Energy storage station network traffic monitoring method and system based on federated learning and non-decryption encrypted traffic analysis, terminal equipment and storage medium
By adopting federated learning and decryption-free encrypted traffic analysis in energy storage stations combined with DPI and machine learning models, the problem of existing technology being difficult to deal with complex network threats is solved, and high-accurate network traffic monitoring and abnormal behavior detection is achieved.
Patent Information
- Application Number
- CN202510394164.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-17
AI Technical Summary
The existing network security protection methods in energy storage stations and industrial control systems are difficult to effectively deal with complex network threats such as unknown attacks, variant APTs, encrypted traffic analysis, and the false alarm rate is high, making it difficult to adapt to dynamic business environments.
The network traffic monitoring method of energy storage stations based on federated learning and undecrypted encrypted traffic analysis is adopted. Network traffic packets are analyzed through DPI technology, traffic characteristics and encrypted communication characteristics are extracted, and abnormal traffic recognition and abnormal behavior judgment are used using the XGBoost model and time series analysis model.
It improves the accuracy of network traffic monitoring of energy storage stations, can accurately identify known and unknown attacks, reduce false alarm rates, enhance the detection ability of encrypted traffic, improve computing efficiency and data security, and adapt to distributed business scenarios.
Smart Images

Figure CN120165950A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical fields of energy storage station flow monitoring and machine learning, and particularly relates to a method, system, terminal device, and storage medium for monitoring the network traffic of an energy storage station based on federated learning and non-decryptive encrypted traffic analysis. Background Art
[0002] With the rapid development of new energy technologies, energy storage stations, as a key link in the energy management system, are crucial for the normal operation of the power grid and industrial control systems in terms of their safety and stability. Energy storage stations involve multi-level heterogeneous network architectures such as the station control layer (SCADA / EMS), energy storage cabin monitoring (BMS), and Internet of Things sensing layer (IoT). Data interaction between each level involves industrial control protocols (Modbus TCP, IEC 61850, DNP3, MQTT, etc.), and usually uses encrypted communication (TLS / SSL) to ensure data transmission security. However, due to the high complexity, coexistence of multiple protocols, and large attack surface of energy storage station systems, network traffic monitoring and abnormal behavior analysis thereof have become important technical issues for ensuring their safety.
[0003] The existing network security protection measures in energy storage stations and industrial control systems (ICS) mainly include firewalls, rule-based intrusion detection systems (IDS / IPS), DPI detection, traditional machine learning traffic analysis, time series prediction traffic baselines, etc. Among them, intrusion detection systems use static rule matching or attack signature databases for traffic detection, mainly applied to known attack patterns (such as denial-of-service attacks, scanning attacks), and typical solutions include Snort, Suricata, Bro IDS, etc. These methods rely on static rule libraries, are difficult to cope with unknown attacks (Zero-Day) or variant APTs, and have a high false alarm rate, making it difficult to adapt to the dynamic business environment of energy storage stations. Traditional DPI cannot directly parse encrypted traffic such as TLS / SSL, resulting in difficulties in detecting APT attacks, C2 (command and control) communications, and data leakage. Traditional machine learning traffic analysis uses decision trees (DT), support vector machines (SVM), and random forests (RF) for traffic classification. The training data mainly comes from normal vs. abnormal traffic samples, and a classification model is constructed through extracting traffic features (such as packet size, time interval, connection frequency) for traffic analysis. This method relies on static training data, is difficult to adapt to the traffic patterns of different energy storage stations, and traditional methods usually require centralized training of traffic data, which may lead to the risk of data leakage. Finally, time series prediction traffic baselines use LSTM (long short-term memory network) or ARIMA for time series modeling to predict traffic change trends, which is applicable to traffic mutation detection and abnormal data upload pattern recognition. However, the problem is that the LSTM model has a large computational complexity, is difficult to run in real time in the edge computing environment of energy storage stations, has insufficient generalization ability for long-term traffic prediction, and has a high false alarm rate.
[0004] The existing traffic monitoring methods are difficult to cope with security risks such as increasingly complex advanced persistent threats (APT), internal attacks, abnormal traffic attacks, and unauthorized access. In addition, energy storage stations are often distributed in different geographical locations, and traditional centralized security analysis methods are difficult to effectively adapt to distributed business scenarios. Therefore, how to improve the accuracy of network traffic monitoring in energy storage stations has become an urgent problem to be solved. Summary of the Invention
[0005] This application provides a method, system, terminal device, and storage medium for monitoring network traffic in energy storage stations based on federated learning and encrypted traffic analysis without decryption, which can improve the accuracy of network traffic monitoring in energy storage stations.
[0006] In a first aspect, an embodiment of this application provides a method for monitoring network traffic in an energy storage station based on federated learning and encrypted traffic analysis without decryption, including:
[0007] Obtain local network traffic packets;
[0008] Perform data parsing on the network traffic packet based on DPI technology and a preset data protocol to obtain data information corresponding to each data protocol;
[0009] Extract features from each of the data information to obtain traffic features, where the traffic features include device interaction behavior features, control instruction features, and data stream features;
[0010] Based on the non-decryption encrypted traffic analysis technology, perform fingerprint feature extraction on the network traffic packet to obtain corresponding encrypted communication features;
[0011] Input the traffic features and encrypted communication features into a preset traffic monitoring model, so that the traffic monitoring model can identify some traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic features, and determine whether there is abnormal behavior in the network traffic packet;
[0012] Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federated server, and the initial traffic monitoring model is constructed based on a machine learning model.
[0013] The embodiment of the present application provides a method for monitoring the network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis. By using DPI technology to perform data parsing on network traffic packets, the accuracy of energy storage station traffic monitoring can be improved, key industrial protocols can be accurately parsed, false alarms and missed reports can be avoided, and the computational overhead can be reduced. And during the data parsing process, the data protocol is preset, and only the traffic of the required industrial protocol is deeply parsed without parsing the entire network traffic, improving the efficiency of data parsing. In addition, the embodiment of the present application also combines the non-decryption encrypted traffic analysis technology, which can break through the limitations of TLS / SSL encrypted traffic, realize encrypted attack detection, and without decryption, improving the computational efficiency and data security while improving the accuracy of network traffic monitoring. In terms of model construction, the method of federated learning is adopted for model construction and training, which can avoid data leakage and improve the generalization ability of the traffic monitoring model. Finally, the traffic features and encrypted communication features obtained by feature extraction are input into the traffic monitoring model, and the traffic monitoring model combines various features to identify abnormal traffic and judge abnormal behavior, which not only realizes automated network traffic monitoring but also improves the accuracy of energy storage station network traffic monitoring.
[0014] Further, the performing data parsing on the network traffic packet based on DPI technology and a preset data protocol to obtain data information corresponding to each data protocol includes:
[0015] Based on the Modbus TCP protocol, parse and extract the device address, function code, and register data from the network traffic packet;
[0016] Parse and extract GOOSE messages and sampled value data from the network traffic packets based on the IEC 61850 protocol;
[0017] Parse and extract Topic, Payload, and QoS data from the network traffic packets based on the MQTT protocol;
[0018] Parse and extract master-slave communication, data objects, and control function information from the network traffic packets based on the DNP3 protocol.
[0019] In the embodiments of the present application, data parsing based on the Modbus TCP protocol, IEC 61850 protocol, MQTT protocol, and DNP3 protocol is defined. These data protocols are important industrial protocols in industrial communication and Internet of Things scenarios. The parsed data information can quickly and real-time detect known abnormal traffic (DDoS attacks, port scans), improving the accuracy of subsequent network traffic monitoring.
[0020] Further, extracting features from each of the data information to obtain traffic features includes:
[0021] Analyze the device interaction mode according to each of the data information to determine the communication topology relationship, master-slave relationship, and data flow mode between several devices corresponding to the network traffic packet, and then extract and obtain the device interaction behavior features;
[0022] Analyze the naming mode according to each of the data information to determine whether the device control instructions in each of the data information conform to the normal working conditions, and then extract and obtain the control instruction features;
[0023] Perform packet statistics according to each of the data information, and combine the data information of several historical network traffic packets to determine the traffic size, packet interval time, and up / down data ratio, and then extract and obtain the data flow features.
[0024] In the embodiments of the present application, by extracting features from each data information, device interaction behavior features, control instruction features, and data flow features are obtained. These data features can help the traffic monitoring model comprehensively analyze the current network traffic packet from different levels in the future, and then identify normal traffic, abnormal traffic, and potential attack traffic in the network traffic. Through the feature extraction of the embodiments of the present application, data preparation is made for subsequent anomaly identification, improving the accuracy of network traffic monitoring.
[0025] Further, the encrypted communication feature is the JA3 fingerprint feature. Based on the non-decryption encrypted traffic analysis technology, extract the fingerprint feature from the network traffic packet to obtain the corresponding encrypted communication feature, including:
[0026] Parse the TLS traffic from the network traffic packet based on the decryption-free encrypted traffic analysis technology;
[0027] Extract the JA3 fingerprint feature according to the TLS handshake information in the TLS traffic.
[0028] In the embodiment of the present application, the TLS traffic is parsed through the decryption-free encrypted traffic analysis technology, and the JA3 fingerprint feature is further extracted according to the TLS handshake information in the TLS traffic, breaking through the limitations of traditional DPI in the analysis of TLS / SSL encrypted traffic, providing data integration for subsequent accurate identification of abnormal behaviors such as APT (Advanced Persistent Threat), covert data leakage, and C2 (Command and Control) communication, and improving the accuracy of energy storage station network traffic monitoring.
[0029] In a possible implementation manner, the traffic monitoring model identifies several traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic feature, and determines whether there is an abnormal behavior in the network traffic packet, including:
[0030] Parse the traffic feature into a network layer feature, an application layer feature, and a statistical feature;
[0031] Input the network layer feature, the application layer feature, the statistical feature, and the encrypted communication feature into the XGBoost model in the traffic monitoring model, so that the XGBoost model performs traffic classification and abnormal behavior detection on the network traffic packet, identifies several traffic in the network traffic packet as abnormal traffic or normal traffic, and determines whether there is an abnormal behavior in the network traffic packet.
[0032] The embodiment of the present application provides a traffic recognition method, which uses the XGBoost model to recognize several traffic flows in a network traffic packet. The XGBoost model can effectively recognize abnormal patterns in network traffic through the gradient boosting framework and regularization strategy. At the same time, the XGBoost model can efficiently process high-dimensional and large-scale data through parallel computing optimization. Therefore, the embodiment of the present application considers introducing the XGBoost model into the energy storage station network traffic monitoring method. Further, in the process of traffic recognition, the embodiment of the present application combines the traffic characteristics extracted by DPI and the encrypted communication characteristics extracted by the encrypted traffic analysis technology without decryption, improving the anomaly detection ability, accurately identifying known and unknown attacks, and intelligently classifying normal traffic, abnormal traffic and potential attack traffic. At the same time, due to the introduction of encrypted communication characteristics, the limitations of traditional DPI in TLS / SSL encrypted traffic analysis are broken through, accurately identifying abnormal behaviors such as APT (Advanced Persistent Threat), covert data leakage, and C2 (Command and Control) communication, improving the defense ability of the energy storage station, detecting new attack patterns, reducing the false alarm rate, and improving the accuracy of energy storage station network traffic monitoring.
[0033] Further, the traffic monitoring model further includes a time series analysis model, and the energy storage station network traffic monitoring method further includes predicting the traffic trend of each abnormal traffic through the time series analysis model and determining whether to output an abnormal alarm, specifically:
[0034] Obtain the traffic characteristics and each abnormal traffic;
[0035] Input the traffic characteristics and each abnormal traffic into the time series analysis model, so that the time series analysis model generates corresponding traffic trend prediction results;
[0036] Compare the traffic trend prediction result with the traffic baseline, and calculate the abnormal deviation degree, where the traffic baseline is generated during the training process of the time series analysis model;
[0037] Determine whether to output an abnormal alarm according to the abnormal deviation degree.
[0038] An embodiment of the present application provides a traffic trend prediction method. By introducing a time series analysis model (TimesNet model) into the traffic monitoring model, after classifying abnormal traffic using the XGBoost model, the time series analysis model is further used to predict the development trend of abnormal traffic, realizing early warning of network security risks. During the traffic trend prediction process, a normal business traffic baseline is constructed by training the time series analysis model in advance, and it is compared with the traffic trend prediction results during real-time monitoring to improve the detection accuracy and reduce false alarms and missed reports. After introducing the time series analysis model, the embodiment of the present application improves the real-time detection ability by optimizing the time series analysis. It can not only predict the traffic trend, but also detect long-term hidden attacks (C2 hidden communication, TLS data leakage) and abnormal network behaviors (internal lateral movement, abnormal encrypted upload), and respond more quickly to potential security threats.
[0039] In a possible implementation manner, constructing the traffic monitoring model by performing federated learning on an initial traffic monitoring model through a preset federated server includes:
[0040] Generate an initial traffic monitoring model;
[0041] Send the initial traffic monitoring model to each energy storage station in the target area, so that each energy storage station trains its own initial traffic monitoring model using a number of local historical network traffic packets, and then generates model parameters corresponding to its own initial traffic monitoring model;
[0042] Obtain and perform cloud aggregation on the initial traffic monitoring model according to the model parameters uploaded by each energy storage station to construct the traffic monitoring model;
[0043] Send the traffic monitoring model to each energy storage station, so that the traffic monitoring model replaces each of the initial traffic monitoring models.
[0044] The embodiment of the present application adopts federated learning to avoid data leakage, improve cross-site detection ability, train traffic modeling and anomaly detection models locally at each energy storage station, and then perform federated aggregation through the cloud to form a globally optimized detection model, improve the model generalization ability, adapt to different site environments, reduce data transmission costs, only upload model update information, avoid data leakage, meet data security requirements, and at the same time support cross-site security collaboration to enhance the detection ability in distributed and heterogeneous environments.
[0045] In a second aspect, an embodiment of the present application provides an energy storage station network traffic monitoring system based on federated learning and non-decryption encrypted traffic analysis, including an acquisition module, a data parsing module, a traffic feature extraction module, a fingerprint feature extraction module, and an anomaly recognition module;
[0046] Among them, the obtaining module is used to obtain the local network traffic packets;
[0047] The data parsing module is used to perform data parsing on the network traffic packets based on the DPI technology and a preset data protocol to obtain data information corresponding to each data protocol;
[0048] The traffic feature extraction module is used to extract features from each of the data information to obtain traffic features, where the traffic features include device interaction behavior features, control instruction features, and data flow features;
[0049] The fingerprint feature extraction module is used to extract fingerprint features from the network traffic packets based on the non-decrypting encrypted traffic analysis technology to obtain corresponding encrypted communication features;
[0050] The anomaly recognition module is used to input the traffic features and the encrypted communication features into a preset traffic monitoring model, so that the traffic monitoring model can identify several traffic in the network traffic packets as abnormal traffic or normal traffic according to the traffic features, and determine whether there is abnormal behavior in the network traffic packets;
[0051] Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federated server, and the initial traffic monitoring model is constructed based on a machine learning model.
[0052] In a third aspect, an embodiment of the present application provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements any one of the energy storage station network traffic monitoring methods based on federated learning and non-decrypting encrypted traffic analysis as described in the embodiments of the present application.
[0053] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, including: a stored computer program, where when the computer program runs, it controls the device where the computer-readable storage medium is located to execute any one of the energy storage station network traffic monitoring methods based on federated learning and non-decrypting encrypted traffic analysis as described in the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the technical solutions of the present application, the accompanying drawings required for implementation will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0055] Figure 1It is a schematic flow chart of a method for monitoring the network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis provided by an embodiment of the present application;
[0056] Figure 2 It is a schematic structural diagram of a specific implementation manner of a method for monitoring the network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis provided by an embodiment of the present application;
[0057] Figure 3 It is a schematic structural diagram of a system for monitoring the network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis provided by an embodiment of the present application. Specific implementation manner
[0058] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions in the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present application belong to the scope of protection of the present application.
[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion.
[0060] In the description of the embodiments of the present application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order, or primary-secondary relationship of the indicated technical features. In the description of the embodiments of the present application, "a plurality" means two or more unless otherwise specifically defined.
[0061] Referring to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0062] In the description of the embodiments of the present application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, both A and B exist simultaneously, and B exists alone. Additionally, in this text, the character " / " generally indicates an "or" relationship between the associated objects before and after.
[0063] In the description of the embodiments of the present application, the term "plurality" refers to two or more (including two). Similarly, "multiple groups" refers to two or more groups (including two groups), and "multiple pieces" refers to two or more pieces (including two pieces).
[0064] In the description of the embodiments of the present application, unless otherwise clearly specified and limited, technical terms such as "installation", "connection", "linkage", "fixation", etc. should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can also be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to specific situations.
[0065] Embodiment 1:
[0066] See Figure 1 , to solve the problem of low accuracy in network traffic monitoring of energy storage stations in the prior art, Embodiment 1 provides an energy storage station network traffic monitoring method based on federated learning and non-decryptive encrypted traffic analysis, including steps S1 - S5:
[0067] Step S1, obtain the local network traffic packet;
[0068] Step S2, based on DPI technology and a preset data protocol, perform data parsing on the network traffic packet to obtain data information corresponding to each data protocol;
[0069] Step S3, perform feature extraction on each data information to obtain traffic features, where the traffic features include device interaction behavior features, control instruction features, and data flow features;
[0070] Step S4, based on non-decryptive encrypted traffic analysis technology, perform fingerprint feature extraction on the network traffic packet to obtain corresponding encrypted communication features;
[0071] Step S5, input the traffic features and encrypted communication features into a preset traffic monitoring model, so that the traffic monitoring model identifies several traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic features, and determines whether there is abnormal behavior in the network traffic packet;
[0072] Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federated server, and the initial traffic monitoring model is constructed based on a machine learning model.
[0073] The embodiment of the present application provides a method for monitoring the network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis. By using DPI technology to parse network traffic packets, the accuracy of energy storage station traffic monitoring can be improved, key industrial protocols can be accurately parsed, false alarms and missed reports can be avoided, and the computing overhead can be reduced. During the data parsing process, data protocols are preset, and only the industrial protocol traffic required is deeply parsed without parsing the entire network traffic, improving the efficiency of data parsing. In addition, the embodiment of the present application also combines non-decryption encrypted traffic analysis technology, which can break through the limitations of TLS / SSL encrypted traffic, realize encrypted attack detection, and without decryption, improving the computing efficiency and data security while improving the accuracy of network traffic monitoring. In terms of model construction, the method of federated learning is used for model construction and training, which can avoid data leakage and improve the generalization ability of the traffic monitoring model. Finally, the traffic features and encrypted communication features extracted by feature extraction are input into the traffic monitoring model, and the traffic monitoring model combines various features to identify abnormal traffic and judge abnormal behaviors, realizing both automated network traffic monitoring and improving the accuracy of energy storage station network traffic monitoring.
[0074] In a preferred embodiment, in step S1, during the operation of the energy storage station, the Zeek traffic analysis tool is used to capture network data, and then local network traffic packets are obtained.
[0075] Further, in step S2, the network traffic packets are parsed based on DPI technology and preset data protocols to obtain data information corresponding to each data protocol, including:
[0076] Based on the Modbus TCP protocol, device address, function code, and register data are parsed and extracted from the network traffic packets;
[0077] Based on the IEC 61850 protocol, GOOSE messages and sampled value data are parsed and extracted from the network traffic packets;
[0078] Based on the MQTT protocol, Topic, Payload, and QoS data are parsed and extracted from the network traffic packets;
[0079] Based on the DNP3 protocol, master-slave station communication, data objects, and control function information are parsed and extracted from the network traffic packets.
[0080] In the embodiments of the present application, data parsing based on the Modbus TCP protocol, IEC 61850 protocol, MQTT protocol, and DNP3 protocol is defined. These data protocols are important industrial protocols in industrial communication and Internet of Things scenarios. The data information obtained by parsing can quickly and real-time detect known abnormal traffic (DDoS attacks, port scans), improving the accuracy of subsequent network traffic monitoring.
[0081] Further, in step S3, the extracting features from each of the data information to obtain traffic features includes:
[0082] Analyze the device interaction mode according to each of the data information to determine the communication topology relationship, master-slave relationship, and data flow mode between several devices corresponding to the network traffic packet, and then extract the device interaction behavior features;
[0083] Analyze the naming mode according to each of the data information to determine whether the device control instructions in each of the data information conform to normal working conditions, and then extract the control instruction features;
[0084] Perform packet statistics according to each of the data information, combine the data information of several historical network traffic packets to determine the traffic size, packet interval time, and up / down data ratio, and then extract the data flow features.
[0085] In the embodiments of the present application, by extracting features from each data information, device interaction behavior features, control instruction features, and data flow features are obtained. These data features can help the traffic monitoring model comprehensively analyze the current network traffic packet from different levels in the future, and then identify normal traffic, abnormal traffic, and potential attack traffic in the network traffic. Through the feature extraction of the embodiments of the present application, data preparation is made for subsequent anomaly recognition, improving the accuracy of network traffic monitoring.
[0086] Further, in step S4, the encrypted communication feature is the JA3 fingerprint feature. Based on the non-decryption encrypted traffic analysis technology, fingerprint feature extraction is performed on the network traffic packet to obtain the corresponding encrypted communication feature, including:
[0087] Parse the TLS traffic from the network traffic packet based on the non-decryption encrypted traffic analysis technology;
[0088] Extract the JA3 fingerprint feature according to the TLS handshake information in the TLS traffic.
[0089] In the embodiment of the present application, TLS traffic is parsed through the decryption-free encrypted traffic analysis technology, and the JA3 fingerprint feature is further extracted according to the TLS handshake information in the TLS traffic, breaking through the limitations of traditional DPI in TLS / SSL encrypted traffic analysis, providing data integration for subsequent accurate identification of abnormal behaviors such as APT (Advanced Persistent Threat), covert data leakage, C2 (Command and Control) communication, etc., and improving the accuracy of energy storage station network traffic monitoring.
[0090] In a possible implementation manner, in step S5, the traffic monitoring model identifies several traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic characteristics, and determines whether there is an abnormal behavior in the network traffic packet, including:
[0091] Parsing the traffic characteristics into network layer characteristics, application layer characteristics, and statistical characteristics;
[0092] Inputting the network layer characteristics, application layer characteristics, statistical characteristics, and encrypted communication characteristics into the XGBoost model in the traffic monitoring model, so that the XGBoost model performs traffic classification and abnormal behavior detection on the network traffic packet, identifies several traffic in the network traffic packet as abnormal traffic or normal traffic, and determines whether there is an abnormal behavior in the network traffic packet.
[0093] The embodiment of the present application provides a traffic identification method, which uses the XGBoost model to identify several traffic in the network traffic packet. The XGBoost model can effectively identify abnormal patterns in network traffic through the gradient boosting framework and regularization strategy. At the same time, the XGBoost model can efficiently process high-dimensional and large-scale data through parallel computing optimization. Therefore, the embodiment of the present application considers introducing the XGBoost model into the energy storage station network traffic monitoring method. Further, in the traffic identification process, the embodiment of the present application combines the traffic characteristics extracted by DPI and the JA3 fingerprint feature extracted by the decryption-free encrypted traffic analysis technology, improving the abnormal detection ability, accurately identifying known and unknown attacks, and intelligently classifying normal traffic, abnormal traffic, and potential attack traffic. At the same time, due to the introduction of encrypted communication characteristics, the limitations of traditional DPI in TLS / SSL encrypted traffic analysis are broken through, abnormal behaviors such as APT (Advanced Persistent Threat), covert data leakage, C2 (Command and Control) communication, etc. are accurately identified, the defense ability of the energy storage station is improved, new attack modes are detected, the false alarm rate is reduced, and the accuracy of energy storage station network traffic monitoring is improved.
[0094] Most of the traditional safety detections of energy storage stations adopt rule matching (such as Snort / Suricata), which are difficult to cope with unknown attacks. The embodiments of this application adopt XGBoost machine learning classification, combined with the traffic features extracted by DPI, to intelligently classify normal traffic, abnormal traffic, and potential attack traffic, break through the limitations of traditional detection methods, and improve the detection capabilities of known and unknown attacks. In addition, traditional DPI cannot directly analyze TLS / SSL encrypted traffic, resulting in difficult detection of APT attacks, C2 (command and control) communications, and data leaks. The embodiments of this application adopt encrypted traffic analysis without decryption (ETA), add the JA3 fingerprint features and traffic statistical features extracted by DPI into the XGBoost classification features, realize accurate abnormal detection of encrypted traffic without decrypting TLS / SSL traffic, improve the data security protection ability, and can detect APT attacks such as C2 communications and TLS tunnel data leaks, which is applicable to encrypted traffic scenarios such as HTTPS, VPN, and SSH, and breaks through the bottleneck of malicious communication detection under the protection of TLS / SSL.
[0095] The industrial traffic features extracted by DPI are used as the input data of XGBoost, aiming to classify normal traffic and abnormal traffic (dangerous control operations, unauthorized access, sensitive data, APT attacks). In a preferred embodiment, the specific process of identifying several traffic in the network traffic packet as abnormal traffic or normal traffic through the XGBoost model is as follows:
[0096] 1. Extract features: (1) Analyze network layer features (protocol type, port number, packet size); (2) Analyze application layer features (Modbus, IEC 61850 instructions, JA3 fingerprint); (3) Extract statistical features (traffic distribution, time interval).
[0097] 2. Online traffic classification, and the XGBoost model performs real-time classification on several traffic in the network traffic packet according to the extracted network layer features, application layer features, and statistical features.
[0098] The JA3 fingerprint generates unique fingerprint information using the features (TLS version, cipher suite, extension field) in the TLS handshake stage, which can be used to detect malicious C2 communications, APT attacks, and encrypted data leaks. In a preferred embodiment, the specific process of judging whether there is abnormal behavior in the network traffic packet through the XGBoost model is as follows:
[0099] 1. DPI analyzes TLS traffic and calculates the JA3 fingerprint features.
[0100] 2. Use the XGBoost model to detect abnormal behaviors based on JA3 fingerprint features, and detect whether there are abnormal behaviors such as large-scale TLS uploads (which may be external outlinks) and abnormal TLS certificates (such as self-signed certificates and expired Let's Encrypt certificates).
[0101] Further, in step S5, the traffic monitoring model further includes a time series analysis model. The energy storage station network traffic monitoring method further includes using the time series analysis model to predict the traffic trend of each abnormal traffic and determine whether to output an abnormal alarm. Specifically:
[0102] Obtain the traffic characteristics and each abnormal traffic;
[0103] Input the traffic characteristics and each abnormal traffic into the time series analysis model, so that the time series analysis model generates corresponding traffic trend prediction results;
[0104] Compare the traffic trend prediction results with the traffic baseline, and calculate the abnormal deviation degree. The traffic baseline is generated during the training process of the time series analysis model;
[0105] Determine whether to output an abnormal alarm according to the abnormal deviation degree.
[0106] The embodiment of the present application provides a traffic trend prediction method. By introducing a time series analysis model (TimesNet model) into the traffic monitoring model, after using the XGBoost model to classify and obtain abnormal traffic, the time series analysis model is further used to predict the development trend of abnormal traffic, so as to realize the early warning of network security risks. During the traffic trend prediction process, by pre-training the time series analysis model to construct a normal business traffic baseline and comparing it with the traffic trend prediction results in the real-time monitoring process, the detection accuracy is improved, and false alarms and missed alarms are reduced. After introducing the time series analysis model in the embodiment of the present application, by optimizing the time series analysis, the real-time detection ability is improved. It can not only predict the traffic trend, but also detect long-term hidden attacks (C2 hidden communication, TLS data leakage) and abnormal network behaviors (internal lateral movement, abnormal encrypted upload), and respond to potential security threats more quickly.
[0107] Existing traffic anomaly detection methods lack the ability of time series analysis and are difficult to detect long-term hidden attacks: C2 server communication (periodic TLS connections), hidden data leakage (small-scale TLS uploads), lateral movement attacks (internal abnormal TLS traffic), etc. The embodiment of the present application uses TimesNet for time series modeling, establishes a normal business traffic baseline, and improves the detection ability of long-term hidden traffic attacks.
[0108] By introducing the TimesNet model, learning the normal traffic patterns of the energy storage station, and improving the anomaly detection ability, long-term hidden attacks such as C2 server communication (periodic TLS connections), covert data leakage (small TLS traffic uploads), and lateral movement attacks (internal abnormal TLS traffic) can be detected. In a preferred embodiment, the process of using the TimesNet model for prediction is specifically as follows:
[0109] (1) Input time series data such as industrial protocol traffic parsed by DPI and abnormal traffic identified by XGBoost into the TimesNet model.
[0110] (2) Predict the traffic trend through the TimesNet model, and combine the traffic baseline obtained during the training process to calculate the anomaly deviation degree based on the traffic trend and the traffic baseline.
[0111] (3) When abnormal phenomena such as traffic deviation from the normal baseline, periodic TLS connections, and long-term small TLS traffic are found, upload the corresponding abnormal phenomena and trigger an alarm.
[0112] In a preferred embodiment, the time series analysis model is a lightweight Transformer model. Using the lightweight Transformer (TimesNet) for time series analysis can reduce the computational overhead, improve the detection efficiency, increase the inference speed, reduce the consumption of computing resources, combine with the efficient decision tree structure of XGBoost to improve the execution speed of the classification model, be applicable to the resource-constrained energy storage station environment, where DPI only parses key industrial protocols, reduces unnecessary data processing, and improves the real-time performance.
[0113] In a possible implementation manner, the traffic monitoring model is constructed after federated learning of the initial traffic monitoring model through a preset federated server, including:
[0114] Generate an initial traffic monitoring model;
[0115] Send the initial traffic monitoring model to each energy storage station in the target area, so that each energy storage station uses a number of local historical network traffic packets to train its own initial traffic monitoring model, and then each generates the model parameters corresponding to the initial traffic monitoring model;
[0116] Obtain and perform cloud aggregation on the initial traffic monitoring model according to the model parameters uploaded by each energy storage station to construct the traffic monitoring model;
[0117] Send the traffic monitoring model to each energy storage station so that the traffic monitoring model replaces each of the initial traffic monitoring models.
[0118] The embodiments of this application adopt federated learning to avoid data leakage, improve cross-site detection capabilities, locally train traffic modeling and anomaly detection models at each energy storage station, and then perform federated aggregation through the cloud to form a globally optimized detection model, improve the generalization ability of the model, adapt to different site environments, and reduce data transmission costs. Only upload model update information to avoid data leakage, meet data security requirements, and at the same time support cross-site secure collaboration to enhance the detection ability in distributed and heterogeneous environments.
[0119] Traditional centralized traffic detection requires uploading all data to the cloud, which poses a risk of data leakage and cannot adapt to different site environments. The present invention adopts federated learning (FL), enabling each energy storage station to locally train traffic modeling and anomaly detection models, and only sending model updates (gradients and weights) to the cloud, and performing federated aggregation through the cloud to form a globally optimized detection model. There is no need for centralized data storage, protecting user data security, improving data security, applicable to collaborative detection of multiple energy storage stations, improving generalization ability, and only uploading model update information to the cloud, reducing data transmission overhead and cloud storage costs.
[0120] In a preferred embodiment, the federated server first trains an initial global traffic detection model using a subset of the available data, and then this model is distributed to all participating energy storage stations. Each energy storage station locally trains a traffic detection model to protect data security and only sends model updates (gradients and weights) to the federated server. Through federated averaging (FedAvg), the model is integrated on the federated server to improve the global detection ability. The federated learning training process is as follows:
[0121] (1) Train the initial XGBoost and TimesNet models.
[0122] (2) Distribute the initial model to each energy storage site for local training.
[0123] (3) Each site only aggregates the model updates in the cloud.
[0124] (4) The federated server issues the optimized model to further optimize and improve the overall detection ability.
[0125] In summary, the beneficial effects of the embodiments of the present application are as follows: Through DPI, the accuracy of flow monitoring in the energy storage station can be improved, key industrial protocols can be accurately parsed, false alarms and missed reports can be avoided, and the computational overhead can be reduced. Only the industrial protocol traffic is deeply parsed without the need to parse the entire network traffic. By using XGBoost machine learning for intelligent classification, known and unknown attacks can be accurately identified, the limitations of traditional rule-based methods can be broken through, and the real-time performance of the classification model can be improved, which is applicable to the high-throughput energy storage station traffic environment. By adopting encrypted traffic analysis without decryption (ETA), the limitations of TLS / SSL encrypted traffic can be broken through, encrypted attack detection can be realized, and decryption is not required, improving the computational efficiency and protecting data security. By using TimesNet for time series analysis to construct a traffic baseline, false alarms can be reduced, real-time performance can be improved, the traffic prediction ability can be optimized, and long-term stealth attacks can be detected, breaking through the short-term limitations of traditional detection technologies. By adopting federated learning (FL), cross-site collaboration is supported, the detection generalization ability is improved, and the risk of data leakage is avoided at the same time.
[0126] Exemplarily, in the specific implementation process, the energy storage station network traffic monitoring method provided by the present application includes but is not limited to the following three implementation schemes:
[0127] (1) DPI + XGBoost scheme (real-time industrial traffic analysis)
[0128] Suitable for energy storage stations with low computing resources, mainly for parsing industrial protocols (Modbus, IEC 61850, DNP3, etc.), capable of quickly and real-time detecting known abnormal traffic (DDoS attacks, port scans), with low computational overhead and applicable to embedded devices. However, it cannot detect long-term stealth attacks (such as APT and C2 communications, etc.), and cannot perform TLS / SSL encrypted traffic analysis.
[0129] (2) XGBoost + TimesNet (advanced behavior analysis)
[0130] Suitable for energy storage stations that require long-term behavior analysis, monitoring potential attacks on TLS encrypted traffic, and detecting stealth attacks such as C2 communications and slow data leakage. The computational overhead is slightly higher than that of Scheme 1, requiring stronger GPU / CPU computing power, and is not suitable for real-time analysis.
[0131] (3) Federated learning (FL) + XGBoost + TimesNet (distributed collaborative detection)
[0132] Such as Figure 2As shown, it is applicable to the collaborative detection of security threats by multiple energy storage stations, enabling cross-site and distributed security analysis. At the same time, it combines federated learning technology to avoid the risk of data leakage caused by centralized data storage, improves the generalization ability of the model, and enhances the cross-site detection accuracy. However, it requires an efficient FL training framework such as FedAvg and FedProx, and a certain network bandwidth for FL parameter exchange.
[0133] In addition, based on the technical concept provided by the embodiments of the present application, the following overall alternative or variant schemes also exist for the energy storage station network traffic monitoring method:
[0134] (1) Traffic anomaly detection based entirely on unsupervised learning
[0135] Use Autoencoder, Isolation Forest, and DBSCAN for unsupervised traffic anomaly detection, without relying on the XGBoost supervised classification model. Perform anomaly detection only based on statistical features and time series features, without the need for DPI to parse specific industrial protocols.
[0136] Compared with the above unsupervised scheme, XGBoost provided by the embodiments of the present application is more interpretable and has a lower false alarm rate. Combining DPI to extract industrial protocol features can also improve the detection accuracy of industrial traffic, is applicable to industrial scenarios, and avoids misdetection of normal traffic by pure statistical methods.
[0137] (2) Use end-to-end deep learning to replace XGBoost
[0138] Use CNN + Transformer to directly automatically learn traffic features without using XGBoost for feature engineering and classification. It is applicable to large-scale traffic data sets and reduces the feature extraction steps.
[0139] XGBoost provided by the embodiments of the present application is more lightweight, applicable to the resource-constrained environment of energy storage stations, has a lower computational overhead than deep learning, is applicable to real-time detection, and uses TimesNet for time series analysis to improve the long-term anomaly detection ability.
[0140] (3) DPI parsing alternative
[0141] Based on the traffic feature analysis of NetFlow / IPFIX, the computational overhead is lower, but it cannot parse industrial protocol instructions; based on eBPF / XDP for traffic filtering and analysis, the performance is higher, but it cannot extract protocol-level instructions; only detect TLS encrypted traffic based on traffic patterns to avoid DPI computational overhead, but the accuracy is reduced.
[0142] (4) XGBoost Machine Learning Classification Alternative
[0143] CNN end-to-end classification, deep learning can automatically extract features, but the computational cost is higher; Random Forest + TLS certificate features, the calculation is lighter, but the detection accuracy decreases.
[0144] (5) TimesNet Time Series Analysis Alternative
[0145] LSTM for time series modeling, with lower computational cost, but weaker long-term prediction ability; DBSCAN for traffic clustering analysis, suitable for short-term detection, but weak in long-term trend analysis.
[0146] Finally, in the future development trend of network traffic monitoring, traditional security systems rely on fixed rules or model training, but AI attack techniques (such as Generative Adversarial Network GAN) can already bypass static security policies. In the future, an adaptive AI countermeasure system can be adopted. When a new attack pattern is discovered, the XGBoost training model can be automatically updated, and TimesNet can be combined for AI countermeasure learning to identify malicious traffic generated by AI (such as automated phishing attacks, automatic C2 server domain name changes), and dynamically adjust the DPI parsing strategy to adapt to new attack patterns.
[0147] There is a risk of tampering in the flow logs of the energy storage station. Attackers may forge flow records to hide attack traces. In the future, blockchain technology (such as Hyperledger Fabric) can be combined to record flow logs to ensure that all flow information cannot be tampered with. Smart contracts can be used to deposit the data parsed by DPI to ensure that each Modbus TCP / IEC 61850 instruction is traceable, and TimesNet can be combined for log time series analysis to detect abnormal log tampering behavior.
[0148] The corresponding English full names and Chinese meanings of the English abbreviations appearing in this specification are shown in the following table.
[0149] English Abbreviations English Full Name Chinese Meaning SCADA Supervisory Control And Data Acquisition Supervisory Control And Data Acquisition EMS Energy Management System Energy Management System BMS Battery Monitoring and Management System Battery Monitoring and Management System IoT Internet of Things Internet of Things TLS Transport Layer Security Transport Layer Security SSL Secure Socket Layer Secure Socket Layer IDS Intrusion Detection System Intrusion Detection System IPS Intrusion Prevention System Module Intrusion Prevention System APT Advanced Persistent Threat Advanced Persistent Threat ICS Industrial Control System Industrial Control System DT Decision Tree Decision Tree SVM Support Vector Machine Support Vector Machine RF Random Forest Distributed Network Protocol 3 LSTM Central Processing Unit Random Forest ARIMA Auto Regression Moving Average Auto Regression Moving Average DPI Deep Packet Inspection Deep Packet Inspection ETA Encrypted Traffic Analytics Encrypted Traffic Analytics FL Federated Learning Federated Learning
[0150] Example Two:
[0151] As Figure 3 shown, Example Two provides an energy storage station network traffic monitoring system based on federated learning and traffic analysis with non-decryptive encryption, including an acquisition module 10, a data parsing module 20, a traffic feature extraction module 30, a fingerprint feature extraction module 40, and an anomaly recognition module 50;
[0152] Among them, the acquisition module 10 is used to acquire local network traffic packets;
[0153] The data parsing module 20 is used to parse the network traffic packet based on DPI technology and a preset data protocol to obtain data information corresponding to each data protocol;
[0154] The traffic feature extraction module 30 is used to extract features from each of the data information to obtain traffic features, where the traffic features include device interaction behavior features, control instruction features, and data flow features;
[0155] The fingerprint feature extraction module 40 is used to extract fingerprint features from the network traffic packet based on the non-decrypting encrypted traffic analysis technology to obtain corresponding encrypted communication features;
[0156] The anomaly recognition module 50 is used to input the traffic features and encrypted communication features into a preset traffic monitoring model, so that the traffic monitoring model identifies some traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic features, and determines whether there is abnormal behavior in the network traffic packet;
[0157] Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federated server, and the initial traffic monitoring model is constructed based on a machine learning model.
[0158] Further, the data parsing module 20 parses the network traffic packet based on DPI technology and a preset data protocol to obtain data information corresponding to each data protocol, including:
[0159] Based on the Modbus TCP protocol, device address, function code, and register data are parsed and extracted from the network traffic packet;
[0160] Based on the IEC 61850 protocol, GOOSE messages and sampled value data are parsed and extracted from the network traffic packet;
[0161] Based on the MQTT protocol, Topic, Payload, and QoS data are parsed and extracted from the network traffic packet;
[0162] Based on the DNP3 protocol, master-slave communication, data objects, and control function information are parsed and extracted from the network traffic packet.
[0163] Further, the traffic feature extraction module 30 extracts features from each of the data information to obtain traffic features, including:
[0164] According to each of the data information, device interaction mode analysis is performed to determine the communication topology relationship, master-slave relationship, and data flow mode among several devices corresponding to the network traffic packet, and then the device interaction behavior features are extracted;
[0165] Perform a naming pattern analysis based on each of the said data information, determine whether the device control instructions in each of the said data information conform to normal operating conditions, and then extract and obtain the control instruction features;
[0166] Perform a data packet statistics based on each of the said data information, combine the data information of several historical network traffic packets, determine the traffic volume, packet interval time, and up / down data ratio, and then extract and obtain the data stream features.
[0167] Further, the encrypted communication feature is the JA3 fingerprint feature. The fingerprint feature extraction module 40 extracts the fingerprint feature from the network traffic packet based on the non-decryption encrypted traffic analysis technology to obtain the corresponding encrypted communication feature, including:
[0168] Parse and obtain the TLS traffic from the network traffic packet based on the non-decryption encrypted traffic analysis technology;
[0169] Extract and obtain the JA3 fingerprint feature according to the TLS handshake information in the TLS traffic.
[0170] In a possible implementation manner, the anomaly recognition module 50 includes an anomaly recognition unit. The anomaly recognition unit is used to identify several traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic feature, and determine whether there is an abnormal behavior in the network traffic packet, including:
[0171] Parse the traffic feature into a network layer feature, an application layer feature, and a statistical feature;
[0172] Input the network layer feature, application layer feature, statistical feature, and encrypted communication feature into the XGBoost model in the traffic monitoring model, so that the XGBoost model performs traffic classification and anomaly behavior detection on the network traffic packet, identify several traffic in the network traffic packet as abnormal traffic or normal traffic, and determine whether there is an abnormal behavior in the network traffic packet.
[0173] Further, the traffic monitoring model also includes a time series analysis model. The anomaly recognition module 50 also includes a time series analysis unit. The time series analysis unit is used to predict the traffic trend of each of the abnormal traffic through the time series analysis model, and determine whether to output an anomaly alarm, specifically:
[0174] Obtain the traffic feature and each of the abnormal traffic;
[0175] Input the traffic feature and each of the abnormal traffic into the time series analysis model, so that the time series analysis model generates a corresponding traffic trend prediction result;
[0176] Compare the predicted traffic trend result with the traffic baseline, and calculate the abnormal deviation degree, where the traffic baseline is generated during the training process of the time series analysis model;
[0177] Judge whether to output an abnormal alarm according to the abnormal deviation degree.
[0178] In a possible implementation manner, the energy storage station network traffic monitoring system further includes a model training module, and the model training module is used to construct the traffic monitoring model through federated learning of an initial traffic monitoring model by a preset federated server, including:
[0179] Generate an initial traffic monitoring model;
[0180] Send the initial traffic monitoring model to each energy storage station in the target area, so that each energy storage station uses a number of local historical network traffic packets to train its own initial traffic monitoring model, and then each generates model parameters corresponding to the initial traffic monitoring model;
[0181] Obtain and perform cloud aggregation on the initial traffic monitoring model according to the model parameters uploaded by each energy storage station to construct the traffic monitoring model;
[0182] Send the traffic monitoring model to each energy storage station, so that the traffic monitoring model replaces each initial traffic monitoring model.
[0183] It can be understood that the above device item embodiments correspond to the method item embodiments of the present application, and can implement the energy storage station network traffic monitoring method based on federated learning and non-decryption encrypted traffic analysis provided by any one of the above method item embodiments of the present application.
[0184] It should be noted that the device embodiments described above are only illustrative, and some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment solution. In addition, in the attached drawings of the device embodiments provided in the present application, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement without creative efforts.
[0185] Embodiment 3:
[0186] Based on the above-mentioned first embodiment, the third embodiment provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the energy storage station network traffic monitoring method based on federated learning and non-decryption encrypted traffic analysis according to any embodiment of the present application.
[0187] Exemplarily, in this embodiment, the computer program can be divided into one or more modules. The one or more modules are stored in the memory and executed by the processor to complete the present application. The one or more module elements can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the terminal device.
[0188] The terminal device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.
[0189] The so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, and uses various interfaces and lines to connect various parts of the entire terminal device.
[0190] Embodiment Four:
[0191] Based on the above-mentioned first embodiment, the fourth embodiment provides a computer-readable storage medium, including a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the energy storage station network traffic monitoring method based on federated learning and non-decryption encrypted traffic analysis described in any of the above method embodiments of the present application.
[0192] Among them, for the modules / units integrated in the device / terminal device, if they are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0193] The above is the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art of the present technology, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present application.
Claims
1. A method for monitoring network traffic of energy storage stations based on federated learning and non-decryption encrypted traffic analysis, characterized in that: include: Get local network traffic packets; Performing data analysis on the network traffic packets based on DPI technology and preset data protocols to obtain data information corresponding to each data protocol; Extracting features from each of the data information to obtain traffic features, wherein the traffic features include device interaction behavior features, control instruction features, and data flow features; Based on the non-decryption encrypted traffic analysis technology, fingerprint feature extraction is performed on the network traffic packet to obtain corresponding encrypted communication features; Inputting the traffic characteristics and the encrypted communication characteristics into a preset traffic monitoring model, so that the traffic monitoring model identifies a number of flows in the network traffic packet as abnormal flows or normal flows according to the traffic characteristics, and determines whether the network traffic packet has abnormal behavior; Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federal server, and the initial traffic monitoring model is constructed based on a machine learning model.
2. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as claimed in claim 1, characterized in that: The data packet of the network traffic is analyzed based on the DPI technology and the preset data protocol to obtain data information corresponding to each data protocol, including: Based on the Modbus TCP protocol, parse and extract the device address, function code and register data from the network traffic packet; Based on the IEC 61850 protocol, GOOSE messages and sampled value data are parsed and extracted from the network traffic packets; Based on the MQTT protocol, the Topic, Payload and QoS data are parsed and extracted from the network traffic packet; Based on the DNP3 protocol, master-slave station communication, data objects and control function information are parsed and extracted from the network traffic packets.
3. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as claimed in claim 1, characterized in that: The extracting features of each piece of data information to obtain traffic features includes: Performing device interaction mode analysis based on each of the data information, determining the communication topology relationship, master-slave relationship and data flow mode between the devices corresponding to the network traffic packet, and then extracting and obtaining the device interaction behavior characteristics; Perform naming pattern analysis according to each of the data information to determine whether the device control instructions in each of the data information conform to normal working conditions, and then extract the control instruction features; Data packet statistics are performed based on each of the data information, and combined with data information of several historical network traffic packets, the traffic size, packet interval time and uplink / downlink data ratio are determined, and then the data flow characteristics are extracted.
4. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as claimed in claim 1, characterized in that: The encrypted communication feature is a JA3 fingerprint feature. The fingerprint feature extraction is performed on the network traffic packet based on the non-decryption encrypted traffic analysis technology to obtain the corresponding encrypted communication feature, including: Parsing and obtaining TLS traffic from the network traffic packet based on non-decryption encrypted traffic analysis technology; The JA3 fingerprint feature is obtained by extracting the TLS handshake information in the TLS traffic.
5. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as claimed in claim 1, characterized in that: The traffic monitoring model identifies several flows in the network traffic packet as abnormal flows or normal flows according to the traffic characteristics, and determines whether the network traffic packet has abnormal behavior, including: Parsing the traffic characteristics into network layer characteristics, application layer characteristics and statistical characteristics; The network layer features, application layer features, statistical features and encrypted communication features are input into the XGBoost model in the traffic monitoring model, so that the XGBoost model can classify the network traffic packets and detect abnormal behavior, identify some traffic in the network traffic packets as abnormal traffic or normal traffic, and determine whether the network traffic packets have abnormal behavior.
6. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as claimed in claim 5, characterized in that: The flow monitoring model also includes a time series analysis model. The energy storage station network flow monitoring method also includes predicting the flow trend of each abnormal flow through the time series analysis model, and determining whether to output an abnormal alarm, specifically: Acquire the flow characteristics and each of the abnormal flows; Inputting the flow characteristics and each of the abnormal flows into the time series analysis model so that the time series analysis model generates a corresponding flow trend prediction result; Comparing the traffic trend prediction result with the traffic baseline to calculate the abnormal deviation, the traffic baseline being generated during the training process of the time series analysis model; Whether to output an abnormality alarm is determined according to the abnormal deviation.
7. A method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as described in any one of claims 1 to 6, characterized in that: The method of constructing the traffic monitoring model by performing federated learning on the initial traffic monitoring model through a preset federated server includes: Generate an initial flow monitoring model; The initial flow monitoring model is sent to each energy storage station in the target area, so that each energy storage station uses a number of local historical network flow packets to train its own initial flow monitoring model, and then generates model parameters corresponding to the initial flow monitoring model; Acquire and aggregate the initial flow monitoring model in the cloud according to the model parameters uploaded by each energy storage station to construct the flow monitoring model; The flow monitoring model is sent to each energy storage station so that the flow monitoring model replaces each initial flow monitoring model.
8. A network traffic monitoring system for energy storage stations based on federated learning and non-decryption encrypted traffic analysis, characterized in that: It includes an acquisition module, a data analysis module, a traffic feature extraction module, a fingerprint feature extraction module and an anomaly recognition module; Wherein, the acquisition module is used to acquire local network traffic packets; The data analysis module is used to perform data analysis on the network traffic packet based on DPI technology and preset data protocols to obtain data information corresponding to each data protocol; The traffic feature extraction module is used to extract features from each of the data information to obtain traffic features, wherein the traffic features include device interaction behavior features, control instruction features, and data flow features; The fingerprint feature extraction module is used to extract fingerprint features from the network traffic packets based on the non-decryption encrypted traffic analysis technology to obtain corresponding encrypted communication features; The abnormal identification module is used to input the traffic characteristics and encrypted communication characteristics into a preset traffic monitoring model, so that the traffic monitoring model can identify some traffic in the network traffic packet as abnormal traffic or normal traffic according to the traffic characteristics, and determine whether the network traffic packet has abnormal behavior; Among them, the traffic monitoring model is constructed by performing federated learning on an initial traffic monitoring model through a preset federal server, and the initial traffic monitoring model is constructed based on a machine learning model.
9. A terminal device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a method for monitoring network traffic of an energy storage station based on federated learning and decryption-free encrypted traffic analysis as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: include: A stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a method for monitoring network traffic of an energy storage station based on federated learning and non-decryption encrypted traffic analysis as described in any one of claims 1 to 7.
Citation Information
Cited By
Power grid internal network flow prediction and anomaly detection method and system based on federated learning and generative AI
CN120434061A