A method and system for detecting and defending cross-domain threats in power systems
By obtaining data from the physical domain and information domain in the power system for cross-domain abnormal event correlation analysis, building an attack traceability map and generating active defense rules, the shortcomings of cross-domain threat detection in the existing technology are solved, and real-time and accurate security protection for the power system is achieved.
Patent Information
- Application Number
- CN202510475156.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-04-16
AI Technical Summary
The existing security threat detection and defense solutions for power systems cannot achieve cross-domain abnormal event correlation analysis and cross-domain attack propagation path identification, it is difficult to deal with complex cross-domain collaborative attack scenarios, and it is impossible to accurately perceive security threats and track defense in real time, resulting in insufficient comprehensiveness and reliability of power system security protection.
By obtaining the operation monitoring data of physical domain nodes and network traffic data of information domain nodes, abnormal event identification and correlation analysis are carried out, cross-domain attack traceability map is built, and active defense rules are generated based on game theory algorithms and reinforcement learning algorithms, cross-domain attack risks are identified in real time and adaptive defense is carried out.
Real-time accurate identification and timely and reliable defense of complex cross-domain attacks have been achieved, the comprehensiveness and reliability of power system security protection has been improved, and the power system's ability to resist network attacks has been improved.
Smart Images

Figure CN120223418B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system security technology, and in particular to a method and system for detecting and defending against cross-domain threats in a power system. Background Art
[0002] The complete architecture of a power system consists of closely interconnected and interacting information and physical domains. The physical domain primarily encompasses the physical equipment and facilities involved in power generation, transmission, transformation, distribution, and consumption, while the information domain primarily addresses the monitoring, control, protection, dispatching, and management of the power system. As a critical infrastructure in modern society, the operational safety and reliability of power systems are of great concern, and the corresponding security threat detection and prevention issues have become a key research topic within the industry.
[0003] Because multi-source data in the physical and information domains differ significantly in time granularity, data format, and data quality, cross-domain anomaly event correlation analysis is difficult. Existing power system security threat monitoring and defense solutions are mostly limited to single-domain threat protection in either the physical or information domain, failing to perform cross-domain anomaly event correlation analysis or identify cross-domain attack propagation paths. Faced with complex attack scenarios in actual power system operations, where attackers exploit multi-domain vulnerabilities to achieve cross-domain coordinated attack targets, these solutions are fundamentally unable to accurately perceive security threats and track and defend against them in real time, making it difficult to ensure the comprehensiveness and reliability of power system security protection. Therefore, there is an urgent need to provide a cross-domain threat defense method that can accurately identify cross-domain attack risks in real time and perform adaptive defense. Summary of the Invention
[0004] The purpose of the present invention is to provide a method for detecting and defending against cross-domain threats in power systems. The method identifies abnormal events in the physical domain and information domain by respectively utilizing the operation monitoring data of physical domain nodes and the traffic data of information domain nodes, and performs correlation analysis on abnormal events in different domains to identify cross-domain abnormal propagation paths and construct a complete attack tracing map. The method also generates active defense rules based on the vulnerability analysis of key nodes for executing security defense for corresponding physical domain nodes and information domain nodes. The method can not only accurately identify complex cross-domain attack risks in real time, but also conduct reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection.
[0005] In order to achieve the above objectives, it is necessary to provide a method and system for detecting and defending cross-domain threats in power systems in response to the above technical problems.
[0006] In a first aspect, an embodiment of the present invention provides a method for detecting and defending against cross-domain threats in a power system, the method comprising the following steps:
[0007] Obtaining operational monitoring data of each physical domain node within the target power grid area, and identifying state anomalies based on the operational monitoring data to obtain corresponding physical domain anomaly identification results; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results, and regional fault levels;
[0008] Obtaining network traffic data of each information domain node in the target power grid area, and performing denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results;
[0009] Perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results;
[0010] According to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack, a corresponding cross-domain attack chain is generated based on a graph theory algorithm;
[0011] Identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack tracing maps based on the key nodes and the key risk propagation paths;
[0012] According to the vulnerability information of key nodes in the attack tracing map, active defense rules are iteratively generated based on game theory algorithms and reinforcement learning algorithms and sent to corresponding physical domain nodes and information domain nodes.
[0013] Furthermore, the operation monitoring data includes operation parameter information and switch protection information; the operation parameter information includes voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency and current frequency; the switch protection information includes equipment switch status and switch opening and closing status information;
[0014] The step of identifying a state anomaly based on the operation monitoring data to obtain a corresponding physical domain anomaly identification result includes:
[0015] Compare each operating parameter information with the corresponding preset parameter safety threshold range to obtain an abnormal measurement identification result; the abnormal measurement identification result includes the abnormal operating parameter and the corresponding abnormal data type and the abnormal occurrence timestamp;
[0016] Comparing the switch opening and closing state information with the corresponding device switch state to obtain an abnormal switch identification result; the abnormal switch identification result includes the state abnormality type corresponding to each abnormal switch identification number and the state abnormality occurrence timestamp;
[0017] The abnormal switch area is located according to the abnormal switch identification result and the preset switch bus association code table to obtain the corresponding fault device identification result; the fault device identification result includes the fault area code and fault timestamp corresponding to each fault switch identifier;
[0018] According to the preset neural network model, feature analysis is performed on the abnormal measurement identification results in the fault area corresponding to the identification results of each faulty device to generate a corresponding feature abnormality weight matrix, and the fault area abnormality level is determined based on the feature abnormality weight matrix to obtain the corresponding regional fault level.
[0019] Furthermore, the information domain attack identification result includes the denial of service attack identification result of each target attack port and the corresponding attack level;
[0020] The step of performing denial of service attack identification based on the network traffic data to obtain a corresponding information domain attack identification result includes:
[0021] Performing centralized identification of abnormal traffic based on the network traffic data to obtain a port traffic aggregation identification result; the network traffic data includes the number of network connections and bandwidth utilization;
[0022] According to the port traffic aggregation identification result, the inflow traffic monitoring data of each traffic aggregation port is obtained, and the denial of service attack is identified based on the inflow traffic monitoring data to obtain the corresponding information domain attack identification result.
[0023] Furthermore, the step of performing centralized identification of abnormal traffic based on the network traffic data to obtain a port traffic aggregation identification result includes:
[0024] Comparing each network traffic data with the corresponding preset rated threshold range to obtain traffic anomaly information; the traffic anomaly information includes the number of abnormal connections, bandwidth utilization and the time when the anomaly occurred;
[0025] According to the traffic anomaly information, relevant port traffic data is obtained, and trend anomaly identification is performed on the relevant port traffic data to obtain corresponding port anomaly identification results; the port anomaly identification results include traffic data corresponding to each abnormal port number;
[0026] According to a preset port traffic judgment matrix, each abnormal port is classified into a traffic abnormality level to obtain a corresponding port traffic abnormality classification result; the preset port traffic judgment matrix is constructed based on preset level judgment indicators; the preset level judgment indicators include port traffic fluctuation amplitude, traffic duration and traffic growth rate;
[0027] According to the abnormal classification results of each port traffic, the corresponding adjacent port traffic data is obtained, and abnormal traffic aggregation analysis is performed based on the adjacent port traffic data to obtain the port traffic aggregation identification result; the port traffic aggregation identification result includes the number of ports in the group corresponding to each traffic aggregation port group and the direction of the aggregated traffic.
[0028] Furthermore, the step of performing denial of service attack identification based on the inflow traffic monitoring data to obtain a corresponding information domain attack identification result includes:
[0029] Determine whether the inflow traffic monitoring data meets a preset traffic aggregation identification condition; if so, determine that the corresponding traffic aggregation port is a traffic flood attack port, and obtain a set of source addresses of data packets with the traffic flood attack port as the destination port; the preset traffic aggregation identification condition is that the inflow traffic exceeds a preset multiple of the port baseline traffic and lasts for more than a preset time;
[0030] Distributed attack identification, half-open connection identification, and malformed packet identification are performed based on the source address connection data records corresponding to the data packet source address set, and attack classification processing is performed on the obtained abnormal feature identification results based on a preset machine learning model to generate the denial of service attack identification results; the denial of service attack identification results include attack source characteristics, attack type, attack duration, and detection timestamp;
[0031] Performing source address dispersion analysis based on the data packet source address set and a preset dispersion identification condition to generate a corresponding source address dispersion identifier; the preset dispersion identification condition is that the minimum physical distance between addresses is greater than a preset distance threshold and the access ratio of each source address is less than a preset ratio; the source address dispersion identifier includes the access record, address location and access timestamp of each source address;
[0032] According to the transmission control protocol specification and the preset inspection field, the inflow data packets of the traffic flood attack port are counted for abnormalities, and when the proportion of abnormal data packets exceeds the abnormal percentage threshold, a corresponding connection abnormality identification result is generated; the preset inspection field includes the handshake packet flag sequence, the packet header length and the checksum; the connection abnormality identification result includes the number of abnormal packets, the total number of inflow data packets and the inspection time;
[0033] The traffic flood attack identifier, source address dispersion identifier and connection anomaly identification result of the traffic flood attack port are comprehensively analyzed to obtain a comprehensive score of the attack behavior, and the corresponding attack level is obtained based on the comprehensive score of the attack behavior; the traffic flood attack identifier includes the target port, inflow traffic, baseline traffic, attack start time and attack duration.
[0034] Furthermore, the step of performing abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain an attack cross-domain anomaly identification result includes:
[0035] Compare the anomaly occurrence timestamps of each physical domain anomaly identification result with each information domain attack identification result, and generate cross-domain anomaly association data based on anomaly events in which the nodes belong to the same physical area and the anomaly occurrence timestamp deviation is less than the preset fault response time. The cross-domain anomaly association data includes the physical domain node number, information domain node number, time correlation, spatial correlation, and correlation timestamp corresponding to each cross-domain anomaly event.
[0036] Based on the cross-domain anomaly association data and the physical connection relationship and communication link relationship of the equipment in the target power grid area, a corresponding electrical primary equipment topology map and a secondary equipment communication topology map are constructed, and abnormal nodes whose distance between the electrical primary equipment topology map and the secondary equipment communication topology map is less than a preset connection layer threshold are obtained to generate corresponding association group data; the association group data includes a physical domain device list, an information domain device list, the physical distance between devices, the number of communication link hops, and the degree of spatial association;
[0037] Perform feature analysis on abnormal events in the associated group data according to a preset feature matching table, and identify the severity of abnormal events using a preset feature combination counting judgment principle to obtain a high-level abnormal group;
[0038] Establishing a device connectivity graph corresponding to the high-level anomaly group, and obtaining a corresponding group diffusion risk value based on the degree of connection between devices in the device connectivity graph;
[0039] When the group diffusion risk value exceeds a preset warning value, the attack cross-domain anomaly identification result is generated; the attack cross-domain anomaly identification result includes a list of risky devices, a diffusion warning level, and a warning release time.
[0040] Furthermore, the step of generating a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack includes:
[0041] Establishing a node mapping relationship matrix between physical domain nodes in the power system topology diagram and communication domain nodes in the communication network topology diagram;
[0042] Perform abnormal node traversal on the power system topology map and the communication network topology map using a depth-first search algorithm, and perform matching analysis on the physical adjacent nodes and communication adjacent nodes of each abnormal node according to the node mapping relationship matrix to generate an abnormal propagation node table;
[0043] The Dykstra algorithm is used to calculate the shortest propagation paths of each abnormal node in the abnormal propagation node table in the power system topology diagram and the communication network topology diagram, and a propagation impact assessment is performed on each shortest propagation path based on the link bandwidth utilization between the communication nodes and the state quantity of the circuit breaker and the protection device action signal between the physical nodes, and a cascade impact path is generated according to the corresponding impact assessment results.
[0044] According to the preset path priority index, the path priority of each cascade impact path is evaluated respectively, and the cascade impact paths are sorted according to the corresponding priority evaluation results to generate the cross-domain attack chain; the preset path priority index includes node connection density, node bandwidth occupancy, node protection configuration and node communication delay; the cross-domain attack chain includes the source node, destination node and path priority corresponding to each propagation path.
[0045] Furthermore, the step of identifying key nodes and key risk propagation paths in the cross-domain attack chain and generating corresponding attack tracing graphs based on the key nodes and the key risk propagation paths includes:
[0046] Obtaining node connection relationship data of the cross-domain attack chain, and calculating the node degree and betweenness centrality index of each node based on the node connection relationship data, and screening key nodes based on the node degree and betweenness centrality index;
[0047] Based on the inter-node connection relationship of all key nodes, the corresponding propagation path is constructed, and the risk of each propagation path is evaluated according to the preset path significance index to obtain the key risk propagation path;
[0048] Based on the force-directed layout algorithm, each key risk propagation path is visually laid out to generate the corresponding risk propagation layout plan;
[0049] According to the risk propagation layout plan and preset graphical annotation rules, the corresponding key risk propagation paths are annotated to generate the attack tracing map; the preset graphical annotation rules include coloring rules and icon sizes for different types of nodes, and pixel setting rules for node-to-node connections based on the degree of influence between nodes.
[0050] Furthermore, the vulnerability information includes the degree of node software version lag, the number of communication protocol vulnerabilities and patch update status;
[0051] The step of iteratively generating active defense rules based on the vulnerability information through a game theory algorithm and a reinforcement learning algorithm includes:
[0052] Perform weighted comprehensive analysis on the vulnerability information of each key node to obtain the corresponding node vulnerability score, and identify the key nodes whose node vulnerability scores exceed a preset score threshold as high-risk nodes;
[0053] Based on the vulnerability identification of each high-risk node and the preset attack and defense game payoff matrix, multiple rounds of game iterative calculations are performed based on a non-zero-sum game algorithm to generate the optimal defense strategy; the vulnerability identification includes the vulnerability level, attack difficulty coefficient and node vulnerability score;
[0054] Generate corresponding initial defense rules according to the optimal defense strategy; the initial defense rules include port restriction rules, flow control rules and electrical parameter adjustment rules;
[0055] According to the preset rule evaluation indicators, the defense effect simulation evaluation of the initial defense rules is performed based on the reinforcement learning algorithm, and according to the corresponding evaluation results, the initial defense rules are optimized to generate the active defense rules; the preset rule evaluation indicators include the percentage decrease in attack success rate after the rule is executed, the percentage increase in equipment operation stability, and the percentage decrease in business impact.
[0056] In a second aspect, an embodiment of the present invention provides a system for detecting and defending against cross-domain threats in a power system, the system comprising:
[0057] A physical domain anomaly identification module is used to obtain operational monitoring data of each physical domain node within the target power grid area, and identify state anomalies based on the operational monitoring data to obtain corresponding physical domain anomaly identification results; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results, and regional fault levels;
[0058] An information domain attack identification module is used to obtain network traffic data of each information domain node in the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results;
[0059] The cross-domain anomaly analysis module is used to perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results;
[0060] An attack chain analysis module is configured to generate a corresponding cross-domain attack chain based on a graph theory algorithm according to a power system topology map and a communication network topology map corresponding to the cross-domain anomaly identification result of the attack;
[0061] A traceability graph construction module is used to identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack traceability graphs based on the key nodes and the key risk propagation paths;
[0062] The attack defense processing module is used to iteratively generate active defense rules based on the vulnerability information of key nodes in the attack tracing map and the game theory algorithm and reinforcement learning algorithm, and send them to the corresponding physical domain nodes and information domain nodes.
[0063] The above-mentioned application provides a method and system for detecting and defending cross-domain threats in a power system. The method realizes obtaining the operation monitoring data of each physical domain node in the target power grid area, performing state anomaly identification based on the operation monitoring data to obtain physical domain anomaly identification results including abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results and regional fault levels, obtaining network traffic data of each information domain node in the target power grid area, performing denial of service attack identification based on the network traffic data to obtain the corresponding information domain attack identification results, performing abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain attack cross-domain anomaly identification results, and then generating a corresponding cross-domain attack chain based on the graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the attack cross-domain anomaly identification results, identifying the key nodes and key risk propagation paths in the cross-domain attack chain, generating a corresponding attack tracing map based on the key nodes and the key risk propagation paths, and iteratively generating active defense rules based on the game theory algorithm and the reinforcement learning algorithm according to the vulnerability information of the key nodes in the attack tracing map and sending them to the corresponding physical domain nodes and information domain nodes. Technical solution. Compared with existing technologies, this method for detecting and defending cross-domain threats in power systems identifies abnormal events by comprehensively utilizing physical domain node operation monitoring data and information domain node traffic data, and constructs a complete attack tracing map by performing correlation analysis on abnormal events in different domains and identifying cross-domain abnormal propagation paths. It also generates active defense rules for adaptive security defense by combining vulnerability analysis of key nodes. This intelligent protection method of automatic detection, analysis and defense can not only accurately identify complex cross-domain attack risks in real time, but also carry out reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, and improving the power system's ability to resist complex network attacks, providing effective technical support for ensuring the safe and stable operation of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Figure 1 1 is a flow chart of a method for detecting and defending against cross-domain threats in a power system according to an embodiment of the present invention;
[0065] Figure 2 2 is a schematic diagram of the structure of a system for detecting and defending against cross-domain threats in a power system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0066] In order to make the purpose, technical solutions and beneficial effects of this application more clear, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. Obviously, the embodiments described below are part of the embodiments of the present invention and are only used to illustrate the present invention, but are not used to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0067] The method for detecting and defending against cross-domain threats to the power system provided by the present invention can be understood as a solution for intelligent monitoring and protection of cross-domain threats to the power system, which is based on the current situation that the existing power system security threat defense is limited to single-domain threat monitoring and protection, cannot realize cross-domain abnormal event correlation analysis, and is difficult to cope with complex attack scenarios of cross-domain coordinated attacks. Instead, it proposes a solution that comprehensively utilizes physical domain node operation monitoring data and information domain node traffic data to conduct cross-domain abnormal event correlation analysis to construct a complete attack tracing map, and combines key node vulnerability analysis to generate active defense rules. The following embodiments will explain in detail the method for detecting and defending against cross-domain threats to the power system of the present invention.
[0068] In one embodiment, Figure 1 As shown, a method for detecting and defending cross-domain threats in a power system is provided, comprising the following steps:
[0069] S11. Obtain the operation monitoring data of each physical domain node in the target power grid area, and identify the state anomaly based on the operation monitoring data to obtain the corresponding physical domain anomaly identification result; wherein, the target power grid area can be understood as the power grid area that needs to perform safety protection in the power system, and the area range can be adjusted according to actual application requirements; the corresponding physical nodes can be understood as the various substation equipment actually deployed in the target power grid area.
[0070] In this embodiment, the operation monitoring data of the physical domain node can be understood as measurement data and status monitoring data that can reflect the actual operation status of the physical equipment; in order to ensure the comprehensiveness and reliability of the physical domain anomaly analysis, the operation monitoring data is preferably set to include operation parameter information and switch protection information, and the operation parameter information includes measurement data such as voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency and current frequency that can be obtained through the substation monitoring and acquisition layer, and the switch protection information includes the equipment switch status (equipment operation status quantity) and switch opening and closing status information (switch opening and closing status information) that can be obtained through the substation equipment status monitoring device; correspondingly, the physical domain anomaly identification result can be understood as the anomaly analysis result obtained based on the analysis and processing of the operation monitoring data, including abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results and regional fault levels.
[0071] Specifically, the step of performing state anomaly identification based on the operation monitoring data to obtain a corresponding physical domain anomaly identification result includes:
[0072] Each operating parameter information is compared with the corresponding preset parameter safety threshold range to obtain the abnormal measurement identification result; wherein, the preset parameter safety threshold range corresponding to each operating parameter information can be understood as the parameter value range under normal operation of the physical device, which can be set according to actual application requirements. For example, the preset parameter safety threshold range of the voltage amplitude is a 10% deviation range of the rated voltage amplitude, the preset parameter safety threshold range of the current amplitude is not higher than 20% of the rated current, the preset parameter safety threshold range of the phase angle is not more than plus or minus 15 degrees, the preset parameter safety threshold range of the frequency is a deviation not exceeding the rated frequency 0.5 Hz, etc., which are not specifically limited here. In actual applications, each operating parameter information is compared with the corresponding preset parameter safety threshold range. If it exceeds the corresponding threshold range, the operating parameter is determined to be abnormal data, and the corresponding abnormal identifier needs to be added. The corresponding abnormal measurement identification result can be obtained, including each abnormal operating parameter and the corresponding abnormal data type and the timestamp of the abnormal occurrence.
[0073] The switch opening and closing state information is compared with the corresponding device switch state to obtain an abnormal switch identification result; if the switch opening and closing state information does not match the actual collected device switch state quantity, it is considered that there is a switch abnormality problem, that is, the abnormal switch identification result includes the state abnormality type and the state abnormality occurrence timestamp corresponding to each abnormal switch identification number, and the state abnormality type can be determined according to the abnormal scenario that may exist in the actual application scenario. This embodiment takes into account that the switch position signal in the substation monitoring device is collected in a normally open and normally closed contact manner, and the switch position signal contacts may be worn due to long-term operation, resulting in inaccurate signals. The actual position state of the switch is determined by combining the switch opening and closing coil current signal and the switch energy storage motor working state signal, thereby effectively improving the accuracy of switch state monitoring.
[0074] The abnormal switch area is located according to the abnormal switch identification result and the preset switch-bus association coding table, and the corresponding fault equipment identification result is obtained; wherein, the preset switch-bus association coding table can be understood as a mapping table of the association relationship between switch equipment and bus, including various connection forms such as bus tie switch and double bus, segmented switch and bus, etc., which can be used to locate the electrical area to which the switch with abnormal status belongs. For example, switch 101 and bus 101 form a coding correspondence table. When switch 101 is abnormal, by querying the switch-bus correspondence table, it can be determined that bus 101 to which switch 101 belongs is the fault area; the corresponding fault equipment identification result includes the fault area code and fault timestamp corresponding to each fault switch identifier. This embodiment uses the preset switch-bus association coding table to locate the abnormal switch area. When the voltage and current abnormal data involve multiple bus areas, the abnormal data range can be determined by tracing the switch connection relationship, and all equipment involved in the abnormal area can be located, thereby achieving accurate demarcation of the abnormal area of the substation.
[0075] Based on a preset neural network model, feature analysis is performed on the abnormal measurement identification results within the fault area corresponding to each faulty device identification result to generate a corresponding feature anomaly weight matrix. The fault area anomaly level is determined based on the feature anomaly weight matrix to obtain the corresponding regional fault level. The preset neural network model can be understood as a neural network pre-trained based on relevant data that can be used to effectively extract and analyze voltage amplitude anomaly data, current amplitude anomaly data, phase angle anomaly data, and frequency anomaly data. The specific network structure can be set according to actual application requirements and is not specifically limited here. The corresponding feature anomaly weight matrix can be understood as a feature importance weight matrix constructed by extracting and classifying the abnormal data within each substation bus area using the preset neural network model and evaluating the importance of each feature to the model analysis results using interpretable analysis tools such as LIME and SHAP. The corresponding regional fault level can be understood as the fault level corresponding to the anomaly score obtained by performing a comprehensive anomaly assessment based on the feature anomaly weight matrix and each abnormal data. It should be noted that the fault level corresponding to different anomaly scores can be set according to actual application requirements and is not specifically limited here.
[0076] This embodiment can achieve real-time and comprehensive perception of physical domain anomalies in the power system by comprehensively analyzing the operating parameter information and switch protection information of the physical domain nodes to identify physical domain equipment anomalies, thereby improving the reliability of physical domain anomaly event analysis.
[0077] S12. Obtain network traffic data for each information domain node within the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results. Information domain nodes can be understood as key points or components related to information transmission and processing in the power system, and are responsible for data collection, transmission, processing, storage, and distribution. Considering that network attacks in the information domain are mainly carried out by sending relevant malicious traffic data packets, this embodiment preferably performs attack identification based on the network traffic data of the information domain nodes. Specific network traffic data includes the number of network connections and bandwidth utilization collected from the network monitoring and collection device. The corresponding denial of service attack identification can be understood as a process of first identifying abnormal traffic accumulation at the outbound port based on the network traffic data, and then performing targeted denial of service attack analysis based on the inbound traffic monitoring data of each traffic aggregation port. The obtained information domain attack identification results include the denial of service attack identification results and corresponding attack levels for each target attack port, and the denial of service attack identification results include attack source characteristics, attack type, attack duration, and detection timestamp.
[0078] Specifically, the step of performing denial of service attack identification based on the network traffic data to obtain a corresponding information domain attack identification result includes:
[0079] Abnormal traffic is centrally identified based on the network traffic data to obtain a port traffic aggregation identification result. Abnormal traffic centrally identified can be understood as a process based on the number of port connections, bandwidth utilization, port traffic trend analysis, and traffic concentration port correlation analysis. The specific steps for obtaining the port traffic aggregation identification result include:
[0080] Each network traffic data is compared with the corresponding preset rated threshold range to obtain traffic anomaly information; in actual application, traffic anomalies such as the number of connections exceeding the preset connection upper limit or the bandwidth utilization exceeding the rated bandwidth range are identified. For example, if the number of network connections exceeds 80% of the preset connection upper limit or the bandwidth utilization exceeds 75% of the rated bandwidth, it is determined that a traffic anomaly exists, and corresponding traffic anomaly information including the number of abnormal connections, bandwidth utilization, the time when the abnormality occurred, and the duration of the abnormality is generated.
[0081] According to the traffic anomaly information, relevant port traffic data is obtained, and trend anomaly identification is performed on the relevant port traffic data to obtain a corresponding port anomaly identification result; wherein, the relevant port traffic data can be understood as the transmission traffic data of all network ports that may cause the above-mentioned traffic anomaly; by comparing the transmission traffic data of each relevant port obtained in real time with the corresponding port historical average traffic, the port traffic trend anomaly is discovered in time, and all port information with traffic trend anomalies is aggregated to obtain a port anomaly identification result including the traffic data corresponding to each abnormal port number.
[0082] According to the preset port traffic judgment matrix, each abnormal port is classified into a traffic anomaly level to obtain the corresponding port traffic anomaly grading result; wherein, the preset port traffic judgment matrix can be understood as a port traffic anomaly level identification matrix constructed based on preset level judgment indicators including port traffic fluctuation amplitude, traffic duration and traffic growth rate. For example, the three abnormality grading rules of port traffic fluctuation amplitude greater than 200%, traffic duration greater than 30 minutes and traffic growth rate greater than 50% per minute can be combined to establish a port traffic anomaly level discrimination matrix containing multiple port traffic anomaly levels, and based on the discrimination matrix, the traffic data of each abnormal port is discriminant analyzed to obtain the corresponding traffic anomaly grading result.
[0083] According to the abnormality classification results of each port traffic, the corresponding adjacent port traffic data is obtained, and abnormal traffic aggregation analysis is performed based on the adjacent port traffic data to obtain the port traffic aggregation identification result; wherein, the adjacent port traffic data can be understood as considering that the actual port usage is usually divided according to the business function, and the corresponding business application port abnormalities are correlated. Based on the traffic abnormality classification results of each abnormal port, the port traffic data that has a horizontal or vertical business upstream and downstream relationship with the abnormal port is obtained. Specifically, the number of adjacent ports is determined based on the traffic abnormality classification. For example, the higher the abnormality level, the more adjacent ports that need to be associated with the analysis can be selected. On the contrary, the lower the abnormality level, only the adjacent ports in one business direction in the horizontal or vertical direction can be selected for association analysis according to the needs. In this embodiment, the abnormal traffic aggregation analysis can be understood as an analysis process to determine whether the inflow traffic data of all adjacent ports of the abnormal port exceeds the corresponding port traffic baseline threshold, and whether the corresponding traffic growth rate exceeds the preset rate threshold; when multiple adjacent ports deviate from the traffic baseline at the same time and show the same change trend, it can be determined that there is a traffic aggregation phenomenon. By analyzing the number of aggregated ports and the direction of traffic transmission, the port traffic aggregation identification result including the number of ports in the group corresponding to each traffic aggregation port group and the direction of aggregated traffic is obtained, which is convenient for quickly locating the scope of the fault business impact.
[0084] According to the port traffic aggregation identification result, inflow traffic monitoring data of each traffic aggregation port is obtained, and denial of service attack identification is performed based on the inflow traffic monitoring data to obtain a corresponding information domain attack identification result; wherein the inflow traffic monitoring data of each traffic aggregation port is obtained by a network monitoring device to obtain the port inflow traffic, and the corresponding denial of service attack identification can be understood as an analysis process based on the port inflow traffic to identify whether there is traffic flooding from multiple sources, incomplete connection attempts, and malformed packets; specifically, the steps of performing denial of service attack identification based on the inflow traffic monitoring data to obtain the corresponding information domain attack identification result include:
[0085] Determine whether the inflow traffic monitoring data meets the preset traffic aggregation identification conditions. If so, determine that the corresponding traffic aggregation port is a traffic flood attack port, and obtain the source address set of data packets with the traffic flood attack port as the destination port; wherein, the preset traffic aggregation identification conditions are that the inflow traffic exceeds the port baseline traffic by a preset multiple and the duration exceeds the preset duration. The port baseline traffic is an abnormality detection reference value calculated based on the traffic average during the normal operation period of the port. The corresponding preset multiple can be determined according to actual application requirements. For example, if the inflow traffic exceeds five times the port baseline traffic and the duration exceeds three minutes, the traffic aggregation port is determined to be a traffic flood attack port, and a traffic flood attack identifier including the target port number, inflow traffic value, baseline traffic value, attack start timestamp, and attack duration attributes is added to the port. In order to facilitate in-depth analysis of the attack traffic, it is necessary to obtain the source address information of all data packets received by the port identified as a traffic flood attack port, and generate a data packet source address set containing several data packet source addresses.
[0086] Distributed attack identification, half-open connection identification, and malformed packet identification are performed according to the source address connection data record corresponding to the data packet source address set, and attack classification processing is performed on the obtained abnormal feature identification result according to the preset machine learning model to generate the denial of service attack identification result; wherein, the source address connection data record can be understood as the connection data information obtained by tracking the communication connection of the IP address within each source address, and the specific content can be selected according to actual needs, such as including the current source address connection number, the source address connection baseline value, the number of source addresses, and the normal connection data packets and half-open connection data of each source address; the specific steps of performing distributed attack identification, half-open connection identification, and malformed packet identification based on the source address connection data record to generate the corresponding denial of service attack identification result may include:
[0087] Determine whether the preset distributed attack conditions are met, such as whether the current number of source address connections exceeds the source address connection benchmark value and continues to time out, or whether the number of source addresses exceeds the normal source address number threshold. If so, generate a distributed attack identifier including the source address list, connection benchmark value, current number of connections and detection timestamp.
[0088] Determine whether the half-open connection data of each source address, including the number of half-open connections, the duration of half-open connections and the number of repeated connection requests, meet the preset half-open connection anomaly judgment rules. If so, generate a source address half-open connection anomaly identifier corresponding to the abnormal source address, the number of half-open connections, the duration of half-open connections and the detection timestamp; wherein, the preset half-open connection anomaly judgment rules can be determined based on the data items of the half-open connection data, for example, it can be set to be when the number of half-open connections of the source address exceeds 2% of the server connection pool capacity, the duration of the half-open connection exceeds 30 seconds, and the number of repeated connection requests initiated by the same source address exceeds five times the normal value. One or more of the following conditions are met at the same time, then it is determined that a half-open connection anomaly exists.
[0089] According to the Transmission Control Protocol specification, content anomaly detection is performed on the normal connection data packets of each source address to generate the corresponding source address malformed packet identifier; among which, the content anomaly detection includes checking whether the packet length field does not match the actual length, the protocol version field value is incorrect, the flag bit combination does not meet the protocol requirements, and the checksum calculation result is incorrect. If more than two verification indicators are abnormal at the same time, the data packet is determined to be a malformed packet, and a malformed packet identifier can be generated, including the abnormal field name and the corresponding field value, the standard value range and the detection timestamp.
[0090] According to the preset machine learning model, feature extraction is performed on the distributed attack identifier, the source address half-open connection anomaly identifier and the source address deformed packet identifier respectively to obtain corresponding anomaly identifier feature values; wherein, the preset machine learning model can be understood as a network model that is pre-trained based on relevant data and can be used to reliably extract features from the above-mentioned distributed attack identifier, source address half-open connection anomaly identifier and source address deformed packet identifier. The specific model type and network structure are not specifically limited here.
[0091] Each abnormal identification feature value is weighted and fused according to the corresponding preset feature value weight to obtain the corresponding abnormal fusion feature, and the attack is classified according to the abnormal fusion feature to generate the denial of service attack identification result; wherein, the preset feature value weight can be set according to the actual application requirements, and the corresponding weighted fusion and attack classification can be implemented by referring to the relevant existing technology, which will not be described in detail here.
[0092] A source address dispersion analysis is performed based on the data packet source address set and the preset dispersion identification conditions to generate a corresponding source address dispersion identifier; wherein, the source address dispersion analysis can be understood as an analysis of the access frequency and address location of the data packet source address, and the corresponding preset dispersion identification conditions are that the minimum physical distance between addresses is greater than the preset distance threshold and the access proportion of each source address is less than the preset ratio. If the minimum geographical distance between the source addresses in the data packet source address set exceeds the preset distance threshold and the number of visits to a single source address is less than the preset percentage of the total number of visits, it is determined that the data packet source address of the port is dispersed, and a source address dispersion identifier including the access records, address locations and access timestamps of each source address can be generated.
[0093] According to the transmission control protocol specification and the preset check field, the incoming data packets of the traffic flood attack port are subjected to abnormal statistics, and when the proportion of abnormal data packets exceeds the abnormal percentage threshold, the corresponding connection abnormality identification result is generated; wherein, the preset check field includes the handshake packet flag sequence, the header length and the checksum; in actual application, each incoming data packet is parsed according to the transmission control protocol specification to obtain each preset check field, and it is judged whether each preset field meets the requirements, such as detecting whether the handshake packet flag sequence meets the connection establishment specification, whether the header length field value is less than twenty bytes, whether the checksum field value is calculated incorrectly, etc. If any of the abnormalities exists, the data packet is considered to be an abnormal traffic packet, and all abnormal traffic packets are statistically summarized, and when the total number of abnormal data packets exceeds a certain percentage of the total number of sampled data packets, a connection abnormality identification result including the number of abnormal packets, the total number of incoming data packets and the inspection time is generated.
[0094] The traffic flood attack identifier, source address dispersion identifier and connection anomaly identification result of the traffic flood attack port are comprehensively analyzed to obtain a comprehensive score of the attack behavior, and the corresponding attack level is obtained based on the comprehensive score of the attack behavior; wherein, the comprehensive analysis can be understood to be achieved by extracting and analyzing various abnormal features through machine learning methods, which will not be described in detail here; it should be noted that the mapping relationship between the comprehensive score of the attack behavior and the attack level can be set according to actual needs.
[0095] This embodiment first performs centralized identification of abnormal traffic based on network traffic data in the information domain, and then combines machine learning to perform in-depth traffic analysis. At the same time, it conducts a comprehensive attack level analysis from the aspects of traffic flood attack identification, source address dispersion identification, and connection anomaly identification. This can not only effectively improve the accuracy of denial of service attack identification, but also ensure the reliability of attack level determination, providing protection for the effectiveness of information domain attack identification results.
[0096] S13. Perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results. The abnormal event correlation analysis can be understood as a cross-domain abnormal event correlation mapping analysis based on the certain sequential temporal correlation between information domain network attacks and physical domain device anomalies. Specifically, the steps of performing abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results include:
[0097] The abnormality identification results of each physical domain are compared with the abnormality occurrence timestamps of each information domain attack identification result, and cross-domain abnormality association data is generated based on abnormal events in which the nodes belong to the same physical area and the abnormality occurrence timestamp deviation is less than the preset fault response time. In actual applications, the abnormal measurement identification results and abnormal switch identification results in each physical domain abnormality identification result are compared with the denial of service attack identification results in each information domain attack identification result. When it is monitored that the communication port of the main transformer protection device is subjected to a denial of service attack and the main transformer current measurement value fluctuates abnormally, the two abnormal event timestamps differ by one. If 30 minutes and 15 seconds is less than the preset fault response time (such as three minutes), and the main transformer protection device and the main transformer are located in the same physical area, and the time-space correlation conditions are met, it is determined that there is a cross-domain abnormal event correlation; after all comparisons and analyses are completed, all information with cross-domain abnormal correlations is summarized to obtain cross-domain abnormality correlation data including the physical domain node number, information domain node number, time correlation, spatial correlation and correlation timestamp corresponding to each cross-domain abnormal event; it should be noted that the time correlation can be quantified by the deviation of the abnormality occurrence time, and the spatial correlation can be quantified by the physical location distance between devices, which will not be described in detail here.
[0098] Based on the cross-domain anomaly association data and the physical connection relationship and communication link relationship of the equipment in the target power grid area, a corresponding electrical primary equipment topology map and a secondary equipment communication topology map are constructed, and abnormal nodes whose distance between the electrical primary equipment topology map and the secondary equipment communication topology map is less than a preset connection layer threshold are obtained to generate corresponding association group data; wherein, the electrical primary equipment topology map can be understood as a topology map constructed based on the physical domain node labels and equipment physical connection relationships involved in the cross-domain anomaly association data, and the secondary equipment communication topology map can be understood as a topology map constructed based on the information domain node labels and communication link relationships involved in the cross-domain anomaly association data. The specific topology map construction process can be implemented with reference to existing topology map construction technology. The association group data in this embodiment can be understood as the device association group division result obtained by classifying device nodes within a certain range of direct or indirect connection layers based on actual physical connections and communication links based on the electrical primary equipment topology map and the secondary equipment communication topology map, including information such as the physical domain device list and information domain device list corresponding to each association group, the physical distance between devices, the number of communication link hops, and the degree of spatial association.
[0099] According to the preset feature matching table, the abnormal events in the associated group data are analyzed for features, and the severity of the abnormal events is identified by the preset feature combination counting judgment principle to obtain a high-level abnormal group; wherein the preset feature matching table can be understood as a mapping relationship table of the severity of abnormal association events and the corresponding feature abnormal range constructed in advance based on the main associated features involved in various possible cross-domain abnormal association events, which can be used to extract and analyze the preset features of the abnormal events in each associated group data. In actual application, if the preset feature matching table includes multiple feature abnormal ranges such as voltage deviation exceeding 10%, current deviation exceeding 20%, protection action abnormality, port flow exceeding five times the baseline value, and the number of half-open connections exceeding the threshold, then the corresponding feature values of the abnormal events in the actual associated group data are matched, and all matching feature abnormal ranges are counted and statistically analyzed. The severity of the abnormal event is determined according to the feature matching combination count size. The larger the feature matching combination count, the more serious it is. For example, an event with a combination count of more than three items is determined as a high-level abnormal event, and the corresponding associated group is set as a high-level abnormal group and a high-level abnormal identifier corresponding to the abnormal indicator value, the number of feature combinations, and the abnormal event level is added to facilitate subsequent analysis.
[0100] A device connectivity graph corresponding to the high-level anomaly group is established, and a corresponding group diffusion risk value is obtained based on the degree of connectivity between devices in the device connectivity graph. The device connectivity graph can be understood as a device connection topology graph established based on an analysis of the physical connection relationships or communication link relationships between devices in the high-level anomaly group. In practical applications, device relationship analysis can be implemented using existing technologies such as neural networks, which will not be discussed further here. The degree of connectivity between devices can be measured based on the number of connection layers (link hops) between devices in the corresponding topology graph. The stronger the degree of connectivity between devices, the greater the group diffusion risk. Based on this, the desired group diffusion risk value can be obtained based on the mapping relationship between device connectivity and group diffusion risk value. It should be noted that device connectivity analysis can reveal fault propagation paths and be used to determine whether the fault will spread. For example, if a busbar fault occurs, the busbar protection device suffers a cyber attack, causing the protection function to fail. Switchgear connected to the busbar cannot clear the fault in a timely manner, causing a cascading trip. The fault can then spread from the communication network to primary equipment, causing a wider power outage. Therefore, performing group diffusion risk analysis based on the device connectivity graph ensures that diffusion risk identification is consistent with actual application scenarios, thereby ensuring the accuracy of the analysis results.
[0101] When the group diffusion risk value exceeds the preset warning value, the attack cross-domain anomaly identification result is generated; wherein, the preset warning value can be set according to actual application requirements. In actual applications, if the obtained group diffusion risk value exceeds the preset warning value, it is considered that there is an attack cross-domain anomaly event that urgently needs attention and resolution. Based on this, an attack cross-domain anomaly identification result including a risk device list, a diffusion warning level and a warning release time can be generated. The risk device list is a list of risky devices involved in the group, and the diffusion warning level can be obtained by matching the corresponding group diffusion risk value.
[0102] This embodiment uses a time-space-correlated cross-domain abnormal event correlation analysis method to effectively capture the abnormal event correlation relationship between the physical domain and the information domain, thereby ensuring the accuracy of real-time perception of cross-domain attack risks.
[0103] S14. Generate a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the attack cross-domain anomaly identification result; wherein, the power system topology map can be understood as a topology relationship map constructed based on the electrical connection relationship data between the physical domain devices involved in the attack cross-domain anomaly identification result, according to the actual physical connection sequence between the circuit breaker, busbar, and transformer, and the communication network topology map can be understood as a topology relationship map constructed based on the communication network link data between the information domain devices involved in the attack cross-domain anomaly identification result, according to the communication port mapping relationship between the monitoring host, network switch, and protection device. The corresponding cross-domain attack chain can be understood as a cross-domain attack link obtained by analyzing the power system topology map and the communication network topology map; specifically, the steps of generating a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the attack cross-domain anomaly identification result include:
[0104] A node mapping relationship matrix is established between the physical domain nodes in the power system topology diagram and the communication domain nodes in the communication network topology diagram; wherein the node mapping relationship matrix can be understood as a cross-domain node mapping relationship matrix constructed based on the association relationship between the physical domain nodes and the information domain nodes in the attack cross-domain anomaly identification results to reflect the correspondence between the physical devices and the communication devices. The matrix elements are 0 or 1, and 1 indicates that the corresponding physical domain node and the information domain node have an association relationship; for example, taking the transformer protection device as an example, the main transformer is the physical domain node, and its corresponding protection device is the communication domain node. The corresponding positions of the two in the mapping matrix have a value of one, indicating that they have a direct mapping relationship. Through this mapping relationship, the cross-domain device can be accurately located.
[0105] The power system topology map and the communication network topology map are traversed for abnormal nodes by a depth-first search algorithm, and the physical adjacent nodes and communication adjacent nodes of each abnormal node are matched and analyzed according to the node mapping relationship matrix to generate an abnormal propagation node table; wherein, the abnormal propagation node table can be understood as being constructed by the physical adjacent nodes directly connected to the abnormal node through the same circuit breaker in the power system topology map, or the communication adjacent nodes directly connected to the abnormal node through the same switch in the communication network topology map, including the physical domain node numbers with adjacent relationships and the corresponding physical connection relationships, as well as the communication domain node numbers with adjacent relationships and the corresponding communication link relationships. The corresponding acquisition process can be understood as first using a depth-first search algorithm to traverse the devices with cross-domain anomalies, and for each abnormal node, obtaining the adjacent nodes directly connected through the circuit breaker in the power topology map, and obtaining the adjacent nodes directly connected through the same switch in the communication network map. If the adjacent nodes have a corresponding relationship in the node mapping relationship matrix, the physical domain node number, communication domain node number, physical connection relationship, and communication link relationship are recorded to generate an abnormal propagation node table; it should be noted that the adjacent node traversal process distinguishes between physical connection and communication connection relationships. Taking the busbar protection device as an example, the adjacent nodes directly connected to the bus in the physical domain include circuit breakers and transformers, and the adjacent nodes directly connected to the protection device in the information domain include network switches and monitoring hosts. When the busbar protection device is attacked, the affected directly adjacent devices in the two domains can be obtained at the same time.
[0106] The Dykstra algorithm is used to calculate the shortest propagation paths of each abnormal node pair in the abnormal propagation node table in the power system topology map and the communication network topology map, and the propagation impact of each propagation shortest path is evaluated based on the link bandwidth utilization between communication nodes, the circuit breaker status quantity between physical nodes, and the protection device action signal, and a cascade influence path is generated based on the corresponding impact evaluation results; the specific cascade influence path acquisition process can be understood as for the node pairs recorded in the abnormal propagation node table, the shortest path between nodes is calculated respectively in the power system topology map and the communication network topology map by the Dykstra algorithm, and the propagation impact evaluation of the shortest path between nodes is performed by combining the link bandwidth utilization between communication nodes, the circuit breaker status quantity between physical nodes, and the protection device action signal. The shortest path between nodes whose obtained propagation impact evaluation value exceeds a preset threshold is determined to be a cascade influence path. It should be noted that the shortest path calculation takes into account the actual connection relationship between devices. Taking the switchgear as an example, the circuit breakers in the physical domain are connected in series through the busbar, and the protection devices in the information domain are connected in cascade through switches. When the switchgear protection device is attacked and causes the circuit breaker to malfunction, the direction of fault propagation can be determined by calculating the shortest path; the cascade impact path analysis combines multiple dimensional indicators. Taking the substation monitoring network as an example, the switch port bandwidth utilization rate exceeds 80%, indicating link congestion, the circuit breaker changes from the closed position to the open position, indicating abnormal equipment operation, and the protection device frequently issues tripping commands, indicating abnormal protection logic. The comprehensive evaluation of multiple abnormal indicators shows that the impact of the attack continues to expand.
[0107] According to the preset path priority index, the path priority evaluation is performed on each cascade impact path respectively, and the cascade impact paths are sorted according to the corresponding priority evaluation results to generate the cross-domain attack chain; wherein, the preset path priority index includes node connection density, node bandwidth occupancy, node protection configuration and node communication delay; the corresponding cross-domain attack chain can be understood as a cross-domain attack chain obtained by analyzing the cascade impact path using a path sorting criterion designed based on the preset path priority index, and the cross-domain attack chain includes the source node, destination node and path priority of each propagation path. It should be noted that the path priority ranking reflects the degree of impact between devices. Transformers are key equipment, and the communication delay between the circuit breakers and protection devices connected to them is less than ten milliseconds, the bandwidth occupancy rate is less than 20%, and the connection density between nodes is high. Once attacked, it is easy to form a chain reaction. Such propagation paths often have higher priorities; the density of node connection reflects the strength of association between devices. The busbar circuit breaker is connected to two busbars at the same time, and the busbar protection device communicates with multiple measurement and control units. Once such closely connected devices are affected by an attack, it is more likely to cause fault spread, and they should be paid special attention to in the propagation path analysis; and the communication link performance indicators affect the attack propagation speed. When the link bandwidth between network devices is sufficient, the communication delay is small, and the packet loss rate is low, the attack impact propagates faster. When the link performance is limited, the attack impact propagation is hindered. This difference directly affects the formation of cascade paths.
[0108] This embodiment uses a graph theory algorithm to calculate the attack propagation path in the physical domain and information domain, obtains the node where the abnormal event occurs and its adjacent nodes within one hop, and analyzes the cascade impact path between the denial of service attack target device and the power grid monitoring and control equipment. The key path from the source node to the destination node is obtained to form a cross-domain attack chain, which can effectively ensure the reliability of attack propagation path identification and provide strong support for the subsequent accurate tracing of cross-domain attacks.
[0109] S15. Identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack tracing maps based on the key nodes and the key risk propagation paths; wherein key nodes can be understood as important attack propagation nodes obtained by performing node evaluation based on node degree and betweenness centrality; corresponding key risk propagation paths can be understood as high-risk propagation paths obtained by performing significance evaluation on propagation paths constructed by key nodes; specifically, the steps of identifying key nodes and key risk propagation paths in the cross-domain attack chain, and generating corresponding attack tracing maps based on the key nodes and the key risk propagation paths include:
[0110] The node connection relationship data of the cross-domain attack chain is obtained, and the node degree and betweenness centrality index of each node are calculated based on the node connection relationship data, and the key nodes are screened based on the node degree and betweenness centrality index; wherein, the calculation method of the node degree and betweenness centrality index can be implemented with reference to the relevant existing technology and will not be repeated here; the screening process of the corresponding key nodes can be understood as judging whether the node degree and betweenness centrality index of each node meet the corresponding index threshold conditions, and the nodes that meet the conditions are used as key nodes, for example, nodes with a node degree greater than four and an betweenness centrality greater than 0.3 are marked as key nodes and a corresponding node importance identifier including the node number, node degree and betweenness centrality index value is generated.
[0111] Based on the inter-node connectivity of all key nodes, corresponding propagation paths are constructed, and each propagation path is risk-assessed based on a preset path significance index to obtain a key risk propagation path. The preset path significance index can be understood as an indicator used to analyze path characteristics, preferably including the number of key nodes, the connection strength between path nodes, and the number of nodes affected by the path. When the number of key nodes included in a propagation path exceeds 30% of the total number of nodes, the connection strength between path nodes is greater than 0.5, and the number of nodes affected by the path exceeds three, the propagation path is considered to have a high risk and can be used as a key risk propagation path. A corresponding propagation path identifier is generated, including the path starting point, path end point, and path significance value. For example, taking the main transformer fault propagation link as an example, the path contains three key nodes: the main transformer protection device, the circuit breaker protection device, and the busbar protection device, accounting for 40% of the total number of nodes. The nodes are directly connected through the measurement and control network, and the connection strength is 0.8. The impact spreads to four adjacent devices, so this path is a key risk propagation path.
[0112] Based on the force-directed layout algorithm, each key risk propagation path is visually laid out to generate a corresponding risk propagation layout plan; the execution process of the force-directed layout algorithm can be understood as realizing node distribution through mechanical principles, with the shortest path length between nodes being three hops and the distance between devices being set to three hundred pixels. Adjacent nodes are brought close by applying gravity, while repulsion is applied to prevent node overlap, until the node positions reach a force balance state, and an arrow is drawn every hundred pixels on the connecting line to indicate the direction of attack propagation; the corresponding risk propagation layout plan acquisition process can be understood as performing force-directed layout operations based on the propagation path identification of each key risk propagation path, setting the node spacing according to the shortest path length between nodes in the propagation link, determining the node coordinate position by balancing the node gravity and repulsion, and drawing arrows at fixed distances on the connecting line between nodes to indicate the propagation direction, and finally generating the required layout plan including node position, node spacing, and connecting line direction. It should be noted that the force-guided layout makes full use of spatial information when positioning nodes. For example, core nodes such as hosts and switches in the substation monitoring network are located in the center of the layout. Nodes connected to multiple devices gain greater gravitational force and automatically gather toward the center, while edge nodes are subject to less gravitational force and are naturally distributed on the periphery, forming a hierarchical layout structure.
[0113] According to the risk propagation layout scheme and the preset graphical annotation rules, the corresponding key risk propagation paths are annotated to generate the attack tracing map; the preset graphical annotation rules include coloring rules and icon sizes of different types of nodes, and pixel setting rules for connecting nodes based on the degree of influence between nodes; the corresponding attack tracing map can be understood as a tracing map obtained by coloring the nodes in the layout scheme, setting the icon size value according to the node type, and setting the connection thickness value according to the degree of influence between nodes; specifically, the attack tracing map generation process can be understood as a tracing map obtained by coloring the nodes in the layout scheme, setting the icon size value according to the node type, and setting the connection thickness value according to the degree of influence between nodes. The nodes are colored, and the attack source node at the starting point of the link is marked red and the icon size is set to twice the standard size. The intermediate propagation node is marked yellow and the icon size is set to the standard size. The affected node at the end is marked orange and the icon size is set to 1.5 times the standard size. The propagation direction arrow is marked on the connection line and the line thickness is set according to the degree of influence between the nodes. For example, the influence between directly connected devices is strong, and the connection thickness is set to four pixels. The influence between indirectly connected devices is weakened, and the connection thickness is reduced to two pixels, etc., which facilitates the rapid identification of key propagation paths and finally obtains a traceability map including the required node color, icon size, and connection thickness. It should be noted that this embodiment displays the attack propagation process through a node coloring scheme, intuitively presents the attack chain with color changes, and effectively enhances the visual impact by changing the size of different node icons, making the attack traceability map more intuitive in displaying the attack path.
[0114] This embodiment identifies key nodes and propagation paths in the cross-domain attack chain, forms a visual presentation, and generates an attack tracing map. The attacked source node, the affected destination node, and the intermediate propagation path are identified in the map, which can highlight the cascading impact chain from the denial of service attack target device to the physical domain anomaly, providing intuitive decision support for subsequent security analysis.
[0115] S16. Based on the vulnerability information of key nodes in the attack tracing graph, iteratively generate active defense rules based on a game theory algorithm and a reinforcement learning algorithm, and distribute them to the corresponding physical domain nodes and information domain nodes; wherein the vulnerability information includes the degree of node software version lag, the number of communication protocol vulnerabilities, and the patch update status; specifically, the step of iteratively generating active defense rules based on the vulnerability information using a game theory algorithm and a reinforcement learning algorithm includes:
[0116] The vulnerability information of each key node is subjected to a weighted comprehensive analysis to obtain the corresponding node vulnerability score, and the key nodes whose node vulnerability scores exceed the preset score threshold are identified as high-risk nodes; wherein, the weighted comprehensive analysis can be understood as the process of converting each vulnerability information into a corresponding indicator score value, and performing weighted summation according to the corresponding preset weight coefficient to obtain the corresponding node vulnerability score; the corresponding preset score threshold can be set according to actual needs, and the key nodes whose node vulnerability scores exceed the preset score threshold are identified as high-risk nodes, and the corresponding vulnerability identification including vulnerability level, attack difficulty coefficient and vulnerability score is added to them. For example, the operating software version of the main transformer protection device of a certain substation lags behind the latest version by two version cycles, has three known communication protocol vulnerabilities, and the security patch update lags for more than three months. The vulnerability score obtained through weighted calculation exceeds the high-risk threshold, and is identified as a high-risk node with a major security risk.
[0117] Based on the vulnerability identification of each high-risk node and a preset attack-defense game payoff matrix, multiple rounds of iterative calculations are performed using a non-zero-sum game algorithm to generate an optimal defense strategy. The preset attack-defense game payoff matrix can be understood as a payoff matrix suitable for attack-defense countermeasures against high-risk nodes, constructed based on the payoff value of the attacker gaining management privileges upon successful intrusion, the defender's loss value upon damaged equipment, the attacker's attack cost, and the defender's investment value. The corresponding optimal defense strategy can be understood as a profit-maximizing defense strategy obtained through multiple rounds of iterative calculations with profit maximization as the optimization goal. This optimal defense strategy includes information such as the protected nodes, protective measures, and payoff values.
[0118] Based on the optimal defense strategy, corresponding initial defense rules are generated. These initial defense rules can be understood as active defense measures, including port restriction rules, flow control rules, and electrical parameter adjustment rules, generated based on a three-parameter protection table established based on the optimal defense strategy, including port connection limit, bandwidth limit, and current setting value limit. To ensure the effectiveness of these active defense measures, this embodiment preferably simulates and verifies the effectiveness of these active defense measures, and dynamically adjusts the relevant rule parameters based on the verification results.
[0119] According to the preset rule evaluation indicators, the defense effect simulation evaluation of the initial defense rules is performed based on the reinforcement learning algorithm, and according to the corresponding evaluation results, the initial defense rules are optimized to generate the active defense rules; wherein, the preset rule evaluation indicators include the percentage decrease in attack success rate after rule execution, the percentage increase in equipment operation stability, and the percentage decrease in business impact; in actual applications, the preset rule evaluation indicators can be used to construct a rule execution effect evaluation function, and it can be combined with the reinforcement learning algorithm to perform defense effect simulation evaluation, so as to iteratively optimize the initial defense rules until the expected optimized rules are obtained and used as the final active defense rules.
[0120] This embodiment identifies key nodes in the attack tracing map by obtaining vulnerability information of electrical equipment in the physical domain and network equipment in the information domain, and automatically analyzes attacker strategies through a game theory algorithm combined with a reinforcement learning algorithm to learn the optimal strategy of the defender and form targeted active defense measures. While accurately perceiving cross-domain attack risks in real time, it implements adaptive defense protection in a timely manner, effectively improving the power system's ability to resist complex network attacks.
[0121] In addition, after the active defense measures are issued to the corresponding physical domain electrical equipment and information domain network equipment, the device parameters can be remotely modified through the relevant device configuration management module, so that the defense strategy can automatically take effect locally, and the policy execution effect can be monitored and evaluated, forming a closed-loop adaptive defense adjustment mechanism. The specific process is as follows: the defense rule content is obtained from the active defense measures, and the defense rule content is converted into a standard device configuration instruction containing attributes such as rule type code, instruction operation code, parameter value code and timestamp; an execution queue is constructed based on the standard device configuration instruction, and an execution sequence is generated according to the numerical order of the device area priority, and a corresponding execution status identifier is generated according to the execution sequence; the execution status identifier is evaluated using a rule evaluation matrix, and the corresponding execution quality score is calculated based on the three indicators of response time, effective time, and adjustment range; the execution quality score is monitored using a threshold-based adaptive mechanism, and the instructions are optimized based on the three indicators of configuration delivery success rate, rule effectiveness accuracy, and attack protection rate to achieve adaptive defense closed-loop control.
[0122] The embodiment of the present application identifies abnormal events by comprehensively utilizing physical domain node operation monitoring data and information domain node traffic data, and constructs a complete attack tracing map by correlating abnormal events in different domains and identifying cross-domain abnormal propagation paths, and generates active defense rules for adaptive security defense through vulnerability analysis of key nodes. This intelligent protection method of automatic detection, analysis and defense effectively solves the application defects of existing power system security threat defense that is limited to single-domain threat monitoring and protection, cannot realize cross-domain abnormal event correlation analysis, and is difficult to cope with complex attack scenarios of cross-domain collaborative attacks. It can not only accurately identify complex cross-domain attack risks in real time, but also carry out reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, improving the power system's ability to resist complex network attacks, and providing effective technical support for ensuring safe and stable operation of the power grid.
[0123] It should be noted that although the steps in the above flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders.
[0124] In one embodiment, Figure 2 As shown, a detection and defense system for cross-domain threats in a power system is provided, the system comprising:
[0125] Physical domain anomaly identification module 1 is used to obtain operation monitoring data of each physical domain node in the target power grid area, and identify state anomalies based on the operation monitoring data to obtain corresponding physical domain anomaly identification results; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results and regional fault levels;
[0126] An information domain attack identification module 2 is configured to obtain network traffic data of each information domain node in the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results;
[0127] Cross-domain anomaly analysis module 3 is used to perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results;
[0128] Attack chain analysis module 4, configured to generate a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack;
[0129] A traceability graph construction module 5 is used to identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack traceability graphs based on the key nodes and the key risk propagation paths;
[0130] The attack defense processing module 6 is used to iteratively generate active defense rules based on the vulnerability information of key nodes in the attack tracing map and the game theory algorithm and reinforcement learning algorithm, and send them to the corresponding physical domain nodes and information domain nodes.
[0131] For the specific definition of the detection and defense system for cross-domain threats in the power system, please refer to the definition of the detection and defense method for cross-domain threats in the power system above. The corresponding technical effects can also be obtained equivalently, which will not be repeated here. Each module in the above-mentioned detection and defense system for cross-domain threats in the power system can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0132] In summary, the embodiments of the present invention provide a method and system for detecting and defending against cross-domain threats in a power system. The method for detecting and defending against cross-domain threats in a power system realizes obtaining operation monitoring data of each physical domain node in a target power grid area, performing state anomaly identification based on the operation monitoring data to obtain a physical domain anomaly identification result including an abnormal measurement identification result, an abnormal switch identification result, a faulty equipment identification result, and a regional fault level, obtaining network traffic data of each information domain node in the target power grid area, performing denial of service attack identification based on the network traffic data to obtain a corresponding information domain attack identification result, performing abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain an attack cross-domain anomaly identification result, and then generating a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the attack cross-domain anomaly identification result, and identifying key nodes and key risk propagation paths in the cross-domain attack chain. According to key nodes and key risk propagation paths, corresponding attack tracing maps are generated. According to the vulnerability information of key nodes in the attack tracing map, active defense rules are iteratively generated based on game theory algorithms and reinforcement learning algorithms and distributed to the corresponding physical domain nodes and information domain nodes. This technical solution identifies abnormal events by comprehensively utilizing physical domain node operation monitoring data and information domain node traffic data, and constructs a complete attack tracing map by performing correlation analysis on abnormal events in different domains and identifying cross-domain abnormal propagation paths. In addition, active defense rules are generated by combining vulnerability analysis of key nodes for adaptive security defense. This intelligent protection method of automatic detection, analysis and defense can not only accurately identify complex cross-domain attack risks in real time, but also carry out reliable adaptive defense in a timely manner, thereby effectively improving the comprehensiveness and reliability of power system security protection, improving the power system's ability to resist complex network attacks, and providing effective technical support for ensuring the safe and stable operation of the power grid.
[0133] Each embodiment in this specification is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. It should be noted that the various technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0134] The above-described embodiments merely represent several preferred implementations of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art could make several improvements and substitutions without departing from the technical principles of the present invention, and these improvements and substitutions should also be considered within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be based on the scope of protection of the claims.
Claims
1. A method for detecting and defending against cross-domain threats in a power system, characterized in that: The method comprises the following steps: Acquire operation monitoring data of each physical domain node in the target power grid area, and perform state anomaly identification based on the operation monitoring data to obtain corresponding physical domain anomaly identification results; Obtaining network traffic data of each information domain node in the target power grid area, and performing denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results; Perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results; According to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack, a corresponding cross-domain attack chain is generated based on a graph theory algorithm; Identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack tracing maps based on the key nodes and the key risk propagation paths; Based on the vulnerability information of key nodes in the attack tracing graph, active defense rules are iteratively generated based on game theory algorithms and reinforcement learning algorithms and sent to the corresponding physical domain nodes and information domain nodes; The step of performing abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain an attack cross-domain anomaly identification result includes: Compare the anomaly occurrence timestamps of each physical domain anomaly identification result with each information domain attack identification result, and generate cross-domain anomaly association data based on anomaly events in which the nodes belong to the same physical area and the anomaly occurrence timestamp deviation is less than the preset fault response time. The cross-domain anomaly association data includes the physical domain node number, information domain node number, time correlation, spatial correlation, and correlation timestamp corresponding to each cross-domain anomaly event. Based on the cross-domain anomaly association data and the physical connection relationship and communication link relationship of the equipment in the target power grid area, a corresponding electrical primary equipment topology map and a secondary equipment communication topology map are constructed, and abnormal nodes whose distance between the electrical primary equipment topology map and the secondary equipment communication topology map is less than a preset connection layer threshold are obtained to generate corresponding association group data; the association group data includes a physical domain device list, an information domain device list, the physical distance between devices, the number of communication link hops, and the degree of spatial association; Perform feature analysis on abnormal events in the associated group data according to a preset feature matching table, and identify the severity of abnormal events using a preset feature combination counting judgment principle to obtain a high-level abnormal group; Establishing a device connectivity graph corresponding to the high-level anomaly group, and obtaining a corresponding group diffusion risk value based on the degree of connection between devices in the device connectivity graph; When the group diffusion risk value exceeds a preset warning value, the attack cross-domain anomaly identification result is generated; the attack cross-domain anomaly identification result includes a list of risky devices, a diffusion warning level, and a warning release time.
2. The method for detecting and defending against cross-domain threats in a power system according to claim 1, wherein: The operation monitoring data includes operation parameter information and switch protection information; the operation parameter information includes voltage amplitude, current amplitude, voltage phase angle, current phase angle, voltage frequency, and current frequency; the switch protection information includes equipment switch status and switch open / close status information; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results, and regional fault levels; The step of identifying a state anomaly based on the operation monitoring data to obtain a corresponding physical domain anomaly identification result includes: Compare each operating parameter information with the corresponding preset parameter safety threshold range to obtain an abnormal measurement identification result; the abnormal measurement identification result includes the abnormal operating parameter and the corresponding abnormal data type and the abnormal occurrence timestamp; Comparing the switch opening and closing state information with the corresponding device switch state to obtain an abnormal switch identification result; the abnormal switch identification result includes the state abnormality type corresponding to each abnormal switch identification number and the state abnormality occurrence timestamp; The abnormal switch area is located according to the abnormal switch identification result and the preset switch bus association code table to obtain the corresponding fault device identification result; the fault device identification result includes the fault area code and fault timestamp corresponding to each fault switch identifier; According to the preset neural network model, feature analysis is performed on the abnormal measurement identification results in the fault area corresponding to the identification results of each faulty device to generate a corresponding feature abnormality weight matrix, and the fault area abnormality level is determined based on the feature abnormality weight matrix to obtain the corresponding regional fault level.
3. The method for detecting and defending against cross-domain threats in a power system according to claim 1, wherein: The information domain attack identification result includes the denial of service attack identification result of each target attack port and the corresponding attack level; The step of performing denial of service attack identification based on the network traffic data to obtain a corresponding information domain attack identification result includes: Performing centralized identification of abnormal traffic based on the network traffic data to obtain a port traffic aggregation identification result; the network traffic data includes the number of network connections and bandwidth utilization; According to the port traffic aggregation identification result, the inflow traffic monitoring data of each traffic aggregation port is obtained, and the denial of service attack is identified based on the inflow traffic monitoring data to obtain the corresponding information domain attack identification result.
4. The method for detecting and defending against cross-domain threats in a power system according to claim 3, wherein: The step of performing centralized identification of abnormal traffic based on the network traffic data to obtain a port traffic aggregation identification result includes: Comparing each network traffic data with the corresponding preset rated threshold range to obtain traffic anomaly information; the traffic anomaly information includes the number of abnormal connections, bandwidth utilization and the time when the anomaly occurred; According to the traffic anomaly information, relevant port traffic data is obtained, and trend anomaly identification is performed on the relevant port traffic data to obtain corresponding port anomaly identification results; the port anomaly identification results include traffic data corresponding to each abnormal port number; According to a preset port traffic judgment matrix, each abnormal port is classified into a traffic abnormality level to obtain a corresponding port traffic abnormality classification result; the preset port traffic judgment matrix is constructed based on preset level judgment indicators; the preset level judgment indicators include port traffic fluctuation amplitude, traffic duration and traffic growth rate; According to the abnormal classification results of each port traffic, the corresponding adjacent port traffic data is obtained, and abnormal traffic aggregation analysis is performed based on the adjacent port traffic data to obtain the port traffic aggregation identification result; the port traffic aggregation identification result includes the number of ports in the group corresponding to each traffic aggregation port group and the direction of the aggregated traffic.
5. The method for detecting and defending against cross-domain threats in a power system according to claim 3, wherein: The step of identifying a denial of service attack based on the inflow traffic monitoring data to obtain a corresponding information domain attack identification result comprises: Determine whether the inflow traffic monitoring data meets a preset traffic aggregation identification condition; if so, determine that the corresponding traffic aggregation port is a traffic flood attack port, and obtain a set of source addresses of data packets with the traffic flood attack port as the destination port; the preset traffic aggregation identification condition is that the inflow traffic exceeds a preset multiple of the port baseline traffic and lasts for more than a preset time; Distributed attack identification, half-open connection identification, and malformed packet identification are performed based on the source address connection data records corresponding to the data packet source address set, and attack classification processing is performed on the obtained abnormal feature identification results based on a preset machine learning model to generate the denial of service attack identification results; the denial of service attack identification results include attack source characteristics, attack type, attack duration, and detection timestamp; Performing source address dispersion analysis based on the data packet source address set and a preset dispersion identification condition to generate a corresponding source address dispersion identifier; the preset dispersion identification condition is that the minimum physical distance between addresses is greater than a preset distance threshold and the access ratio of each source address is less than a preset ratio; the source address dispersion identifier includes the access record, address location and access timestamp of each source address; According to the transmission control protocol specification and the preset inspection field, the inflow data packets of the traffic flood attack port are counted for abnormalities, and when the proportion of abnormal data packets exceeds the abnormal percentage threshold, a corresponding connection abnormality identification result is generated; the preset inspection field includes the handshake packet flag sequence, the packet header length and the checksum; the connection abnormality identification result includes the number of abnormal packets, the total number of inflow data packets and the inspection time; The traffic flood attack identifier, source address dispersion identifier and connection anomaly identification result of the traffic flood attack port are comprehensively analyzed to obtain a comprehensive score of the attack behavior, and the corresponding attack level is obtained based on the comprehensive score of the attack behavior; the traffic flood attack identifier includes the target port, inflow traffic, baseline traffic, attack start time and attack duration.
6. The method for detecting and defending against cross-domain threats in a power system according to claim 1, wherein: The step of generating a corresponding cross-domain attack chain based on a graph theory algorithm according to the power system topology map and the communication network topology map corresponding to the cross-domain anomaly identification result of the attack comprises: Establishing a node mapping relationship matrix between physical domain nodes in the power system topology diagram and communication domain nodes in the communication network topology diagram; Perform abnormal node traversal on the power system topology map and the communication network topology map using a depth-first search algorithm, and perform matching analysis on the physical adjacent nodes and communication adjacent nodes of each abnormal node according to the node mapping relationship matrix to generate an abnormal propagation node table; The Dykstra algorithm is used to calculate the shortest propagation paths of each abnormal node in the abnormal propagation node table in the power system topology diagram and the communication network topology diagram, and a propagation impact assessment is performed on each shortest propagation path based on the link bandwidth utilization between the communication nodes and the state quantity of the circuit breaker and the protection device action signal between the physical nodes, and a cascade impact path is generated according to the corresponding impact assessment results. According to the preset path priority index, the path priority of each cascade impact path is evaluated respectively, and the cascade impact paths are sorted according to the corresponding priority evaluation results to generate the cross-domain attack chain; the preset path priority index includes node connection density, node bandwidth occupancy, node protection configuration and node communication delay; the cross-domain attack chain includes the source node, destination node and path priority corresponding to each propagation path.
7. The method for detecting and defending against cross-domain threats in a power system according to claim 1, wherein: The steps of identifying key nodes and key risk propagation paths in the cross-domain attack chain and generating corresponding attack tracing graphs based on the key nodes and the key risk propagation paths include: Obtaining node connection relationship data of the cross-domain attack chain, and calculating the node degree and betweenness centrality index of each node based on the node connection relationship data, and screening key nodes based on the node degree and betweenness centrality index; Based on the inter-node connection relationship of all key nodes, the corresponding propagation path is constructed, and the risk of each propagation path is evaluated according to the preset path significance index to obtain the key risk propagation path; Based on the force-directed layout algorithm, each key risk propagation path is visually laid out to generate the corresponding risk propagation layout plan; According to the risk propagation layout plan and preset graphical annotation rules, the corresponding key risk propagation paths are annotated to generate the attack tracing map; the preset graphical annotation rules include coloring rules and icon sizes for different types of nodes, and pixel setting rules for node-to-node connections based on the degree of influence between nodes.
8. The method for detecting and defending against cross-domain threats in a power system according to claim 1, wherein: The vulnerability information includes the degree of node software version lag, the number of communication protocol vulnerabilities and patch update status; The step of iteratively generating active defense rules based on the vulnerability information through a game theory algorithm and a reinforcement learning algorithm includes: Perform weighted comprehensive analysis on the vulnerability information of each key node to obtain the corresponding node vulnerability score, and identify the key nodes whose node vulnerability scores exceed a preset score threshold as high-risk nodes; Based on the vulnerability identification of each high-risk node and the preset attack and defense game payoff matrix, multiple rounds of game iterative calculations are performed based on a non-zero-sum game algorithm to generate the optimal defense strategy; the vulnerability identification includes the vulnerability level, attack difficulty coefficient and node vulnerability score; Generate corresponding initial defense rules according to the optimal defense strategy; the initial defense rules include port restriction rules, flow control rules and electrical parameter adjustment rules; According to the preset rule evaluation indicators, the defense effect simulation evaluation of the initial defense rules is performed based on the reinforcement learning algorithm, and according to the corresponding evaluation results, the initial defense rules are optimized to generate the active defense rules; the preset rule evaluation indicators include the percentage decrease in attack success rate after the rule is executed, the percentage increase in equipment operation stability, and the percentage decrease in business impact.
9. A detection and defense system for cross-domain threats in power systems, characterized in that: The method for detecting and defending against cross-domain threats in a power system according to claim 1 is applied, wherein the system comprises: A physical domain anomaly identification module is used to obtain operational monitoring data of each physical domain node within the target power grid area, and identify state anomalies based on the operational monitoring data to obtain corresponding physical domain anomaly identification results; the physical domain anomaly identification results include abnormal measurement identification results, abnormal switch identification results, faulty equipment identification results, and regional fault levels; An information domain attack identification module is used to obtain network traffic data of each information domain node in the target power grid area, and perform denial of service attack identification based on the network traffic data to obtain corresponding information domain attack identification results; The cross-domain anomaly analysis module is used to perform abnormal event correlation analysis on all physical domain anomaly identification results and all information domain attack identification results to obtain cross-domain attack anomaly identification results; An attack chain analysis module is configured to generate a corresponding cross-domain attack chain based on a graph theory algorithm according to a power system topology map and a communication network topology map corresponding to the cross-domain anomaly identification result of the attack; A traceability graph construction module is used to identify key nodes and key risk propagation paths in the cross-domain attack chain, and generate corresponding attack traceability graphs based on the key nodes and the key risk propagation paths; The attack defense processing module is used to iteratively generate active defense rules based on the vulnerability information of key nodes in the attack tracing map and the game theory algorithm and reinforcement learning algorithm, and send them to the corresponding physical domain nodes and information domain nodes.
Citation Information
Patent Citations
Attack tracing method based on multi-dimensional information
CN115664703A
Attack path prediction method and device based on distributed energy system
CN117579398A