Intelligent power grid communication network flow anomaly detection method
Through the traffic abnormality detection method of smart grid communication network, the adaptive threshold method is used to eliminate abnormal effects caused by the environment and equipment ambient temperature, which improves detection efficiency and reduces false alarm rate, and solves the problems of low detection accuracy and large false alarm rate in the prior art.
Patent Information
- Application Number
- CN202510155649.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art compares the fixed threshold, lacks consideration of some traffic changes caused by normal conditions, and is thus identified as abnormal conditions, resulting in low detection accuracy of traffic data and large false alarm rate.
A method for detecting traffic anomaly in smart grid communication networks is proposed. By obtaining traffic data and behavioral data, calculating the abnormality coefficient and behavioral abnormality coefficient of data, generating data packets based on the content of the data packet, adjusting the abnormality threshold value, and using an adaptive threshold method to eliminate the abnormal effects caused by ambient temperature and equipment ambient temperature, generating a comprehensive abnormality coefficient and issuing an alarm signal.
It improves the detection efficiency of abnormal traffic in the communication network, reduces the false alarm rate, and avoids abnormal false alarms caused by environmental data and equipment environment data.
Smart Images

Figure CN120200778A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of smart grids, and specifically relates to a method for detecting abnormal traffic in a smart grid communication network. Background Art
[0002] A smart grid is based on an integrated, high-speed two-way communication network. Through the application of advanced sensing and measurement technologies, advanced equipment technologies, advanced control methods, and advanced decision support system technologies, the goals of reliable, safe, economical, efficient, environmentally friendly, and user-safe power grids are achieved. The communication network of the smart grid undertakes a large number of data transmission tasks, including key information such as power dispatching, equipment monitoring, and fault diagnosis. With the rapid development of the smart grid, the security and stability of the communication network have become key elements.
[0003] With the expansion of the network scale and the increase in complexity, problems of abnormal communication network traffic have become increasingly prominent, such as data leakage, malicious attacks, etc. These problems seriously threaten the safe and stable operation of the smart grid. Most of the existing methods for detecting abnormal communication network traffic are based on statistical analysis or machine learning algorithms, and use fixed thresholds for comparison to determine the occurrence of abnormalities. To a certain extent, they can identify abnormal traffic, but there will still be some normal situations that may cause changes in the traffic data of the communication network and thus be identified as abnormal situations, resulting in problems such as low detection accuracy of traffic data and a high false alarm rate; for example, if the ambient temperature in an area is higher than the normal temperature, air conditioners or refrigeration equipment may be needed in that area, resulting in a higher power consumption in that area, triggering frequent recording of power data, and causing the packet size in that area to exceed the standard packet size, resulting in the corresponding traffic data being identified as an abnormal situation. Therefore, further improvement is still needed for the method of detecting abnormal communication network traffic. Summary of the Invention
[0004] This application aims to solve at least one of the technical problems existing in the prior art; for this purpose, this application proposes a method for detecting abnormal traffic in a smart grid communication network, which is used to solve the technical problems that the prior art uses fixed thresholds for comparison, lacks consideration of traffic changes caused by some normal situations and thus is identified as abnormal situations, resulting in low detection accuracy of traffic data and a high false alarm rate.
[0005] To achieve the above object, the first aspect of this application provides a method for detecting abnormal traffic in a smart grid communication network, including:
[0006] S0: Obtain traffic data and behavior data; the traffic data includes a number of data packets; the data packet includes a data packet ID, an IP address, a port number, a data packet size, and a data packet content;
[0007] S1: Calculate the data packet anomaly coefficient according to the data packet;
[0008] S2: Obtain the data packet content with the data packet exception coefficient greater than the corresponding data packet exception threshold; perform a decryption operation on the data packet content to obtain the decrypted data packet content; the data packet content includes a region ID and its corresponding power log; the power log includes power consumption, ambient temperature, and time tag.
[0009] S3: Generate a data packet adjustment exception threshold according to the data packet content; generate a traffic exception coefficient according to the data packet exception coefficient and the data packet adjustment exception threshold.
[0010] S4: Calculate a behavior exception coefficient according to the behavior data; calculate a behavior adjustment exception threshold according to the device environment data corresponding to the acquisition device.
[0011] S5: Generate a comprehensive exception coefficient according to the behavior exception coefficient and the traffic exception coefficient; generate an alarm signal according to the comprehensive exception coefficient.
[0012] S6: Give a prompt according to the alarm signal and contact the management personnel.
[0013] In this application, the data packet exception coefficient is calculated according to the data packet; the data packet content with the data packet exception coefficient greater than the corresponding data packet exception threshold is obtained; a data packet adjustment exception threshold is generated according to the data packet content; a traffic exception coefficient is generated according to the data packet exception coefficient and the data packet adjustment exception threshold; a behavior exception coefficient is calculated according to the behavior data; a behavior adjustment exception threshold is calculated according to the device environment data corresponding to the acquisition device; a comprehensive exception coefficient is generated according to the behavior exception coefficient and the traffic exception coefficient; an alarm signal is generated according to the comprehensive exception coefficient. Multiple data are used to jointly measure the abnormal situation of the communication network. And when an abnormal situation occurs, the result caused by the ambient temperature is excluded by the adaptive threshold method, avoiding false alarms of abnormal situations caused by environmental data, improving the detection efficiency of abnormal traffic in the communication network, and reducing the false alarm rate at the same time.
[0014] Further, the calculating the data packet exception coefficient according to the data packet includes:
[0015] Obtain the status tags of the data packet ID, IP address, and port number in the data packet, their corresponding exception degree level YCD, and the data packet size SBDX.
[0016] Calculate the data packet anomaly coefficient SBYX through the formula SBYX = ∑(fi × YCDi) + [|SBDX - BZDZ| / (k1 × BZDX)] × YCDsd; where i represents the serial number corresponding to each parameter in the data packets whose status labels except for the data packet size are anomaly labels, i = 1, 2, …, M; M represents the total number of parameters in the data packets whose status labels except for the data packet size are anomaly labels; fi represents the value corresponding to each data status label in the data packet except for the data packet size, when the status label is a normal label, fi = 0; when the status label is an anomaly label, fi = 1; YCDsd represents the anomaly degree level of the data packet size, BZDX represents the standard size of the data packet; k1 is a proportionality coefficient, k1 ∈ (0, 1).
[0017] Further, the status label is obtained in the following way, including:
[0018] Obtain the data packet ID, IP address, and port number in the data packet;
[0019] Judge whether the data packet ID exists in the database; if yes, set the data packet ID as an anomaly label; if no, when the data packet ID does not conform to the expected rule, set the data packet ID as an anomaly label; otherwise, do nothing;
[0020] Judge whether the IP address and port number are in their respective whitelists; if yes, do nothing; otherwise, set them as the corresponding anomaly labels.
[0021] Further, the data packet anomaly threshold is calculated through the historical data packet size, including:
[0022] Obtain several historical data packet sizes SBDXj of the data packets with normal labels under normal environmental temperature;
[0023] Calculate the average data packet size SDP through the formula SDP = (∑(SBDXj)) / max(j);
[0024] Extract the maximum value and the minimum value in SBDXj, calculate the absolute value of the difference one and the absolute value of the difference two from the average data packet size; select the largest absolute value of the difference as the calculated difference JC;
[0025] Calculate the data packet anomaly threshold SBYX through the formula SBYX = k2 × JC / DD × YCDsd; where j represents the serial number of the historical data packet, j = 1, 2, …, N; N represents the total number of historical data packets; k2 is a proportionality coefficient, k2 ∈ (0, 1); YCDsd represents the anomaly degree level of the data packet size; DD represents the unit size.
[0026] Further, generating a data packet adjustment anomaly threshold according to the data packet content includes:
[0027] Obtain the area ID in the data packet content and its corresponding power log; the power log includes power consumption, ambient temperature, and time tag;
[0028] Determine whether the ambient temperature is within the standard temperature range;
[0029] No. Calculate the environmental anomaly coefficient HYX according to the ambient temperature; calculate the data packet adjustment anomaly threshold SBTYY through the formula SBTYY = (1 + HYX) × SBYY;
[0030] Yes. Assign the data packet anomaly threshold SBYY to the data packet adjustment anomaly threshold SBTYY.
[0031] This application determines whether the ambient temperature in the area corresponding to the data packet content is a factor causing data packet anomalies. When the ambient temperature is the cause of data packet anomalies, the data packet anomaly threshold is modified through the environmental anomaly coefficient, excluding the influence of ambient temperature on data packet anomalies and reducing the false alarm rate of data packet anomaly detection.
[0032] Further, calculating the environmental anomaly coefficient according to the ambient temperature includes:
[0033] Obtain the ambient temperature HW in the area, the standard temperature median BWZ, and the temperature floating deviation WFP in the standard temperature range;
[0034] When the ambient temperature is not within the standard temperature range;
[0035] Calculate the environmental anomaly coefficient HYX through the formula HYX = gw × arctan(((|HW - BWZ| - WFP) / DW)^βw); where, gw is the proportionality coefficient, gw ∈ (0, π / 2); βw is the exponential coefficient, βw ∈ (0, 1); DW is the unit temperature;
[0036] Otherwise, let HYX = 0.
[0037] Further, generating a traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold includes:
[0038] Obtain a number of data packet anomaly coefficients SBYX and their corresponding data packet adjustment anomaly thresholds SBTYY;
[0039] When SBYX is greater than SBTYY, calculate the traffic anomaly coefficient LYX through the formula;
[0040] LYX = ∑(1 - exp(-(SBYXb - SBTYYb)^β1)); where b represents the packet number when SBYX is greater than SBTYY, b = 1, 2,..., P; P represents the total number of packets when SBYX is greater than SBTYY; β1 is an exponential coefficient, β1 ∈ (0, 1).
[0041] Further, calculating the behavior anomaly coefficient based on the behavior data includes:
[0042] Obtaining the access frequency FP and the packet size distribution SBDF in the behavior data; the packet size distribution is expressed as the average value of the sizes of several packets in the traffic data;
[0043] Calculating the behavior anomaly coefficient XYX through a formula;
[0044] XYX = 1 - exp(-(α1×(|FP - BFP| / DFP)^β2 + α2×(|SBDF - BDF| / DDF)^β3));
[0045] where α1 and α2 are weight coefficients, α1 and α2 ∈ (0, 1); β2 and β3 are exponential coefficients, β2 and β3 ∈ (0, 1); BFP is the standard access frequency, BDF is the standard size distribution; DFP is the unit access frequency, and DDF is the unit size range.
[0046] Further, calculating the behavior adjustment anomaly threshold based on the device environment data corresponding to the acquisition device includes:
[0047] Obtaining the device environment temperature corresponding to the acquisition device and the behavior anomaly threshold XYY;
[0048] Judging whether the device environment temperature is within the standard temperature range;
[0049] Yes, assign the behavior anomaly threshold XYY to the behavior adjustment anomaly threshold XTY;
[0050] No, calculate the device environment anomaly coefficient SHYX according to the device environment temperature;
[0051] Calculate the behavior adjustment anomaly threshold XTY through the formula XTY = (1 + SHYX)×XYY.
[0052] This application determines whether the device environment temperature of the device for acquiring behavior data is a factor causing the behavior data to be abnormal. When the device environment temperature is the factor causing the behavior data to be abnormal, the behavior anomaly threshold is modified through the device environment anomaly coefficient, excluding the influence of the device environment temperature on the abnormal behavior data and reducing the false alarm rate of the abnormal behavior data detection.
[0053] Further, generating a comprehensive anomaly coefficient based on the behavior anomaly coefficient and the traffic anomaly coefficient includes:
[0054] Obtain the behavior anomaly coefficient XYX and the traffic anomaly coefficient LYX;
[0055] Through the formula ZYX = α3 × XYX + α4 × LYX; where, α3 and α4 are weight coefficients, and α3 and α4 ∈ (0, 1).
[0056] Further, generating an alarm signal based on the comprehensive anomaly coefficient includes:
[0057] Obtain the comprehensive anomaly coefficient, the traffic anomaly coefficient, the behavior anomaly coefficient, the data packet anomaly coefficient, the data packet adjustment anomaly threshold, and the behavior adjustment anomaly threshold;
[0058] Judge whether the comprehensive anomaly coefficient is greater than the comprehensive anomaly threshold;
[0059] Yes, generate a communication network anomaly alarm signal;
[0060] No, judge whether the traffic anomaly coefficient is greater than the traffic anomaly threshold. If yes, generate a traffic anomaly alarm signal. If no, judge whether the data packet anomaly coefficient is greater than the data packet adjustment anomaly threshold. If yes, generate a data packet anomaly alarm signal. If no, do nothing;
[0061] Judge whether the behavior anomaly coefficient is greater than the behavior adjustment anomaly threshold; if yes, generate a behavior anomaly alarm signal, if no, do nothing.
[0062] Compared with the prior art, the beneficial effects of the present application are:
[0063] 1. The present application calculates the data packet anomaly coefficient according to the data packet; obtains the data packet content with the data packet anomaly coefficient greater than the corresponding data packet anomaly threshold; generates the data packet adjustment anomaly threshold according to the data packet content; generates the traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold; calculates the behavior anomaly coefficient according to the behavior data; calculates the behavior adjustment anomaly threshold according to the device environment data corresponding to the acquisition device; generates the comprehensive anomaly coefficient according to the behavior anomaly coefficient and the traffic anomaly coefficient; generates the alarm signal according to the comprehensive anomaly coefficient. It uses multi-source data to jointly measure the anomaly situation of the communication network, and when an anomaly occurs, it excludes the results caused by the environmental temperature through the adaptive threshold method, avoiding false alarms of anomaly situations caused by environmental data, improving the detection efficiency of abnormal traffic in the communication network, and reducing the false alarm rate at the same time.
[0064] 2. The present application determines whether the ambient temperature in the corresponding area of the data packet content is a factor causing the data packet anomaly. When the ambient temperature is the factor causing the data packet anomaly, the data packet anomaly threshold is modified through the ambient anomaly coefficient, eliminating the influence of the ambient temperature on the data packet anomaly and reducing the false alarm rate of the data packet anomaly detection.
[0065] 3. The present application determines whether the device ambient temperature of the device for collecting behavior data is a factor causing the behavior data anomaly. When the device ambient temperature is the factor causing the behavior data anomaly, the behavior anomaly threshold is modified through the device ambient anomaly coefficient, eliminating the influence of the device ambient temperature on the behavior data anomaly and reducing the false alarm rate of the behavior data anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0067] Figure 1 It is a flowchart of a method for detecting abnormal traffic in an intelligent power grid communication network according to the present application;
[0068] Figure 2 It is a flowchart for generating an alarm signal according to the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0069] The following will clearly and completely describe the technical solutions of the present application in combination with the embodiments. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0070] Please refer to Figure 1 , an embodiment of the first aspect of the present application provides a method for detecting abnormal traffic in an intelligent power grid communication network, including:
[0071] S0: Obtain traffic data and behavior data; the traffic data includes a number of data packets; the data packets include data packet ID, IP address, port number, data packet size, and data packet content, etc.; the behavior data includes access frequency and data packet size distribution, etc.;
[0072] S1: Calculate the data packet anomaly coefficient according to the data packet; the data packet anomaly coefficient is a coefficient for measuring the abnormal situation of the data packet;
[0073] S2: Obtain the data packet content with the data packet anomaly coefficient greater than the corresponding data packet anomaly threshold; perform a decryption operation on the data packet content to obtain the decrypted data packet content; the data packet content includes the area ID and its corresponding power log; the power log includes power consumption, ambient temperature, time stamp, etc.; the reason for performing the decryption operation on the data packet content is that the power data in the smart grid is an important piece of data and cannot be easily obtained by viewing. Generally, when data is transmitted, the content will be encrypted, and the corresponding decryption operation needs to be performed when viewing.
[0074] S3: Generate a data packet adjustment anomaly threshold according to the data packet content; generate a traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold; the data packet adjustment anomaly threshold is a threshold set for the ambient temperature to exclude the influence of the ambient temperature on the data packet; the traffic anomaly coefficient is a coefficient that measures whether the traffic data is abnormal.
[0075] S4: Calculate the behavior anomaly coefficient according to the behavior data; calculate the behavior adjustment anomaly threshold according to the device environment data corresponding to the acquisition device; the behavior anomaly coefficient is a coefficient that measures whether the behavior data is abnormal, and the behavior adjustment anomaly threshold is a threshold set for the device ambient temperature to exclude the influence of the device ambient temperature on the behavior data.
[0076] S5: Generate a comprehensive anomaly coefficient according to the behavior anomaly coefficient and the traffic anomaly coefficient; generate an alarm signal according to the comprehensive anomaly coefficient; the comprehensive anomaly coefficient is a coefficient that measures whether the communication network is abnormal.
[0077] S6: Give a prompt according to the alarm signal and contact the management personnel; the alarm signal includes a communication network anomaly alarm signal, a traffic anomaly alarm signal, a data packet anomaly alarm signal, a behavior anomaly alarm signal, etc.
[0078] In this embodiment, by calculating the data packet anomaly coefficient according to the data packet; obtaining the data packet content with the data packet anomaly coefficient greater than the corresponding data packet anomaly threshold; generating a data packet adjustment anomaly threshold according to the data packet content; generating a traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold; calculating the behavior anomaly coefficient according to the behavior data; calculating the behavior adjustment anomaly threshold according to the device environment data corresponding to the acquisition device; generating a comprehensive anomaly coefficient according to the behavior anomaly coefficient and the traffic anomaly coefficient; generating an alarm signal according to the comprehensive anomaly coefficient, multiple data are used to jointly measure the abnormality of the communication network, and when an abnormal situation occurs, the results caused by the ambient temperature are excluded by the adaptive threshold method, avoiding false alarms of abnormal situations caused by environmental data, improving the detection efficiency of abnormal traffic in the communication network, and reducing the false alarm rate at the same time.
[0079] Calculating the data packet anomaly coefficient according to the data packet in this embodiment includes:
[0080] Obtain the status tags of the packet ID, IP address, and port number in the data packet, their corresponding abnormal degree levels YCD, and the data packet size SBDX; the abnormal degree level is evaluated by experts and is used to measure the abnormal level of the status tag.
[0081] Calculate the data packet anomaly coefficient SBYX through the formula SBYX = ∑(fi × YCDi) + [|SBDX - BZDZ| / (k1 × BZDX)] × YCDsd; where, i represents the serial number corresponding to each parameter in the data packets whose status tags except the data packet size are abnormal tags, i = 1, 2,..., M; M represents the total number of parameters in the data packets whose status tags except the data packet size are abnormal tags; fi represents the value corresponding to each data status tag in the data packet except the data packet size. When the status tag is a normal tag, fi = 0; when the status tag is an abnormal tag, fi = 1; YCDsd represents the abnormal degree level of the data packet size, BZDX represents the standard size of the data packet; k1 is a proportionality coefficient, k1 ∈ (0, 1), and the specific value is set according to experience; the larger the number of abnormal tags of each data in the data packet, and the greater the difference between the data packet size and the standard data packet size, it indicates that the data packet deviates more from the normal state, and its abnormal degree is more serious; therefore, the data packet anomaly coefficient will increase accordingly.
[0082] The standard data packet size in this embodiment is obtained through the corresponding historical data packet sizes, including:
[0083] Obtain several historical data packet sizes, where the historical data packet size is the data packet size when the data packet is in a normal state under normal environmental temperature.
[0084] Calculate its average value as the standard data packet size of this data packet.
[0085] The status tags in this embodiment are obtained through the following methods, including:
[0086] Obtain the packet ID, IP address, and port number in the data packet.
[0087] Judge whether the packet ID exists in the database; if yes, set the packet ID as an abnormal tag; if not, when the packet ID does not conform to the expected rule, set the packet ID as an abnormal tag; otherwise, do nothing; the packet ID is unique. If a duplicate ID appears, it means an abnormal situation occurs; the generation of packet IDs in each area also has a regularity, which can be generated according to an arithmetic sequence or a combination of letters and numbers, and they are all packet IDs with regularity.
[0088] Determine whether the IP address and port number are in their respective whitelists; if so, do nothing; otherwise, set them to the corresponding exception tags; the whitelist means that both the IP address and port number are known and correct data.
[0089] The data packet anomaly threshold in this embodiment is calculated from the historical data packet sizes and includes:
[0090] Obtain several historical data packet sizes SBDXj with normal tags for the data packets at normal ambient temperatures;
[0091] Calculate the average data packet size SDP through the formula SDP = (∑(SBDXj)) / max(j); the larger the historical data packet size, the greater the corresponding average data packet size will be;
[0092] Extract the maximum and minimum values from SBDXj, and calculate the absolute value of the difference one and the absolute value of the difference two from the average data packet size; select the largest absolute value of the difference as the calculated difference JC;
[0093] Calculate the data packet anomaly threshold SBYY through the formula SBYY = k2×JC / DD×YCDsd; where j represents the number of the historical data packet, j = 1, 2,..., N; N represents the total number of historical data packets; k2 is a proportionality coefficient, k2 ∈ (0, 1), and the specific value is set according to experience; YCDsd represents the anomaly degree level of the data packet size; DD represents the unit size, and the specific value is based on the unit size. In this embodiment, DD is set to 1MB; when the anomaly degree level of the data packet size is determined, SBYY increases with the increase of JC.
[0094] The generation of the data packet adjustment anomaly threshold according to the data packet content in this embodiment includes:
[0095] Obtain the area ID in the data packet content and its corresponding power log; the power log includes power consumption, ambient temperature, time tag, etc.;
[0096] Determine whether the ambient temperature is within the standard temperature range;
[0097] If not, calculate the ambient anomaly coefficient HYX according to the ambient temperature; calculate the data packet adjustment anomaly threshold SBTYY through the formula SBTYY = (1 + HYX)×SBYY; the larger the ambient anomaly coefficient, the greater the abnormal impact of the ambient temperature on the data packet size, and it is necessary to increase the corresponding anomaly threshold to offset the impact of the ambient temperature, so the data packet adjustment anomaly threshold will increase accordingly;
[0098] If so, assign the data packet anomaly threshold SBYY to the data packet adjustment anomaly threshold SBTYY.
[0099] In this embodiment, by determining whether the ambient temperature in the corresponding area of the data packet content is a factor causing the data packet anomaly, when the ambient temperature is the cause of the data packet anomaly, the data packet anomaly threshold is modified by the environmental anomaly coefficient, eliminating the influence of the ambient temperature on the data packet anomaly and reducing the false alarm rate of the data packet anomaly detection.
[0100] Calculating the environmental anomaly coefficient according to the ambient temperature in this embodiment includes:
[0101] Obtain the ambient temperature HW in the area, the standard temperature median BWZ and the temperature floating deviation WFP in the standard temperature range;
[0102] When the ambient temperature is not within the standard temperature range;
[0103] Calculate the environmental anomaly coefficient HYX through the formula HYX = gw × arctan(((|HW - BWZ| - WFP) / DW)^βw); where, gw is the proportionality coefficient, gw ∈ (0, π / 2), and the specific value is set according to experience. The setting of gw is to make HYX ∈ (0, 1); βw is the exponential coefficient, βw ∈ (0, 1), and the specific value is set according to experience; DW is the unit temperature, and the specific value is set according to experience. In this embodiment, DW is set to 1°C; the greater the difference between the ambient temperature and the standard temperature range, the more the ambient temperature deviates from the standard temperature range. In this case, the content of the power log in the data packet will increase, resulting in an increase in the data packet size, and thus an increase in the data packet anomaly coefficient. Therefore, the environmental anomaly coefficient increases accordingly;
[0104] Otherwise, let HYX = 0.
[0105] In another embodiment, the standard temperature median BWZ and the temperature floating deviation WFP are obtained in the following manner, including: obtaining the standard temperature range; the standard temperature range includes the standard temperature range maximum value WZD and the standard temperature range minimum value WZX;
[0106] Calculate the standard temperature median ZWZ through the formula BWZ = (WFD + WFX) / 2;
[0107] Calculate the temperature floating deviation WFP through the formula WFP = (WFD - WFX) / 2; the larger the standard temperature range, the greater the temperature floating deviation will be.
[0108] Generating the traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjusted anomaly threshold in this embodiment includes:
[0109] Obtain a number of data packet anomaly coefficients SBYX and their corresponding data packet adjusted anomaly thresholds SBTYY;
[0110] When SBYX is greater than SBTYY, calculate the traffic anomaly coefficient LYX through a formula;
[0111] LYX = ∑(1 - exp(-(SBYXb - SBTYYb)^β1)); where b represents the packet number when SBYX is greater than SBTYY, b = 1, 2,..., P; P represents the total number of packets when SBYX is greater than SBTYY; β1 is an exponential coefficient, β1 ∈ (0, 1), and the specific value is set according to experience; the larger the packet anomaly coefficient and the larger the number of packets with SBYX greater than SBTYY, the more serious the traffic data anomaly, so the traffic anomaly coefficient increases accordingly.
[0112] Calculating the behavior anomaly coefficient according to the behavior data in this embodiment includes:
[0113] Obtain the access frequency FP and the packet size distribution SBDF in the behavior data; the packet size distribution is expressed as the average value of the sizes of several packets in the traffic data;
[0114] Calculate the behavior anomaly coefficient XYX through the formula XYX = 1 - exp(-(α1×(|FP - BFP| / DFP)^β2 + α2×(|SBDF - BDF| / DDF)^β3)); where α1 and α2 are weight coefficients, α1 and α2 ∈ (0, 1), and the specific values are set according to experience; β2 and β3 are exponential coefficients, β2 and β3 ∈ (0, 1), and the specific values are set according to experience; BFP is the standard access frequency, BDF is the standard size distribution, DFP is the unit access frequency, and DDF is the unit size range, and the specific values are set according to experience.
[0115] Calculating the behavior adjustment anomaly threshold according to the device environment data corresponding to the acquisition device in this embodiment includes:
[0116] Obtain the device environment temperature corresponding to the acquisition device and the behavior anomaly threshold XYY; the behavior anomaly threshold is set according to experience;
[0117] Judge whether the device environment temperature is within the standard temperature range;
[0118] Yes, assign the behavior anomaly threshold XYY to the behavior adjustment anomaly threshold XTY;
[0119] No, calculate the device environment anomaly coefficient SHYX according to the device environment temperature;
[0120] Calculate the behavior adjustment anomaly threshold XTY by the formula XTY = (1 + SHYX) × XY; the larger the device environment anomaly coefficient, the greater the abnormal impact of the device environment temperature on the behavior data, and it is necessary to increase the corresponding anomaly threshold to offset the impact of the device environment temperature. Therefore, the behavior adjustment anomaly threshold will increase accordingly.
[0121] In this embodiment, by determining whether the device environment temperature of the device collecting behavior data is a factor causing abnormal behavior data, and when the device environment temperature is a factor causing abnormal behavior data, the behavior anomaly threshold is modified through the device environment anomaly coefficient, excluding the influence of the device environment temperature on the occurrence of abnormal behavior data and reducing the false alarm rate of abnormal behavior data detection.
[0122] Generating a comprehensive anomaly coefficient based on the behavior anomaly coefficient and the traffic anomaly coefficient in this embodiment includes:
[0123] Obtain the behavior anomaly coefficient XYX and the traffic anomaly coefficient LYX;
[0124] Through the formula ZYX = α3 × XYX + α4 × LYX; where α3 and α4 are weight coefficients, α3 and α4 ∈ (0, 1), and the specific values are set according to experience; the comprehensive anomaly coefficient increases with the increase of the behavior anomaly coefficient and the traffic anomaly coefficient.
[0125] Please refer to Figure 2 , generating an alarm signal based on the comprehensive anomaly coefficient in this embodiment includes:
[0126] Obtain the comprehensive anomaly coefficient, the traffic anomaly coefficient, the behavior anomaly coefficient, the data packet anomaly coefficient, the data packet adjustment anomaly threshold, and the behavior adjustment anomaly threshold;
[0127] Judge whether the comprehensive anomaly coefficient is greater than the comprehensive anomaly threshold; the comprehensive anomaly threshold is set according to experience;
[0128] Yes, generate a communication network anomaly alarm signal;
[0129] No, judge whether the traffic anomaly coefficient is greater than the traffic anomaly threshold, the traffic anomaly threshold is set according to experience, yes, generate a traffic anomaly alarm signal, no, judge whether the data packet anomaly coefficient is greater than the data packet adjustment anomaly threshold, yes, generate a data packet anomaly alarm signal, no, do nothing;
[0130] Judge whether the behavior anomaly coefficient is greater than the behavior adjustment anomaly threshold; yes, generate a behavior anomaly alarm signal, no, do nothing.
[0131] Some of the data in the above formula is calculated by removing the dimension and taking its numerical value. The formula is obtained by software simulation of a large amount of collected data to get a formula that is closest to the actual situation. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.
[0132] The working principle of this application: Obtain traffic data and behavior data; calculate the packet anomaly coefficient according to the data packet; obtain the data packet content with the packet anomaly coefficient greater than the corresponding packet anomaly threshold; perform decryption operation on the said data packet content to obtain the decrypted data packet content; generate a packet adjustment anomaly threshold according to the data packet content; generate a traffic anomaly coefficient according to the packet anomaly coefficient and the packet adjustment anomaly threshold; calculate a behavior anomaly coefficient according to the behavior data; calculate a behavior adjustment anomaly threshold according to the device environment data corresponding to the collection device; generate a comprehensive anomaly coefficient according to the behavior anomaly coefficient and the traffic anomaly coefficient; generate an alarm signal according to the comprehensive anomaly coefficient; issue a prompt according to the alarm signal and contact the management personnel. Use multiple data to jointly measure the anomaly situation of the communication network, and when an anomaly occurs, exclude the results caused by the environmental temperature through the adaptive threshold method, avoid false alarms of anomaly situations caused by environmental data, improve the detection efficiency of abnormal traffic in the communication network, reduce the false alarm rate at the same time, and avoid the problems of low detection accuracy and large false alarm rate of traffic data caused by the prior art comparing through fixed thresholds and lacking consideration of traffic changes caused by some normal situations and thus being identified as abnormal situations.
[0133] The above embodiments are only used to illustrate the technical method of this application and not to limit it. Although this application has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of this application can be modified or equivalently replaced without departing from the spirit and scope of the technical method of this application.
Claims
1. A method for detecting abnormal traffic in a smart grid communication network, characterized in that: include: Obtaining traffic data and behavior data; the traffic data includes a number of data packets; the data packets include a data packet ID, an IP address, a port number, a data packet size, and data packet content; Calculate the data packet anomaly coefficient according to the data packet; and obtain the data packet content whose data packet anomaly coefficient is greater than the corresponding data packet anomaly threshold; decrypt the data packet content to obtain the decrypted data packet content; Generate a data packet adjustment anomaly threshold according to data packet content; generate a traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold; Calculate the behavior anomaly coefficient based on the behavior data; calculate the behavior adjustment anomaly threshold based on the device environment data corresponding to the collection device; A comprehensive abnormality coefficient is generated according to the behavior abnormality coefficient and the flow abnormality coefficient; and an alarm signal is generated according to the comprehensive abnormality coefficient.
2. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The step of calculating the data packet anomaly coefficient according to the data packet includes: Obtain the status labels of the data packet ID, IP address, port number and their corresponding abnormality level YCD and data packet size SBDX in the data packet; The data packet anomaly coefficient SBYX is calculated by the formula SBYX=∑(fi×YCDi)+[|SBDX-BZDZ| / (k1×BZDX)]×YCDsd; wherein, i represents the number corresponding to each parameter in the data packet whose status label is an abnormal label excluding the data packet size, i=1, 2,…, M; M represents the total number of parameters in the data packet whose status label is an abnormal label excluding the data packet size; fi represents the numerical value corresponding to each data status label in the data packet excluding the data packet size, when the status label is a normal label, fi=0; when the status label is an abnormal label, fi=1; YCDsd represents the abnormal degree level of the data packet size, BZDX represents the standard size of the data packet; k1 is the proportional coefficient, k1∈(0,1).
3. A method for detecting abnormal traffic in a smart grid communication network according to claim 2, characterized in that: The state label is obtained by: Get the packet ID, IP address and port number in the data packet; Determine whether the data packet ID exists in the database; if yes, set the data packet ID as an abnormal label; if no, when the data packet ID does not conform to the expected pattern, set the data packet ID as an abnormal label; otherwise, do nothing; Determine whether the IP address and port number are in their corresponding whitelists; if yes, do nothing; otherwise, set them to the corresponding exception labels.
4. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The data packet abnormality threshold is calculated based on the historical data packet size, including: Obtain the sizes SBDXj of several historical data packets with normal labels under normal ambient temperature; The average data packet size SDP is calculated by the formula SDP = (∑ (SBDXj)) / max (j); Extract the maximum and minimum values in SBDXj, calculate the absolute value of the difference between the average value of the data packet size and the absolute value of the difference; select the largest absolute value of the difference as the calculated difference JC; The data packet anomaly threshold SBYY is calculated by the formula SBYY=k2×JC / DD×YCDsd; wherein, j represents the number of the historical data packet, j=1, 2,…, N; N represents the total number of historical data packets; k2 is the proportional coefficient, k2∈(0, 1); YCDsd represents the abnormality level of the data packet size; DD represents the unit size.
5. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: Generating a data packet adjustment abnormal threshold according to the data packet content includes: Obtaining the area ID in the data packet content and its corresponding power log; the power log includes power consumption, ambient temperature, and time tag; Determine whether the ambient temperature is within the standard temperature range; No, calculate the environmental anomaly coefficient HYX according to the environmental temperature; calculate the data packet adjustment anomaly threshold SBTYY by the formula SBTYY=(1+HYX)×SBYY; Yes, the data packet anomaly threshold SBYY is assigned to the data packet adjustment anomaly threshold SBTYY.
6. A method for detecting abnormal traffic in a smart grid communication network according to claim 5, characterized in that: The calculating of the environmental anomaly coefficient according to the ambient temperature includes: Obtain the ambient temperature HW in the area, the standard temperature middle value BWZ in the standard temperature range, and the temperature floating deviation WFP; When the ambient temperature is not within the standard temperature range; The environmental anomaly coefficient HYX is calculated by the formula HYX=gw×arctan(((|HW-BWZ|-WFP) / DW)^βw); wherein gw is the proportionality coefficient, gw∈(0,π / 2); βw is the exponential coefficient, βw∈(0,1); and DW is the unit temperature; Otherwise, set HYX=0.
7. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The generating of the traffic anomaly coefficient according to the data packet anomaly coefficient and the data packet adjustment anomaly threshold comprises: Obtain several data packet anomaly coefficients SBYX and their corresponding data packet adjustment anomaly thresholds SBTYY; When SBYX is greater than SBTYY, the flow abnormality coefficient LYX is calculated by the formula; LYX=∑(1-exp(-(SBYXb-SBTYYb)^β1)); wherein b represents the number of the data packet when SBYX is greater than SBTYY, b=1, 2, …, P; P represents the total number of data packets when SBYX is greater than SBTYY; β1 is the exponential coefficient, β1∈(0, 1).
8. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The calculating of the abnormal behavior coefficient according to the behavior data comprises: Obtaining access frequency FP and data packet size distribution SBDF in the behavior data; the data packet size distribution is represented as an average value of several data packet sizes in the traffic data; Calculate the behavioral abnormality coefficient XYX through the formula; XYX=1-exp(-(α1×(|FP-BFP| / DFP)^β2+α2×(|SBDF-BDF| / DDF)^β3)); Among them, α1 and α2 are weight coefficients, α1 and α2∈(0,1); β2 and β3 are exponential coefficients, β2 and β3∈(0,1); BFP is the standard access frequency, BDF is the standard size distribution; DFP is the unit access frequency, and DDF is the unit size range.
9. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The generating of the comprehensive abnormality coefficient according to the abnormal behavior coefficient and the abnormal flow coefficient comprises: Obtain the behavior abnormality coefficient XYX and the flow abnormality coefficient LYX; Through the formula ZYX=α3×XYX+α4×LYX; wherein α3 and α4 are weight coefficients, α3 and α4∈(0,1).
10. A method for detecting abnormal traffic in a smart grid communication network according to claim 1, characterized in that: The generating of an alarm signal according to the comprehensive abnormality coefficient comprises: Obtaining a comprehensive anomaly coefficient, a traffic anomaly coefficient, a behavior anomaly coefficient, a data packet anomaly coefficient, a data packet adjustment anomaly threshold, and a behavior adjustment anomaly threshold; It is judged that the comprehensive abnormality coefficient is greater than the comprehensive abnormality threshold; Yes, generate a communication network abnormality alarm signal; No, determine whether the traffic anomaly coefficient is greater than the traffic anomaly threshold, if yes, generate a traffic anomaly alarm signal, no, determine whether the packet anomaly coefficient is greater than the packet adjustment anomaly threshold, if yes, generate a packet anomaly alarm signal, if no, do nothing; Determine whether the behavior abnormality coefficient is greater than the behavior adjustment abnormality threshold; if yes, generate a behavior abnormality alarm signal; if no, do nothing.