state vector and the error covariance matrix P k+1|k at the current moment k + 1 according to the UKF model established in S5, calculate the Kalman gain K k according to the observed data and the predicted value, update the state estimation vector and the covariance matrix P k+1|k+1 , and calculate the difference between the state variable and the measured value, the difference between the predicted value and the measured value according to the optimal estimated value and the actual measured value Z k+1 , and further calculate the attack detection index, and generate the data integrity detection vector ADI = [r 1 ,... r n for multiple nodes within a fixed time period.
[0078] In this embodiment, the data integrity detection value Taking the detection at the 30th second as an example, the generated data integrity detection vector
[0079] ADI 30 =[0.1023, 0.2354, 0.1231, 0.2674, 0.5112, 0.77245, 0.1983, 0.0945, 0.3146, 0.0987]. Where is the static state estimation value at the (i + 1)-th moment, is the state mixing prediction value at the (i + 1)-th moment, and x' is the deviation vector from the i-th moment to the (i + 1)-th moment; is the average value of x'.
[0080] S15: According to the aggregated packet traffic data, predict the current packet traffic, calculate the difference between the measured value of the packet traffic and the detection threshold, and generate the traffic throughput detection vector TDV = [Δf 1 ,..., Δf n .
[0081] In this embodiment, the detection threshold is the 95% confidence interval of the predicted value. Taking the 30th second as an example, the generated traffic throughput detection vector
[0082] TDV 30 =[0.1023, 0.0854, 0.1231, 0.0674, 0.0912, 0.1245, 0.0983, 0.0945, 0.1146, 0.0987]
[0083] S16: Calculate the Hamming distance value between each packet and the canonical packet, and generate the packet specification detection vector PNV = [d 1 ,..., d n according to the time aggregation scale;
[0084] In this embodiment, taking the 30th second as an example, the normalized packet specification detection vector PNV = [0, 0, 0, 0, 0, 0.723,..., 0, 0, 0.103, 0]
[0085] S17: Obtain the detection vectors ADI, TDV, and PNV in the aforementioned detection stage, and construct the packet feature sequence O = [o 1 , o 2 ,..., o n .
[0086] S18: Use the forward algorithm to calculate the packet sequence probability Set the detection threshold T p , if P(O|λ) < Tp , it is determined that the current message sequence is abnormal and there is an attack behavior. If P(O|λ) ≥ T p , it is determined that the current message sequence is normal.
[0087] In this embodiment, after the fusion feature vector at the 30th second is calculated by the hidden Markov model, P(O 30 |λ inject ) = 0.734 > T p , so it is determined that a false data injection attack occurred in the system's detection at the 30th second.
[0088] In addition, it should be understood that although this specification is described according to embodiments, not every embodiment only contains an independent technical solution. This narrative way of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A method for detecting intrusion in smart substations based on hidden Markov model, characterized in that: The method comprises the following steps: S1: Segment the continuous network traffic according to the time scale, extract the message identifier, message transmission measurement data and message throughput size that can characterize the message protocol compliance in the same time window, and build a complete intrusion detection data set; S2: Extract the measurement data of the node, calculate the difference between the state variable and the measurement value based on the unscented Kalman filter method, and establish a state model that can calculate the attack detection index that reflects the degree of variable deviation; S3: The real-time traffic of packets is regarded as time series data and modeled through the ARIMA model. Based on the traffic change law, the traffic model with the best fitting effect is selected from the traffic models after multiple fittings. The confidence interval of the detection is determined based on the screening rules, and a time series model that can calculate the traffic throughput is established. S4: Based on the IEC 61850 protocol specification, multiple protocol compliance detection rules are established, and based on the Hamming distance calculation method, a standard detection model is established to determine whether the message complies with the communication protocol specification; S5: Real-time detection of smart substation network traffic. The data integrity detection vector, traffic throughput detection vector, and protocol compliance detection vector are calculated based on the models established in S2, S3, and S4. After normalization, they are used as input variables of the hidden Markov model. Combined with the observed sequence data, a comprehensive analysis of the system abnormal characteristics is performed to achieve final judgment.
2. The detection method according to claim 1, characterized in that: The steps of segmenting the continuous network traffic according to the time scale in S1 are: counting the historical network traffic of the smart substation, classifying different messages, selecting the time window size according to the detection accuracy requirements of the smart substation and the size of the real-time data volume, and segmenting the continuous network traffic to ensure that the traffic in each time unit has temporal correlation and behavioral consistency.
3. The detection method according to claim 1, characterized in that: The specific steps of S2 are as follows: S2.1: Model the electrical observables of the smart substation and establish the voltage amplitude state equation, voltage phase angle state equation, and node current state equation; S2.2: Discretize the three state equations to obtain the state equation of a single node, where F is the state transfer matrix, indicating the evolution of the system state over time; S2.3: Establish the observation equation Z k =HX k +V s ,in Z k is the observation vector, H is the observation matrix, V s is the measured noise, X k is the state vector, They are the sensor measurement values of voltage, phase angle and current respectively; S2.4: Establish UKF model, state prediction equation: X k|k-1 =f(X k-1 )+ω k , measurement prediction equation: Z k|k-1 =h(X k|k-1 )+v k , where f(·) is the data state equation, h(·) is the measurement nonlinear equation, ω k ,v k is the noise of normal distribution.
4. The detection method according to claim 1, characterized in that: The specific steps of S3 are as follows: S3.1: Establish a smart substation flow model, select the time window size according to the substation flow characteristics, divide the original message data according to the time window, and perform a stability test through the ADF test. If it is not stable, perform a differential operation until it passes the ADF check; S3.2: Establish an ARIMA model for predicting traffic throughput changes, determine the model order according to the Akaike Information Criterion, and fit the model parameters using the exact maximum likelihood method based on historical traffic throughput data; S3.3: Fit the model multiple times, set rules to screen the model, and generate detection thresholds based on the multiple generated models. The screening rules are as follows: Among them, y max represents the maximum observed value in historical data, represents the j-th observation value predicted by the model, represents the mean of all predicted values, X t represents the true value of historical observation data, in accordance with Determine the confidence interval of the model detection, where P is the confidence level and S inside is the number of sequences within the flow threshold interval, S total The total number of sequences predicted for the simulation; a timing model is built that can calculate the traffic throughput.
5. The detection method according to claim 1, characterized in that: The specific steps of S4 are: S4.1: Count the protocol specifications of more than IEC-61850 messages, generate multiple detection rules for protocol compliance detection of message identifiers, and establish a message protocol specification detection rule base; S4.2: Generate a message standard detection vector Y based on the detection results of multiple rules for a single message n =[y1,...,y n ]; Perform protocol compliance detection on different fields of the message, output 1 if the detection setting is passed, and output 0 if it fails; establish a protocol compliance detection model: Where P H is the protocol compliance of the message, y i Y n The i-th element in y0 is the standard message protocol specification detection vector.
6. The detection method according to claim 3, characterized in that: The specific steps of S5 are: S5.1: Combine the feature vectors obtained by the above models under the same time window, establish a hidden Markov model, continue training according to the feature vectors of historical data, and calculate the model parameters λ = (π, A, B), where π is the initial state probability distribution, A is the state transition probability matrix, and B is the observation probability matrix; S5.2: Capture real-time network traffic from switches at the process layer and the bay layer, and extract message identifiers, message transmission data, and message throughput from real-time messages that can characterize message protocol compliance; S5.3: Extract the voltage amplitude V from multiple node measurement messages k , voltage phase angle θ k and the current amplitude I flowing through the node k , generating the state vector X k =[V k ,θ k ,I k ]; S5.4: Predict the state vector at the current time k+1 according to the UKF model established in S2.4 and the error covariance matrix P k+1|k , calculate the Kalman gain K based on the observed data and the predicted value k , update the state estimate vector and the covariance matrix P k+1|k+1 , according to the optimal estimate Compared with the actual measured value Z k+1 , calculate the difference between the state variable and the measured value, the difference between the predicted value and the measured value, and further calculate the attack detection index to generate the data integrity detection vector ADI=[r1,...r n ]. S5.5: According to the aggregated packet flow data, the current packet flow is predicted, the difference between the real-time packet flow measured value and the detection threshold is calculated, and the flow throughput detection vector TDV=[Δf1,...,Δf n ]; S5.6: Calculate the Hamming distance between each message and the standard message, and generate the message protocol compliance detection vector PNV=[d1,...,d n ] S5.7: The detection phase described above obtains the detection vectors ADI, TDV, and PNV, and constructs the message feature sequence O = [o1, o2, ..., o n ]; S5.8: Calculate message sequence probability using the forward algorithm Where P(O|λ) is the probability of the sequence O appearing under the model parameter λ, N is the total number of hidden states, α T (i) represents the probability of being in state i at time T; set the detection threshold T p , if P(O|λ)<T p , then the current message sequence is judged to be abnormal and there is an attack behavior. If P(O|λ)≥T p , then the current message sequence is determined to be normal.
Citation Information
Patent Citations
Repeated machining process concealment attack detection method based on hidden Markov model
CN110290118A
Power system abnormal behavior analysis method based on hidden Markov model
CN114218998A
Active power distribution network attack detection method based on distributed state estimation
CN116865991A