Power system network attack consequence evaluation method considering switch modularization
Through modular switch modeling and double-layer offense and defense optimization model of the power system, the problem of insufficient protection of the power system when facing network attacks is solved, accurate evaluation and effective defense of complex attacks are achieved, and the system's security and response capabilities are improved.
Patent Information
- Application Number
- CN202510399343.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-01
AI Technical Summary
When facing cyber attacks, the protection mechanism of existing power systems is mainly designed for a single type of attack, and lacks the ability to protect against complex multi-level cyber attacks, and cannot deeply identify the vulnerability of key equipment in the site, resulting in insufficient accuracy and effectiveness of defense strategies.
The modular switch modeling method is adopted to modularly model key switching devices in the power system, combine network attack scenarios to quantify the impact of different attack methods on the system state, and simulate the strategic game between the attacker and the defender, solve the optimal attack path and defense configuration scheme, and build a double-layer offensive and defense optimization model to evaluate the risk and recovery time of the network attack.
It realizes accurate simulation and risk assessment of power system network attacks, identify potential vulnerable links and key nodes, optimizes defense strategies, and improves the system's security and emergency response efficiency.
Smart Images

Figure CN120337742A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system security protection and emergency response. Specifically, it relates to a method for evaluating the consequences of cyber attacks on a power system considering switch modularization. Background Art
[0002] With the rapid development and wide popularization of smart grids and energy Internet, the interaction between power device networks and communication networks has increased significantly. The core of smart grid technology lies in using advanced information and communication technology (ICT) to achieve the efficient, reliable, and economic operation of power systems. This naturally promotes the transformation of traditional power systems, forming a more compact and complex power-information physical system (Cyber-Physical System, CPS) between power device networks and information networks. However, this also provides potential entry points for cyber attackers.
[0003] With the increase in the interaction between information flow, control flow, and power flow, the security boundary of power systems has become more blurred. Any fault or attack in any link may trigger a chain reaction, affecting the stability and reliability of the entire system. Therefore, today's power systems still have the following two major problems when facing cyber attacks: First, the current protection mechanism is mainly designed for single-type cyber attacks and has deficiencies in the granularity of attack analysis, resulting in relatively weak protection capabilities when dealing with complex and multi-level cyber attacks; Second, in current research, the refined modeling method of switch modularization has not been adopted, resulting in the identification of vulnerable points being limited to the substation level and unable to deeply identify the vulnerabilities of key devices within the substation. This limitation makes the system lack a comprehensive ability to identify potential threats of attacks, thereby affecting the accuracy and effectiveness of defense strategies. Summary of the Invention
[0004] To solve the above problems, the purpose of the present invention is to provide a technology for evaluating the consequences of cyber attacks on a power system considering switch modularization, aiming to provide a scientific basis for the security protection and emergency response of power systems.
[0005] To achieve the above technical purpose, the present application provides a method for evaluating the consequences of cyber attacks on a power system considering switch modularization, including the following steps:
[0006] Perform modular modeling on key switch devices in the power system to clarify their functional logic and fault propagation paths;
[0007] Combine cyber attack scenarios to quantify the impact of different attack methods on the system state;
[0008] Solve the optimal attack path and generate a defense configuration plan by simulating the strategy game between attackers and defenders.
[0009] Preferably, in the process of quantifying the impact of different attack methods on the system state, by constructing a state transition model SMP of the attack path, the step-by-step probabilities of the attack probability and the recovery time are analyzed to quantify the impact of different attack methods on the system state.
[0010] Preferably, in the process of analyzing the step-by-step probabilities of the attack probability and the recovery time, the attack path is optimized, expressed as:
[0011]
[0012] In the formula, P path is related to the selection of the attack path; P time is the impact at the attack moment, indicating the impact of the selection of the attack timing on the success rate; P vulnerability represents the vulnerability probability at the i-th step of the attack path; γ·P defense (i,t) is the impact factor of the defense system, indicating the reaction of the defense intensity on the attack success probability.
[0013] Preferably, in the process of analyzing the step-by-step probabilities of the attack probability and the recovery time, the recovery time after the attack is expressed as:
[0014] ΔT = R t + D d + T trans + U t + C s
[0015]
[0016] In the formula, R is the response time factor, related to the dispatcher's detection of the attack, making corresponding responses, and allocating resources; T trans is the transmission delay factor; U t is the set of uncertain factors existing in the attack scenario; C s is the repair time when physical losses of the device may occur R t = R detect + R decision + R allocate is the sum of the dispatcher's detection, decision-making, and response times; T send + T prop + T process is the time consumed by communication transmission; U risk + U failure + U scenario is the impact time factor generated by different attack scenarios; T repair,max is the maximum repair time required to damage the device.
[0017] Preferably, in the process of simulating the strategic game between the attacker and the defender, by constructing a double-layer attack and defense optimization model, the upper-layer attacker optimizes the attack path to maximize the network risk, and the lower-layer defender adjusts resources to minimize the load loss, so as to simulate the process of the strategic game between the attacker and the defender.
[0018] Preferably, before the process of simulating the strategic game between the attacker and the defender, quantify the consequences of network attacks on the power system, and the quantification process is expressed as:
[0019] CR = P i ·(α·T i )·(β·D i )
[0020] Wherein, P i is the success probability of the i-th attack path; α·T i is the product of the recovery time required after the attack is successful and the weighting coefficient; β·D i is the product of the load shedding amount caused after the attack is successful and the weighting coefficient.
[0021] Preferably, when constructing the double-layer attack and defense optimization model, by modeling the attack logic of substations, IEDs and the lines they control, the constraint conditions are obtained as:
[0022] {a n , v e , w l} ∈ A
[0023]
[0024] Wherein, {a n , v e , w l} is the vector form of the attack decision vector of the substation, IED and line; A is the set of all possible attack decisions; o(l), d(l) represent the IEDs at both ends of line L; is the attack resource for the attacker to invade the substation, and K2 is the attack resource for the attacker to tamper with the IED device; The left side of the equation indicates that the number of IEDs controlled is not less than the number of successfully attacked substations, and the right side indicates the attack resource constraint; w l represents the binary variable of the line open circuit state, w l = 1 indicates that the line is open, w l = 0 indicates that the line is normal; ν e∈Ω(n) ≤ a n If the substation is not invaded, the IEDs inside the station will not be controlled; w l ≥ ν e=o(l) , w l ≥ ν e=d(l)It means that if any IEDs at both ends of the line are successfully attacked, the line will be disconnected; w l ≤ ν e=o(l) + ν e=d(l) It means that if both ends of the line are not attacked, it is safe; is the attack resource for the attacker to invade the power plant, and K4 is the attack resource for the attacker to control the unit equipment in the power plant; The left side means that the number of controlled units is not less than the number of successfully attacked substations, and the right side means the attack resource constraint; ν m∈Ω(g) ≤ a g If the substation is not invaded, the units in the station will not be controlled; It means that the substation is successfully attacked and the number of controlled units is greater than or equal to 1; ΔP g is the change in unit output, G unit,g represents the capacity of a single unit in the power plant.
[0025] Preferably, when constructing the attack-defense two-layer optimization model, the lower-layer defender model is expressed as:
[0026]
[0027] A BL · f l = A BG · P g - A BD ·( D d -Δ D d )
[0028]
[0029] In the formula, f l is the branch power flow; z l represents the line switching 0-1 variable, 1 means the line is connected, and 0 means the line is disconnected; b l is the admittance of line l; θ n is the voltage phase angle; is the node-branch incidence matrix; A BG is the node-generator incidence matrix; A BD is the node-load incidence matrix; P g is the generator output.
[0030] Preferably, when solving the optimal attack path and generating the defense configuration plan, the strong duality condition is used to transform the two-layer model into a single-layer model for solution, evaluate the risk of the attack path, and provide the optimal resource allocation plan for the defender according to the evaluation results.
[0031] The present invention also discloses a power system network attack consequence evaluation system considering switch modularization, which is used to implement a power system network attack consequence evaluation method considering switch modularization mentioned above, including:
[0032] A modeling module, which is used to perform modular modeling on key switch devices in the power system to clarify their functional logic and fault propagation paths;
[0033] A quantification module, which is used to quantify the impact of different attack methods on the system state in combination with network attack scenarios;
[0034] An evaluation module, which is used to solve the optimal attack path and generate a defense configuration plan by simulating the strategy game between the attacker and the defender.
[0035] The present invention discloses the following technical effects:
[0036] In the present invention, the core equipment in power plants and substations is divided into multiple modules according to the service logic and jurisdiction scope of switch control, which can more accurately simulate the impact of network attacks on the power system, help analyze the vulnerable links and key nodes of network attacks, and identify potential network attack paths and risks;
[0037] With the help of the SMP (Stochastic Markov Process) model, the present invention quantitatively evaluates the dynamic process of network attacks and their impact on the power system. This model can clearly describe the transition from the normal state to the fault state, reveal the state transition characteristics under different attack methods, so as to optimize the defense strategy and improve the response efficiency.
[0038] The present invention also combines the analysis of each sub-step of the attack probability and the recovery time model to comprehensively evaluate the attack success probability and recovery efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0040] Figure 1 is the wiring diagram of primary equipment in the substation described in the present invention;
[0041] Figure 2 is the substation module division and typical attack use cases described in the present invention;
[0042] Figure 3 is the power plant module division and typical attack use cases described in the present invention;
[0043] Figure 4 is the traditional SMP model described in the present invention;
[0044] Figure 5 is the SMP model of man-in-the-middle attack described in the present invention;
[0045] Figure 6 is the overall model flow chart described in the present invention. Detailed implementation manners
[0046] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only some of the embodiments of the present application, rather than all of the embodiments. Components of the embodiments of the present application described and illustrated herein generally may be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but is merely representative of selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts fall within the scope of protection of the present application.
[0047] As Figures 1-6 shown, the present invention provides a method for evaluating the consequences of network attacks on a power system considering switch modularization. First, modular modeling is performed on key switch devices in the power system to clarify their functional logic and fault propagation paths; then, combined with network attack scenarios, a state transition model (SMP) of the attack path is constructed to quantify the impact of different attack methods on the system state, evaluate the attack success probability, recovery time and potential damage, and provide a quantitative risk assessment basis for the system. Finally, through a two-layer optimization model, the strategy games of the attacker and the defender are respectively simulated, and the optimal attack path and defense configuration plan are solved to realize the identification of high-risk components and the quantification analysis of consequences under attacks for typical power plants and substations, providing a theoretical basis and decision support for the security defense strategy of the power system; specifically including the following steps:
[0048] Step 1: Substation and plant module division. The power system is subdivided into key modules through switch modular modeling to clarify its structure and logical relationship.
[0049] Step 2: Network attack path modeling. Combining the SMP model to describe the dynamic interaction between modules to clarify the attack path and key nodes.
[0050] Step 3: Analysis of attack probability and recovery time. Quantify the success probability of each sub-step of the attack, and analyze the system recovery time in combination with response, repair and transmission delays.
[0051] Step 4: Analyze the consequences of network attacks to assist the subsequent double-layer model in identifying vulnerable points.
[0052] Step 5: Construct an upper and lower layer optimization model for attack and defense. The upper layer attacker optimizes the attack path to maximize network risk, and the lower layer defender adjusts resources to minimize load loss.
[0053] Step 6: Solve the optimization model. The finally obtained single-layer mixed-integer linear programming model can be directly solved to obtain the optimal attack strategy and defense measures.
[0054] Example: 1. Modeling of network attack paths:
[0055] 1.1 Modular modeling of switches:
[0056] In the power system, the particularity of network attacks lies in their ability to precisely intervene in the control layer. By invading the network of power plants or control centers, attackers can accurately locate and manipulate key devices such as switches and circuit breakers, thereby achieving precise damage to the power transmission path and posing a serious threat to the operation stability and power supply security of the system. For example, in a substation, attackers can manipulate key devices such as external transmission lines, high-voltage side incoming modules, circuit breaker groups, transformers, and low-voltage side outgoing modules, resulting in power transmission interruption or anomalies. The following is the wiring method of a common substation.
[0057] To more effectively analyze and respond to potential network attacks, using a modular classification method helps to refine the system structure and provides a clear framework for system security assessment and fault response. In this context, the modular classification of power plants and substations can not only clarify the functions and roles of each link but also provide an effective reference basis for formulating protection and control strategies. By carefully dividing multiple modules such as communication modules, control modules, measurement and control modules, protection and automation modules, and generator set modules, it is possible to assist in analyzing the possible intrusion paths and potential risk points of attackers, thereby enhancing the protection ability and response efficiency of the power system. A typical substation / power plant can be divided into the following key modules, as Figures 2-3 shown.
[0058] 1.2 Markov process (SMP) model of network attack paths:
[0059] Network attacks usually manifest as an orderly step-by-step intrusion process. Attackers need to pass through a series of precise steps to gradually penetrate each link of the power system. In this process, the success of each step not only depends on the conditions of the previous step, but also the attack paths and strategies tend to be gradually refined and in-depth.
[0060]
[0061] Where Pattack,success Denotes the probability of the attacker achieving the goal; P step,i Is the attack probability for each step of the intrusion;
[0062] To quantify the impact of a cyber attack on the power system, the SMP (State-Machine-Based Protocol) model is used to describe the attacker's behavior. The Markov process (SMP) model is as Figures 4-5 shown and consists of multiple states. The first state G represents the normal or secure state of the SCADA system. The second process describes the intrusion process of the SCADA system, which is divided into multiple stages, with each stage representing a step of the attack. The attacker sequentially executes attack actions, gradually elevates privileges, and sends a trip command to the intelligent devices in the substation. Finally, the F state represents the fault state, describing the fault of the substation SCADA system. In the SMP model, the state G and the intrusion process are regarded as transient states, while the fault state F is an absorbing state. Determining whether a state is transient or absorbing depends on the way and type of the attack.
[0063] The following introduces a classic cyber attack path model, the man-in-the-middle attack (MITM) model. A MITM attack refers to an attacker intercepting and modifying traffic between two hosts without being detected by the victim. For example, the attacker can intercept and modify the information in the application service data unit (ASDU). In this way, the attacker may trip the generators or transmission line circuit breakers in the power plant / substation. One specific type of MITM attack is the SSL MITM attack. When the user and the application do not correctly verify the server certificate, the SSL connection is vulnerable to a MITM attack. The attacker intercepts the communication between the client and the server, forges an identity, and tampers with the data. The SSL MITM attack is usually divided into three stages:
[0064] 1. The attacker's proxy intercepts the SSL handshake process between the client and the server and obtains the key.
[0065] 2. The attacker replaces it with a malicious key and forges the identities of the client and the server in the SSL session.
[0066] 3. The attacker replaces the public key or the private key during the key exchange process, can read and control the data between the client and the server, causing the key components of the system to malfunction or refuse to operate.
[0067] The probability of the overall attack success can be calculated by the product of the success probabilities of each stage, as shown in formula (1).
[0068] 1.3. Analysis of the probabilities of each step of the attack probability and the recovery time:
[0069] Cyber attacks are usually carried out step by step. That is, the attacker advances gradually, with different goals, methods, and required resources at each step. At each stage, the attacker adopts different strategies according to the current security protection level and system vulnerabilities, gradually achieving control over the target system. Each stage of the attack may introduce new risks and complexities, and the attacker needs to evaluate the success probability and cost of each step and optimize the attack path.
[0070]
[0071] Where P path is related to the choice of the attack path;
[0072] P time represents the impact at the attack moment, indicating the influence of the choice of attack timing on the success rate;
[0073] P vulnerability represents the vulnerability probability at the i-th step of the attack path, such as the vulnerability of each component in the path;
[0074] γ·P defense (i,t) is the influence factor of the defense system, indicating the reverse effect of the defense intensity on the attack success probability. If the defense system is very strong, the attack success probability will drop significantly.
[0075] To comprehensively evaluate the impact of cyber attacks, not only the attack success probability and damage degree need to be concerned, but also the recovery time after the attack must be considered.
[0076] ΔT = R t + D d + T trans + U t + C s (3)
[0077] Where R is the response time factor, related to the dispatcher's perception of the attack, making corresponding actions, and allocating resources;
[0078] T trans is the transmission delay factor;
[0079] U t is the set of uncertain factors existing in the attack scenario;
[0080] C s is the repair time when physical losses of equipment may occur.
[0081]
[0082] Where R t = R detect + R decision + R allocateIt is the sum of the detection, decision-making, and response times of the dispatching party;
[0083] T send +T prop +T process It is the time consumed by communication transmission;
[0084] U risk +U failure +U scenario They are the impact time factors generated by different attack scenarios;
[0085] T repair,max It is the maximum repair time required to damage the equipment.
[0086] 2. Double-layer optimization model considering attack recovery time:
[0087] In the network attack and defense double-layer optimization model in this patent, the consequences of an attack are mainly quantified by two factors: the load shedding amount and the power outage time. The load shedding amount refers to the power load demand that cannot be met due to an attack, and the power outage time is the time experienced by the system from the occurrence of an attack to the restoration of normal power supply. Therefore, the comprehensive evaluation of the attack consequences can be expressed as the product of the load shedding amount and the power outage time, which reflects the actual impact degree and economic loss of the attack on the power system. Further, the risk of a network attack can be measured by the product of the attack success probability, the load shedding amount, and the power outage time. The probability of attack success determines the likelihood of the occurrence of the attack event, while the load shedding amount and the power outage time determine the specific damage degree to the system after the attack is successful. In this way, the model can not only evaluate the severity of the attack but also provide a quantitative basis for the optimization of defense strategies, thereby effectively improving the power system's ability to respond to potential network attacks.
[0088] 2.1 Analysis of network attack consequences:
[0089] Based on the previous detailed discussion of the potential threats to the power system after a network attack, especially the analysis of different attack paths, the present invention will further elaborate on the specific consequences of a network attack on the power system. The evaluation of the attack consequences needs to comprehensively consider the results of different attack paths, including factors such as the attack probability, load shedding amount, and power outage time of the power system after being attacked. To quantify these consequences, the following mathematical model is proposed:
[0090] CR = P i ·(α·T i )·(β·D i ) (5)
[0091] Where P i is the success probability of the i-th attack path;
[0092] α·Ti It is the product of the recovery time required after a successful attack and the weighting coefficient;
[0093] β·D i It is the product of the load shedding amount caused after a successful attack and the weighting coefficient;
[0094] By evaluating the consequences of attacks, it can provide a basis for subsequent defense strategies.
[0095] 2.2. Double - layer optimization model for attack and defense:
[0096] Through the above - mentioned analysis of the consequences of network attacks, potential risks existing in the system can be identified. The present invention further accurately identifies the vulnerable points in network attacks. In the power system, it is necessary to deeply explore specific attack paths and core devices to enhance the defense ability.
[0097] Based on the diagrams of switch modularization mentioned above, this patent selects a specific network attack scenario for analysis among these typical scenarios: that is, the attacker invades the supply chain of a power plant or a substation, obtains control authority, and then uses intelligent electronic devices (IEDs) to issue false commands, resulting in the tripping of lines or the shutdown of units. And its potential consequences are deeply explored, especially in the evaluation of influencing factors such as the load shedding amount and power outage time in the power system.
[0098] According to the IEEE1686 protocol, each IED has a corresponding password. Different from invading the control center, after the attacker invades the substation, they still need to crack the corresponding password to continue obtaining the control authority of the IEDs in the substation.
[0099] When the attacker chooses to invade the central dispatching center or the regional dispatching center, in this scenario, assuming a successful invasion, the attacker can cause all intelligent IEDs to disconnect for the maximum possible effect.
[0100] When the attacker chooses to invade the IEDs of each plant station, in this scenario, the successful invasion probabilities of different plant stations are independent of each other, and the cracking of the permissions of each IED after invading the substation is also conditionally independent. Therefore, the probability of invading a certain plant station and obtaining the control authority of each IED satisfies the following formula:
[0101] P(I1,...,I e |F n )=P(I1|F n )·...·P(I e |F n ) (6)
[0102] In the formula, e is the index of the IEDs in the substation;
[0103] I1,F nis a discrete random variable;
[0104] represents the probability that the e-th IED under the substation located at node n is successfully invaded;
[0105] P(I1,...,I e |F n ) represents the probability of successfully controlling e IEDs.
[0106] The network risk of the power system can be defined as:
[0107]
[0108] where h represents the probability that h IEDs in each substation are successfully controlled;
[0109] P is the probability of successful attack on substation n;
[0110] ΔD is the load shedding caused by the abnormal state of the controlled IED;
[0111] ΔT represents the recovery time required after the component refuses to operate due to a cyber attack.
[0112] The objective function of the upper-layer attacker model is to maximize the network risk CR:
[0113]
[0114] where a n ,ν e respectively represent the binary variables indicating whether the substation and the IED are attacked. If a n =1,ν e =1, it means that the corresponding substation n is attacked and the IEDe is attacked;
[0115] Ω(n) represents the set of all IEDs installed in substation n;
[0116] ΔT represents the recovery time required after the component refuses to operate due to a cyber attack.
[0117] Constraint conditions: Modeling the attack logic of substations, IEDs, and the lines they control:
[0118] {a n ,v e ,w l}∈A(9)
[0119]
[0120] where, {a n ,v e ,w l} is the vector form of the attack decision vectors for substations, IEDs, and lines, and A is the set of all possible attack decisions; o(l) and d(l) represent the IEDs at both ends of line L. is the attack resource for the attacker to invade the substation, and K2 is the attack resource for the attacker to tamper with the IED device. The left side indicates that the number of controlled IEDs is not less than the number of successfully attacked substations, and the right side represents the attack resource constraint; w l is a binary variable representing the line open - circuit state, w l = 1 indicates that the line is disconnected, w l = 0 indicates that the line is normal; ν e∈Ω(n) ≤ a n If the substation is not invaded, the IEDs inside the station will not be controlled; w l ≥ ν e=o(l) , w l ≥ ν e=d(l) indicates that if any IED at both ends of the line is successfully attacked, the line will be disconnected; w l ≤ ν e=o(l) + ν e=d(l) indicates that if both ends of the line are not attacked, it is safe. is the attack resource for the attacker to invade the power plant, and K4 is the attack resource for the attacker to control the unit equipment inside the power plant. The left side indicates that the number of controlled units is not less than the number of successfully attacked substations, and the right side represents the attack resource constraint; ν m∈Ω(g) ≤ a g If the substation is not invaded, the units inside the station will not be controlled. indicates that the substation is successfully attacked and the number of controlled units is greater than or equal to 1; ΔP g is the change in unit output, G unit,g represents the capacity of a single unit in the power plant
[0121] Lower - layer defender model:
[0122]
[0123] The lower - layer model simulates the role of the dispatcher, adjusting generator output, adjusting line topology, and shedding loads that cannot be satisfied, with the goal of minimizing the system load shedding loss.
[0124] In the formula, f l is the branch power flow; z l represents the line switching 0 - 1 variable, 1 indicates the line is connected, and 0 indicates the line is disconnected; b l is the admittance of line l; θ n is the voltage phase angle; is the node - branch incidence matrix; A BG is the node - generator incidence matrix; ABD is the node load incidence matrix; P g is the generator output.
[0125] 2.3 Solution method:
[0126] For a two - layer mixed - integer programming model, if the lower layer is a linear programming problem, the KKT conditions or the strong duality conditions are usually used to transform the two - layer model into a single - layer model for solution. This patent uses the strong duality conditions for transformation.
[0127] First, linearize the objective function by taking the logarithm:
[0128]
[0129] σ = log(ΔD) (12)
[0130] Furthermore, log(ΔD) can be piece - wise linearized as follows:
[0131]
[0132] where λ t and c are consecutive variables introduced for auxiliary piece - wise linearization, σ t is the endpoint value of the piece - wise linearization function, and t is the piece - wise index.
[0133] Since the lower - layer scheduling model is a linear programming problem, the original two - layer model can be transformed into a single - layer model by adding the dual constraints of the lower - layer model and the strong duality conditions:
[0134]
[0135] {a n , v e , w l} ∈ A(15)
[0136]
[0137] where u l , λ n , w l , β g , δ a , are the dual variables of the constraints in {a n , v e , w l} ∈ A; w l ·θ n , w l·u l It can be linearized by the Big M method:
[0138]
[0139] In the formula, z1 is the introduced auxiliary continuous variable; the larger the value of M, the higher the solution accuracy. The single-layer mixed-integer linear programming model at this time can directly solve the system vulnerability points.
[0140] The present invention uses a two-layer optimization model to analyze network attack scenarios, and models the attacker and the defender respectively. The attacker model helps to identify the best attack path, evaluate the IED / unit control authority and network risks; the defender model minimizes the load loss by adjusting the generator output and line topology, and enhances the system's anti-attack ability. Using the strong duality condition, the two-layer model is transformed into a single-layer model, which simplifies the solution process and improves the efficiency. By linearizing the objective function and introducing auxiliary variables, the model can effectively handle complex attack and defense decisions.
[0141] Furthermore, the present invention details the modeling of the attack scenarios of substation IED / power plant unit equipment tampering, quantifies the intrusion probability and system risks, and provides a scientific risk assessment basis for the defender. Finally, considering the resource constraints of the attacker, the model can accurately calculate the attack path risk, provide the defender with an optimal resource allocation plan, and achieve the maximum benefit with a limited defense budget.
[0142] Generally speaking, through accurate modeling, simplified solution and quantitative evaluation, the present invention provides a comprehensive network attack protection scheme for the power system, improves the security and optimizes the resource allocation.
[0143] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0144] In the description of the present invention, it should be understood that the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality of" means two or more unless otherwise specifically defined.
[0145] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.
Claims
1. A method for evaluating the consequences of cyber-attacks on a power system considering switch modularity, characterized in that, It includes the following steps: Modularly model the key switch equipment in the power system to clarify its functional logic and fault propagation path; Combine network attack scenarios to quantify the impact of different attack methods on the system state; Through simulating the strategic game between the attacker and the defender, solve the optimal attack path and generate a defense configuration plan.
2. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 1, characterized in that: In the process of quantifying the impact of different attack methods on the system state, by constructing a state transition model SMP of the attack path, analyze the probability of each sub-step of the attack probability and the recovery time to quantify the impact of different attack methods on the system state.
3. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 2, characterized in that: In the process of analyzing the probability of each sub-step of the attack probability and the recovery time, optimize the attack path, which is expressed as: where P path is related to the selection of the attack path; P time represents the influence at the attack moment, indicating the influence of the attack timing selection on the success rate; P vulnerability represents the vulnerability probability at the i-th step of the attack path; γ·P defense (i,t) is the influence factor of the defense system, indicating the counteraction of the defense intensity on the attack success probability.
4. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 3, characterized in that: In the process of analyzing the probability of each sub-step of the attack probability and the recovery time, the recovery time after the attack is expressed as: ΔT = R t + D d + T trans + U t + C s Wherein, R is the response time factor, which is related to the dispatcher's perception of the attack, making a response, and allocating resources; T trans is the transmission delay factor; U t is the set of uncertain factors existing in the attack scenario; C s is the repair time R when physical losses of the equipment may be caused t = R detect + R decision + R allocate is the sum of the dispatcher's perception, decision-making, and response times; T send + T prop + T process is the time consumed by communication transmission; U risk + U failure + U scenario is the impact time factor generated by different attack scenarios; T repair,max is the maximum repair time required to damage the equipment.
5. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 4, characterized in that: In the process of simulating the strategic game between the attacker and the defender, by constructing a two-layer attack and defense optimization model, use the upper-layer attacker to optimize the attack path to maximize the network risk, and use the lower-layer defender to adjust resources to minimize the load loss to simulate the strategic game process between the attacker and the defender.
6. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 5, characterized in that: Before the process of simulating the strategic game between the attacker and the defender, quantify the consequences of network attacks on the power system, and the quantification process is expressed as: CR = P i ·(α·T i )·(β·D i ) Where P i is the success probability of the i-th attack path; α·T i is the product of the recovery time required after a successful attack and the weighting coefficient; β·D i is the product of the load shedding amount caused after a successful attack and the weighting coefficient.
7. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 6, characterized in that: When constructing a two-layer attack and defense optimization model, by modeling the attack logic of substations, IEDs and the lines they control, the obtained constraint conditions are: {a n , v e , w l} ∈ A where {a n , v e , w l} is the vector form of the attack decision vectors of the substation, IED, and line; A is the set of all possible attack decisions; o(l) and d(l) represent the IEDs at both ends of line L; is the attack resource for the attacker to invade the substation, and K2 is the attack resource for the attacker to tamper with the IED device; The left side of the equation indicates that the number of IEDs controlled is not less than the number of successfully attacked substations, and the right side indicates the attack resource constraint; w l represents the binary variable of the line open - circuit state. w l = 1 indicates that the line is open, and w l = 0 indicates that the line is normal; ν e∈Ω(n) ≤a n If the substation is not invaded, the IEDs inside the station will not be controlled; w l ≥ν e=o(l) , w l ≥ν e=d(l) Indicates that if any IEDs at both ends of the line are successfully attacked, the line will be disconnected; w l ≤ν e=o(l) +ν e=d(l) Indicates that if both ends of the line are not attacked, it is safe; is the attack resource for the attacker to invade the power plant, and K4 is the attack resource for the attacker to control the unit equipment in the power plant; The left formula indicates that the number of controlled units is not less than the number of successfully attacked substations, and the right formula indicates the attack resource constraint; ν m∈Ω(g) ≤a g If the substation is not invaded, the units inside the station will not be controlled; Indicates that the substation is successfully attacked and the number of controlled units is greater than or equal to 1; ΔP g is the change in unit output, G unit,g Indicates the capacity of a single unit in the power plant.
8. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 7, characterized in that: When constructing a two-layer attack and defense optimization model, the lower-layer defender model is expressed as: A BL ·f l = A BG ·P g - A BD ·(D d - ΔD d ) where f l is the branch power flow; z l represents the line switching 0-1 variable, 1 means the line is connected, and 0 means the line is disconnected; b l is the admittance of line l; θ n is the voltage phase angle; is the node-branch incidence matrix; A BG is the node-generator incidence matrix; A BD is the node-load incidence matrix; P g is the generator output.
9. The method for evaluating the consequences of network attacks on a power system considering switch modularity according to claim 8, characterized in that: When solving the optimal attack path and generating a defense configuration plan, use the strong duality condition to transform the two-layer model into a single-layer model for solution, evaluate the risk of the attack path, and based on the evaluation results, provide the defender with an optimal resource allocation plan.
10. A power system network attack consequence assessment system considering switch modularity, which is used to implement a power system network attack consequence assessment method considering switch modularity as described in claim 1, characterized in that, It includes: A modeling module for modularly modeling the key switch equipment in the power system to clarify its functional logic and fault propagation path; A quantification module for combining network attack scenarios to quantify the impact of different attack methods on the system state; An evaluation module, which is used to solve the optimal attack path and generate a defense configuration plan by simulating the strategic game between the attacker and the defender.
Citation Information
Patent Citations
Power distribution network risk assessment method based on random game network under network attack
CN112819300A
Network security protection security method and system based on unit cell
CN114978584A
Defense method for dynamic network attack of power system
CN115065499A
Power system attack risk assessment method based on multi-scene distribution
CN119011220A
Game theoretic recommendation system and method for security alert dissemination
EP2271047A1