A method for identifying key equipment in power transmission systems against low-granularity timing attacks
By building a modular topological model and fault propagation matrix, optimizing attack sequence and defense scheduling, the problem of not being able to identify key equipment in the power transmission system in the existing technology is solved, and efficient protection and recovery of low-grained timing attacks is achieved.
Patent Information
- Application Number
- CN202510219543.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-02-26
AI Technical Summary
When responding to low-grained timing attacks, the existing technology cannot accurately identify key equipment in the power transmission system, and lacks dynamic adjustment and recovery capabilities, resulting in poor protection effects.
Build a modular topology model, establish a fault propagation matrix, select the attack target area through the depth-first search algorithm, set resource limits, optimize the attack sequence, and combine the defense scheduling strategy to minimize system load loss.
It improves the recognition ability of low-grained timing attacks, enhances the system's security and defense response efficiency, avoids resource waste, and optimizes the attack effect.
Smart Images

Figure CN120146282B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system security protection, and in particular to a method for identifying key equipment in a power transmission system oriented to low-granularity timing attacks. Background Art
[0002] As power systems become increasingly complex, the cybersecurity threats they face are also increasing. This is particularly true of timing attacks targeting transmission systems, which are often concealed and complex, posing challenges to traditional defense mechanisms. In real life, power is at the core of national infrastructure, and any systemic failure can have widespread societal impacts. Therefore, improving the transmission system's ability to resist attacks and enhancing the identification capabilities of key equipment are urgent issues that need to be addressed.
[0003] Existing technologies typically rely on holistic defense strategies, focusing on the comprehensive monitoring and protection of equipment and lines. Traditional transmission system attack protection primarily relies on static topology models and protection level settings to ensure effective protection against simple attacks. These solutions typically address single points of failure and maintain basic system stability. Existing technologies also address attacks through resource allocation optimization, primarily by regularly evaluating the performance and health of key equipment to ensure the overall system's fault tolerance.
[0004] However, existing technologies have some shortcomings when dealing with low-granularity timing attacks. First, most existing methods rely on coarse-grained system models, ignoring the specific distribution and interrelationships of devices, making it difficult to accurately identify key modules after an attack. For complex timing attacks, traditional models cannot track the attack path and its impact on other devices in real time, and are prone to missing protection for critical facilities. Second, existing attack resource allocation schemes are mostly static configurations and cannot dynamically adjust resources to cope with changes in multiple rounds of attacks, resulting in poor protection effects. Finally, although existing technologies have certain solutions for single-point fault recovery, they lack sufficient refined analysis when it comes to fault propagation between modules and cannot accurately predict the system status after an attack. Summary of the Invention
[0005] In response to the shortcomings of the existing technology, the present invention provides a method for identifying key equipment in the power transmission system under low-granularity timing attacks, which solves the problems in the existing technology that the key equipment in the power transmission system under low-granularity timing attacks cannot be accurately identified and lacks dynamic adjustment and recovery capabilities.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a method for identifying key equipment in a power transmission system against low-granularity timing attacks, comprising the following steps:
[0007] S1. Build a modular topology model for the power transmission system, dividing the equipment in the power transmission system into multiple equipment modules based on their geographical clustering. The module division is based on the electrical connection relationship, geographical location, geographical clustering characteristics, and functional aggregation of the equipment.
[0008] S2. Establish a fault propagation matrix to simulate the fault propagation path between modules and analyze the impact of module failure on other modules in the system;
[0009] S3. Select the target area from the attacker's perspective, set the goal of maximizing the load loss within the target area, and limit the maximum proportion of additional load loss outside the area;
[0010] S4. Based on the depth-first search algorithm, expand outward from the load nodes in the target area, gradually search all possible power supply paths, record the modules and lines involved in the path, and form an attack decision variable set;
[0011] S5. Define attack decision variables and recovery state variables to represent the attack state and recovery state of each module, and calculate their impact on system fault propagation;
[0012] S6. Set resource limits for each attack round, control the number of modules in each attack round, and ensure that the load loss outside the area does not exceed the preset threshold;
[0013] S7. Optimize the selection of attack target modules based on temporal analysis, calculate the cumulative impact of multiple rounds of attacks on load loss, select the modules that are most likely to cause load loss in each round for attack through temporal analysis and optimization algorithms, and adjust the attack sequence to maximize the load loss in the target area;
[0014] S8. Set the defender's scheduling strategy, simulate the load recovery process after the attack, and minimize the system's load loss by optimizing the scheduling plan;
[0015] S9. Optimize module recovery time. Adjust the selection of attack target modules based on recovery time and repair status to ensure module stability after recovery.
[0016] S10. Identify key equipment in the power transmission system based on the attack results, and determine key modules through impact analysis.
[0017] The present invention provides a method for identifying key equipment in a power transmission system against low-granularity timing attacks.
[0018] It has the following beneficial effects:
[0019] 1. This invention modularizes the power transmission system based on geographic clustering, dividing devices into multiple modules to clearly visualize the connections within the power system. Unlike traditional monolithic network models, this modular division makes identifying low-granularity attacks more efficient, improving system security.
[0020] 2. Construct a fault propagation matrix to simulate inter-module fault propagation and accurately analyze the mutual impact of modules in the system. This method effectively addresses the existing technology's lack of consideration of inter-module fault interactions, making fault assessment more scientific and comprehensive.
[0021] 3. For multi-round sequential attacks, this invention proposes a precise attack target optimization strategy. By rationally allocating attack resources and adjusting the attack sequence, it is possible to maximize the load loss in the target area while limiting external load loss. This strategy is more flexible and efficient than existing methods, avoiding resource waste and optimizing attack effectiveness.
[0022] 4. This invention utilizes a two-tiered optimization model to achieve dynamic coordination between attackers and defenders. By simultaneously optimizing both attack and defense decisions, it not only maximizes attack effectiveness but also improves the efficiency of defense responses. Unlike traditional approaches that address attack and defense separately, this integrated optimization framework ensures more comprehensive system protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the specification of the present invention. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0025] Please see the attached Figure 1 The embodiment of the present invention provides a method for identifying key equipment in a power transmission system against low-granularity timing attacks, comprising the following steps:
[0026] S1. Build a modular topology model for the power transmission system, dividing the equipment in the power transmission system into multiple equipment modules based on their geographical clustering. The module division is based on the electrical connection relationship, geographical location, geographical clustering characteristics, and functional aggregation of the equipment.
[0027] The purpose of step S1 is to construct a modular topology model of the power transmission system. This step divides the various devices in the power transmission system and organizes them into multiple functional modules based on geographical clustering. The core concept of the modular topology model is to break down the complex structure of the power system into multiple relatively independent modules, facilitating subsequent fault propagation analysis, attack path optimization, and identification of critical equipment.
[0028] In this step, each device module contains several devices, which are often closely related in terms of functionality. For example, busbars, circuit breakers, and transformers within a substation may be divided into different modules, and the devices within these modules work together through electrical connections. Therefore, the functional relationships between modules also determine their roles in the power system. This modular division facilitates precise control and identification of system status and attack effects.
[0029] Alternatively, the module partitioning method in this invention can be based on a graph theory model, where each module is considered a node, and the edges between nodes represent the electrical connections between modules. This method can clearly represent the connection paths between modules, which provides a foundation for fault propagation and attack path optimization in subsequent steps.
[0030] Specifically, the division of modules needs to consider the following factors:
[0031] Electrical connections: The devices within each module share certain functions through electrical connections such as transmission lines, busbars, and transformers. A detailed analysis of the devices' electrical connections can help determine which devices should be grouped into the same module.
[0032] Functional aggregation: The functional characteristics of each module determine its importance to the system operation.
[0033] Geographical proximity: The geographic proximity and clustering characteristics of devices are also important factors to consider when assigning modules. Geographically adjacent and functionally closely related devices should be grouped into the same module whenever possible. This helps improve the accuracy of system analysis and attack identification.
[0034] In one possible implementation, each substation is divided into modules, with the individual devices (such as transformers, circuit breakers, and busbars) categorized by their electrical connections and functions. The module divisions are based not only on the electrical characteristics of the devices but also on their geographic location, clustering, and operational tasks.
[0035] In this step, the electrical relationship between devices is expressed by constructing the association matrix between modules and circuits. n, we define the set of power transmission paths it connects to R n , the set contains all n Related power transmission paths. The correlation matrix between modules and lines:
[0036]
[0037] Among them, M i,j is the electrical connection status between module i and module j; N is the total number of modules in the system; i, j are the module numbers, representing different modules in the system.
[0038] This matrix is used to represent the electrical connection status of each module with other modules and provides a basis for subsequent attack path selection and fault propagation analysis. Module electrical transmission path collection:
[0039] For each module M n , we define its electrical transmission path set R n :
[0040] R n ={R n1 ,R n2 ,...,R nw};
[0041] Among them, R n Indicates module M n The set of all power transmission paths; R nk Indicates module M n The kth power transmission path in the module M n The number of power transmission paths.
[0042] This set describes the module M n The connection relationship of all internal power transmission paths provides a path basis for subsequent fault propagation analysis.
[0043] For each module, a functional association matrix F is defined to represent the functional aggregation relationship of each device in the module:
[0044]
[0045] Among them, F i,j is the functional relationship between device i and device j; u is the total number of devices in the module; i, j are device numbers, representing different devices in the module.
[0046] This matrix is used to express the functional relationship between devices within the module, helping to identify devices that have close functional connections within the module, thereby providing a basis for subsequent attack identification and path optimization.
[0047] By constructing a modular topological model of the transmission system, the electrical connection relationship, functional aggregation, geographical location, and geographical aggregation characteristics of each module can be clearly described, which provides a solid foundation for subsequent fault propagation analysis, attack path optimization, and key equipment identification.
[0048] S2. Establish a fault propagation matrix to simulate the fault propagation path between modules and analyze the impact of module failure on other modules in the system;
[0049] The goal of step 2 is to analyze the system's vulnerability by quantifying the impact of each module's failure on other modules, particularly the transmission effects of failures in key devices in the system when facing low-granularity timing attacks. Establishing a fault propagation matrix provides critical data support for subsequent steps, such as attack path identification and load loss calculation.
[0050] In this step, the fault propagation matrix is constructed based on the electrical connections between modules. Each module can be considered a node in a network, with electrical connections forming edges between nodes. When a module fails, its fault status affects all connected modules. By modeling the electrical connections between these modules and constructing the fault propagation matrix, we can accurately depict the path of fault propagation from the source module to other modules.
[0051] As an option, the fault propagation matrix can be represented in a similar way to the adjacency matrix. The elements in the matrix D i,j It represents the propagation relationship of module i to module j fault. If D i,j =1, it means that the failure of module i will directly affect module j. If D i,j = 0, it means that the failure of module i will not directly affect module j. These propagation relationships are calculated directly based on the electrical connections between modules and the device functions.
[0052] Specifically, when constructing a fault propagation matrix, the electrical connections between modules must be considered first. The electrical transmission paths between modules can be used to derive the fault propagation relationships between each module. These paths include not only directly connected lines but also indirect transmission through devices such as transformers and circuit breakers. Each element in the matrix reflects the dependencies between modules, providing a foundation for subsequent analysis.
[0053] Fault propagation matrix D n It is a core tool used to represent the fault propagation path. The purpose of this matrix is to calculate and describe the direct or indirect impact that a module failure may have on other modules in the system, including the fault propagation matrix:
[0054]
[0055] Among them, Dj,j is the fault propagation effect of module i on module j. If it is 1, it means that the failure of module i will cause the failure of module j; if it is 0, it means there is no direct impact; u is the total number of modules in the system, which represents the dimension of the fault propagation matrix; i, j are the module numbers, representing different modules in the system; the fault propagation matrix D n It provides a basis for subsequent attack path identification and system vulnerability analysis, and can quantify the fault propagation effect between modules.
[0056] For each module M n , define its fault propagation path set R n , the set contains all possible n Path affected by the fault.
[0057] For each module M n , define a fault impact function f n , used to describe the module M n The impact of a fault on the propagation of faults in the entire system. The form of this function is:
[0058]
[0059] Among them, f n Indicates module M n The impact of the fault on other modules in the system; D n,i For module M n For module M i The degree of impact of the failure; R n,i For module M n To module M i fault propagation path.
[0060] This function is used to quantify the system impact of module failures, providing a quantitative basis for subsequent attack path optimization and system vulnerability identification.
[0061] The above formulas and technical details can accurately describe the fault propagation path between modules and quantify the impact of each module failure on other modules. This not only provides data support for attack path selection and load loss calculation in subsequent steps, but also helps identify potentially vulnerable modules in system analysis.
[0062] S3. Select the target area from the attacker's perspective, set the goal of maximizing the load loss within the target area, and limit the maximum proportion of additional load loss outside the area;
[0063] S3 further determines the target area for attack and sets the attack strategy to maximize the load loss within the target area while limiting the additional load loss caused by the attack in other areas of the system to ensure the locality and accuracy of the attack.
[0064] In this step, the attacker's goal is to select one or more power plants as targets, maximizing load loss within the target area while ensuring that additional load loss outside the area is within a reasonable range. This process involves several key parameters, including the selection of the target area, the calculation method for load loss, the allocation strategy for attack resources, and the constraints on additional load loss outside the area.
[0065] In general, the selection of target areas should consider factors such as the location of load centers, the redundancy of power equipment, and the ability to recover after an attack. Furthermore, the target area should not overlap with the core nodes of the entire system to avoid cascading failures beyond the controllable range.
[0066] In one possible implementation, a mathematical optimization model can be used to solve the target area selection and attack strategy. Specifically, the optimization objective function of the attack target area can be expressed as:
[0067] The objective function for maximizing the load loss in the target area is:
[0068]
[0069] in: V represents the load loss of substation n after the tth round of attack; in represents the set of all substations in the selected target area; n∈V in represents the set of substations or load nodes in the target area, where V in is the set of all load nodes or substations in the target area, n represents a specific node in the set; max represents the maximization of the objective function.
[0070] The significance of this objective function is to select the area that can cause the maximum load loss among all possible attack targets to optimize the attack effect. Additional load loss constraints outside the area:
[0071]
[0072] Where: V out represents the set of all substations in the system that do not belong to the target area; ξ t The maximum proportion of additional load loss outside the area, usually set to less than or equal to 0.2; is the total load of the system during the tth attack cycle.
[0073] The purpose of this constraint is to control the scale of load loss outside the area, ensure the localization and precision of the attack, and avoid large-scale power outages caused by excessive attacks.
[0074]
[0075] Among them: B n represents the set of all busbar nodes in substation n; represents the load loss of the i-th bus in substation n.
[0076] This formula is used to calculate the load loss of each substation in the target area and is further refined to the bus level to quantify the load impact of different buses.
[0077] To achieve the above goals, we need to define the attack decision variables
[0078]
[0079] in: Indicates whether module i in substation n is attacked; when When , it means that the module is selected as the attack target in this round of attack; when , it means the module has not been attacked.
[0080] This variable is used to control the target of the attack and to find the optimal choice of the attack target through optimization. Attack resource constraints:
[0081]
[0082] Among them: A t represents the maximum attack resource available to the attacker in the tth round of attack; A represents the set of all optional attack targets; Indicates whether module i is selected as the attack target in the tth round of attack; It represents the total number of modules selected as attack targets in the tth round of attack.
[0083] This constraint is used to control the resource limit of each round of attack, ensuring that the attacker can perform the optimal attack within the limited resource range.
[0084] Using the above formula and optimization strategy, this step accurately selects the target area for attack and, through mathematical optimization, maximizes the load loss within the target area while keeping the additional load loss outside the area within a controllable range. The introduction of attack decision variables makes the selection of attack targets more flexible, while the constraint on attack resources ensures that the attacker can execute the optimal strategy within limited resources.
[0085] The optimization process in this step can be performed using methods such as mixed integer linear programming (MILP) or genetic algorithms (GA) to quickly obtain the optimal attack path and target combination. This strategy not only improves the accuracy of the attack, but also ensures its effectiveness and avoids excessive damage to the overall stability of the system.
[0086] Through this strategy, attackers can effectively carry out low-granularity timing attacks, identify and attack critical power equipment, thereby achieving maximum disability in local areas and maintaining the concealment and controllability of the attack within a certain range.
[0087] S4. Based on the depth-first search algorithm, expand outward from the load nodes in the target area, gradually search all possible power supply paths, record the modules and lines involved in the path, and form an attack decision variable set;
[0088] S4 uses a depth-first search algorithm to expand outward from the load nodes in the target area, gradually exploring all possible power supply paths, and recording the equipment modules and lines involved in the paths, ultimately forming an attack decision variable set.
[0089] This step begins at the load nodes in the target area and expands outward using a depth-first search algorithm, progressively searching all possible power supply paths. For each path, the modules and circuits involved are recorded and used as a variable set for subsequent attack decision-making. The definition of each power supply path not only helps attackers target critical power supply pathways in the system but also enables them to make precise attack decisions based on the modules in the path.
[0090] Generally, searching all possible power supply paths starting from the load node ensures that the most important power supply paths in the system are captured. By using a depth-first search algorithm, an attacker can systematically traverse all paths, ensuring that no modules or lines that may become targets are missed.
[0091] In one possible implementation, in order to improve the search efficiency, the search range can be limited by setting the search depth and the maximum length of the path to avoid redundant calculations during the search process. For example, we can set a maximum search depth D max , and adjust the search strategy according to the topology and resource constraints of the power grid to ensure that the attacker can efficiently identify the critical path within a suitable range.
[0092] In this step, the most critical mathematical representation involves searching and recording the power supply path. To do this, we define the path is the power supply path from the target area node n to the external power source node k. The path is gradually expanded through the depth-first search algorithm. The path search is:
[0093]
[0094] in: represents the power supply path from the target area node n to the external power source node k; n represents the load node of the target area; l1, l2, ..., l mis the power line node in the path; k1, k2, …, k are the equipment nodes in the path.
[0095] This path representation helps us to gradually expand the search, recording all power paths related to the target area.
[0096] Define P n It is the set of all possible power supply paths for the load node n in the target area, which contains the lines and equipment modules directly or indirectly related to the target area:
[0097]
[0098] Where: P n represents the set of all power supply paths starting from the load node n in the target area; represents the distance from the target area load node n to different external power source nodes k1, k2, ..., k m power supply path.
[0099] By recording the modules and lines involved in the path, the attacker can form the attack decision variable set A n , which represents the attack status of the device module in each path during the attack process. Define the attack status of each module
[0100] In order to facilitate the subsequent path selection and attack decision analysis, the association matrix R between the path and the module is defined n2 , indicating the association between each module in each power supply path:
[0101]
[0102] Where: R n2 A matrix representing the module's recovery state; Represents the recovery state of module u after the mth round of attack; u is the total number of modules, indicating the number of modules participating in the attack in the target area; m is the total number of attack rounds, indicating the number of rounds in the attack process, which affects the recovery time and recovery process.
[0103] Using a depth-first search algorithm, we can gradually expand the search to all possible power supply paths, starting from the load nodes in the target area. In each path, the modules and lines involved will be recorded to form a set of attack decision variables.
[0104] S5. Define attack decision variables and recovery state variables to represent the attack state and recovery state of each module, and calculate their impact on system fault propagation;
[0105] The task of S5 is to define the attack decision variables and recovery state variables of each module, which provides important technical support for the subsequent attack process, resource allocation and recovery state management.
[0106] In this step, we further define the attack decision variables and recovery state variables so that we can track the attack and recovery status of the module during the attack process and calculate and evaluate the overall impact of these states on the system. Specifically, the attack decision variables And restore state variables It continues to change throughout the attack, affecting the efficiency of the attack and the system's recovery capabilities.
[0107] The definition of these variables is crucial for attack decision making and resource optimization. It is used to determine whether module i in the target area will be selected as the attack target in a certain round of attack; and the state variable is restored. It is used to mark whether module i has recovered to its normal state after being attacked. This mechanism not only supports the optimization of multiple rounds of attacks, but also reasonably allocates attack resources and controls the negative impact of the attack process.
[0108] Generally speaking, to accurately calculate the state of each module, the attack decision variable and recovery state variable need to be dynamically updated according to the different circumstances of each attack round. During each attack round, the module's recovery state changes as the recovery process progresses, affecting the subsequent attack choices. Therefore, the design of these two variables is key to ensuring the effective implementation of the attack strategy.
[0109] As an option, the update of the recovery status is closely linked to the module's recovery time. Recovery time is defined as the time it takes for a module to return to normal after an attack and is typically determined by module hardware repairs, system scheduling, and external factors. Each module's recovery status is adjusted to determine whether it is recovering or fully recovered.
[0110] Specifically, define the attack decision variables and restore state variables as follows:
[0111] Restore state variables Indicates whether module i has recovered to normal state after the tth round of attack. It means that module i has returned to normal; if This means that module i has not been restored.
[0112]
[0113] in: Indicates that module i has returned to normal status; Indicates that module i has not been restored.
[0114] In one possible implementation, the recovery state is related to the module's recovery time. Refers to the time it takes from the start of the attack to the module returning to normal state. Recovery time The repair process varies depending on factors such as the type of module, the number of devices to be repaired, and the external environment.
[0115] The recovery time is calculated as follows:
[0116]
[0117] Where: t is the current attack time; tx is the time when module i is attacked; is the recovery time of module i.
[0118] Furthermore, if a module takes a long time to recover, it cannot be attacked again during the recovery period. Therefore, modules with long recovery times may become more valuable attack targets. Through this strategy, attackers can maximize system losses within a limited time.
[0119] Attack decision variables and recovery state variables can not only accurately describe the status of each module, but also optimize the attack strategy by calculating the mutual influence between modules to ensure the maximum benefit of each round of attack.
[0120] S6. Set resource limits for each attack round, control the number of modules in each attack round, and ensure that the load loss outside the area does not exceed the preset threshold;
[0121] The primary purpose of S6 is to set resource limits for the attack, ensuring that each attack round is conducted within the controlled resource range and preventing the load loss outside the attack area from exceeding a predetermined threshold. This step is closely linked to the aforementioned step S5, ensuring the rational allocation of attack resources and maximizing the attack effectiveness. To achieve this goal, precise control of resources for each attack round is required, as well as calculation of the choice of attack targets and their impact on other areas.
[0122] Through step S6, we can ensure that attack resources are not overconsumed during multiple rounds of attacks. This allows us to allocate sufficient resources to the target area across multiple rounds, while maintaining system stability and avoiding excessive impact on other areas. In particular, controlling the loss of load outside the area is crucial to preventing system collapse. This strategy optimizes attack effectiveness while effectively reducing the risk of a complete system failure.
[0123] The attack resource constraint formula in S3 is used to limit the resources for each round of attack.
[0124] Generally speaking, A t It is set according to the size of the target area, the recovery status of the module and the current attack strategy. For example, if the power load of the target area is large, the attacker may need to invest more resources to attack, so A t If the target area has a small power load or the system is well restored, then A t It may be smaller.
[0125] In some embodiments, A t The setting of A may depend on dynamic factors. For example, the current load level of the system, the recovery status of the module, or the degree of damage in the system can affect A. t For example, when the attacker chooses to attack a module with a smaller impact range, A t It can be reduced appropriately to avoid excessive consumption of system resources.
[0126] in addition, This represents the attack decision for each module within a specific round. By carefully selecting modules, attackers can focus their attacks on the most critical infrastructure, rapidly crippling the transmission system. To avoid overly dispersed attacks, the number of modules targeted in each round is strictly controlled, ensuring high attack efficiency and minimizing negative impacts on unrelated areas.
[0127] In step S6, the most important control mechanism is to limit the resources of each round of attack. This limit is not only related to the attacker's decision-making, but also affects the sustainability of the entire attack process and the system's recovery ability. The attack strategy can be flexibly adjusted to prevent attackers from over-relying on a single target module, thereby maximizing the comprehensive effect under multiple rounds of attacks.
[0128] As a further illustration, in practice, when the attack decision of module i changes, A t Real-time adjustments can also be made based on the strategy, ensuring that the attack is not only strategically significant but also flexible based on actual conditions. In this way, step S6 effectively combines the allocation of attack resources with system load control, ensuring the accuracy of the attack and the stability of the system.
[0129] Specifically, if the attacker's goal is to ensure that the load loss outside the area is controlled within a certain acceptable range, then A t The load distribution must be considered when setting the tCalculations are dynamically assessed based on the overall load outside the region to ensure that each attack does not cause widespread power outages. This allows attackers to precisely control resource allocation and minimize negative impacts on the rest of the system.
[0130] By limiting the number of attack modules in each attack round and ensuring that the load loss outside the area does not exceed a predetermined threshold, the attack can be carried out efficiently and orderly, thus achieving the best results over multiple rounds of attacks. At the same time, reasonable resource allocation ensures that the attacker can continue to effectively attack the target area without excessively consuming system resources and avoiding the risk of excessive system crashes.
[0131] S7. Optimize the selection of attack target modules based on temporal analysis, calculate the cumulative impact of multiple rounds of attacks on load loss, select the modules that are most likely to cause load loss in each round for attack through temporal analysis and optimization algorithms, and adjust the attack sequence to maximize the load loss in the target area;
[0132] The goal of S7 is to optimize the selection of attack target modules based on temporal analysis. By leveraging the cumulative effects of multiple rounds of attacks, the attack sequence is optimized to maximize the load loss in the target area. The key to this step is to fully utilize the temporal nature of the attack, comprehensively consider the load loss of each module, and adjust the order of attack target modules to achieve the optimal attack effect.
[0133] The goal of step S7 is to dynamically adjust the attack sequence based on the load loss during each attack round, maximizing the system's total load loss over multiple rounds. Timing analysis can predict the chain reaction after each attack round, allowing for the optimal selection of attack sequences and target modules to maximize load loss in the target area.
[0134] Based on the effects of load loss and cascading failures, calculate the load loss inflicted on the system after each attack. The target module is not only directly affected by the attack but can also cause cascading failures in other connected modules and lines. Therefore, when selecting attack targets, it is necessary to consider the inter-module connections and predict the impact of the current attack on subsequent load loss.
[0135] According to temporal analysis, during multiple rounds of attacks, the results of the previous round may affect the effectiveness of the next. For example, some modules may remain inactive for a long time after being attacked, exacerbating the effects of subsequent attacks. Therefore, step S7 needs to consider the cumulative impact of each attack round and optimize the order of attacking target modules so that subsequent attacks can maximize the effects of the previous round and increase the overall load loss.
[0136] Optimize the selection of attack targets during multiple rounds of attacks. By establishing a loss assessment model, we analyze the load loss after each attack round. This model considers the system impact of different modules after the attack, optimizing the selection of target modules. By dynamically adjusting the attack targets, we ensure that each attack round inflicts the maximum load loss on the system.
[0137] Specifically, the attack sequence should be adjusted based on factors such as the module's potential for load loss, the likelihood of cascading failures, and recovery time. The failure of some modules may have a prolonged impact on system load, while others may recover quickly. Therefore, when selecting attack targets, it is necessary to comprehensively assess the impact and recovery time of each module to achieve the optimal attack strategy.
[0138] In one possible implementation, an optimal attack sequence can be determined by searching through all possible attack sequences in the system, maximizing load loss within given attack resource constraints. This strategy, based on a global understanding of the system, dynamically adjusts the attack strategy, enabling the attacker to achieve maximum damage to the target area over multiple rounds.
[0139] The specific loss calculation model can be described by the following formula:
[0140]
[0141] in: represents the load loss of substation n after the tth round of attack; represents the load loss of module i in substation n after the tth round of attack; B n Represents the module set in substation n, including busbar, transformer, circuit breaker and other modules.
[0142] This formula is used to calculate the total load loss across all modules in the substation after the tth attack round. The load loss of each module is determined by its own characteristics and is also affected by the status of other modules. Therefore, calculating the load loss after each attack round provides a basis for optimizing subsequent attack strategies.
[0143] S7 not only calculates the load loss of each attack round but also dynamically adjusts the attack sequence so that the effects of each attack round are cumulative, maximizing the system's load loss. This ensures that the attacker can adjust their strategy based on the results of the previous attack round, thereby achieving optimal attack results across multiple rounds.
[0144] S8. Set the defender's scheduling strategy, simulate the load recovery process after the attack, and minimize the system's load loss by optimizing the scheduling plan;
[0145] The goal of S8 is to establish a dispatching strategy for the defender, ensuring that the power system can resume normal operations as quickly as possible after multiple rounds of attacks, while minimizing load losses. This step requires rationally dispatching resources within the power grid based on post-attack system status information, specifically fine-tuning the allocation of power resources during the recovery process. By optimizing the dispatching plan, the defender can restore power to critical areas as much as possible and avoid excessive load shedding.
[0146] First, based on the load loss after each attack, the system enters recovery mode. The primary task of power system recovery is to redeploy power from available areas to damaged areas and, through rational scheduling, restore power to damaged modules as quickly as possible. Specifically, the load recovery simulation is based on the current state of the system. Assuming that some modules fail after an attack, the defender's task is to restore the load of these modules by dispatching resources.
[0147] In this example, the system's load loss is minimized by optimizing the scheduling scheme. The goal of this optimization scheme is to ensure that as many load zones as possible are restored while avoiding unnecessary load shedding. Among multiple possible restoration schemes, the one that results in the fastest load restoration and the least loss is selected. To achieve this goal, the defender simulates different scheduling strategies and evaluates their impact on system stability and load restoration speed.
[0148] The scheduling process is adjusted in real time based on the load status and module recovery time after each round of attack. Specifically, the scheduling process takes into account the following key factors:
[0149] Minimize load loss: Ensure that as much load as possible is restored through dispatch and prevent large-scale power outages due to untimely restoration.
[0150] Recovery time: The module recovery time has a significant impact on the scheduling plan. Modules with longer recovery times should be restored first to reduce the risk of system instability.
[0151] Power transmission paths between modules: During the recovery process, it is necessary to consider the power connection paths between modules and ensure recovery efficiency by optimizing the power flow along these paths.
[0152] To optimize load restoration, we need to introduce an optimization objective function that aims to minimize the total load loss while taking into account restoration time and power flow constraints.
[0153] The optimization problem can be described by the following formula:
[0154]
[0155] Where: P dIndicates the load recovery status of the system; ΔPd i represents the load loss caused by module i during the recovery process after the attack, and B is the set of all affected modules in the system.
[0156] The objective function is to minimize the sum of the load losses of all modules.
[0157] Load adjustment constraints are a key part of ensuring that the adjustment of each load node complies with the electrical characteristics and line transmission capacity. They are specifically expressed as:
[0158]
[0159] Where: p i is the load of the i-th node, indicating the power load borne by the node; v i is the voltage value of the i-th node; x i is the conductance of the line, indicating the conductivity of the i-th line, which determines the current transmission effect; θ o(i) is the initial voltage angle of the i-th node; θ d(i) is the target voltage angle of the i-th node, that is, the target voltage angle after recovery.
[0160] This constraint controls the load adjustment through the relationship between voltage and voltage angle difference, ensuring that the load change of each node is consistent with the system electrical characteristics, thereby ensuring that the power transmission during the restoration process does not violate the system electrical constraints.
[0161] In order to ensure that the load does not exceed the power generation capacity when it is restored, the defender needs to ensure that the power output of each generator set is limited to its allowed range. The specific formula is:
[0162]
[0163] Where: g j is the power generation capacity of the jth generator set; G j is the set of load nodes connected to the j-th generator set; p i is the load of the i-th node; ΔP di is the load change of the i-th load node.
[0164] This constraint ensures that the output of the generator set does not exceed its maximum power generation capacity, avoiding over-reliance on certain generator sets, which may lead to system overload or instability.
[0165] The load restoration process of the system is strictly limited by the line flow to avoid system instability caused by excessive load. The load restoration amount of each power line is limited by its transmission capacity. The constraints are:
[0166] 0≤ΔP di ≤Pmax
[0167] ΔP di is the load change of the i-th node, indicating the load adjustment of the node; P max is the maximum load limit of the i-th node.
[0168] This constraint ensures that during the restoration process, load adjustments do not exceed the maximum capacity of the grid, avoiding power outages or equipment damage due to line overload.
[0169] During load recovery, nodes with the greatest impact on system stability must be restored first, based on the recovery time and importance of each node. This constraint ensures that each node can be restored in a reasonable order during the recovery process, preventing system failures due to untimely recovery. The specific constraints are:
[0170]
[0171] Where: ΔT i is the recovery time change of the i-th node, which indicates the time required for load recovery.
[0172] T max The maximum recovery time allowed by the system.
[0173] This constraint ensures that the recovery time of each node in the system will not exceed the specified maximum recovery time to avoid unnecessary delays or conflicts during the recovery process.
[0174] During load restoration, voltage and phase angle control are key factors in ensuring grid stability, preventing grid instability caused by excessive voltage angles or voltage out of range. Voltage constraints and phase angle constraints can be expressed in the following ways:
[0175] Voltage Constraints:
[0176] V min ≤v i ≤V max
[0177] Where: v i is the voltage of the i-th node; V min is the minimum allowable value of the voltage at the i-th node; V max is the maximum allowable value of the voltage at the i-th node.
[0178] This constraint ensures that the voltage at each node does not exceed its maximum and minimum allowed values, preventing overvoltage or undervoltage conditions in the grid from causing equipment damage or system crash.
[0179] Phase angle constraint:
[0180] θ o(i)-θ d(i) ≤Δθ max
[0181] Where: θ o(i) is the initial voltage angle of the i-th node; θ d(i) is the target voltage angle of the i-th node; Δθ max Indicates the maximum allowed voltage angle difference.
[0182] This constraint ensures that the voltage angle difference between nodes in the power grid will not be too large, preventing the power grid from being unstable or collapsing due to excessive phase angle differences.
[0183] The defender's dispatch strategy ensures rapid system recovery and stable operation during the restoration process by introducing constraints on voltage, current, generator capacity, line flow, and restoration time priority. These constraints not only minimize load loss but also control key factors in the system's restoration process, such as voltage, phase angle, and generator output, ensuring grid stability and security during restoration. Furthermore, the phase angle and voltage constraints used during the restoration process further enhance the physical stability of the grid, helping to effectively restore the power system to the point of multiple attacks.
[0184] S9. Optimize module recovery time. Adjust the selection of attack target modules based on recovery time and repair status to ensure module stability after recovery.
[0185] S9's core task is to optimize module recovery time, taking into account recovery status and repair cycles, and rationally select target modules to ensure stability after recovery. This process not only considers the individual module recovery but also analyzes the system's overall power transmission path to ensure stable operation after recovery and avoid further attack. This step focuses on leveraging module recovery status, repair time, and inter-module power transmission dependencies to develop effective recovery and attack strategies for subsequent rounds of attacks.
[0186] During multiple rounds of attacks, the recovery time and repair cycle of each module directly impacts the speed and stability of the power system's recovery. Recovery time is typically determined by the time it takes for the devices within the module to recover, which varies from device to device. Therefore, this step first evaluates the module's overall recovery time based on the recovery time of each device within the module. Modules with long recovery times are often bottlenecks in the system's recovery process and require priority recovery; otherwise, the overall system's load recovery and power stability will be impacted.
[0187] Recovery time prioritization and module selection relies on the following formula:
[0188]
[0189] in: represents the recovery state of device i in module n at time t; M n is the set of devices contained in module n; is the recovery state of device j in module n at time t; The recovery time of module n depends on the recovery status of all devices in the module. The device with the longest recovery time is selected as the reference time for module recovery.
[0190] This formula calculates the recovery status of all devices in module n and finally obtains the recovery status of the module, which is used as a basis to formulate the module recovery strategy.
[0191] During the actual recovery process, the recovery speed of different modules is affected by a variety of factors, including their critical role in the power transmission path and the potential for further attacks during the recovery process. Therefore, to improve system recovery efficiency, in this embodiment, the defender dynamically adjusts the selection of target modules, prioritizing those with longer recovery times and important positions in the power transmission path. By analyzing the module's recovery status and repair progress in real time, the defender can select and protect modules with longer recovery times and greater impact during each attack round.
[0192] When making module selection, the module's recovery priority can be calculated using the following formula:
[0193]
[0194] in: is the recovery state of module i at time t; t x is module i at time t x the moment of attack; is the repair period of module i, starting from the time t when it is attacked x Start, go through The module recovery of each cycle is completed; Indicates the status of module i after the repair cycle ends. The recovery status is 1, indicating that the module is fully recovered.
[0195] This formula reflects how the defender dynamically adjusts the selection of attack target modules based on the module's repair cycle and recovery status during multiple rounds of attacks, and ensures the stability of the system during the module recovery process.
[0196] The interplay between modules is a key factor in determining the effectiveness of a recovery strategy. Certain modules may directly or indirectly affect the recovery of other modules. For example, some modules may serve as critical nodes along multiple power transmission paths. Failure to promptly recover these modules will directly impact the flow of power to other modules. Therefore, in this embodiment, when determining module recovery priority, not only the module's own recovery time is considered, but also its position within the power network and its interdependencies with other modules.
[0197] In order to calculate the mutual influence between modules, the correlation matrix R between the defined paths and modules in S4 is used. n2 , represents the correlation between each module in each power supply path to simulate the dynamic changes of module recovery in the power transmission path.
[0198] The recovery path matrix describes the dynamic changes of the recovery paths between modules, which can help the defender adjust the power transmission path in real time to ensure that the power system is restored as soon as possible.
[0199] By optimizing module recovery time and dynamically adjusting repair status, S9 enables defenders to adjust their target modules during multiple attacks, minimizing negative impacts on the system and ensuring stability after module recovery. By combining the module's recovery status, repair cycle, and dependencies on power transmission paths, defenders can effectively optimize the recovery process, improving system recovery efficiency and stability.
[0200] S10. Identify key equipment in the power transmission system based on the attack results and determine key modules through impact analysis.
[0201] The goal of S10 is to further identify critical equipment in the transmission system by evaluating the attack results generated in the previous steps and to determine critical modules through fault propagation impact analysis. This process identifies the equipment and modules that would have the greatest impact on system stability if attacked. The goal is to ensure that components critical to power system operation, whose failures could cause widespread system outages, are identified, thus providing a basis for subsequent defense and remediation strategies.
[0202] The goal of impact analysis is to identify the most critical modules and equipment based on the fault propagation and impact of each module. In this step, the module's fault propagation effect is quantified using the impact factor. A higher impact factor indicates a more widespread system impact if a module fails. By evaluating all modules and equipment, the critical equipment and modules that are crucial to power system stability are ultimately identified.
[0203] In this embodiment, the calculation formula of the influence degree is as follows:
[0204]
[0205] Among them: I n is the impact of module n on the entire system, reflecting the impact of the failure of module n on the system. The greater the impact, the more serious the propagation effect of the failure. is the recovery status of device i on path j in module n; f is the fault propagation coefficient of device i on path j, which reflects the impact of device failure on path j. This formula calculates the impact degree I of module n by calculating the recovery status and fault propagation coefficient of each device. n , helping the defender identify which modules have a greater impact on system operation.
[0206] Modules with larger impact values are considered critical modules. Once these modules fail, they may cause large-scale system failures.
[0207] During implementation, the formula for selecting key modules is as follows:
[0208] M key ={m n |I n ≥α·max(I)};
[0209] Where: M key is a collection of key modules; m n Indicates module n; I n The influence of module n; α is the influence threshold coefficient. This coefficient is used to determine which modules are influential enough to be considered critical modules. Typically, the value of α depends on the actual tolerance and ranges from 0 to 1. max(I) is the maximum influence of all modules, which is used to calculate the threshold.
[0210] Through this formula, modules with an impact higher than the threshold can be screened out. These modules are considered critical modules and should be given priority in protection or repair in the defense strategy.
[0211] The identification of critical equipment does not only rely on the impact of the module, but also should consider the connectivity of the equipment in the power network and identify those devices that connect multiple modules and affect multiple paths.
[0212] Use the following formula to identify key devices:
[0213] C key ={c i |f ci >β·max(f)};
[0214] Where: C key A collection of key equipment; c i For device i; f ci For device c iThe fault propagation coefficient represents the impact of a device failure on a path or system. β is the fault propagation coefficient threshold, which determines which device failures have a greater impact on the system. max(f) is the maximum value of the fault propagation coefficients of all devices.
[0215] Through the aforementioned impact analysis and critical module identification process, the ultimate goal is to comprehensively identify the critical modules and devices in the system. Failures in these modules and devices will directly impact the overall stability and load distribution of the system. Therefore, the identification process should not only focus on individual devices but also comprehensively consider the interdependencies between modules and the role of devices in multiple paths.
[0216] Through detailed impact analysis and fault propagation calculations, S10 can identify the most vulnerable and critical parts of the system. This analysis provides a scientific basis for subsequent defense and recovery measures, ensuring effective protection of key parts of the system, thereby improving the power system's resilience and risk resistance in the face of attacks.
[0217] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A method for identifying key equipment in a power transmission system against low-granularity timing attacks, characterized in that: The following steps are involved: S1. Build a modular topology model for the power transmission system, dividing the equipment in the power transmission system into multiple equipment modules based on their geographical clustering. The module division is based on the electrical connection relationship, geographical location, geographical clustering characteristics, and functional aggregation of the equipment. S2. Establish a fault propagation matrix to simulate the fault propagation path between modules and analyze the impact of module failure on other modules in the system; S3. Select the target area from the attacker's perspective, set the goal of maximizing the load loss within the target area, and limit the maximum proportion of additional load loss outside the area; S4. Based on the depth-first search algorithm, expand outward from the load nodes in the target area, gradually search all possible power supply paths, record the modules and lines involved in the path, and form an attack decision variable set; S5. Define attack decision variables and recovery state variables to represent the attack state and recovery state of each module, and calculate their impact on system fault propagation; S6. Set resource limits for each attack round, control the number of modules in each attack round, and ensure that the load loss outside the area does not exceed the preset threshold; S7. Optimize the selection of attack target modules based on temporal analysis, calculate the cumulative impact of multiple rounds of attacks on load loss, select the modules that are most likely to cause load loss in each round for attack through temporal analysis and optimization algorithms, and adjust the attack sequence to maximize the load loss in the target area; S8. Set the defender's scheduling strategy, simulate the load recovery process after the attack, and minimize the system's load loss by optimizing the scheduling plan; S9. Optimize module recovery time. Adjust the selection of attack target modules based on recovery time and repair status to ensure module stability after recovery. S10. Identify key equipment in the power transmission system based on the attack results, and determine key modules through impact analysis.
2. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The module division includes: Each module includes at least one or more of a busbar, a circuit breaker and a transformer; Divide equipment modules according to their geographical distribution and electrical functions and associate them in the system through module identifiers; The association matrix between modules and power lines is constructed to describe the connection relationship between modules and lines.
3. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The fault propagation matrix construction includes: Construct a fault propagation matrix between modules, where the matrix elements Indicates whether the failure of module i will directly or indirectly lead to the failure of module j; Based on the fault propagation matrix, calculate the impact of each module failure on other modules in the system and identify the key equipment in the system; By analyzing the fault propagation path, vulnerable modules and possible attack impact ranges can be identified.
4. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The target area selection includes: Based on the attacker's analysis of the system, identify key areas in the system and select target areas with greater load loss; Set the maximum load loss within the target area as the attack goal, and control the additional load loss outside the target area to ensure that it does not exceed the preset maximum ratio; Optimize the selection of attack areas through network analysis and determine the device modules that are attacked first.
5. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The path search algorithm includes: Starting from the load nodes in the target area, all power supply paths are gradually searched using the depth-first search algorithm; Record all modules and lines involved in the search path and remove paths that are not directly related to the target area; Construct an attack decision variable set and ensure that the power supply path within the attack area is effectively attacked by optimizing path selection.
6. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The definitions of the attack decision variables and recovery state variables include: Define attack decision variables for each module in Indicates that module i is attacked during the tth attack, Indicates that it has not been attacked; Define recovery state variables for each module in represents the recovery state of module i after the tth attack, Indicates not restored; Based on the attack and recovery status of a module, its impact on other modules is calculated, and the attack decision is dynamically optimized.
7. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: Attack resource restrictions include: Set the maximum attack resource amount A for each round of attack t , limit the number of modules in each round of attack to no more than A t ; By optimizing attack decision variables, we ensure the rational allocation of attack resources and reduce attacks on modules outside the target area; Calculate and ensure that the load loss outside the area does not exceed the preset maximum acceptable ratio ξ t .
8. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The timing analysis includes: Optimize the selection of attack target modules based on module recovery time and attack sequence, giving priority to attacking modules with long recovery time and large load loss; Calculate the cumulative load loss through a multi-round attack model and adjust the attack sequence to ensure the maximum attack effect; By analyzing the impact of each round of attack, the attack plan and attack coverage can be optimized.
9. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The defender scheduling optimization includes: The defender conducts emergency dispatch based on the state of the power transmission system after the attack to minimize load loss; By optimizing the scheduling strategy, the power supply of each node in the system is ensured to be balanced, avoiding excessive load shedding that may cause system instability; Adjust the attack strategy based on the scheduling optimization results to ensure that the defense effect matches the dynamic adjustment of the attack target.
10. The method for identifying key equipment in a power transmission system against low-granularity timing attacks according to claim 1, characterized in that: The module recovery time optimization includes: Define repair times for each module And adjust the attack decision based on the device's repair cycle and repair status; Prioritize restoring modules that have a longer repair time and a greater impact on load loss to ensure stable power supply after module restoration; Avoid attacking the module again during the module recovery period to ensure system stability during the repair period.
Citation Information
Patent Citations
Data processing method and device based on high and low carry instruction, and electronic equipment
CN116192391A
Network attack prediction method and system based on attack portrait
CN116938527A