Attack type prediction method and device of power system, medium and equipment

By building a hierarchical support vector machine model based on decision tree, using Gaussian kernel function and penalty coefficient optimization, the power system network log data is classified layer by layer, and the problem of inability to accurately predict attack types in the existing technology is solved, the detection efficiency and accuracy are improved, the false alarm rate is reduced, and the security and stability of the power system is ensured.

CN120238359APending Publication Date: 2025-07-01GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510468026.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The prior art cannot accurately predict the attack type of power system based on the support vector machine, and it is difficult to identify unknown threats, have high false alarms and are unable to adapt to dynamic network environments.

Method used

A hierarchical support vector machine model based on decision tree is constructed, and the power system network log data is extracted and classified through a binary tree structure. The Gaussian kernel function and penalty coefficient optimization model are used to classify log data layer by layer to identify attack types.

Benefits of technology

It significantly improves the detection efficiency and accuracy of network security threats in power system, reduces the false alarm and missed alarm rates, ensures the stability and adaptability of the model in complex network environments, and provides strong guarantees for the safe operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238359A_ABST
    Figure CN120238359A_ABST
Patent Text Reader

Abstract

The invention discloses an attack type prediction method and device of a power system, a medium and equipment. According to the method, the network log data of the power system in the preset time period are acquired, the key features are extracted from the network log data to form the feature vector, and then the feature vector is input into the hierarchical support vector machine model based on the decision-making tree, so that the attack type in the future preset time period is predicted. According to the model, a decision tree is constructed based on a binary tree structure, and optimization training is performed on historical log data by replacing a preset kernel function and adjusting a penalty coefficient, so that high accuracy and strong generalization ability of the model in a complex network environment are ensured; the problem that the attack type of the power system cannot be accurately predicted according to the support vector machine in the prior art is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of attack type prediction of power systems, and in particular to a method, device, medium and equipment for predicting attack types of power systems. Background Art

[0002] With the development of information technology and intelligentization of power systems, the cyber security threats they face are becoming increasingly severe. As a key national infrastructure, the power system may cause serious consequences such as large-scale power outages when it is attacked by a cyber attack, threatening social order and national security. Traditional security protection measures mainly rely on rule-based matching methods such as firewalls and intrusion detection systems. These methods have certain effects in dealing with known attacks, but they are obviously insufficient in the face of new attacks and complex and changing network environments.

[0003] First, traditional methods have difficulty identifying unknown threats. They rely on predefined attack patterns and rules, and attackers can easily bypass detection by fine-tuning attack features or adopting new attack techniques. Second, traditional methods have high false positive and false negative rates. Due to the complexity of network traffic and behavior, static rules cannot accurately distinguish between normal and abnormal behavior, and slight fluctuations in the network environment may cause a large number of false positives or false negatives. Finally, traditional methods cannot adapt to dynamic network environments. In cloud environments or containerized environments, IP addresses, ports, and application configurations change frequently, and detection methods based on static rules are difficult to adjust in real time, resulting in reduced detection effectiveness.

[0004] In recent years, machine learning technology has gradually emerged in the field of network security, providing new ideas for power system log analysis. As a supervised learning method, support vector machine (SVM) is good at handling high-dimensional data classification and anomaly detection problems, and is very suitable for anomaly detection in the field of power system network security. However, a single SVM model still has certain limitations when facing various attack behaviors in power system networks. These limitations make it impossible for existing technologies to accurately predict the types of attacks on power systems based on support vector machines. Summary of the invention

[0005] The present invention provides a method, device, medium and equipment for predicting attack types of a power system, so as to solve the problem in the prior art that the attack types of the power system cannot be accurately predicted based on a support vector machine.

[0006] In a first aspect, the present application provides a method for predicting attack types of a power system, comprising:

[0007] Obtain network log data of the power system for a preset time period;

[0008] Performing feature extraction on the network log data to obtain a feature vector;

[0009] Input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the prediction result of the attack type of the network log data in a preset future time period;

[0010] Among them, the hierarchical support vector machine model constructs a decision tree according to a binary tree structure, and after training on a historical log data training set based on a support vector machine on the decision tree, it is optimized on a historical log data test set according to a replaced preset kernel function and penalty coefficient.

[0011] This application obtains the power system network log data within a preset time period, extracts its key features to form a feature vector, and then uses a hierarchical support vector machine model based on a decision tree to predict the attack type of the network log data. This model constructs a decision tree according to a binary tree structure, and is trained and optimized on historical log data. In particular, the accuracy and generalization ability of the model are improved by replacing the preset kernel function and adjusting the penalty coefficient. Through this technical means, this application can effectively overcome the defects of traditional methods that are difficult to identify unknown threats, have a high false alarm and missed alarm rate, and cannot adapt to dynamic network environments. The hierarchical support vector machine model can accurately classify log data layer by layer, quickly identify normal behaviors and various attack behaviors, and significantly improve the detection efficiency and accuracy of power system network security threats. At the same time, the optimization process of the model ensures its stability and adaptability in complex network environments, providing a strong guarantee for the safe operation of the power system. This application effectively solves the problem that the prior art cannot accurately predict the attack type of the power system according to the support vector machine.

[0012] As a preferred embodiment of the first aspect, the hierarchical support vector machine model constructs a decision tree according to a binary tree structure, and after training on a historical log data training set based on a support vector machine on the decision tree, it is optimized on a historical log data test set according to a replaced preset kernel function and penalty coefficient. Specifically:

[0013] Train the historical log data training set on the decision tree according to the preset Gaussian kernel function and penalty coefficient to obtain an initial support vector machine model;

[0014] Evaluate the prediction result of the initial support vector machine model according to the historical log data test set;

[0015] If the accuracy rate of the prediction result is less than a preset first threshold, replace the kernel function type and adjust the value of the preset penalty coefficient according to the cross-validation method, and then retrain on the historical log data training set according to the initial support vector machine model;

[0016] Among them, the types of kernel functions include polynomial kernel functions and linear kernel functions;

[0017] If the accuracy rate of the prediction result is greater than or equal to a preset first threshold, the initial support vector machine model is used as the preset hierarchical support vector machine model.

[0018] In this preferred embodiment, the present application realizes the efficient classification of power system network log data and the prediction of attack types by constructing a hierarchical support vector machine model based on a binary tree structure. The model is initially trained with a preset Gaussian kernel function and penalty coefficient, and the accuracy rate of the prediction result is evaluated on the test set. If the accuracy rate is lower than the preset threshold, the model will automatically change the type of kernel function (such as polynomial kernel function or linear kernel function), and adjust the penalty coefficient in combination with the cross-validation method, and retrain to optimize the performance. This process not only ensures the adaptability of the model under different data distributions, but also significantly improves the classification accuracy rate and generalization ability of the model by dynamically adjusting the kernel function and penalty coefficient. Finally, when the accuracy rate of the model reaches or exceeds the preset threshold, the training stops, and an optimized hierarchical support vector machine model is obtained. This optimization strategy enables the model to effectively cope with complex attack patterns in the power system network, significantly reduces the false alarm rate and missed alarm rate, improves the efficiency and reliability of power system network security detection, and provides a strong guarantee for the stable operation of the power system.

[0019] As a preferred embodiment of the first aspect, the inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs a prediction result of the attack type of the network log data in a preset future time period, specifically:

[0020] Input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model classifies the network log data layer by layer through a multi-layer decision tree structure;

[0021] According to the decision trees of each layer of the hierarchical support vector machine model, use the preset hyperplane function in each layer of decision tree to classify the network log data:

[0022] If the output value of the hyperplane function of the current layer is a preset first value, determine that the network log data belongs to the preset attack type of the current layer; if the output value of the hyperplane function of the current layer is a preset second value, input the network log data into the hyperplane function of the next layer of decision tree for further classification until the attack type of the network log data is determined or the bottom layer of the decision tree is reached.

[0023] The using the preset hyperplane function in each layer of decision tree to classify the network log data specifically is:

[0024] The first hyperplane function of the first decision tree of the hierarchical support vector machine model is as follows:

[0025]

[0026] In the formula, f (1) (x) is the first hyperplane function; λ i is each Lagrange multiplier obtained through iteration; b is the updated bias term; x i is the row vector of the standardized matrix X; x is the variable of the first hyperplane function; γ is the width parameter of the kernel function;

[0027] The second hyperplane function of the second decision tree of the hierarchical support vector machine model is as follows:

[0028]

[0029] In the formula, f (2) (x) is the second hyperplane function; λ i is each Lagrange multiplier obtained by the same method as the first-layer hyperplane function for the second-layer data; b is the updated bias term for the second layer; x i is the row vector of the standardized matrix formed by the second-layer data; x is the variable of the second hyperplane function; γ is the width parameter of the kernel function.

[0030] In this preferred embodiment, the present application inputs the feature vector into the hierarchical support vector machine model based on the decision tree, and uses its multi-layer decision tree structure to classify the network log data layer by layer, realizing the accurate prediction of the attack type within a preset future time period. In each layer of the decision tree, the log data is classified through a preset hyperplane function: if the output value is +1, it is directly determined that the data belongs to the preset attack type of the current layer; if the output value is -1, the data is passed to the next layer for further classification until its attack type is determined or the bottom layer of the decision tree is reached. This layer-by-layer classification method can effectively solve the problem that it is difficult for a single classifier in traditional methods to handle multi-category complex data, significantly improving the model's recognition ability and classification accuracy for different attack types. At the same time, the hierarchical structure reduces the computational complexity of the model and improves the prediction efficiency, enabling the system to quickly respond to potential network attacks and providing an efficient and reliable guarantee for the network security of the power system.

[0031] As a preferred embodiment of the first aspect, the network log data of the power system in the preset time period includes source IP type, source IP geographical location, number of login failures in the preset time period, number of source IPs logged in during the preset time period, login account, number of connection ports in the preset time period, number of data packets in the preset time period, number of file transfers in the preset time period, number of communications using uncommon protocols in the preset time period, number of unauthorized commands or uncommon system commands executed in the preset time period, and number of abnormal process startups or shutdowns in the preset time period.

[0032] In this preferred embodiment, the present application constructs a comprehensive and detailed feature system by selecting log data with multi-dimensional features such as source IP type, source IP geographical location, number of login failures, number of source IPs logged in, login account, number of connection ports, number of data packets, number of file transfers, number of communications using uncommon protocols, number of unauthorized commands executed, and number of abnormal process startups or shutdowns. These features can reflect the operating status and potential threats of the power system network from different angles. By using these features as inputs, the model can more accurately capture the differences between normal behavior and abnormal behavior, thereby achieving efficient identification and classification of attack types. The comprehensive use of such multi-dimensional features not only improves the adaptability of the model to complex network environments but also significantly enhances the detection ability for various known and unknown attack behaviors, reduces false alarm and missed alarm rates, and provides more comprehensive and accurate protection for the network security of the power system.

[0033] In the second aspect, the present application provides an attack type prediction device for a power system. The attack type prediction device for the power system includes: an acquisition module, a feature extraction module, and a prediction module;

[0034] The acquisition module is used to acquire the network log data of the power system in the preset time period;

[0035] The feature extraction module is used to extract features from the network log data to obtain a feature vector;

[0036] The prediction module is used to input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the attack type prediction result of the network log data in a future preset time period;

[0037] Wherein, the hierarchical support vector machine model is constructed by building a decision tree according to a binary tree structure, and after training on a historical log data training set based on a support vector machine on the decision tree, it is optimized according to a replaced preset kernel function and penalty coefficient on a historical log data test set.

[0038] This device uses three modules to divide the work and coordinate with each other, which can more accurately predict the types of attacks on the power system. This application obtains the power system network log data within a preset time period, extracts its key features to form a feature vector, and then uses a hierarchical support vector machine model based on a decision tree to predict the attack types of the network log data. This model constructs a decision tree through a binary tree structure, and trains and optimizes it on the historical log data. In particular, the accuracy and generalization ability of the model are improved by replacing the preset kernel function and adjusting the penalty coefficient. Through this technical means, this application can effectively overcome the defects of traditional methods, such as difficulty in identifying unknown threats, high false alarm and missed alarm rates, and inability to adapt to dynamic network environments. The hierarchical support vector machine model can accurately classify the log data layer by layer, quickly identify normal behaviors and various attack behaviors, and significantly improve the detection efficiency and accuracy of power system network security threats. At the same time, the optimization process of the model ensures its stability and adaptability in complex network environments, providing a strong guarantee for the safe operation of the power system. This application effectively solves the problem that the prior art cannot accurately predict the attack types on the power system according to the support vector machine.

[0039] As a preferred embodiment of the second aspect, the hierarchical support vector machine model constructs a decision tree according to a binary tree structure, and after training on the historical log data training set based on the support vector machine on the decision tree, it is optimized on the historical log data test set according to the replacement of the preset kernel function and the penalty coefficient. Specifically:

[0040] Train the historical log data training set on the decision tree according to the preset Gaussian kernel function and penalty coefficient to obtain an initial support vector machine model;

[0041] Evaluate the prediction results of the initial support vector machine model according to the historical log data test set;

[0042] If the accuracy rate of the prediction results is less than the preset first threshold, replace the kernel function type and adjust the value of the preset penalty coefficient according to the cross-validation method, and then retrain on the historical log data training set according to the initial support vector machine model;

[0043] Among them, the kernel function types include polynomial kernel function and linear kernel function;

[0044] If the accuracy rate of the prediction results is greater than or equal to the preset first threshold, use the initial support vector machine model as the preset hierarchical support vector machine model.

[0045] In this preferred embodiment, the present application realizes the efficient classification of power system network log data and the prediction of attack types by constructing a hierarchical support vector machine model based on a binary tree structure. The model is initially trained with a preset Gaussian kernel function and penalty coefficient, and the accuracy of the prediction results is evaluated on the test set. If the accuracy is lower than the preset threshold, the model will automatically change the type of kernel function (such as polynomial kernel function or linear kernel function), and adjust the penalty coefficient in combination with the cross-validation method, and retrain to optimize the performance. This process not only ensures the adaptability of the model under different data distributions, but also significantly improves the classification accuracy and generalization ability of the model by dynamically adjusting the kernel function and penalty coefficient. Finally, when the model accuracy reaches or exceeds the preset threshold, the training stops, and an optimized hierarchical support vector machine model is obtained. This optimization strategy enables the model to effectively cope with complex attack patterns in the power system network, significantly reduces the false alarm and miss rate, improves the efficiency and reliability of power system network security detection, and provides a strong guarantee for the stable operation of the power system.

[0046] As a preferred embodiment of the second aspect, the prediction module is configured to input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs a prediction result of the attack type of the network log data in a preset future time period, specifically:

[0047] Input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model classifies the network log data layer by layer through a multi-layer decision tree structure;

[0048] According to the decision trees of each layer of the hierarchical support vector machine model, use the preset hyperplane function in each layer of decision tree to classify the network log data:

[0049] If the output value of the hyperplane function of the current layer is a preset first value, determine that the network log data belongs to the preset attack type of the current layer; if the output value of the hyperplane function of the current layer is a preset second value, input the network log data into the hyperplane function of the next layer of decision tree for continued classification until the attack type of the network log data is determined or the bottom layer of the decision tree is reached.

[0050] In this preferred embodiment, the present application inputs the feature vector into a hierarchical support vector machine model based on a decision tree, and uses its multi-layer decision tree structure to classify the network log data layer by layer, achieving accurate prediction of the attack types within a preset future time period. In each layer of the decision tree, the log data is classified through a preset hyperplane function: if the output value is +1, it is directly determined that the data belongs to the preset attack type of the current layer; if the output value is -1, the data is passed to the next layer for further classification until its attack type is determined or the bottom layer of the decision tree is reached. This layer-by-layer classification method can effectively solve the problem that a single classifier in traditional methods is difficult to handle multi-category complex data, significantly improving the model's recognition ability and classification accuracy for different attack types. At the same time, the hierarchical structure reduces the computational complexity of the model and improves the prediction efficiency, enabling the system to quickly respond to potential network attacks and providing an efficient and reliable guarantee for the network security of the power system.

[0051] In a third aspect, the present application provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the attack type prediction method for a power system as described above. Its beneficial effects are the same as those of the attack type prediction method for a power system provided in the first aspect of the present application.

[0052] In a fourth aspect, the present application provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements any one of the attack type prediction methods for a power system as described in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 : A flowchart of an embodiment of the attack type prediction method for a power system provided by the present application;

[0054] Figure 2 : A flowchart of an embodiment of the soft margin support vector machine prediction based on a decision tree provided by the present application;

[0055] Figure 3 : A structural diagram of an embodiment of constructing a decision tree using a binary tree structure provided by the present application;

[0056] Figure 4 : A structural diagram of an embodiment of the functional module provided by the present application;

[0057] Figure 5 : A structural diagram of an embodiment of the attack type prediction device for a power system provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts belong to the scope of protection of the present invention.

[0059] Embodiment 1

[0060] Please refer to Figure 1 , which is a method for predicting the attack type of a power system provided by an embodiment of the present invention.

[0061] In this embodiment, the process of the method for predicting the attack type of the power system in this application is described in detail through steps S01 - S03.

[0062] The soft - margin support vector machine based on decision tree (ST - soft - margin - SVMs) adopted in this application is a classification method that combines decision tree and soft - margin support vector machine, and is often used to handle the classification complexity in multi - classification tasks. The basic idea of ST - soft - margin - SVMs is to split the original multi - class classification task into a series of binary classification problems by constructing the hierarchical structure of the decision tree, and each node is decided by a soft - margin SVM classifier. This method can not only improve the classification efficiency, but also reduce the training cost in multi - classification problems by using the decision tree structure. The overall process of this application is as Figure 2 shown;

[0063] The first step is to first determine the relevant features of the power system network security logs;

[0064] The second step is to collect various power system network attack - related log data and normal operation logs;

[0065] The third step is to label and classify the training set data and perform feature engineering;

[0066] The fourth step is to construct a decision tree structure. According to the class hierarchical relationship or feature similarity of the data, the multi - class data is divided into multiple hierarchical subsets. These subsets form a tree - like structure, and each subset contains multiple classes;

[0067] The fifth step is to train the SVM classifier models for each layer from the root node downwards of the decision tree. For the SVM classifier of each node, select the Gaussian kernel function and hyperparameters to ensure that the classifier can accurately divide the data at that node.

[0068] In the sixth step, the Sequential Minimal Optimization (SMO) algorithm is used to iteratively solve the Lagrange multipliers of the SVM model until all multipliers converge.

[0069] In the seventh step, the model construction is completed, and all parameter values of the model are determined, including the penalty coefficient, the initial value of the Lagrange multiplier, etc.

[0070] In the eighth step, the trained model is used to test the data in the test set. If the result does not meet the expectation, the penalty coefficient can be changed first. If the result still does not meet the expectation, the kernel function of the model can be changed to retrain the model until the test result meets the expectation.

[0071] Before model training, feature extraction needs to be carried out first. After feature extraction, feature encoding is required to numericalize the feature data. In this application, Label Encoding is used to assign a unique integer label to each different classification value.

[0072] S01: Obtain the network log data of the power system for a preset time period.

[0073] As a preferred embodiment of Embodiment 1, the obtaining of the network log data of the power system for a preset time period includes the source IP type (known device is 1, unknown device is 2), the geographical location of the source IP (within the province is 1, within the country is 2, abroad is 3), the number of login failures within a period of time, the number of source IPs logged in within a period of time, the login time period (normal working hours is 1, night is 2, special working hours is 3), the login account (no account is 0, system account is 1, administrator account is 2, other accounts is 3), the number of connection ports within a period of time, the number of data packets within a period of time, the number of file transfers within a period of time, the number of communications using uncommon protocols within a period of time, the number of non - authorized commands or uncommon system commands executed within a period of time, the number of abnormal process startups or shutdowns within a period of time, and so on. After feature selection and label encoding, the input training set of the model can be obtained. The "period of time" in the features can be selected as a time range such as one hour, 24 hours, etc.

[0074] In this preferred embodiment, the present application constructs a comprehensive and detailed feature system by selecting log data containing multi-dimensional features such as source IP type, source IP geographical location, number of login failures, number of source IPs for login, login accounts, number of connection ports, number of data packets, number of file transfers, number of communications using uncommon protocols, number of unauthorized commands executed, and number of abnormal process startups or shutdowns. These features can reflect the operating status and potential threats of the power system network from different perspectives. By using these features as inputs, the model can more accurately capture the differences between normal and abnormal behaviors, thereby achieving efficient identification and classification of attack types. The comprehensive use of such multi-dimensional features not only improves the adaptability of the model to complex network environments but also significantly enhances the detection ability for various known and unknown attack behaviors, reduces false alarm and missed alarm rates, and provides more comprehensive and accurate protection for the network security of the power system.

[0075] S02: Extract features from the network log data to obtain feature vectors.

[0076] As a preferred embodiment of Embodiment 1, the extracting features from the network log data to obtain feature vectors is specifically as follows:

[0077] Based on the above-obtained feature data, initial data is used to construct the following initial matrix A and label matrix Y:

[0078]

[0079] Y=(y1 y2…y N ) T

[0080] Where N represents the number of collected samples, that is, the rows of the matrix represent the collected log feature data. M represents the number of features, and the c value of the matrix represents the observed value of a certain sample feature collected; Y is the label matrix indicating the classification result to which the sample belongs, and y i ∈{+1, -1} represents the attack type of the i-th sample (when performing the first-layer classification of the decision tree, y i =+1 can be set to represent normal data, and y i =-1 represents attack data).

[0081] To handle the noise and fluctuations in the data, feature engineering is used to process the data in the initial matrix. To handle the missing values in the initial data and the impact brought by different dimensions, first, dimensionless processing is performed, that is, the following operation is performed on each column of the initial matrix:

[0082] a=(a - Min) / (Max - Min);

[0083] where a represents the current value, Min represents the minimum value of the current column, and Max represents the maximum value of the current column. Next, the matrix A is normalized. Here, the cosine distance metric is used for normalization, that is, for each matrix element a of the initial matrix A ij Calculate Thus, the normalized matrix X is obtained:

[0084]

[0085] S03: Input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the prediction result of the attack type of the network log data in a preset future time period;

[0086] Among them, the hierarchical support vector machine model constructs a decision tree according to a binary tree structure, and after training on a training set of historical log data based on a support vector machine on the decision tree, it is optimized on a test set of historical log data according to a replaced preset kernel function and penalty coefficient.

[0087] As a preferred embodiment of Embodiment 1, the hierarchical support vector machine model constructs a decision tree according to a binary tree structure, and after training on a training set of historical log data based on a support vector machine on the decision tree, it is optimized on a test set of historical log data according to a replaced preset kernel function and penalty coefficient. Specifically:

[0088] After processing the initial data, the next step is to construct a decision tree. Here, a binary tree structure is used to construct the decision tree, as Figure 3 shown:

[0089] Under normal circumstances, most of the data collected in the power system is normal data. Therefore, considering performance, when classifying for the first time, the normal log data and all other attack log data are separated first, and then the log data of attack type 1 and the log data of other types of attacks are separated for the second time. Each time, the log data is divided into two subclasses. After reaching the last attack type, the right child node is marked as the unknown attack type. When classifying each time, the data of the left child node is marked as +1, and the data of the right child node is marked as -1.

[0090] After constructing the decision tree structure, the next step is to construct and train the SVM model of the first layer. Considering that each different type of attack log data is probably linearly inseparable, the soft margin SVM algorithm based on the Gaussian kernel function is used for classification here. Find an optimal hyperplane (w T· φ(x) + b, where w is the normal vector of the hyperplane, φ(x) is the transformation function from low dimension to high dimension, and b is the bias term) to classify the samples in matrix X. Before training, the classification of all samples needs to be known. When classifying for the first time, normal log data is marked as +1 and attack log data is marked as -1. The optimization objective of SVM soft margin classification is as follows:

[0091]

[0092] where w is the normal vector of the hyperplane, C is the penalty coefficient that controls the balance between the margin and the number of misclassified samples, and ξ i ≥ 0 is the slack factor,

[0093] represents the allowable error of the i-th sample. The constraint conditions of the above formula are:

[0094] y i [w T φ(x i ) + b] ≥ 1 - ξ i , ξ i ≥ 0, i = 1, 2,..., N

[0095] When there is a large amount of noise in the sample data, there will be some outliers. A smaller C value will make the SVM model pay more attention to the "soft margin", that is, allow more misclassifications to improve the generalization ability of the model and reduce the risk of overfitting. For example, you can start trying from C = 0.1 or C = 1. In the case where the data is relatively clean and the cost of misclassification is high, a larger C value will make the SVM model pay more attention to the "hard margin", that is, require fewer misclassifications, but may lead to the model being more prone to overfitting. For example, you can start trying to build the model from C = 10 or C = 100.

[0096] After solving the parameters w and b, the optimal segmentation hyperplane f (1) (x) = w T · φ(x) + b can separate the normal log data and the attack data.

[0097] By introducing the parameters λ and μ using the Lagrange multiplier method, we can obtain Then the solution of formula (1) is equivalent to solving the following formula:

[0098]

[0099] (2) The constraint conditions of the formula are: 0 ≤ λ i ≤ C, i = 1, 2,..., N.

[0100] For the convenience of solving, the Gaussian kernel function K(x i , x j) = exp(-γ||x i - x j || 2 ) = φ(x i )φ(x j ), where γ ranges from (0, 1], and any value within this range can be taken first, for example, 0.5. Then, equation (2) is equivalent to:

[0101]

[0102] Next, use the Sequential Minimal Optimization (SMO) algorithm to solve all the Lagrange multipliers λ in equation (3). The steps are as follows:

[0103] 1. Initialize all Lagrange multipliers λ = 0.

[0104] 2. In each iteration, select any two Lagrange multipliers λ i and λ j , and introduce two variables L and H: If y i = y j , then H = min(C, λ i + λ j ); If y i ≠ y j , then H = min(C, C + λ j - λ i ).

[0105] 3. Calculate the new λ j , where η = 2exp(-γ||x i - x j || 2 ) - exp(-γ||x i - x i || 2 ) - exp(-γ||x j - x j || 2 ).

[0106] 4. Clip to the [L, H] range calculated in the second step. If it exceeds, clip it to L or H.

[0107] 5. Calculate the new λ i ,

[0108] 6. Update the bias term b,

[0109] 7. Repeat steps 2 to 6 until all Lagrange multipliers λ satisfy the KKT conditions, i.e., the optimization goal is achieved. The KKT conditions are as follows: C ≥ λ i ≥ 0, i = 1, 2,..., N, λ i [y i (w T φ(x i ) + b) - 1 + ξ i = 0, i = 1, 2,..., N, μ i ξ i = 0, i = 1, 2,...., N, μ i ≥ 0, i = 1, 2,..., N.

[0110] After calculating all the Lagrange multipliers λ, substitute them into to obtain the normal vector w of the hyperplane that divides the first - layer normal log data and attack data in the decision tree. Therefore, the function of the optimal first - layer segmentation hyperplane is:

[0111]

[0112] After dividing the first - layer normal power system log data and power system log data generated by attacks in the decision tree, the next step is to divide the log data of attack type 1 and other attack - type log data in the second layer. Similar to the data classification in the first layer, the function of the optimal second - layer segmentation hyperplane can be obtained as:

[0113]

[0114] Keep classifying until the log data of the last two attack types are classified to obtain the (k - 1) - th segmentation hyperplane f (k-1) (x), and the construction of the entire soft - margin support vector machine model based on the decision tree can be completed.

[0115] In this preferred embodiment, the present application inputs the feature vector into a hierarchical support vector machine model based on a decision tree, and uses its multi-layer decision tree structure to classify the network log data layer by layer, achieving accurate prediction of the attack types within a preset future time period. In each layer of the decision tree, the log data is classified through a preset hyperplane function: if the output value is +1, it is directly determined that the data belongs to the preset attack type of the current layer; if the output value is -1, the data is passed to the next layer for further classification until its attack type is determined or the bottom layer of the decision tree is reached. This layer-by-layer classification method can effectively solve the problem that a single classifier in traditional methods is difficult to handle multi-category complex data, significantly improving the model's recognition ability and classification accuracy for different attack types. At the same time, the hierarchical structure reduces the computational complexity of the model and improves the prediction efficiency, enabling the system to quickly respond to potential network attacks and providing an efficient and reliable guarantee for the network security of the power system.

[0116] Further, the step of inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree to enable the hierarchical support vector machine model to output the prediction result of the attack type of the network log data in a preset future time period is specifically as follows:

[0117] The classification result of the model is verified by inputting the test set data into the model. For example, if the f (1) (x) value output by the first layer is +1, then the input log data is normal data. If the f (1) (x) value output by the first layer is -1, then the second-layer SVM is used for classification. If the f (2) (x) value output by the second layer is +1, then the log data is generated by attack type 1. If the f (2) (x) value output by the second layer is -1, the data is input to the third layer for classification, and so on until the log data is classified into the corresponding attack type.

[0118] If the SVM of the last layer cannot classify the log data successfully, the log data is defined as an unknown attack type. Observe the classification result of the test set data. If the result is not satisfactory, the kernel function K(x i ,x j ) and the penalty coefficient C can be adjusted for the model until the model can well fit the training set data and complete the accurate classification of the power system log data.

[0119] This application realizes the efficient classification of power system network log data and the prediction of attack types by constructing a hierarchical support vector machine model based on a binary tree structure. The model is initially trained with a preset Gaussian kernel function and penalty coefficient, and the accuracy of the prediction results is evaluated on the test set. If the accuracy is lower than the preset threshold, the model will automatically change the type of kernel function (such as polynomial kernel function or linear kernel function), and adjust the penalty coefficient in combination with the cross-validation method, and retrain to optimize the performance. This process not only ensures the adaptability of the model under different data distributions, but also significantly improves the classification accuracy and generalization ability of the model by dynamically adjusting the kernel function and penalty coefficient. Finally, when the model accuracy reaches or exceeds the preset threshold, the training stops, and an optimized hierarchical support vector machine model is obtained. This optimization strategy enables the model to effectively cope with complex attack patterns in the power system network, significantly reducing the false alarm and missed alarm rates, improving the efficiency and reliability of power system network security detection, and providing a strong guarantee for the stable operation of the power system.

[0120] As a preferred embodiment of Embodiment 1, the method of this application further includes various functional modules, and the various modules are as Figure 4 shown;

[0121] Data acquisition module:

[0122] Responsible for real-time collection of log data related to the network security of power system equipment assets, including network communication logs, system operation logs, user behavior logs, etc. This module supports multiple log formats and performs data preprocessing, such as timestamp standardization, log level filtering, etc.

[0123] Data cleaning and preprocessing module:

[0124] Clean the collected log data, remove irrelevant or redundant information, and handle missing data, duplicate data, etc. Then convert the log information into structured features for the model to use. In addition, it can convert the log information into a vectorized representation, such as through methods like tagging, one-hot encoding, etc., so that the log data can be processed by the SVM model.

[0125] Model training module:

[0126] This module first extracts the key features of the log, such as source IP, access time, operation type, packet size, etc., to generate feature vectors. Use a feature selection algorithm (such as feature selection based on information gain) to remove redundant features and improve the training efficiency and prediction accuracy of the model. Then train the processed log feature data based on the soft margin SVM model of the decision tree. Optimize the accuracy of the model in attack detection through kernel function and penalty coefficient adjustment.

[0127] Real-time detection and analysis module:

[0128] This module uses a trained soft margin SVM model based on decision trees to perform definite classification and attack detection on real-time log data. When predicting real-time logs, if a log or a group of logs conforms to the attack characteristics of the model, it is determined as a network attack or abnormal behavior. Moreover, the detection engine of this module supports batch data processing and real-time analysis.

[0129] Alarm module:

[0130] When the real-time detection and analysis module detects abnormal behavior or signs of attack, this module can generate alarm information in real time. The alarm includes information such as attack type, alarm level, alarm description, source and destination IP, and attack time. In addition, this module supports the addition of alarm rules, and users can define alarm rules for the output data of the detection and analysis module.

[0131] Data visualization and reporting module:

[0132] This module generates charts and reports based on the analysis results, providing administrators with comprehensive information such as network attack trends and attack characteristic distributions. It shows the current system health status and recent alarm records. In addition, it displays the system operation status, historical attack data, and detection results through dashboards and reports to help the security team conduct timely analysis and decision-making.

[0133] Storage and log management module:

[0134] This module stores the collected original logs and system analysis results for subsequent review and further analysis. It manages the storage time of logs, performs regular cleaning and archiving, providing guarantee for long-term data storage and retrospective analysis. It regularly archives historical log data, reducing storage pressure and improving system response speed.

[0135] Model update and adaptation module:

[0136] This module retrains the SVM model and decision tree model regularly, enabling the models to dynamically adapt to new types of attacks and changes in the system environment. The model retraining engine uses the latest log data and detection results to re-optimize the model parameters, so as to improve the detection effect of the models in a dynamic environment and reduce the false alarm rate.

[0137] This application obtains the power system network log data within a preset time period, extracts its key features to form a feature vector, and then uses a hierarchical support vector machine model based on a decision tree to predict the attack type of the network log data. This model constructs a decision tree through a binary tree structure, and trains and optimizes it on historical log data. In particular, the accuracy and generalization ability of the model are improved by replacing the preset kernel function and adjusting the penalty coefficient. Through this technical means, this application can effectively overcome the defects of traditional methods, such as difficulty in identifying unknown threats, high false alarm and missed alarm rates, and inability to adapt to dynamic network environments. The hierarchical support vector machine model can accurately classify log data layer by layer, quickly identify normal behaviors and various attack behaviors, and significantly improve the detection efficiency and accuracy of power system network security threats. At the same time, the optimization process of the model ensures its stability and adaptability in complex network environments, providing a strong guarantee for the safe operation of the power system. This application effectively solves the problem that the prior art cannot accurately predict the attack type of the power system according to the support vector machine.

[0138] Embodiment 2

[0139] Please refer to Figure 5 , which is an attack type prediction device for a power system provided by an embodiment of this application.

[0140] In this embodiment, the attack type prediction device for the power system includes an acquisition module 10, a feature extraction module 20, and a prediction module 30.

[0141] The soft margin support vector machine based on decision tree (ST-soft-margin-SVMs) adopted in this application is a classification method that combines a decision tree and a soft margin support vector machine, and is commonly used to handle the classification complexity in multi-classification tasks. The basic idea of ST-soft-margin-SVMs is to split the original multi-class classification task into a series of binary classification problems by constructing a hierarchical structure of the decision tree, and each node is decided by a soft margin SVM classifier. This method can not only improve the classification efficiency, but also use the decision tree structure to reduce the training cost in multi-classification problems. The overall process of this application is as Figure 2 shown;

[0142] The first step is to first determine the relevant features of the power system network security log;

[0143] The second step is to collect various power system network attack-related log data and normal operation logs;

[0144] The third step is to label and classify the training set data and perform feature engineering;

[0145] In the fourth step, construct a decision tree structure. According to the class hierarchy relationship or feature similarity of the data, divide the multi-class data into multiple hierarchical subsets. These subsets form a tree structure, and each subset contains multiple classes;

[0146] In the fifth step, train the SVM classifier model for each layer from the root node downwards of the decision tree. For the SVM classifier of each node, select the Gaussian kernel function and hyperparameters to ensure that the classifier can accurately divide the data at that node.

[0147] In the sixth step, use the SMO (Sequential Minimal Optimization) algorithm to iteratively solve the Lagrange multipliers of the SVM model until all multipliers converge.

[0148] In the seventh step, complete the model construction and determine all parameter values of the model, including the penalty coefficient, the initial value of the Lagrange multiplier, etc.

[0149] In the eighth step, use the trained model to test the test set data. If the result does not meet the expectation, the penalty coefficient can be changed first. If the result still does not meet the expectation, the kernel function of the model can be changed to retrain the model until the test result meets the expectation.

[0150] Before model training, feature extraction needs to be carried out first. After feature extraction, feature encoding is required to numericalize the feature data. In this application, label encoding is used to assign a unique integer label to each different classification value.

[0151] The acquisition module 10 is used to acquire the network log data of the power system for a preset time period.

[0152] As a preferred embodiment of the second embodiment, the acquisition of the network log data of the power system for a preset time period includes the source IP type (known device is 1, unknown device is 2), the geographical location of the source IP (within the province is 1, within the country is 2, abroad is 3), the number of login failures within a period of time, the number of source IPs logged in within a period of time, the login time period (normal working hours is 1, night is 2, special working hours is 3), the login account (no account is 0, system account is 1, administrator account is 2, other accounts is 3), the number of connection ports within a period of time, the number of data packets within a period of time, the number of file transfers within a period of time, the number of communications using uncommon protocols within a period of time, the number of times of executing unauthorized commands or uncommon system commands within a period of time, the number of abnormal process startups or shutdowns within a period of time, etc. After feature selection and label encoding, the input training set of the model can be obtained. The "period of time" in the features can select a time range such as one hour, 24 hours, etc.

[0153] In this preferred embodiment, the present application constructs a comprehensive and detailed feature system by selecting log data containing multi-dimensional features such as source IP type, source IP geographical location, number of login failures, number of source IPs for login, login account, number of connection ports, number of data packets, number of file transfers, number of communications using uncommon protocols, number of unauthorized commands executed, and number of abnormal process startups or shutdowns. These features can reflect the operating status and potential threats of the power system network from different perspectives. By using these features as inputs, the model can more accurately capture the differences between normal and abnormal behaviors, thereby achieving efficient identification and classification of attack types. The comprehensive use of such multi-dimensional features not only improves the adaptability of the model to complex network environments but also significantly enhances the detection ability for various known and unknown attack behaviors, reduces the false alarm and missed alarm rates, and provides more comprehensive and accurate protection for the network security of the power system.

[0154] The feature extraction module 20 is used to extract features from the network log data to obtain feature vectors.

[0155] As a preferred embodiment of the second embodiment, the extracting features from the network log data to obtain feature vectors is specifically as follows:

[0156] According to the above-obtained feature data, initial data is used to construct the following initial matrix A and label matrix Y:

[0157]

[0158] Y=(y1 y2…y N ) T

[0159] Where N represents the number of collected samples, that is, the rows of the matrix represent the collected log feature data. M represents the number of features, and the c value of the matrix represents the observed value of a certain sample feature collected; Y is the label matrix indicating the classification result to which the sample belongs, and y i ∈{+1, -1} represents the attack type of the i-th sample (when performing the first-layer classification of the decision tree, it can be set that y i =+1 represents normal data, and y i =-1 represents attack data).

[0160] To handle the noise and fluctuations in the data, feature engineering is used to process the data in the initial matrix. To handle the missing values in the initial data and the influence brought by different dimensions, first, a dimensionless processing is performed, that is, the following operation is performed on each column of the initial matrix:

[0161] a=(a - Min) / (Max - Min);

[0162] Where a represents the current value, Min represents the minimum value of the current column, and Max represents the maximum value of the current column. Next, the matrix A is normalized. Here, the cosine distance metric is used for normalization, that is, for each matrix element a of the initial matrix A ij Calculate Thus, the normalized matrix X is obtained:

[0163]

[0164] The prediction module 30 is used to input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the prediction result of the attack type of the network log data in a preset future time period;

[0165] Among them, the hierarchical support vector machine model is constructed by building a decision tree according to a binary tree structure, and after training on the training set of historical log data based on the support vector machine on the decision tree, it is optimized on the test set of historical log data according to the replacement of the preset kernel function and penalty coefficient.

[0166] As a preferred embodiment of the second embodiment, the hierarchical support vector machine model is constructed by building a decision tree according to a binary tree structure, and after training on the training set of historical log data based on the support vector machine on the decision tree, it is optimized on the test set of historical log data according to the replacement of the preset kernel function and penalty coefficient. Specifically:

[0167] After processing the initial data, the next step is to construct a decision tree. Here, a decision tree is constructed using a binary tree structure, as Figure 3 shown:

[0168] Under normal circumstances, most of the data collected in the power system is normal data. Therefore, considering performance, when classifying for the first time, the normal log data and all other attack log data are separated first, and then the log data of attack type 1 and the log data of other types of attacks are separated for the second time. Each time, the log data is divided into two subclasses. After reaching the last attack type, the right child node is marked as the unknown attack type. When classifying each time, the data of the left child node is marked as +1, and the data of the right child node is marked as -1.

[0169] After constructing the decision tree structure, the next step is to construct and train the SVM model of the first layer. Considering that each different type of attack log data is probably linearly inseparable, the soft margin SVM algorithm based on the Gaussian kernel function is used for classification here. Find an optimal hyperplane (w T·φ(x) + b, where w is the normal vector of the hyperplane, φ(x) is the transformation function from low dimension to high dimension, and b is the bias term) to classify the samples in matrix X. Before training, the classification of all samples needs to be known. When classifying for the first time, normal log data is marked as +1, and attack log data is marked as -1. The optimization objective of SVM soft margin classification is as follows:

[0170]

[0171] where w is the normal vector of the hyperplane, C is the penalty coefficient, which controls the balance between the margin and the number of misclassified samples, and ξ i ≥0 is the slack factor,

[0172] represents the allowable error of the i-th sample. The constraint conditions of the above formula are:

[0173] y i [w T φ(x i ) + b] ≥ 1 - ξ i , ξ i ≥0, i = 1, 2,..., N

[0174] When there is a large amount of noise in the sample data, there will be some outliers. A smaller C value will make the SVM model pay more attention to the "soft margin", that is, allow more misclassifications to improve the generalization ability of the model and reduce the risk of overfitting. For example, you can start trying from C = 0.1 or C = 1. In the case where the data is relatively clean and the cost of misclassification is high, a larger C value will make the SVM model pay more attention to the "hard margin", that is, require fewer misclassifications, but may lead to the model being more prone to overfitting. For example, you can start trying to build the model from C = 10 or C = 100.

[0175] After solving the parameters w and b, the optimal segmentation hyperplane f (1) (x) = w T ·φ(x) + b can separate the normal log data and the attack data.

[0176] By introducing the parameters λ and μ using the Lagrange multiplier method, we can obtain Then the solution of formula (1) is equivalent to solving the following formula:

[0177]

[0178] (2) The constraint conditions of the formula are: 0 ≤ λ i ≤ C, i = 1, 2,..., N.

[0179] To facilitate the solution, the Gaussian kernel function K(x i , x j) = exp(-γ||x i - x j || 2 ) = φ(x i )φ(x j ), where γ ranges from (0, 1], and any value within this range can be taken first, for example, 0.5. Then, equation (2) is equivalent to:

[0180]

[0181] Next, use the Sequential Minimal Optimization (SMO) algorithm to solve all Lagrange multipliers λ in equation (3). The steps are as follows:

[0182] 1. Initialize all Lagrange multipliers λ = 0.

[0183] 2. In each iteration, select any two Lagrange multipliers λ i and λ j , and introduce two variables L and H: If y i = y j , then H = min(C, λ i + λ j ); If y i ≠ y j , then H = min(C, C + λ j - λ i ).

[0184] 3. Calculate the new λ j , where η = 2exp(-γ||x i - x j || 2 ) - exp(-γ||x i - x i || 2 ) - exp(-γ||x j - x j || 2 ).

[0185] 4. Clip to the range [L, H] calculated in the second step. If it exceeds, clip it to L or H.

[0186] 5. Calculate the new λ i ,

[0187] 6. Update the bias term b,

[0188] 7. Repeat steps 2 to 6 until all Lagrange multipliers λ satisfy the KKT conditions, i.e., the optimization goal is achieved. The KKT conditions are as follows: C ≥ λ i ≥ 0, i = 1, 2,..., N, λ i [y i (w T φ(x i ) + b) - 1 + ξ i = 0, i = 1, 2,..., N, μ i ξ i = 0, i = 1, 2,...., N, μ i ≥ 0, i = 1, 2,..., N.

[0189] After calculating all the Lagrange multipliers λ, substitute them into to obtain the normal vector w of the hyperplane that divides the first-layer normal log data and attack data in the decision tree. Therefore, the function of the best first-layer dividing hyperplane is:

[0190]

[0191] After dividing the first-layer normal power system log data and the power system log data generated by attacks in the decision tree, the next step is to divide the attack type 1 log data and other attack type log data in the second layer. Similar to the data classification in the first layer, the function of the best second-layer dividing hyperplane can be obtained as:

[0192]

[0193] Keep classifying until the log data of the last two attack types are classified to obtain the (k - 1)-th dividing hyperplane f (k-1) (x), and the construction of the entire soft margin support vector machine model based on the decision tree can be completed.

[0194] In this preferred embodiment, the present application inputs the feature vector into a hierarchical support vector machine model based on a decision tree, and uses its multi-layer decision tree structure to classify the network log data layer by layer, achieving accurate prediction of the attack types within a preset future time period. In each layer of the decision tree, the log data is classified through a preset hyperplane function: if the output value is +1, it is directly determined that the data belongs to the preset attack type of the current layer; if the output value is -1, the data is passed to the next layer for further classification until its attack type is determined or the bottom layer of the decision tree is reached. This layer-by-layer classification method can effectively solve the problem that a single classifier in traditional methods is difficult to handle multi-category complex data, significantly improving the model's recognition ability and classification accuracy for different attack types. At the same time, the hierarchical structure reduces the computational complexity of the model and improves the prediction efficiency, enabling the system to quickly respond to potential network attacks and providing an efficient and reliable guarantee for the network security of the power system.

[0195] Further, the step of inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree to enable the hierarchical support vector machine model to output the prediction result of the attack type of the network log data in a preset future time period is specifically as follows:

[0196] The classification result of the model is verified by inputting the test set data into the model. For example, if the f (1) (x) value output by the first layer is +1, then the input log data is normal data. If the f (1) (x) value output by the first layer is -1, then the second-layer SVM is used for classification. If the f (2) (x) value output by the second layer is +1, then the log data is generated by attack type 1. If the f (2) (x) value output by the second layer is -1, the data is input to the third layer for classification, and so on until the log data is classified into the corresponding attack type.

[0197] If the SVM of the last layer cannot classify the log data successfully, the log data is defined as an unknown attack type. Observe the classification result of the test set data. If the result is not ideal, the kernel function K(x i , x j ) and the penalty coefficient C can be adjusted for the model until the model can well fit the training set data and complete the accurate classification of the power system log data.

[0198] This application realizes the efficient classification of power system network log data and the prediction of attack types by constructing a hierarchical support vector machine model based on a binary tree structure. The model is initially trained with a preset Gaussian kernel function and penalty coefficient, and the accuracy of the prediction results is evaluated on the test set. If the accuracy is lower than the preset threshold, the model will automatically change the type of kernel function (such as polynomial kernel function or linear kernel function), and adjust the penalty coefficient in combination with the cross-validation method, and retrain to optimize the performance. This process not only ensures the adaptability of the model under different data distributions, but also significantly improves the classification accuracy and generalization ability of the model by dynamically adjusting the kernel function and penalty coefficient. Finally, when the model accuracy reaches or exceeds the preset threshold, the training stops, and an optimized hierarchical support vector machine model is obtained. This optimization strategy enables the model to effectively cope with complex attack patterns in the power system network, significantly reducing the false alarm and missed alarm rates, improving the efficiency and reliability of power system network security detection, and providing a strong guarantee for the stable operation of the power system.

[0199] This device uses three modules to work separately and coordinately to more accurately predict the attack types of the power system. This application obtains the power system network log data within a preset time period, extracts its key features to form a feature vector, and then uses a hierarchical support vector machine model based on a decision tree to predict the attack types of the network log data. The model constructs a decision tree through a binary tree structure and is trained and optimized on historical log data. In particular, the accuracy and generalization ability of the model are improved by changing the preset kernel function and adjusting the penalty coefficient. Through this technical means, this application can effectively overcome the defects of traditional methods, such as difficulty in identifying unknown threats, high false alarm and missed alarm rates, and inability to adapt to dynamic network environments. The hierarchical support vector machine model can accurately classify the log data layer by layer, quickly identify normal behaviors and various attack behaviors, and significantly improve the detection efficiency and accuracy of power system network security threats. At the same time, the optimization process of the model ensures its stability and adaptability in complex network environments, providing a strong guarantee for the safe operation of the power system. This application effectively solves the problem that the prior art cannot accurately predict the attack types of the power system according to the support vector machine.

[0200] Embodiment 3:

[0201] An embodiment of this application provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method for predicting the attack types of a power system as described above.

[0202] Among them, for the method for predicting the attack type of a power system, when it is implemented in the form of a software functional unit and used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0203] Embodiment 4

[0204] This application provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements any one of the methods for predicting the attack type of a power system as described in Embodiment 1.

[0205] The above-described specific embodiments have further elaborated on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only for the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. It is particularly pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for predicting attack types of a power system, characterized in that: include: Obtain network log data of the power system for a preset time period; Performing feature extraction on the network log data to obtain a feature vector; Inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs a prediction result of the attack type of the network log data in a preset time period in the future; The hierarchical support vector machine model is constructed by constructing a decision tree based on a binary tree structure, and after training a historical log data training set based on a support vector machine on the decision tree, it is optimized on a historical log data test set by replacing a preset kernel function and penalty coefficient.

2. The method for predicting attack types of a power system according to claim 1, characterized in that: The hierarchical support vector machine model is constructed based on a binary tree structure to build a decision tree, and after training the historical log data training set based on the support vector machine on the decision tree, it is optimized on the historical log data test set by replacing the preset kernel function and penalty coefficient, specifically: According to a preset Gaussian kernel function and a penalty coefficient, the historical log data training set is trained on the decision tree to obtain an initial support vector machine model; Evaluating the prediction results of the initial support vector machine model according to the historical log data test set; If the accuracy of the prediction result is less than a preset first threshold, the kernel function type is changed and the value of the preset penalty coefficient is adjusted according to the cross-validation method, and then the initial support vector machine model is retrained on the historical log data training set; Wherein, the kernel function types include polynomial kernel function and linear kernel function; If the accuracy of the prediction result is greater than or equal to a preset first threshold, the initial support vector machine model is used as the preset hierarchical support vector machine model.

3. The attack type prediction method for the power system according to claim 1 is characterized in that: The step of inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree so that the hierarchical support vector machine model outputs a prediction result of the attack type of the network log data in a preset time period in the future is specifically as follows: Inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model classifies the network log data layer by layer through a multi-layer decision tree structure; According to the decision trees of each layer of the hierarchical support vector machine model, the network log data is classified using the hyperplane functions preset in each layer of the decision trees: If the output value of the hyperplane function of the current layer is a preset first value, it is determined that the network log data belongs to the preset attack type of the current layer; if the output value of the hyperplane function of the current layer is a preset second value, the network log data is input into the hyperplane function of the next layer of decision tree for further classification until the attack type of the network log data is determined or the bottom layer of the decision tree is reached.

4. The method for predicting attack types of a power system according to claim 3, characterized in that: The network log data is classified by using the preset hyperplane function in each layer of the decision tree, specifically: The first hyperplane function of the first layer decision tree of the hierarchical support vector machine model is: In the formula, f (1) (x) is the first hyperplane function; λ i That is, each Lagrange multiplier obtained through iteration; b is the updated bias term; x i is the row vector of the standardized matrix X; x is the variable of the first hyperplane function; γ is the width parameter of the kernel function; The second hyperplane function of the second layer decision tree of the hierarchical support vector machine model is: In the formula, f (2) (x) is the second hyperplane function; λ i is each Lagrange multiplier obtained by the same method of the first layer hyperplane function for the second layer data; b is the bias term updated in the second layer; x i is the row vector of the standardized matrix composed of the second layer data; x is the variable of the second hyperplane function; γ is the width parameter of the kernel function.

5. The method for predicting attack types of a power system according to any one of claims 1 to 4, characterized in that: The network log data of the power system in the preset time period includes the source IP type, the source IP geographic location, the number of login failures in the preset time period, the number of source IPs logged in in the preset time period, the login account, the number of connection ports in the preset time period, the number of data packets in the preset time period, the number of file transfers in the preset time period, the number of uncommon protocol communications in the preset time period, the number of unauthorized commands or uncommon system commands executed in the preset time period, and the number of abnormal process startups or shutdowns in the preset time period.

6. A device for predicting attack types of a power system, characterized in that: include: Acquisition module, feature extraction module and prediction module; The acquisition module is used to acquire network log data of the power system in a preset time period; The feature extraction module is used to extract features from the network log data to obtain feature vectors; The prediction module is used to input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the attack type prediction result of the network log data in a preset time period in the future; The hierarchical support vector machine model is constructed by constructing a decision tree based on a binary tree structure, and after training a historical log data training set based on a support vector machine on the decision tree, it is optimized on a historical log data test set by replacing a preset kernel function and penalty coefficient.

7. The attack type prediction device for a power system according to claim 6, characterized in that: The hierarchical support vector machine model is constructed based on a binary tree structure to build a decision tree, and after training the historical log data training set based on the support vector machine on the decision tree, it is optimized on the historical log data test set by replacing the preset kernel function and penalty coefficient, specifically: According to a preset Gaussian kernel function and a penalty coefficient, the historical log data training set is trained on the decision tree to obtain an initial support vector machine model; Evaluating the prediction results of the initial support vector machine model according to the historical log data test set; If the accuracy of the prediction result is less than a preset first threshold, the kernel function type is changed and the value of the preset penalty coefficient is adjusted according to the cross-validation method, and then the initial support vector machine model is retrained on the historical log data training set; Wherein, the kernel function types include polynomial kernel function and linear kernel function; If the accuracy of the prediction result is greater than or equal to a preset first threshold, the initial support vector machine model is used as the preset hierarchical support vector machine model.

8. The attack type prediction device for a power system according to claim 6, characterized in that: The prediction module is used to input the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model outputs the attack type prediction result of the network log data in a preset time period in the future, specifically: Inputting the feature vector into a preset hierarchical support vector machine model based on a decision tree, so that the hierarchical support vector machine model classifies the network log data layer by layer through a multi-layer decision tree structure; According to the decision trees of each layer of the hierarchical support vector machine model, the network log data is classified using the hyperplane functions preset in each layer of the decision trees: If the output value of the hyperplane function of the current layer is a preset first value, it is determined that the network log data belongs to the preset attack type of the current layer; if the output value of the hyperplane function of the current layer is a preset second value, the network log data is input into the hyperplane function of the next layer of decision tree for further classification until the attack type of the network log data is determined or the bottom layer of the decision tree is reached.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the attack type prediction method for the power system according to any one of claims 1 to 5.

10. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for predicting the attack type of the power system according to any one of claims 1 to 5 is implemented.