A method for assessing consequences of cyber attacks on power system networks considering switching modularization
By modularly modeling and optimizing the attack and defense two-layer model for key switching equipment in the power system, the problem of insufficient protection capability of the power system against complex network attacks in the existing technology is solved. It realizes accurate simulation and risk assessment of network attacks on the power system, optimizes the defense strategy, and improves the system's protection capability and response efficiency.
Patent Information
- Application Number
- CN202510399343.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-04-01
AI Technical Summary
Existing power system protection mechanisms are mainly designed for single types of network attacks, and lack sufficient granularity in attack analysis, failing to deeply identify the vulnerabilities of critical equipment within the substation. This results in weak protection against complex, multi-layered network attacks, and the failure to adopt a refined modeling method based on switch modules affects the accuracy and effectiveness of defense strategies.
By modularly modeling key switching equipment in the power system and combining it with network attack scenarios, the impact of different attack methods on the system state is quantified. Furthermore, by simulating the strategic game between attackers and defenders, the optimal attack path and defense configuration scheme are solved, and a two-layer attack and defense optimization model is constructed to evaluate the consequences of network attacks.
It enables accurate simulation and risk assessment of network attacks on power systems, identifies potential vulnerabilities, optimizes defense strategies, and improves the system's protection capabilities and response efficiency.
Smart Images

Figure CN120337742B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power system security protection and emergency response, and particularly relates to a power system network attack consequence evaluation method considering switch modularization. BACKGROUND
[0002] With the rapid development and wide popularization of smart grid and energy internet, the interaction between power equipment network and communication network has significantly increased. The core of smart grid technology is to realize the efficient, reliable and economic operation of power system by using advanced information communication technology (ICT). This naturally promotes the transformation of traditional power system, and forms a more close and complex cyber-physical system (CPS) between power equipment network and information network. However, this also provides potential entry points for network attackers.
[0003] With the increase of interaction between information flow, control flow and power flow, the security boundary of power system becomes more blurred, and the failure or attack of any link may trigger a chain reaction, affecting the stability and reliability of the whole system. Therefore, the current power system still has the following two problems when facing network attacks: first, the current protection mechanism is mainly designed for single type of network attack, and there is a lack of attack analysis granularity, which leads to weak protection ability when dealing with complex and multi-level network attacks; second, in the current research, the switch modularization refinement modeling method is not used, which leads to the identification of vulnerable points being limited to the station level, and the vulnerability of key equipment in the station cannot be further identified. This limitation makes the system lack comprehensive identification ability for potential threats of attacks, and further affects the accuracy and effectiveness of defense strategies. SUMMARY
[0004] In order to solve the above problems, the purpose of the present application is to provide a power system network attack consequence evaluation technology considering switch modularization, which aims to provide a scientific basis for the security protection and emergency response of power system.
[0005] In order to achieve the above technical purpose, the present application provides a power system network attack consequence evaluation method considering switch modularization, which comprises the following steps:
[0006] The key switch equipment in the power system is modeled modularly, and the function logic and fault propagation path are determined;
[0007] In combination with the network attack scene, the influence of different attack modes on the system state is quantified;
[0008] By simulating the strategy game between the attacker and the defender, the optimal attack path is solved and the defense configuration scheme is generated.
[0009] Preferably, in the process of quantifying the influence of different attack modes on system state, the attack probability step-by-step probability and recovery time analysis is carried out by constructing the state transition model SMP of the attack path to quantify the influence of different attack modes on system state.
[0010] Preferably, in the process of attack probability step-by-step probability and recovery time analysis, the attack path is optimized, which is expressed as:
[0011]
[0012] In the formula, P path is related to the selection of the attack path; P time is the influence at the attack time, indicating the influence of the selection of attack opportunity on the success rate; P vulnerability is the vulnerability probability at the i-th step of the attack path; γ·P defense is the influence factor of the defense system, indicating the counteraction of the defense strength on the attack success probability.
[0013] Preferably, in the process of attack probability step-by-step probability and recovery time analysis, the recovery time after attack is expressed as:
[0014] ΔT = R t + D d + T trans + U t + C s
[0015]
[0016] In the formula, R is the response time factor, which is related to the awareness of the attack by the dispatcher, the corresponding response, and the allocation of resources; T trans is the transmission delay factor; U t is the set of uncertain factors existing in the attack scenario; C s is the repair time R t when possible physical loss of equipment occurs; R detect + R decision + R allocate is the sum of the awareness, decision-making, and response time of the dispatcher; T send + T prop + T process is the time consumed by communication transmission; U risk + U failure + U scenario is the influence time factor generated by different attack scenarios; T repair,max is the maximum repair time required for damaged equipment.
[0017] Preferably, in the process of simulating the strategy game between the attacker and the defender, an attack-defense double-layer optimization model is built to simulate the process of the strategy game between the attacker and the defender, in which the upper-layer attacker optimizes the attack path to maximize the network risk, and the lower-layer defender adjusts the resources to minimize the load loss.
[0018] Preferably, before the process of simulating the strategy game between the attacker and the defender, the consequences of the network attack on the power system are quantified, and the quantification process is represented as:
[0019] CR = P i · (a · T i ) · (b · D i )
[0020] In the formula, P i is the success probability of the i th attack path; a · T i is the product of the recovery time required after the attack succeeds and the weighting coefficient; b · D i is the product of the amount of cut load caused after the attack succeeds and the weighting coefficient.
[0021] Preferably, when the attack-defense double-layer optimization model is built, the constraint condition is obtained by modeling the substation, IED, and line attack logic controlled thereby as:
[0022] {a n ,v e ,w l} e A
[0023]
[0024] In the formula, {a n ,v e ,w l} is a vector form of the substation, IED, and line attack decision vector; A is a set of all possible attack decisions; o (l), d (l) represent the IEDs of two sections of the line L; K1 is the attack resource of the attacker invading the substation, and K2 is the attack resource of the attacker tampering with the IED device; The left formula indicates that the number of IEDs controlled will not be less than the number of substations attacked successfully, and the right formula indicates the attack resource constraint; w l represents a binary variable of the line open state, w l = 1 indicates that the line is disconnected, and w l = 0 indicates that the line is normal; v e∈Ω(n) ≤ a n If the substation is not invaded, the IED in the substation will not be controlled; w l ≥ v e=o(l) , w l ≥ v e=d(l)If any IED at both ends of the line is successfully attacked, the line will be disconnected; w l ≤v e=o(l) +v e=d(l) If no IED at both ends of the line is attacked, the line is safe. K4 is the attack resource of the attacker to control the unit equipment in the power plant; The left formula indicates that the number of units controlled will not be less than the number of substations successfully attacked, and the right formula indicates the attack resource constraint; v m∈Ω(g) ≤a g If the substation is not invaded, the units in the substation will not be controlled. It indicates that the attack on the substation is successful, and the number of unit controls is greater than or equal to 1; ΔP g is the unit power change, G unit,g represents the capacity of a single unit in the power plant.
[0025] Preferably, in constructing the attack-defense two-layer optimization model, the lower-layer defender model is represented as:
[0026]
[0027] A BL ·f l =A BG ·P g -A BD ·(D d -ΔD d )
[0028]
[0029] In the formula, f l is the branch power flow; z l represents a 0-1 variable for line switching, 1 indicating that the line is connected, and 0 indicating that the line is disconnected; b l is the admittance of line l; θ n is the voltage phase angle; is the node-branch incidence matrix; A BG is the node-generator incidence matrix; A BD is the node-load incidence matrix; P g is the generator power.
[0030] Preferably, in solving the optimal attack path and generating the defense configuration scheme, the strong duality condition is used to convert the two-layer model into a single-layer model for solving, the attack path risk is evaluated, and the optimal resource configuration scheme is provided for the defender according to the evaluation result.
[0031] The application further discloses a power system network attack consequence assessment system considering switch modularization, which is used for realizing the power system network attack consequence assessment method considering switch modularization.
[0032] A modeling module is used for modularly modeling key switch devices in the power system, and explicitly functions logic and fault propagation paths thereof;
[0033] A quantifying module is used for quantifying influences of different attack modes on system states in combination with network attack scenes;
[0034] An assessment module is used for solving an optimal attack path and generating a defense configuration scheme by simulating strategy game between an attacker and a defender.
[0035] The application discloses the following technical effects:
[0036] The application divides core devices in a power plant and a substation into multiple modules according to business logic and jurisdiction ranges of switch control, can more accurately simulate influences of network attacks on the power system, is helpful for analyzing vulnerable links and key nodes of the network attacks, and identifies potential network attack paths and risks.
[0037] The application quantitatively evaluates a dynamic process of the network attacks and influences of the network attacks on the power system by means of an SMP (Stochastic Markov Process) model, which can clearly describe transitions from a normal state to a fault state, and reveal state transition characteristics under different attack modes, so as to optimize a defense strategy and improve response efficiency.
[0038] The application further combines attack probability step-by-step analysis and a recovery time model, and comprehensively evaluates attack success probability and recovery efficiency. DETAILED DESCRIPTION
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can be obtained from these drawings without creative labor.
[0040] Figure 1 is a primary equipment wiring diagram of a substation according to the application;
[0041] Figure 2 is substation module division and a typical attack use case according to the application;
[0042] Figure 3 is power plant module division and a typical attack use case according to the application;
[0043] Figure 4 is a conventional SMP model described in the present application;
[0044] Figure 5 is an SMP model of a man-in-the-middle attack described in the present application;
[0045] Figure 6 is an overall model flowchart described in the present application. DETAILED DESCRIPTION
[0046] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. The components of the embodiments of the present application described and shown in the drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work belong to the scope of protection of the present application.
[0047] As shown in Figures 1-6 , the present application provides a power system network attack consequence evaluation method considering switch modularization. Firstly, the key switch devices in the power system are modeled modularly to clearly define their function logic and fault propagation path. Then, in combination with a network attack scene, a state transition model (SMP) of the attack path is constructed to quantify the influence of different attack modes on the system state, evaluate the attack success probability, recovery time and potential damage, and provide a quantitative risk evaluation basis for the system. Finally, through a double-layer optimization model, the strategy game of the attacker and the defender is simulated respectively to solve the optimal attack path and defense configuration scheme, realize the high-risk element identification and consequence quantization analysis of the typical power plant and substation under attack, and provide a theoretical basis and decision support for the security defense strategy of the power system; specifically including the following steps:
[0048] Step 1: Plant and substation module division. The power system is subdivided into key modules through switch modularization modeling to clearly define their structure and logical relationship.
[0049] Step 2: Network attack path modeling. The dynamic interaction between modules is described in combination with the SMP model to clearly define the attack path and key nodes.
[0050] Step 3: Attack probability and recovery time analysis. The success probability of each attack step is quantified, and the system recovery time is analyzed in combination with the response, repair and transmission delay.
[0051] Step 4: Network attack consequence analysis, helping the subsequent bi-level model to identify vulnerable points.
[0052] Step 5: Constructing a bi-level attack-defense optimization model, the upper layer attacker optimizes the attack path to maximize network risk, and the lower layer defender adjusts resources to minimize load loss.
[0053] Step 6: Solve the optimization model, the final single-layer mixed integer linear programming model can be directly solved to obtain the optimal attack strategy and defense measures.
[0054] Embodiment: 1, network attack path modeling:
[0055] 1.1, Switch modular modeling:
[0056] In the power system, the particularity of network attack is that it can accurately intervene in the control layer. Attackers can precisely locate and control key devices such as switches, circuit breakers, etc. by hacking the network of power plants or control centers, and then achieve precise destruction of power transmission paths, causing serious threats to system operation stability and power supply safety. For example, in a substation, attackers can control key devices such as external power transmission lines, high-voltage side incoming line modules, circuit breaker groups, transformers, and low-voltage side outgoing line modules, causing power transmission interruption or abnormality. The following is a common substation wiring method.
[0057] In order to more effectively analyze and respond to potential network attacks, a modular classification method can help to refine the system structure and provide a clear framework for system security evaluation and fault response. In this context, the modular classification of power plants and substations can not only clarify the function and role of each link, but also provide effective reference for the formulation of protection and control strategies. By classifying multiple modules such as communication modules, control modules, measurement and control modules, protection and automation modules, and generator set modules, it can help analyze the possible intrusion path and potential risk points of attackers, thereby improving the protection capability and response efficiency of the power system. A typical substation / power plant can be divided into the following key modules, as shown in the figure. Figures 2-3
[0058] 1.2, Markov process (SMP) model of network attack path:
[0059] Network attacks usually exhibit a sequential and step-by-step intrusion process, where attackers need to penetrate each link of the power system through a series of precise steps. In this process, the success of each step depends not only on the previous step, but also on the gradual refinement and deepening of the attack path and strategy.
[0060]
[0061] where Pattack,success represents the probability of achieving the attacker's goal; P step,i is the attack probability for each step of the intrusion;
[0062] To quantify the impact of cyber attacks on power systems, a SMP (State-Machine-Based Protocol) model is used to describe the behavior of attackers. The SMP model, as shown in Figures 4-5 , consists of multiple states. The first state G represents the normal or secure state of the SCADA system. The second process describes the intrusion process of the SCADA system, which is divided into multiple stages, each representing a step of the attack. The attacker gradually enhances the authority by sequentially executing attack actions and sends trip commands to intelligent devices in the substation. Finally, the F state represents the fault state, which describes the failure of the substation SCADA system. In the SMP model, the states G and the intrusion process are considered as transient states, while the fault state F is an absorbing state. Whether a state is transient or absorbing depends on the way and type of attack.
[0063] A classic model of network attack path, MITM (Man-in-the-Middle) attack, is introduced below. MITM attack refers to the interception and modification of traffic between two hosts by an attacker without being detected by the victim. For example, the attacker can intercept and modify the information in the Application Service Data Unit (ASDU). In this way, the attacker may trip the generator or transmission line circuit breaker in the power plant / substation. One specific MITM attack is the SSL MITM attack. When the user and the application do not properly verify the server certificate, the SSL connection is vulnerable to MITM attacks. The attacker intercepts the communication between the client and the server, forges the identity and tampers with the data. The SSL MITM attack is usually divided into three stages:
[0064] 1. The attacker proxies the SSL handshake process between the client and the server and obtains the key.
[0065] 2. The attacker replaces the malicious key, forging the identity of the client and server in the SSL session.
[0066] 3. The attacker replaces the public key or private key in the key exchange process, enabling the attacker to read and control the data between the client and the server, causing the system critical components to malfunction or refuse to operate.
[0067] The overall success probability of the attack can be calculated by multiplying the success probability of each stage, as shown in equation (1).
[0068] 1.3, Attack probability analysis of each step and recovery time:
[0069] Network attacks are usually step-by-step, with attackers advancing step by step, each step targeting, method, and required resources are different. At each stage, the attacker takes different strategies according to the current security protection level and system vulnerabilities, and gradually realizes the control of the target system. Each stage of attack may introduce new risks and complexity, and the attacker needs to evaluate the success probability and cost of each step to optimize the attack path.
[0070]
[0071] P path Related to the selection of attack path;
[0072] P time The impact of attack time, indicating the impact of attack timing on success rate;
[0073] P vulnerability Indicates the vulnerability probability of the i-th step of the attack path, such as the vulnerability of each component in the path;
[0074] γ·P defense (i,t) is the impact factor of the defense system, indicating the effect of defense strength on attack success probability. If the defense system is strong, the success probability of the attack will be greatly reduced.
[0075] In order to comprehensively evaluate the impact of network attacks, not only the success probability and damage degree of the attack should be concerned, but also the recovery time after the attack should be considered.
[0076] ΔT=R t +D d +T trans +U t +C s (3)
[0077] In the formula, R is the response time factor, which is related to the attacker's awareness of the attack, the corresponding response, and the allocation of resources;
[0078] T trans is the transmission delay factor;
[0079] U t is the set of uncertain factors existing in the attack scenario;
[0080] C s is the repair time when the device may cause physical loss.
[0081]
[0082] In the formula, R t =R detect +R decision +R allocateThe sum of the awareness, decision-making, and response time of the scheduling party;
[0083] T send +T prop +T process The time consumed for communication transmission;
[0084] U risk +U failure +U scenario The impact time factor generated by different attack scenarios;
[0085] T repair,max The maximum repair time required for damaged equipment.
[0086] 2. Double-layer optimization model considering attack recovery time:
[0087] In the network attack and defense double-layer optimization model in the present patent, the consequences of attacks are mainly quantified through the two factors of load shedding amount and outage time. Load shedding amount refers to the power load demand that cannot be met due to the attack, and outage time is the time experienced by the system from the occurrence of the attack to the recovery of normal power supply. Therefore, the comprehensive evaluation of attack consequences can be represented as the product of load shedding amount and outage time, which reflects the actual impact degree and economic loss of the attack on the power system. Further, the risk of network attack can be measured by the product of attack success probability, load shedding amount, and outage time. The probability of attack success determines the possibility of the occurrence of the attack event, while the load shedding amount and outage time determine the specific damage degree to the system after the attack is successful. In this way, the model not only can evaluate the severity of the attack, but also can provide a quantitative basis for the optimization of defense strategies, thereby effectively improving the response capability of the power system to potential network attacks.
[0088] 2.1. Analysis of consequences of network attacks:
[0089] Based on the detailed discussion of the potential threats to the power system after encountering network attacks in the foregoing, especially the analysis of different attack paths, the present invention will further elaborate the specific consequences of network attacks on the power system. The evaluation of attack consequences needs to consider the results of different attack paths comprehensively, including factors such as attack probability, load shedding amount, and outage time of the power system after encountering attacks. In order to quantify these consequences, the following mathematical model is proposed:
[0090] CR=P i ·(α·T i )·(β·D i ) (5)
[0091] where P i is the success probability of the i-th attack path;
[0092] α·Ti is the product of the recovery time required after the attack is successful and the weighting coefficient;
[0093] β·D i is the product of the amount of load shedding caused after the attack is successful and the weighting coefficient;
[0094] Through the evaluation of the attack consequences, basis can be provided for subsequent defense strategies.
[0095] 2.2, attack and defense double-layer optimization model:
[0096] Through the analysis of the consequences of network attacks above, potential risks existing in the system can be identified. The present application further precisely identifies the vulnerable points in network attacks. In the power system, specific attack paths and core devices need to be deeply mined to enhance the defense capability.
[0097] Based on the aforementioned switch modularization diagram, the present patent selects a specific network attack scenario for analysis in these typical scenarios: after the attacker invades the supply chain of the power plant or substation and obtains control authority, the attacker uses the intelligent electronic device (IED) to issue false commands, resulting in line tripping or unit stopping consequences. The potential consequences are discussed in depth, especially the evaluation of factors such as load shedding amount and outage time in the power system.
[0098] According to the IEEE1686 protocol, each IED has a corresponding password. Unlike invading the control center, after the attacker invades the substation, the attacker still needs to crack the corresponding password to continue to obtain the control authority of the IED in the substation.
[0099] When the attacker chooses to invade the central or district dispatching, in this scenario, it is assumed that the invasion is successful, and the attacker can disconnect all intelligent IEDs to maximize the effect.
[0100] When the attacker chooses to invade the IEDs of each plant station, in this scenario, the success invasion probabilities of different plant stations are independent of each other, and the invasion of the substation and the cracking of the authority of each IED are also conditionally independent. Therefore, the probability of invading a certain plant station and obtaining the control authority of each IED satisfies the following formula:
[0101] P(I1,...,I e |F n )=P(I1|F n )·...·P(I e |F n ) (6)
[0102] In the formula, e is the index of the IED in the substation;
[0103] I1,F nIt is a discrete random variable;
[0104] This represents the probability that the e-th IED located under the power station at node n is successfully compromised;
[0105] P(I1,...,I e |F n ) represents the probability of successfully controlling e IEDs.
[0106] Network risks in power systems can be defined as:
[0107]
[0108] In the formula, h represents the probability that h IEDs in each substation are successfully controlled;
[0109] P represents the probability of a successful attack on plant n;
[0110] ΔD represents the load loss caused by abnormal control IED status;
[0111] ΔT represents the recovery time required after a network attack causes a component to fail to operate.
[0112] The objective function of the upper-layer attacker model is to maximize the network risk CR.
[0113]
[0114] In the formula a n ,ν e Binary variables representing whether the power plant and IED have been attacked, respectively. If a n =1,ν e =1 indicates that the corresponding substation n was attacked, and IEDe was attacked;
[0115] Ω(n) represents the set of all IEDs installed in plant n;
[0116] ΔT represents the recovery time required after a network attack causes a component to fail to operate.
[0117] Constraints: Modeling attack logic for substations, IEDs, and their controlled lines:
[0118] {a n ,v e ,w l}∈A(9)
[0119]
[0120] In the formula, {a n ,v e ,w l} is the vector form of the attack decision vector of the station, IED, and line attack, A is the set of all possible attack decisions; o(l), d(l) represent the IEDs of the two sections of line L; is the attack resource of the attacker invading the substation, K2 is the attack resource of the attacker tampering with the IED device; The left formula indicates that the number of IEDs controlled is not less than the number of successful attacks on the station, and the right formula indicates the attack resource constraint; l is a binary variable representing the open state of the line, w l = 1 indicates that the line is open, w l = 0 indicates that the line is normal; v e∈Ω(n) ≤ a n If the station is not invaded, the IEDs in the station will not be controlled; l ≥ v e=o(l) , w l ≥ v e=d(l) If any IED at both ends of the line is successfully attacked, the line will be disconnected; l ≤ v e=o(l) + v e=d(l) If the IEDs at both ends of the line are not attacked, it is safe; is the attack resource of the attacker invading the power plant, K4 is the attack resource of the attacker controlling the unit devices in the power plant; The left formula indicates that the number of units controlled is not less than the number of successful attacks on the station, and the right formula indicates the attack resource constraint; v m∈Ω(g) ≤ a g If the station is not invaded, the units in the station will not be controlled; indicates that the attack on the station is successful, and the number of unit controls is greater than or equal to 1; ΔP g is the unit output change, G unit,g indicates the capacity of a single unit in the power plant
[0121] Lower defender model:
[0122]
[0123] The lower model simulates the role of the dispatcher, adjusts the generator output, adjusts the line topology, and removes the load that cannot be met, and the target is to minimize the system load shedding loss.
[0124] In the formula, f l is the branch power flow; z l is a 0-1 variable for line switching, which is 1 for line connection and 0 for line disconnection; b l is the admittance of line l; θ n is the voltage phase angle; is the node-branch incidence matrix; A BG is the node-generator incidence matrix; ABD P is the node load correlation matrix; g To provide power to the generator.
[0125] 2.3 Solution Method:
[0126] For bilevel mixed integer programming models, if the underlying layer is a linear programming problem, the bilevel model can usually be transformed into a single-level model for solution using KKT conditions or strong duality conditions. This patent uses strong duality conditions for transformation.
[0127] First, linearize the objective function by taking its logarithm:
[0128]
[0129] σ=log(ΔD) (12)
[0130] Furthermore, log(ΔD) can be piecewise linearized as follows:
[0131]
[0132] In the formula λ t c is a coherent variable introduced for auxiliary piecewise linearization, and σ t t represents the endpoint values of the piecewise linearized function, and t represents the segment index.
[0133] Since the underlying scheduling model is a linear programming problem, the original two-layer model can be transformed into a single-layer model by adding dual constraints and strong dual conditions to the underlying model.
[0134]
[0135] {a n ,v e ,w l}∈A(15)
[0136]
[0137] In the formula u l , λ n , w l , β g , delta a , For {a n ,v e ,w l The dual variable of the constraint in A; w l ·θ n ,w l·u l The large M method can be used for linearization:
[0138]
[0139] where z1 is an auxiliary continuous variable introduced; the larger the value of M, the greater the solution accuracy. The single-layer mixed integer linear programming model at this time can be directly solved to obtain the system vulnerability.
[0140] The present application adopts a double-layer optimization model to analyze the network attack scenario, and models the attacker and the defender respectively. The attacker model helps to identify the optimal attack path, evaluate the IED / unit control authority and network risk; the defender model minimizes the load loss by adjusting the generator output and line topology to enhance the system attack resistance. The double-layer model is converted into a single-layer model using the strong duality condition, which simplifies the solving process and improves the efficiency. By linearizing the objective function and introducing auxiliary variables, the model can effectively handle complex attack and defense decisions.
[0141] Furthermore, the present application models the attack scenario of substation IED / power plant unit equipment tampering in detail, quantifies the intrusion probability and system risk, and provides a scientific risk assessment basis for the defender. Finally, considering the resource constraints of the attacker, the model can accurately calculate the attack path risk, and provide the defender with an optimal resource allocation scheme to achieve the maximum benefit with limited defense budget.
[0142] Overall, the present application provides a comprehensive network attack protection scheme for power systems through accurate modeling, simplified solving and quantitative evaluation, and improves the security and optimizes the resource allocation.
[0143] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks. Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.
[0144] In the description of the application, it needs to be understood that the terms "first", "second" are only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the application, the meaning of "multiple" is two or more, unless otherwise specifically limited.
[0145] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1. A method for assessing consequences of cyber-attacks on power system networks considering switching modularity, characterized in that, The method comprises the following steps: Modular modeling of key switching devices in the power system to clarify their functional logic and fault propagation path; Quantifying the influence of different attack methods on the system state in combination with network attack scenarios; Solving the optimal attack path and generating a defense configuration scheme by simulating the strategy game between the attacker and the defender; In the process of quantifying the influence of different attack methods on the system state, the state transition model SMP of the attack path is constructed to analyze the attack probability of each step and the recovery time, so as to quantify the influence of different attack methods on the system state; In the process of simulating the strategy game between the attacker and the defender, an attack-defense double-layer optimization model is constructed, the upper-layer attacker optimizes the attack path to maximize the network risk, and the lower-layer defender adjusts the resources to minimize the load loss, so as to simulate the strategy game between the attacker and the defender; In constructing the attack-defense double-layer optimization model, the constraint conditions are obtained by modeling the attack logic of the substation, IED and the line controlled thereby: wherein, is the vector form of the station, IED, line attack decision vector; A is the set of all possible attack decisions; represents the IEDs of the two sections of the line L; is the attack resource of the attacker invading the substation, K2 is the attack resource of the attacker tampering with the IED device; The left formula indicates that the number of IEDs controlled is not less than the number of substation attack successes, and the right formula indicates the attack resource constraint; represents a binary variable of the line breaking state, = 1 indicates that the line is disconnected, = 0 indicates that the line is normal; If the substation is not invaded, the IEDs in the station will not be controlled; , indicates that if any IED at both ends of the line is successfully attacked, the line will be disconnected; indicates that if both ends of the line are not attacked, it is safe; is the attack resource of the attacker invading the power plant, K4 is the attack resource of the attacker controlling the unit device in the power plant; The left formula indicates that the number of units controlled is not less than the number of substation attack successes, and the right formula indicates the attack resource constraint; If the substation is not invaded, the units in the station will not be controlled; indicates that the attack on the substation is successful, and the number of unit controls is greater than or equal to 1; is the unit output change amount, indicates the capacity of a single unit of the power plant, v m ; The objective function of the upper-layer attacker model is to maximize the network risk CR: (8) where a n c are binary variables representing whether substation and IED are attacked, a n = 1, v c = 1 means that the corresponding substation n and IED e are attacked. denotes the set of all IEDs installed in substation n. denotes the recovery time required after the network attack causes the element to refuse to operate, △D is the loss of load caused by the abnormal state of the control IED, F n is a discrete random variable, and P represents the attack success probability of the substation. In constructing the attack-defense double-layer optimization model, the lower-layer defender model is represented as: wherein, is the branch flow; is the line switching 0-1 variable, 1 means the line is connected, 0 means the line is disconnected; is the admittance of line l; is the voltage phase angle; is the node-branch incidence matrix; is the node-generator incidence matrix; is the node-load incidence matrix; is the generator output; In solving the optimal attack path and generating the defense configuration scheme, the double-layer model is converted into a single-layer model for solving by using the strong duality condition, the attack path risk is evaluated, and the optimal resource allocation scheme is provided for the defender according to the evaluation result.
2. The method according to claim 1, wherein: In the process of analyzing the attack probability of each step and the recovery time, the attack path is optimized and represented as: wherein with respect to the selection of the attack path; with respect to the timing of the attack, indicating the influence of the selection of the attack timing on the success rate; indicating the vulnerability probability at the i-th step of the attack path; with respect to the defense system, indicating the counteraction of the defense strength on the attack success probability.
3. The method according to claim 2, wherein: In the process of analyzing the attack probability of each step and the recovery time, the recovery time after the attack is represented as: wherein, is a response time factor related to the time taken by the scheduler to perceive the attack, respond to it and allocate resources; is a transmission delay factor; is a set of uncertainty factors related to the existence of attack scenarios; is the repair time when the device is physically lost, is the sum of the perception, decision and response time of the scheduler; is the time taken for communication transmission; is the impact time factor for different attack scenarios; is the maximum repair time required for a damaged device.
4. The method according to claim 1, wherein: Before the process of simulating the strategy game between the attacker and the defender, the consequences of network attacks on the power system are quantified, and the quantification process is represented as: In the formula, is the success probability of the i-th attack path; is the product of the recovery time required after the attack succeeds and the weighting factor; is the product of the amount of cut load caused after the attack succeeds and the weighting factor.
5. A system for assessing consequences of cyber attacks on power system networks considering switching modularity, for implementing a method for assessing consequences of cyber attacks on power system networks considering switching modularity according to claim 1, characterized in that, Comprising: A modeling module for modular modeling of key switching devices in the power system to clarify their functional logic and fault propagation path; A quantification module for quantifying the influence of different attack methods on the system state in combination with network attack scenarios; An evaluation module for solving the optimal attack path and generating a defense configuration scheme by simulating the strategy game between the attacker and the defender.
Citation Information
Patent Citations
Network security protection security method and system based on unit cell
CN114978584A
Power system attack risk assessment method based on multi-scene distribution
CN119011220A