Power system data security analysis method, device, equipment and medium
By using machine learning algorithms to predict security strategies and unsupervised clustering analysis in the power system, we can identify known and unknown APT attacks in the power system, and solve the problem of insufficient detection accuracy in the prior art, and achieve reliable and accurate guarantees for the security of power system data.
Patent Information
- Application Number
- CN202510747985.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
The prior art is difficult to accurately identify advanced persistent threat (APT) attacks in power systems, especially new or variant attacks, resulting in insufficient detection accuracy.
The security analysis strategy for predicting future time periods is adopted by machine learning algorithms, and combined with the judgment of known attack feature and cluster analysis of unsupervised machine learning, we can identify known and unknown attack features.
It improves the accuracy and timeliness of data security detection of power system, can actively explore unknown threats, and enhances the comprehensiveness and accuracy of detection of new or variant APT attacks.
Smart Images

Figure CN120281570A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power systems, and in particular, to a method, device, equipment and medium for power system data security analysis. Background Art
[0002] With the development of informatization and intelligence of power systems, power systems are facing increasingly complex security threats, especially attacks of Advanced Persistent Threat (APT). Therefore, in order to monitor the security of power systems in real time, it is necessary to identify the attack characteristics of APT to ensure the data security of power systems.
[0003] In related technologies, traditional security detection technologies rely on known APT attack characteristics in APT attack detection, and due to the weak data retrieval ability of traditional security detection technologies, it is impossible to accurately monitor new or variant APT attacks that are difficult to identify, thus affecting the detection accuracy of attack behaviors. Summary of the Invention
[0004] The problem solved by the present invention is how to improve the detection accuracy of power system data security.
[0005] To solve the above problems, the present invention provides a method, device, equipment and medium for power system data security analysis.
[0006] In a first aspect, a method for power system data security analysis of the present invention includes: Obtain the operation data of a host in a current time period; Determine the security analysis strategy of the host in a future time period according to the operation data in the current time period through a machine learning algorithm; Obtain the network traffic data of the host in the future time period according to the security analysis strategy, and analyze the network traffic data to obtain multiple data characteristics of the network traffic data; Judge whether the network traffic data has known attack characteristics according to each data characteristic; If the network traffic data has the known attack characteristics, it is determined that there is an attack behavior in the network traffic data; If the network traffic data does not have the known attack characteristics, perform clustering analysis on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; Judge whether the network traffic data has unknown attack characteristics according to the clustering result; If so, it is determined that there is an attack behavior in the network traffic data; if not, it is determined that there is no attack behavior in the network traffic data.
[0007] Optionally, the method for determining the security analysis strategy of the host in a future time period according to the operation data in the current time period through a machine learning algorithm includes: Through a machine learning algorithm, feature extraction is performed on the operation data in the current time period to obtain the CPU usage rate, memory usage rate, and network load of the host, and the CPU usage rate, memory usage rate, and network load are used as key features of the operation data; Predict according to the key features to obtain the operation data of the host in the future time period; According to the operation data in the future time period, obtain the security detection frequency and security detection depth of the host; Generate the security analysis strategy of the host in the future time period according to the security detection frequency and the security detection depth.
[0008] Optionally, the method for analyzing the network traffic data to obtain multiple data features of the network traffic data includes: Determine the traffic volume of the network traffic data according to the sum of the lengths of all data packets in the network traffic data; Determine the flow direction of the network traffic data according to the source IP address and destination IP address in the network traffic data; Determine the number of times the host establishes a connection with an external IP address according to the network traffic data, and determine the connection frequency according to the number of times; For the length of each data packet in the network traffic data, determine the data packet length distribution of the network traffic data; Use the traffic volume, flow direction, connection frequency, and data packet length distribution as the data features.
[0009] Optionally, the method for determining whether the network traffic data has known attack features according to each data feature includes: Compare the data features with the attack feature database to determine whether the data features match the attack features in the attack feature database; If the data features match the attack features in the attack feature database, it is determined that the network traffic data has known attack features; If the data features do not match the attack features in the attack feature database, it is determined that the network traffic data does not have known attack features.
[0010] Optionally, if the known attack features do not exist in the network traffic data, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result, including: After determining that the known attack features do not exist in the network traffic data, similarity analysis is performed on the network traffic data through the K-Means algorithm to obtain the Euclidean distances between all data points in the network traffic data and multiple initial clustering centers; According to the Euclidean distances between the data points and the initial clustering centers, each data point is assigned to the initial clustering center with the smallest Euclidean distance corresponding to the data point, obtaining multiple clustering clusters of the network traffic data, and taking the clustering clusters as the clustering result.
[0011] Optionally, judging whether the network traffic data has unknown attack features according to the clustering result includes: According to the clustering result, the characteristic statistical values of each clustering cluster of the network traffic data are determined, and the characteristic statistical values include the number of data points and distribution data of the clustering cluster; According to the number of data points and distribution data of the clustering cluster, it is judged whether the network traffic data has an abnormal clustering cluster; If so, it is determined that the network traffic data has unknown attack features; If not, it is determined that the network traffic data does not have unknown attack features.
[0012] Optionally, judging whether the network traffic data has an abnormal clustering cluster according to the number of data points and distribution data of the clustering cluster includes: According to the number of data points of the clustering cluster and the total number of data points of the network traffic data, the proportion of the clustering cluster is obtained; According to the distribution data of the clustering cluster, the inter-cluster distance between every two clustering clusters is determined; When the inter-cluster distance between the clustering cluster and other clustering clusters exceeds a preset distance threshold, and / or the proportion of the clustering cluster exceeds a preset proportion threshold, it is determined that the network traffic data has an abnormal clustering cluster.
[0013] In a second aspect, a power system data security analysis device of the present invention includes: A data acquisition unit for acquiring the operation data of the host in the current time period; A prediction unit for determining the security analysis strategy of the host in the future time period according to the operation data in the current time period through a machine learning algorithm; A feature extraction unit, configured to obtain network traffic data of the host in the future time period according to the security analysis policy, and analyze the network traffic data to obtain multiple data features of the network traffic data; A known attack feature judgment unit, configured to judge whether the network traffic data has known attack features according to each of the data features; if the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; if the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; An unknown attack feature judgment unit, configured to judge whether the network traffic data has unknown attack features according to the clustering result; if so, it is determined that the network traffic data has an attack behavior, and if not, it is determined that the network traffic data does not have an attack behavior.
[0014] In a third aspect, an electronic device of the present invention includes a computer-readable storage medium storing a computer program and a processor. When the computer program is read and run by the processor, the power system data security analysis method as described above is implemented.
[0015] In a fourth aspect, a computer-readable storage medium of the present invention stores a computer program, and when the computer program is executed by a processor, the power system data security analysis method as described above is implemented.
[0016] The power system data security analysis method, device, equipment and medium of the present invention obtain the operation data of the host in the current time period, and then, through machine learning algorithms, determine the security analysis strategy of the host in the future time period according to the operation data in the current time period. By using machine learning algorithms to mine the potential rules and trends in the data, the security analysis strategy of the host in the future time period is predicted, so as to better adapt to the real-time changes of the operation state of the power system, adjust the detection focus and resource allocation in advance, and thus more effectively cope with various security risks, significantly improving the accuracy and timeliness of detection. Obtaining the network traffic data of the host in the future time period according to the security analysis strategy ensures the pertinence and effectiveness of data collection. Analyzing the network traffic data to obtain multiple data features of the network traffic data; according to each data feature, judging whether the network traffic data has known attack features. Through the comprehensive investigation of these features, the characteristics of the network traffic can be more comprehensively understood, so as to accurately identify whether the network traffic contains known attack features. If the network traffic data has known attack features, it is determined that there is an attack behavior in the network traffic data, avoiding the detection delay and omission problems caused by relying on manual experience or fixed rules in traditional detection technologies. If the network traffic data does not have known attack features, clustering analysis is performed on the network traffic data through unsupervised machine learning algorithms to automatically discover potential abnormal patterns and structures in the data. By analyzing the clustering results, unknown attack features significantly different from the normal traffic pattern are identified, thus forming an active exploration method for unknown threats, effectively making up for the deficiencies of traditional detection technologies in the face of new or variant APT attacks, and greatly enhancing the comprehensiveness and accuracy of detection. The present invention uses dynamic adjustment of the security analysis strategy and at the same time actively explores the unknown attack features in the network traffic data through unsupervised machine learning algorithms, improving the detection accuracy of the power system data security, and thus providing a more reliable and accurate guarantee for the power system data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a schematic flowchart of the power system data security analysis method in an embodiment of the present invention; Figure 2 It is a schematic structural diagram of the power system data security analysis device in another embodiment of the present invention; Figure 3 It is a schematic structural diagram of an electronic device in still another embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of specific embodiments of the present invention with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.
[0019] It should be understood that the various steps recorded in the method embodiments of the present invention can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.
[0020] As used herein, the term "comprising" and its variants are open-ended, that is, "including but not limited to"; the term "based on" means "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order of functions performed by these devices, modules, or units or their interdependent relationships.
[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly specified otherwise in the context, it should be understood as "one or more".
[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0023] In view of the problems existing in the above related technologies, this embodiment provides a method, device, equipment, and medium for power system data security analysis.
[0024] Combined with Figure 1 As shown, a method for power system data security analysis provided by an embodiment of the present invention includes: Obtain the operation data of the host in the current time period.
[0025] Specifically, the host plays a core role in the monitoring and data acquisition system of the power system. The SCADA system collects various data from power generation stations, substations, and transmission lines through the host and conducts real-time monitoring and analysis. When the host obtains the operation data of the host in the current time period, data acquisition tools are usually required to collect data from multiple key indicators of the host in real time. In the preferred embodiment of the present invention, the collected operation data includes CPU usage rate, memory usage rate, and network load, etc. Taking the CPU usage rate as an example, through system interfaces such as performance counters, the usage data of the CPU is regularly read to ensure that it can accurately reflect the current operation state of the host. The collection of the memory usage rate involves monitoring the allocation and usage of memory to understand the occupancy status of the host memory resources. The collection of network load data is usually achieved through traffic monitoring tools or network card drivers to obtain information such as the size and quantity of network data packets entering and leaving the host in real time.
[0026] Through machine learning algorithms, according to the operation data in the current time period, determine the security analysis strategy of the host in the future time period.
[0027] Specifically, to use machine learning algorithms to determine the future security analysis strategy, first, the length of the future time period needs to be determined. For example, predicting the security status in the next five minutes, one hour, or one day depends on specific security requirements and the real-time nature of the data. Then, preprocess the collected operation data, including operations such as data cleaning and normalization, to eliminate noise and outliers in the data and make the data more suitable for the input requirements of the algorithm. Then, select a time series prediction algorithm to predict the operation trend of the host. Based on the prediction results, formulate a detailed security analysis strategy, clarify the detection frequency and depth, so as to make the security detection more forward-looking and targeted. In the preferred embodiment of the present invention, the machine learning algorithm can be a long short-term memory network. After preprocessing and standardizing the operation data of the host in the current time period, it is input into the trained LSTM model. The model outputs the predicted results of the security status of the host in the future time period, which may include the predicted values of various security indicators, such as the expected network traffic size, the expected CPU usage rate, etc.
[0028] Obtain the network traffic data of the host in the future time period according to the security analysis strategy, and analyze the network traffic data to obtain multiple data characteristics of the network traffic data.
[0029] Specifically, in accordance with the formulated security analysis strategy, use a network traffic monitoring tool to obtain the network traffic data of the host in real time in the future time period. After obtaining the data, use a feature extraction algorithm to analyze it and extract multiple key data characteristics, such as traffic size, flow direction, connection frequency, packet length distribution, etc. These characteristics will provide important basis for subsequent attack detection.
[0030] Based on each of the said data features, determine whether the network traffic data has known attack features.
[0031] Specifically, search the known attack feature library to query various common attack feature patterns, such as the high-traffic feature of DDoS attacks, the specific packet structure of SQL injection attacks, etc. Compare and match the extracted data features with this feature library one by one. For example, if the extracted traffic size feature increases sharply within a short period of time and far exceeds the normal business traffic range, and at the same time matches the traffic feature pattern of DDoS attacks, it can be preliminarily determined that there are known attack features in the network traffic data.
[0032] If the network traffic data has the said known attack features, it is determined that there is an attack behavior in the network traffic data.
[0033] Specifically, when it is determined that there are known attack features in the network traffic data, immediately trigger the attack determination mechanism. Through preset determination rules, such as when the matching degree of attack features reaches a certain threshold, it is determined that there is an attack behavior in the network traffic data. This process needs to ensure the accuracy and reliability of the determination rules to avoid misjudgment.
[0034] If the network traffic data does not have the said known attack features, perform clustering analysis on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result.
[0035] Specifically, in the case of no match of known attack features, select a suitable unsupervised clustering algorithm, such as K-Means, to perform clustering analysis on the network traffic data. In the preferred embodiment of the present invention, the unsupervised machine learning algorithm is the K-Means algorithm. First, randomly initialize the clustering centers for the data, calculate the distances between the data points and the clustering centers through iteration, assign the data points to the clustering clusters belonging to the nearest clustering centers, and continuously update the positions of the clustering centers until the clustering centers no longer change or reach the maximum number of iterations, and finally obtain the clustering result.
[0036] Based on the clustering result, determine whether the network traffic data has unknown attack features.
[0037] Specifically, by analyzing the clustering result, identify abnormal clustering clusters that are significantly different from the normal traffic pattern. For example, the features such as the traffic size and connection frequency of some clustering clusters are significantly different from the normal traffic pattern. By setting abnormal determination rules, such as when the density of the clustering cluster is lower than a certain threshold or the similarity between the features of the clustering cluster and the normal pattern is lower than the set value, it is determined that there are unknown attack features in the network traffic data.
[0038] If so, it is determined that there is an attack behavior in the network traffic data; if not, it is determined that there is no attack behavior in the network traffic data.
[0039] Specifically, according to the analysis and judgment of the clustering result, if there are unknown attack characteristics, it is determined that there is an attack behavior in the network traffic data; otherwise, it is determined that there is no attack behavior, thus ensuring the accuracy and reliability of the determination result.
[0040] The power system data security analysis method of the present invention obtains the operation data of the host in the current time period, and then through a machine learning algorithm, determines the security analysis strategy of the host in the future time period according to the operation data in the current time period, and uses the machine learning algorithm to mine the potential rules and trends in the data, so as to predict the security analysis strategy of the host in the future time period, so as to better adapt to the real-time changes of the operation state of the power system, adjust the detection focus and resource allocation in advance, and thus more effectively respond to various security risks, significantly improving the accuracy and timeliness of detection. Obtaining the network traffic data of the host in the future time period according to the security analysis strategy ensures the pertinence and effectiveness of data collection. Analyze the network traffic data to obtain multiple data characteristics of the network traffic data; according to each data characteristic, judge whether the network traffic data has known attack characteristics. By comprehensively examining these characteristics, the characteristics of the network traffic can be more comprehensively understood, so as to accurately identify whether the network traffic contains known attack characteristics. If the network traffic data has known attack characteristics, it is determined that there is an attack behavior in the network traffic data, avoiding the detection delay and omission problems caused by relying on manual experience or fixed rules in traditional detection technologies. If the network traffic data does not have known attack characteristics, perform clustering analysis on the network traffic data through an unsupervised machine learning algorithm, automatically discover potential abnormal patterns and structures from the data, and identify unknown attack characteristics that are significantly different from the normal traffic pattern by analyzing the clustering result, thus forming an active exploration method for unknown threats, effectively making up for the deficiencies of traditional detection technologies in the face of new or variant APT attacks, and greatly enhancing the comprehensiveness and accuracy of detection. The present invention uses dynamic adjustment of the security analysis strategy, and at the same time actively explores the unknown attack characteristics in the network traffic data through an unsupervised machine learning algorithm, improving the detection accuracy of the power system data security, and thus providing a more reliable and accurate guarantee for the power system data security.
[0041] Optionally, the determining, by a machine learning algorithm, the security analysis strategy of the host in the future time period according to the operation data in the current time period includes: Extract features from the operation data of the current time period through a machine learning algorithm to obtain the CPU usage rate, memory usage rate, and network load of the host, and use the CPU usage rate, the memory usage rate, and the network load as key features of the operation data; Predict based on the key features to obtain the operation data of the host in the future time period; Obtain the security detection frequency and security detection depth of the host according to the operation data of the future time period; Generate the security analysis strategy of the host in the future time period according to the security detection frequency and the security detection depth.
[0042] Specifically, key features are extracted from the operation data of the host in the current time period. Among them, PCA can be used for feature extraction. PCA is a commonly used method for data dimensionality reduction and feature extraction. By performing a linear transformation on the original data, the data is projected onto new coordinate axes, making the new features (principal components) uncorrelated and sorted by variance magnitude. In the data security analysis of power systems, PCA can be used to preprocess the operation data of the host and extract the most important features, such as CPU usage, memory usage, and network load. Through this method, the dimensionality of the data can be reduced, redundant information can be removed, while the main features of the data are retained, improving the efficiency and accuracy of subsequent analysis. The operation data covers multiple indicators such as CPU usage, memory usage, and network load. Machine learning algorithms screen out CPU usage, memory usage, and network load as key features. The reason is that CPU usage can reflect the computing load of the host, memory usage reflects the occupancy of storage resources, and network load is directly related to network communication conditions. The three can effectively characterize the operation state of the host and lay a foundation for subsequent prediction. Based on the extracted key features, a suitable time series prediction model is used for training. For example, assume that we select the length of the historical data sequence to be 10 and the length of the predicted future data sequence to be 2. An input-output pair is constructed with the extracted key feature sequence. Among them, the input sequence is the key feature values at the 1st to 10th moments, and the output sequence is the key feature values at the 11th and 12th moments. After model training, when a new key feature sequence is input, the key feature values in the future time period can be predicted, which are regarded as the future operation data of the host, providing a basis for the security analysis strategy. Based on the predicted future operation data, the security detection frequency and depth of the host are set. For example, if it is predicted that the future network load of the host will increase, which may increase the risk of being attacked by the network. At this time, the security detection frequency can be appropriately increased to monitor the change of network traffic in real time and detect potential threats in time; at the same time, the detection depth is deepened to carefully check the content of network traffic and accurately identify attack features. Considering factors such as the security detection frequency and depth, a security analysis strategy for the host in the future time period is generated. This strategy clarifies how to implement security detection, making the security detection dynamically adaptable, capable of adjusting the detection plan according to the future operation trend of the host, and improving the data security protection level of the power system.
[0043] In the embodiment of the present invention, through machine learning algorithms, feature extraction is performed on the current operation data of the host, future operation data is predicted, and a security analysis strategy is formulated, effectively improving the accuracy and adaptability of data security detection in the power system. At the same time, the dynamically generated security analysis strategy can closely fit the future operation state of the host, enhancing the forward-looking and flexibility of data security protection in the power system.
[0044] Optionally, analyzing the network traffic data to obtain multiple data features of the network traffic data, including: Determining the traffic volume of the network traffic data according to the sum of the lengths of all data packets in the network traffic data; Determining the flow direction of the network traffic data according to the source IP address and the destination IP address in the network traffic data; Determining the number of times the host establishes a connection with an external IP address according to the network traffic data, and determining the connection frequency according to the number of times; Determining the data packet length distribution of the network traffic data for the length of each data packet in the network traffic data; Regarding the traffic volume, the flow direction, the connection frequency, and the data packet length distribution as the data features.
[0045] Specifically, count the sum of the lengths of all data packets in the network traffic data. For example, within a given time period (such as one minute), if the sum of the data packet lengths is 10 MB, the traffic volume for this time period is 10 MB. This directly reflects the scale of the data volume of network communication. Analyze the source IP and destination IP addresses. If the source IP is an external network and the destination IP is an internal host, the traffic is inbound; otherwise, it is outbound. For example, if host A (internal IP: 192.168.1.100) receives a data packet from Internet IP 110.100.100.100, it is recorded as inbound traffic. Through flow direction analysis, the data transmission direction can be understood, inbound and outbound traffic can be distinguished, and a basis for formulating security policies can be provided. Count the number of times the host connects to an external IP address. For example, within one minute, if the host establishes connections with 100 different external IPs, the connection frequency is 100 times / minute. A high connection frequency may indicate a scanning attack or brute force cracking. Analyze the length of each data packet and count the proportion of data packets in different length intervals. For example, statistics show that within a certain time period, data packets with a length of 100 - 200 bytes account for 30% of the total traffic, and those with a length of 300 - 400 bytes account for 50%. This distribution feature helps to identify abnormal communication behaviors, such as fixed-length data packets generated during the spread of specific malware. Integrate the traffic volume, the flow direction, the connection frequency, and the data packet length distribution into data features. These features comprehensively describe the characteristics of network traffic and provide multi-dimensional information for subsequent attack detection.
[0046] In the embodiments of the present invention, through multi-dimensional analysis of network traffic data and extraction of data features, through the correlation analysis of multi-dimensional features, an in-depth understanding of network traffic is achieved, the accuracy and reliability of security detection are improved, and further the data security of the power system is enhanced.
[0047] Optionally, determining whether the network traffic data has known attack features according to each of the data features includes: Comparing the data features with an attack feature database to determine whether the data features match the attack features in the attack feature database; If the data features match the attack features in the attack feature database, it is determined that the network traffic data has known attack features; If the data features do not match the attack features in the attack feature database, it is determined that the network traffic data does not have known attack features.
[0048] Specifically, to determine whether the network traffic data has known attack features, the data features need to be precisely matched with the attack feature database. In a preferred embodiment of the present invention, taking a DDoS attack as an example, the attack feature database stores typical features of such attacks. When the data features of the monitored network traffic show that the connection frequency increases abnormally, such as the number of connections far exceeds the normal threshold within a short period of time, the data features are then compared with the high connection frequency features of DDoS attacks in the database. If the match is successful, it can be determined that the current network traffic has known DDoS attack features; conversely, if no corresponding match is found for the data features, it is considered that there are no known attack features.
[0049] In the embodiment of the present invention, by comparing the extracted data features with the known attack feature database, known attack behaviors in network traffic can be quickly and accurately identified. This detection method based on feature matching not only reduces the misjudgment rate but also can timely detect and warn of attacks, providing sufficient time for the power system to take protective measures and effectively ensuring data security.
[0050] Optionally, if the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result, including: After determining that the network traffic data does not have the known attack features, similarity analysis is performed on the network traffic data through the K-Means algorithm to obtain the Euclidean distances between all data points in the network traffic data and multiple initial clustering centers; According to the Euclidean distances between the data points and the initial clustering centers, each data point is assigned to the initial clustering center with the smallest Euclidean distance corresponding to the data point, obtaining multiple clustering clusters of the network traffic data, and taking the clustering clusters as the clustering result.
[0051] Specifically, after determining that the network traffic data does not have known attack characteristics, the K-Means algorithm is used to initiate the similarity analysis process, which includes calculating the Euclidean distance between each data point in the network traffic data and multiple initial cluster centers. Taking the data points and cluster centers in a two-dimensional space as an example, the Euclidean distance formula is: L = ; where L is the Euclidean distance, (x1, y1) are the coordinate data of the data point in the two-dimensional space coordinate system, and (x2, y2) are the coordinate data of the cluster center in the two-dimensional space coordinate system. Accordingly, the similarity between the data point and the cluster center is quantified. Based on the calculated Euclidean distance, each data point is assigned to the cluster corresponding to the nearest initial cluster center. If the distance between data point A and cluster center C1 is less than its distances from other cluster centers such as C2 and C3, then A is temporarily classified into cluster C1. After all data points are assigned, multiple clusters are initially formed. The center point of each cluster is recalculated as the new cluster center. Repeat the above steps, that is, recalculate the distance between the data points and the new cluster center, and reassign the data points until the position of the cluster center is stable or the preset number of iterations is reached. The final clustering result includes the set of data points within each cluster and their corresponding features. For example, a cluster may contain a set of connection data points with high traffic but short duration, initially presenting the internal structure of the data points.
[0052] In the embodiment of the present invention, the hidden patterns in the network traffic data are deeply mined through the K-Means algorithm, normal traffic patterns can be identified, potential attack traffic can be effectively distinguished, and the detection accuracy is improved. Collaborating with the traditional method of detecting known attack characteristics, the data security of the power system is comprehensively guaranteed.
[0053] Optionally, the judging whether the network traffic data has unknown attack characteristics according to the clustering result includes: According to the clustering result, determine the feature statistical values of each cluster of the network traffic data, and the feature statistical values include the number of data points and distribution data of the cluster; Judge whether there are abnormal clusters in the network traffic data according to the number of data points and distribution data of the cluster; If so, it is determined that the network traffic data has unknown attack characteristics; If not, it is determined that the network traffic data does not have unknown attack characteristics.
[0054] Specifically, based on the clustering results, characteristic statistical values such as the number of data points and distribution data in each clustering cluster are calculated. The number of data points directly reflects the size of the clustering cluster; the distribution data reveals the density or sparsity of the data points within the clustering cluster, comprehensively reflecting the characteristics of the clustering cluster. Whether there are abnormal clustering clusters is judged according to the number of data points and distribution data of the clustering cluster. Since normal clustering clusters usually contain a large number of data points, if the number of data points in a certain clustering cluster is too small, such as only accounting for 1% of the total number of data points, it may be an abnormal clustering cluster. At the same time, if the data points in a certain clustering cluster are sparsely distributed and the distance between data points is significantly greater than that of other clustering clusters, it may also be an abnormal clustering cluster, indicating that the characteristics of its data points are quite different from normal traffic. If there are abnormal clustering clusters, it is determined that the network traffic data has unknown attack characteristics; otherwise, it does not. For example, in a certain clustering analysis, it is found that the number of data points in a clustering cluster is extremely small and the data points are sparsely distributed. Further analysis reveals that the data packets in this clustering cluster have special payload contents and abnormal traffic patterns, which are significantly inconsistent with normal business traffic. Therefore, it is determined that there are unknown attack characteristics. In a preferred embodiment of the present invention, the network traffic data is clustered by the K-Means algorithm to obtain multiple clustering clusters. The total number of data points is 1000. Among them, clustering cluster A contains 950 data points, with the data points densely distributed, accounting for 95% of the total number of data points; clustering cluster B contains 30 data points, accounting for 3%, and the data points are slightly sparsely distributed; clustering cluster C has only 10 data points, accounting for 1%, and the data points are extremely sparsely distributed, and the distance between data points is significantly greater than that of other clustering clusters. Further analyzing clustering cluster C, it is found that its data packets have special payload contents, including uncommon binary patterns, which are significantly different from the normal continuous and stable traffic patterns of the power system. Combining this information, it is determined that clustering cluster C is an abnormal clustering cluster, and its characteristics are significantly different from normal business traffic. Based on this, it is determined that the network traffic data has unknown attack characteristics, which may be caused by new attacks or variant attacks.
[0055] In an embodiment of the present invention, by analyzing the clustering results to judge whether the network traffic data has unknown attack characteristics, the detection ability of the power system for new attacks can be effectively improved, the comprehensiveness and adaptability of data security detection can be significantly enhanced, potential threats can be discovered in time and measures can be taken. This helps the power system formulate countermeasures in advance and reduce the risks brought by unknown attacks.
[0056] Optionally, the judging whether there are abnormal clustering clusters in the network traffic data according to the number of data points and distribution data of the clustering cluster includes: Obtaining the proportion of the clustering cluster according to the number of data points of the clustering cluster and the total number of data points of the network traffic data; Determining the inter-cluster distance between every two clustering clusters according to the distribution data of the clustering cluster; When the inter-cluster distances between the cluster and other clusters all exceed a preset distance threshold, and / or the proportion of the cluster exceeds a preset proportion threshold, it is determined that there is an abnormal cluster in the network traffic data.
[0057] Specifically, it is calculated according to the formula "cluster proportion = the number of data points in the cluster / the total number of data points × 100%". For example, if a certain cluster has 100 data points and the total number of data points in the network traffic data is 1000, then the proportion of this cluster is 10%. If the cluster proportion exceeds the preset proportion threshold (such as 5%), it may be an abnormal cluster. In addition, the Euclidean distance formula is used to calculate the distance between different clusters. The formula is: The Euclidean distance calculation formula is: (Taking a two-dimensional space as an example). For cluster A (center coordinates (a1, a1)) and cluster B (center coordinates (b2, b2)), substitute the formula to calculate the Euclidean distance between the center coordinates of the clusters. If this distance exceeds the preset distance threshold, it is considered that there is a significant difference between these two clusters. When the inter-cluster distances between the cluster and other clusters all exceed the preset distance threshold, or the proportion of the cluster exceeds the preset proportion threshold, it is determined that there is an abnormal cluster in the network traffic data. In a preferred embodiment of the present invention, in a certain clustering analysis, it is found that the inter-cluster distances between cluster C and the remaining clusters all exceed 3, or its proportion is as high as 20% (exceeding the set 5% threshold), then it is determined that there is an abnormal cluster.
[0058] In the embodiment of the present invention, by comprehensively considering the proportion of data points in the cluster and the inter-cluster distance to judge the abnormal cluster, the detection accuracy and reliability of the power system for unknown attack features can be effectively improved. Proportion analysis can identify clusters with abnormal scales, which may be caused by large-scale attacks or abnormal traffic of a small number of hosts; inter-cluster distance analysis can find clusters with large feature differences, or be caused by independent attack behaviors. This method enables the power system to accurately and timely discover unknown attack threats, enhances the tightness and effectiveness of data security protection, and is of great significance for ensuring the stable operation of the power system.
[0059] Combined with Figure 2 As shown in A data acquisition unit for acquiring the operation data of the host in the current time period; A prediction unit for determining the security analysis strategy of the host in the future time period according to the operation data in the current time period through a machine learning algorithm; A feature extraction unit for obtaining the network traffic data of the host in the future time period according to the security analysis strategy and analyzing the network traffic data to obtain multiple data features of the network traffic data; A known attack feature judgment unit is configured to determine whether the network traffic data has known attack features according to each of the data features; if the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; if the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; An unknown attack feature judgment unit is configured to determine whether the network traffic data has unknown attack features according to the clustering result; if so, it is determined that the network traffic data has an attack behavior, and if not, it is determined that the network traffic data does not have an attack behavior.
[0060] The power system data security analysis device of the present invention has the same advantages as the power system data security analysis method compared with the prior art, and will not be elaborated here.
[0061] An electronic device provided by an embodiment of the present invention includes a computer-readable storage medium storing a computer program and a processor. When the computer program is read and run by the processor, the power system data security analysis method as described above is implemented.
[0062] Or, an electronic device 300 includes a memory 310 and a processor 320 connected to the memory 310; the memory 310 is configured to store a computer program; the processor 320 is configured to perform the following operations when executing the computer program: Obtain the operation data of the host in the current time period; Through a machine learning algorithm, determine the security analysis strategy of the host in the future time period according to the operation data in the current time period; Obtain the network traffic data of the host in the future time period according to the security analysis strategy, and analyze the network traffic data to obtain multiple data features of the network traffic data; Determine whether the network traffic data has known attack features according to each of the data features; If the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; If the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; Determine whether the network traffic data has unknown attack features according to the clustering result; If so, it is determined that the network traffic data has an attack behavior, and if not, it is determined that the network traffic data does not have an attack behavior.
[0063] The electronic device of the present invention has the same advantages over the prior art as those of the above-mentioned power system data security analysis method over the prior art, which will not be elaborated herein.
[0064] A computer-readable storage medium provided by an embodiment of the present invention, on which a computer program is stored. When the computer program is executed by a processor, the power system data security analysis method as described above is implemented.
[0065] Or, a non-volatile computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor performs the following operations: Obtain the operation data of the host in the current time period; Determine the security analysis strategy of the host in the future time period according to the operation data in the current time period through a machine learning algorithm; Obtain the network traffic data of the host in the future time period according to the security analysis strategy, and analyze the network traffic data to obtain multiple data features of the network traffic data; Judge whether the network traffic data has known attack features according to each data feature; If the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; If the network traffic data does not have the known attack features, perform clustering analysis on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; Judge whether the network traffic data has unknown attack features according to the clustering result; If so, it is determined that the network traffic data has an attack behavior; if not, it is determined that the network traffic data does not have an attack behavior.
[0066] The computer-readable storage medium of the present invention has the same advantages over the prior art as those of the above-mentioned power system data security analysis method over the prior art, which will not be elaborated herein.
[0067] Although the present invention is disclosed as above, the protection scope of the present invention is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will all fall within the protection scope of the present invention.
Claims
1. A method for analyzing the data security of a power system, characterized in that, Including: Obtain the operation data of the host in the current time period; Determine the security analysis strategy of the host in the future time period according to the operation data in the current time period through a machine learning algorithm; Obtain the network traffic data of the host in the future time period according to the security analysis strategy, and analyze the network traffic data to obtain multiple data features of the network traffic data; Judge whether the network traffic data has known attack features according to each data feature; If the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; If the network traffic data does not have the known attack features, perform clustering analysis on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; Judge whether the network traffic data has unknown attack features according to the clustering result; If so, it is determined that the network traffic data has an attack behavior, and if not, it is determined that the network traffic data does not have an attack behavior.
2. The power system data security analysis method according to claim 1, wherein The determining, through a machine learning algorithm, the security analysis strategy of the host in the future time period according to the operation data in the current time period includes: Extract features from the operation data in the current time period through a machine learning algorithm to obtain the CPU usage rate, memory usage rate, and network load of the host, and use the CPU usage rate, memory usage rate, and network load as key features of the operation data; Perform prediction according to the key features to obtain the operation data of the host in the future time period; Obtain the security detection frequency and security detection depth of the host according to the operation data in the future time period; Generate the security analysis strategy of the host in the future time period according to the security detection frequency and the security detection depth.
3. The power system data security analysis method according to claim 1, wherein The analyzing the network traffic data to obtain multiple data features of the network traffic data includes: Determine the traffic volume of the network traffic data according to the sum of the lengths of all data packets in the network traffic data; Determine the flow direction of the network traffic data according to the source IP address and destination IP address in the network traffic data; Determine the number of connections established by the host with an external IP address according to the network traffic data, and determine the connection frequency according to the number; Determine the data packet length distribution of the network traffic data for the length of each data packet in the network traffic data; Use the traffic volume, the flow direction, the connection frequency, and the data packet length distribution as the data features.
4. The power system data security analysis method according to claim 1, characterized in that The judging whether the network traffic data has known attack features according to each data feature includes: Compare the data features with an attack feature database to judge whether the data features match the attack features in the attack feature database; If the data features match the attack features in the attack feature database, it is determined that the network traffic data has known attack features; If the data feature does not match the attack feature in the attack feature database, it is determined that the network traffic data does not have known attack features.
5. The power system data security analysis method according to claim 1, wherein If the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result, including: After determining that the network traffic data does not have the known attack features, similarity analysis is performed on the network traffic data through the K-Means algorithm to obtain the Euclidean distances between all data points in the network traffic data and multiple initial clustering centers; According to the Euclidean distances between the data points and the initial clustering centers, each data point is assigned to the initial clustering center with the smallest Euclidean distance corresponding to the data point to obtain multiple clustering clusters of the network traffic data, and the clustering clusters are used as the clustering result.
6. The power system data security analysis method according to claim 5, characterized in that According to the clustering result, determining whether the network traffic data has unknown attack features includes: According to the clustering result, the feature statistical values of each clustering cluster of the network traffic data are determined, and the feature statistical values include the number of data points and distribution data of the clustering cluster; According to the number of data points and distribution data of the clustering cluster, it is judged whether the network traffic data has abnormal clustering clusters; If so, it is determined that the network traffic data has unknown attack features; If not, it is determined that the network traffic data does not have unknown attack features.
7. The power system data security analysis method according to claim 6, wherein According to the number of data points and distribution data of the clustering cluster, determining whether the network traffic data has abnormal clustering clusters includes: According to the number of data points of the clustering cluster and the total number of data points of the network traffic data, the proportion of the clustering cluster is obtained; According to the distribution data of the clustering cluster, the inter-cluster distance between every two clustering clusters is determined; When the inter-cluster distance between the clustering cluster and other clustering clusters all exceeds a preset distance threshold, and / or the proportion of the clustering cluster exceeds a preset proportion threshold, it is determined that the network traffic data has abnormal clustering clusters.
8. A power system data security analysis device, characterized in that, Including: A data acquisition unit for acquiring the operation data of the host in the current time period; A prediction unit for determining the security analysis strategy of the host in the future time period according to the operation data in the current time period through a machine learning algorithm; A feature extraction unit for acquiring the network traffic data of the host in the future time period according to the security analysis strategy and analyzing the network traffic data to obtain multiple data features of the network traffic data; A known attack feature judgment unit for judging whether the network traffic data has known attack features according to each data feature; If the network traffic data has the known attack features, it is determined that the network traffic data has an attack behavior; If the network traffic data does not have the known attack features, clustering analysis is performed on the network traffic data through an unsupervised machine learning algorithm to obtain a clustering result; An unknown attack feature judgment unit is configured to determine whether there are unknown attack features in the network traffic data according to the clustering result; if so, it is determined that there is an attack behavior in the network traffic data, and if not, it is determined that there is no attack behavior in the network traffic data.
9. An electronic device, characterized in that, It includes a computer-readable storage medium storing a computer program and a processor. When the computer program is read and run by the processor, the power system data security analysis method according to any one of claims 1-7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the power system data security analysis method according to any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Power Internet of Things intrusion detection method based on Snort
CN116599725A
Industrial control network APT attack detection system and method based on time sequence prediction
CN117354058A
Network intrusion attack identification system and method based on Internet of Things
CN118337540A
System and method for monitoring abnormal network traffic of class imbalance
CN119167122A
Network security defense method and system based on incremental network attack analysis learning
CN120200810A