Power system network space precision linkage defense control method and device
By dynamically mapping network topology and key asset distribution maps in real time in the power system, and generating dynamic defense strategies in deep learning algorithms, the problems of low threat identification accuracy and lagging defense strategies in the existing technology are solved, and intelligent identification and efficient defense of complex network threats are achieved.
Patent Information
- Application Number
- CN202510401537.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-18
AI Technical Summary
The network security protection of existing power systems lacks real-time dynamic mapping capabilities, and cannot effectively integrate multi-level data sources for in-depth analysis, resulting in low accuracy in threat identification, lagging in defense strategy generation, unable to quickly adjust, and difficult to deal with complex cyber threats.
Real-time dynamic mapping is carried out based on spatial surveying and mapping technology, network topology structure and key asset distribution maps are generated, correlation analysis is carried out in combination with deep learning algorithms, dynamic defense strategies are generated, and threat knowledge base and rule base are optimized through real-time monitoring and feedback mechanisms.
It realizes precise linkage defense of the power system network space, improves the accuracy and response speed of threat identification, reduces resource waste, and improves the long-term security and dynamic response capabilities of the system.
Smart Images

Figure CN120342668A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, particularly to the field of power system management, and more particularly to a precise linkage defense control method and device for the cyber space of a power system. Background Art
[0002] With the acceleration of the intelligent and digital processes of power systems, the power monitoring network has gradually become the core infrastructure for carrying power dispatching, equipment monitoring, and data management. However, the complexity and openness of the power network make it vulnerable when facing increasingly complex network security threats. In the prior art, the security protection of power systems usually relies on passive monitoring or defense strategies based on static rules, and this approach has limitations in dealing with dynamic changes in network structures and advanced persistent threats (APTs).
[0003] The main problems of the prior art are the lack of real-time dynamic mapping capabilities for cyber space, which limits the comprehensive understanding of network topologies and the distribution of key assets. In addition, the ability to integrate multi-level data sources and conduct in-depth analysis is insufficient, which reduces the accuracy of threat identification. The existing defense strategy generation methods fail to combine threat types with real-time network states for dynamic optimization, and the lag of the feedback mechanism also cannot achieve rapid adjustment of defense measures, which limits the defense effect. Therefore, there is an urgent need to develop a new precise linkage defense device for the cyber space of power systems. Summary of the Invention
[0004] Embodiments of the present invention provide a precise linkage defense control method and device for the cyber space of a power system to improve the accuracy and efficiency of cyber space defense.
[0005] In a first aspect, embodiments of the present invention provide a precise linkage defense control method for the cyber space of a power system, including:
[0006] Based on spatial mapping technology, perform real-time dynamic mapping of the cyber space of the power system to generate a network topology structure and a distribution map of key assets, and extract the operating status data and potential risk information of network nodes in the network topology structure and the distribution map of key assets;
[0007] According to the operating status data and potential risk information of network nodes, integrate data sources at different levels of the power system and use deep learning algorithms for correlation analysis to obtain network threat classification results;
[0008] Generate a dynamic defense strategy based on the network threat classification results and the network operating status; wherein, the strategy includes defense path selection, response node scheduling, and risk isolation measures;
[0009] Execute the generated dynamic defense strategy, obtain the real-time monitoring results, evaluate the effectiveness of the defense measures according to the feedback mechanism of the real-time monitoring results, and collect historical defense records, threat characteristics and response effects, and update the threat knowledge base and defense rule base based on data analysis technology.
[0010] In a possible implementation, the real-time dynamic mapping of the power system cyber space based on spatial mapping technology to generate a network topology structure and a critical asset distribution map includes:
[0011] Obtain the real-time operation data of the power system network, including the performance level data of each node, link traffic, historical failure times, and node correlation degree;
[0012] Calculate the weight w of the link between nodes through spatial mapping technology ij ;
[0013] According to the calculated weight w ij , construct a link weight matrix W;
[0014] Based on the link weight matrix W, construct a network topology structure G(V,E); where, the node set V is all devices in the power system, and the edge set E is the connection between all nodes;
[0015] Calculate the importance index C of node i i :
[0016] Sort all nodes according to the importance index, and select a specified number of nodes with the highest importance index as critical assets to generate a critical asset distribution map.
[0017] In a possible implementation, the weight w of the link between nodes ij The calculation formula is:
[0018]
[0019] Among them, w ij Is the link weight between node i and node j; α1, α2 and α3 are weight adjustment factors; T ij Is the link traffic between node i and node j; R ij Is the node correlation degree between node i and node j, calculated through the historical interaction frequency between nodes; S i Is the current performance level data of node i, including CPU utilization; F i (τ) is the number of failures of node i at time τ; t start Is the start time of the time window, t is the current time; t1 is the total length of the time window.
[0020] In a possible implementation, the importance index C of node i i is calculated as follows:
[0021] C i = ∑ j∈V w ij
[0022] where w ij is the link weight between node i and node j.
[0023] In a possible implementation, extracting the operating status data and potential risk information of network nodes in the network topology structure and critical asset distribution map includes:
[0024] Based on the network topology structure, determine the communication relationship and link attributes of nodes and their neighbor nodes, and extract the interaction characteristics between nodes as operation status correlation data;
[0025] According to the critical asset distribution map, locate the critical asset nodes, and combine with the operation status correlation data to extract the node operation status and link load information related to the critical assets;
[0026] Based on the extracted node operation status and link load information related to the critical assets, analyze the link anomaly trend, node interaction anomaly and topology change, and generate potential risk information of the critical asset nodes.
[0027] In a possible implementation, according to the operating status data and potential risk information of network nodes, integrating data sources at different levels of the power system and using deep learning algorithms for correlation analysis to obtain network threat classification results includes:
[0028] Preprocess the operating status data and potential risk information of network nodes to obtain time series features; where the preprocessing includes formatting and normalization processing; the time series features include node operating status, link traffic, historical fault records and communication anomaly behaviors;
[0029] Based on the time series features, use a pre-trained deep learning model to obtain the probability distribution and classification labels of each network threat type; where the network threats include denial of service attacks, unauthorized access, and data tampering.
[0030] In a possible implementation, the deep learning model includes a time series feature embedding module, a dynamic pattern analysis module and a threat classification module;
[0031] The obtaining the probability of each network threat based on the time series features using a pre-trained deep learning model includes:
[0032] The time series feature embedding module receives the preprocessed time series feature data; inputs the received data into a one-dimensional convolutional neural network to extract the local feature patterns of each time slice, generating a feature map tensor; inputs the feature map tensor into the encoding part of an autoencoder to further compress the feature dimension, generating a low-dimensional embedding matrix;
[0033] The dynamic pattern analysis module receives the low-dimensional embedding matrix generated by the time series feature embedding module; processes the received data through a long short-term memory network to obtain a hidden state sequence; inputs the hidden state sequence into a graph attention network, and combines the network topology structure and the communication relationship matrix between nodes, and calculates the interaction weights for each pair of nodes through an attention mechanism, generating an interaction weight matrix between nodes; according to the hidden state sequence and the interaction weight matrix, through a weighted aggregation operation, fuses the own features of each node with the features of its neighbor nodes, generating a dynamic feature representation matrix of the nodes;
[0034] The threat classification module receives the dynamic feature representation matrix and the interaction weight matrix provided by the dynamic pattern analysis module; generates a threat feature representation for each node according to the dynamic feature representation matrix and the interaction weight matrix; according to the threat feature representation, extracts the feature patterns of threat types including denial-of-service attacks, unauthorized access, and data tampering layer by layer through a fully connected neural network, and realizes classification through a Softmax layer, outputting the probability distribution and classification label of each threat type.
[0035] In a possible implementation manner, the step of fusing the own features of each node with the features of its neighbor nodes through a weighted aggregation operation according to the hidden state sequence and the interaction weight matrix to generate a dynamic feature representation matrix of the nodes includes:
[0036] Calculate the initial weighted value z between node i and its neighbor node j ij :
[0037]
[0038] where, w ij is the weight value in the interaction weight matrix, reflecting the interaction intensity between nodes i and j; h i is the hidden state feature vector of node i; h j is the hidden state feature vector of node j; M is a trainable weight matrix; b ij is the bias term; σ is the activation function;
[0039] Calculate the neighbor feature representation of node i
[0040]
[0041] Among them, N(i) is the set of neighbor nodes of node i;
[0042] Calculate the dynamic feature representation h of node i i ′ :
[0043]
[0044] Among them, α4 is the fusion coefficient, W1 and W2 are trainable weight matrices; b1 and b2 are bias terms.
[0045] In a possible implementation, when the autoencoder processes the input feature mapping tensor X, a time slice weight calculation sub-module that assigns weights to different time steps is introduced;
[0046] The time slice weight calculation sub-module calculates the time slice weight:
[0047]
[0048] Among them, α t is the importance weight of time slice t; ΔS(t) is the difference between the node running state of the node at time slice t and the node running state of the node at time slice t-1, and the node running state includes the utilization rate of the node CPU; ΔT(t) is the difference between the link traffic of the node at time slice t and the link traffic of the node at time slice t-1, and the link traffic includes the packet transmission rate or the network bandwidth utilization rate; N is the total number of time slices.
[0049] In a possible implementation, the time series feature embedding module includes a multi-scale feature extraction mechanism for enhancing the expression ability of features with different time granularities. The multi-scale feature extraction mechanism is specifically used for:
[0050] Process the received time series feature data through multi-scale convolutional layers, and each convolutional layer has a different convolutional kernel size to capture the feature patterns of short time slices and long time slices respectively;
[0051] Align the output feature maps of the multi-scale convolutional layers across time, and unify the time steps through interpolation or padding to ensure that features with different time granularities can be superimposed in the same feature space;
[0052] Perform weighted fusion on the multi-scale feature maps after cross-time alignment, and the fusion weights are dynamically adjusted according to the change rate of the time series features to highlight the expression of fast-changing features;
[0053] Use the fused multi-scale feature maps as input and pass them to the encoding part of the autoencoder to further compress the feature dimensions.
[0054] In a possible implementation, the dynamic mode analysis module further includes a historical buffer mechanism based on node behavior for dynamically adjusting the calculation accuracy of the interaction weights between nodes. The historical buffer mechanism is specifically used for:
[0055] When generating the interaction weight matrix between nodes, establish a behavior historical buffer for each node to store the operation status data, link traffic data, and interaction characteristics of the node within a preset time window;
[0056] The dynamic mode analysis module extracts the time series behavior data of the nodes from the historical buffer through a sliding window mechanism, and combines it with the hidden state sequence of the current time slice to calculate the short-term trend of the node behavior;
[0057] According to the calculated short-term trend, dynamically adjust the interaction weights between the node and its neighbor nodes to highlight the identification of abnormal interaction behaviors. The weight adjustment includes enhancing the weights of abnormal interactions and suppressing the influence of normal interactions;
[0058] Use the adjusted interaction weight matrix for the calculation of subsequent node dynamic feature characterization.
[0059] In a second aspect, an embodiment of the present invention provides a precise linkage defense control device for the cyber space of a power system, including:
[0060] A cyber space mapping unit for real-time dynamic mapping of the cyber space of the power system based on space mapping technology, generating a network topology structure and a distribution map of key assets, and extracting the operation status data and potential risk information of network nodes in the network topology structure and the distribution map of key assets;
[0061] A fusion and threat recognition unit for integrating data sources at different levels of the power system and performing correlation analysis using deep learning algorithms based on the operation status data and potential risk information of network nodes to obtain network threat classification results;
[0062] A defense strategy generation unit for generating a dynamic defense strategy based on the network threat classification results and the network operation status; wherein, the strategy includes defense path selection, response node scheduling, and risk isolation measures;
[0063] An execution and feedback unit for executing the generated dynamic defense strategy, obtaining real-time monitoring results, and evaluating the effectiveness of the defense measures according to the feedback mechanism of the real-time monitoring results;
[0064] An analysis and update unit for collecting historical defense records, threat characteristics, and response effects, and updating the threat knowledge base and the defense rule base based on data analysis techniques.
[0065] An embodiment of the present invention provides a method and device for precise coordinated defense control in the cyberspace of a power system, which realizes real-time dynamic mapping of the cyberspace of the power system based on spatial mapping technology. This can not only generate accurate network topologies and distribution maps of key assets, but also extract the operating status and potential risk information of network nodes, providing comprehensive basic data support for subsequent threat identification and formulation of defense strategies. By integrating multi-level data sources and using deep learning algorithms for correlation analysis, intelligent identification and classification of complex network threats are achieved. This method can dynamically perceive potential threats in the network, improve the accuracy of identification and response speed, significantly superior to traditional static rule analysis methods. Combining the identified threat types and network operating status, a dynamic defense strategy including defense path selection, response node scheduling, and risk isolation measures is generated. Through real-time optimized strategy generation and execution, resource waste in the defense process can be effectively reduced and the threat impact can be minimized. By real-time monitoring the defense effect and updating the threat knowledge base and rule base, future threat identification and defense strategies are continuously optimized. This adaptive optimization mechanism can cope with evolving complex network threats and enhance the long-term security and dynamic response capabilities of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0067] Figure 1 is a schematic flowchart of the method for precise coordinated defense control in the cyberspace of the power system provided by the embodiment of the present invention;
[0068] Figure 2 is a schematic structural diagram of the device for precise coordinated defense control in the cyberspace of the power system provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0069] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present invention. However, those skilled in the art should clearly understand that the present invention can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present invention.
[0070] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will be described through specific embodiments in conjunction with the drawings.
[0071] Figure 1 The following is the implementation flowchart of the precise linkage defense control method for the cyber space of the power system provided by the embodiments of the present invention:
[0072] S101, based on the real-time dynamic mapping of the cyber space of the power system by using space mapping technology, generate a network topology structure and a critical asset distribution map, and extract the operation status data and potential risk information of network nodes in the network topology structure and the critical asset distribution map.
[0073] S102, according to the operation status data and potential risk information of network nodes, integrate data sources at different levels of the power system and use deep learning algorithms for correlation analysis to obtain network threat classification results.
[0074] S103, generate a dynamic defense strategy based on the network threat classification results and the network operation status; wherein, the strategy includes defense path selection, response node scheduling, and risk isolation measures.
[0075] S104, execute the generated dynamic defense strategy, and obtain real-time monitoring results. Evaluate the effectiveness of defense measures according to the feedback mechanism of the real-time monitoring results, and collect historical defense records, threat characteristics, and response effects. Update the threat knowledge base and the defense rule base based on data analysis technology.
[0076] In this embodiment, the real-time dynamic mapping of the cyber space of the power system is realized based on space mapping technology. This can not only generate accurate network topology structures and critical asset distribution maps, but also extract the operation status and potential risk information of network nodes, providing comprehensive basic data support for subsequent threat identification and defense strategy formulation. By integrating multi-level data sources and using deep learning algorithms for correlation analysis, the intelligent identification and classification of complex network threats are realized. This method can dynamically sense potential threats in the network, improve the accuracy of identification and the response speed, and is significantly superior to traditional static rule analysis methods. Combining the identified threat types and the network operation status, a dynamic defense strategy including defense path selection, response node scheduling, and risk isolation measures is generated. Through the real-time optimized strategy generation and execution, the waste of resources in the defense process can be effectively reduced and the threat impact can be minimized. By real-time monitoring the defense effect and updating the threat knowledge base and the rule base, the future threat identification and defense strategies are continuously optimized. This adaptive optimization mechanism can cope with the continuously evolving complex network threats and enhance the long-term security and dynamic response ability of the system.
[0077] In a possible implementation manner, in step S101, the real-time dynamic mapping of the cyber space of the power system by using space mapping technology to generate a network topology structure and a critical asset distribution map includes:
[0078] Obtain the real-time operation data of the power system network, including the performance level data of each node, link traffic, historical failure times, and node correlation degree;
[0079] Calculate the weight w of the link between nodes through spatial mapping technology ij ;
[0080] According to the calculated weight w ij , construct the link weight matrix W;
[0081] Based on the link weight matrix W, construct the network topology G(V, E); where, the node set V is all the devices in the power system, and the edge set E is all the connections between nodes;
[0082] Calculate the importance index C of node i i :
[0083] Sort all nodes according to the importance index, and select the specified number of nodes with the highest importance index as key assets to generate a key asset distribution map.
[0084] In a possible implementation, the weight w of the link between nodes ij The calculation formula is:
[0085]
[0086] where, w ij is the link weight between node i and node j; α1, α2, and α3 are weight adjustment factors; α1 is the weight adjustment factor for link traffic, and its recommended value is 0.3 to 0.5; α2 is the weight adjustment factor for node correlation degree, and its recommended value is 0.4 to 0.6; α3 is the weight adjustment factor for historical failure records, and its recommended value is 0.2 to 0.4.
[0087] T ij is the link traffic between node i and node j in bits per second (bps), which is obtained by real-time monitoring of the packet transmission rate in the network.
[0088] R ij is the node correlation degree between node i and node j, calculated through the historical interaction frequency between nodes; S i is the current performance level data of node i, including CPU utilization; F i (τ) is the number of failures of node i at time τ; t start is the start time of the time window, t is the current time; t1 is the total length of the time window.
[0089] In a possible implementation, according to the calculated weight w ij , construct the link weight matrix W;
[0090] Calculate the weight w between each pair of nodes through the above formula ij , and organize the weight values of all nodes into a symmetric matrix W. Each element W[i][j] of the matrix = w ij , representing the link weight between node i and node j. The dimension of the matrix is |V|×|V|, where |V| is the total number of nodes in the network.
[0091] Based on the link weight matrix W, construct the network topology structure G(V, E), where the node set V represents all devices in the power system, and the edge set E represents all connections between nodes.
[0092] In a possible implementation, the importance index C of node i i is calculated as follows:
[0093] C i = ∑ j∈V w ij
[0094] where w ij is the link weight between node i and node j.
[0095] In a possible implementation, in step S101, extract the operation status data and potential risk information of the network nodes in the network topology structure and the critical asset distribution map, including:
[0096] Based on the network topology structure, determine the communication relationship and link attributes of the node and its neighbor nodes, and extract the node interaction characteristics as operation status correlation data;
[0097] According to the critical asset distribution map, locate the critical asset nodes, and combine the operation status correlation data to extract the node operation status and link load information related to the critical assets;
[0098] Based on the extracted node operation status and link load information related to the critical assets, analyze the link anomaly trend, node interaction anomaly and topology change, and generate potential risk information of the critical asset nodes.
[0099] In a possible implementation, in step S102, according to the operation status data and potential risk information of the network nodes, integrate the data sources at different levels of the power system and use deep learning algorithms for correlation analysis to obtain the network threat classification results, including:
[0100] Preprocess the operation status data and potential risk information of the network nodes to obtain time series features; among them, the preprocessing includes formatting and normalization processing; the time series features include node operation status, link traffic, historical fault records and communication anomaly behaviors;
[0101] According to the time series characteristics, use a pre-trained deep learning model to obtain the probability distribution and classification labels of each network threat type; where the network threats include denial of service attacks, unauthorized access, and data tampering.
[0102] In a possible implementation, the deep learning model includes a time series feature embedding module, a dynamic pattern analysis module, and a threat classification module;
[0103] According to the time series characteristics, use a pre-trained deep learning model to obtain the probabilities of each network threat, including:
[0104] The time series feature embedding module receives the preprocessed time series feature data; inputs the received data into a one-dimensional convolutional neural network to extract the local feature patterns of each time slice, generating a feature map tensor; inputs the feature map tensor into the encoding part of an autoencoder to further compress the feature dimension, generating a low-dimensional embedding matrix;
[0105] The dynamic pattern analysis module receives the low-dimensional embedding matrix generated by the time series feature embedding module; processes the received data through a long short-term memory network to obtain a hidden state sequence; inputs the hidden state sequence into a graph attention network, and combines the network topology structure and the communication relationship matrix between nodes, and calculates the interaction weights for each pair of nodes through the attention mechanism, generating an interaction weight matrix between nodes; according to the hidden state sequence and the interaction weight matrix, through a weighted aggregation operation, fuse the own features of each node with the features of its neighbor nodes, generating a dynamic feature representation matrix of the nodes;
[0106] The threat classification module receives the dynamic feature representation matrix and the interaction weight matrix provided by the dynamic pattern analysis module; generates the threat feature representation of each node according to the dynamic feature representation matrix and the interaction weight matrix; according to the threat feature representation, layer by layer extracts the feature patterns of threat types including denial of service attacks, unauthorized access, and data tampering through a fully connected neural network, and realizes classification through a Softmax layer, outputting the probability distribution and classification labels of each threat type.
[0107] In a possible implementation, according to the hidden state sequence and the interaction weight matrix, through a weighted aggregation operation, fuse the own features of each node with the features of its neighbor nodes, generating a dynamic feature representation matrix of the nodes, including:
[0108] Calculate the initial weighted value z between node i and its neighbor node j ij :
[0109]
[0110] where, w ijis the weight value in the interaction weight matrix, reflecting the interaction strength between nodes i and j. This value is usually calculated based on the communication frequency, data transmission volume, or importance of topological connections between nodes, and its range is non - negative real numbers. The recommended calculation method is based on normalized communication frequency and traffic weight, and the range is recommended to be from 0.1 to 1, depending on the dynamic requirements of network communication.
[0111] h i is the hidden state feature vector of node i; h j is the hidden state feature vector of node j; M is a trainable weight matrix; b ij is the bias term; σ is the activation function; for example, ReLU;
[0112] Calculate the neighbor feature representation of node i
[0113]
[0114] where N(i) is the set of neighbor nodes of node i;
[0115] Calculate the dynamic feature representation h of node i i ′ :
[0116]
[0117] where α4 is the fusion coefficient, usually set to 0.5 at the beginning of training, and then dynamically adjusted according to the model performance
[0118] The recommended range is from 0.3 to 0.7; W1 and W2 are trainable weight matrices; b1 and b2 are bias terms.
[0119] In a possible implementation, when the auto - encoder processes the input feature mapping tensor X, a time - slice weight calculation sub - module that assigns weights to different time steps is introduced;
[0120] The time - slice weight calculation sub - module calculates the time - slice weight:
[0121]
[0122] where α t is the importance weight of time - slice t; ΔS(t) is the difference between the node running state of the node at time - slice t and the node running state of the node at time - slice t - 1. The node running state includes the utilization rate of the node's CPU; ΔT(t) is the difference between the link traffic of the node at time - slice t and the link traffic of the node at time - slice t - 1. The link traffic includes the packet transmission rate or network bandwidth utilization rate; N is the total number of time - slices.
[0123] ΔS(t) represents the change in the running state of a node at time slice t, which is defined as the difference between the running states of the node at time slice t and time slice t - 1. The measurement criteria for the running state can include the CPU utilization rate, memory occupancy rate, or task load of the node, etc. In actual implementation, ΔS(t) mainly reflects the performance fluctuations of the node. For example, when the CPU utilization rate of a certain node increases significantly in a short period of time, it may mean that it is processing an abnormally high request traffic or suffering from a denial-of-service attack. The recommended measurement range is from 0 to 1, and the actual running state of the node can be mapped to this range through normalization processing.
[0124] ΔT(t) represents the change in the link traffic of a node at time slice t, which is defined as the difference in the link traffic of the node between time slice t and time slice t - 1. The link traffic can be measured by the data packet transmission rate or the network bandwidth utilization rate. Specifically, the data packet transmission rate reflects the total amount of data passing through the link per unit time, while the network bandwidth utilization rate indicates the current load level of the link. The higher the value of ΔT(t), the more abnormal network activities may occur during this time slice. For example, a large number of data packets may correspond to unauthorized access or data leakage behaviors. The recommended measurement range is from 0 to 1, and normalization processing is also required.
[0125] The denominator in the formula represents the sum of the changes in the running state and the changes in the link traffic over all time slices, which is used to normalize the weight of each time slice to ensure that the sum of the weights of all time slices is 1. Through this normalization operation, the time slice weight α t reflects the proportion of the importance of the current time slice in the global scope.
[0126] The time slice weight α t is assigned to the feature processing stage of the autoencoder to amplify the influence of key time slices on feature extraction. For example, when the weight of a certain time slice is high, the autoencoder will assign a higher learning priority to the input features of this time slice, making the model pay more attention to abnormal behaviors or key events.
[0127] Through the above calculation and assignment of the time slice weights, the autoencoder can dynamically adjust the feature contributions of different time slices, ensuring that when processing time series data, the model can give priority to key time slices, thereby enhancing the ability to capture abnormal events and the ability to distinguish normal patterns.
[0128] In a possible implementation, the time series feature embedding module includes a multi-scale feature extraction mechanism for enhancing the expression ability of features at different time granularities. The multi-scale feature extraction mechanism is specifically used for:
[0129] Process the received time - series feature data through a multi - scale convolutional layer. Each convolutional layer has a different convolutional kernel size to capture the feature patterns of short - time slices and long - time slices respectively;
[0130] Align the output feature maps of the multi - scale convolutional layer across time. Unify the time steps through interpolation or padding methods to ensure that features of different time granularities can be superimposed in the same feature space;
[0131] Perform weighted fusion on the multi - scale feature maps after cross - time alignment. The fusion weights are dynamically adjusted according to the change rate of the time - series features to highlight the expression of fast - changing features;
[0132] Take the fused multi - scale feature maps as input and pass them to the encoding part of the auto - encoder to further compress the feature dimensions.
[0133] The time - series feature embedding module realizes the effective expression of features with different time granularities by introducing a multi - scale feature extraction mechanism, providing rich and diverse input features for deep - learning models. This mechanism is based on the step - by - step processing of multi - scale convolution, cross - time alignment, and weighted fusion, ensuring the integrity of time - series features and the ability to capture dynamic changes.
[0134] In the multi - scale feature extraction mechanism, the received time - series feature data is first input into the multi - scale convolutional layer. The multi - scale convolutional layer consists of several convolutional layers with different convolutional kernel sizes. Different convolutional kernel sizes correspond to different time granularities. For example, a small - size convolutional kernel can capture local feature patterns within a short - time slice, such as sudden surges in link traffic or node performance fluctuations; while a large - size convolutional kernel can capture global feature patterns within a longer - time slice, such as gradually increasing network load or the change trend of long - term operating states. This multi - scale processing method can extract information at different levels from time - series data, making the feature expression more comprehensive.
[0135] Due to differences in time steps, there may be alignment problems in the output feature maps of the multi - scale convolutional layer. To ensure the accuracy of subsequent processing, the feature maps need to be cross - time aligned. The alignment operation uses interpolation or padding methods to convert the feature maps generated by different convolutional kernel sizes into a unified time step. For example, for feature maps with shorter time steps, the feature values can be complemented by linear interpolation to match the feature maps with longer time steps; for feature maps with longer time steps, the time - point resolution can be increased by repeated padding. The aligned feature maps are mapped into the same feature space, ensuring the superposability of features with different time granularities.
[0136] After cross - time alignment is completed, the multi - scale feature maps are integrated into a unified feature representation through weighted fusion. The weighted fusion process dynamically adjusts the fusion weights according to the change rate of the time - series features. For example, when the change rate of the features in the time series is high, the weights of the short - time - slice features are enhanced to capture sudden changes; while when the change rate is low, higher weights are assigned to the long - time - slice features to better represent the global pattern. The dynamic adjustment of the weights can be achieved by analyzing the gradient or frequency of the feature changes, so as to ensure that the fused feature maps can take into account both local changes and global trends.
[0137] Finally, the fused multi - scale feature maps are passed to the encoding part of the auto - encoder. The auto - encoder further compresses the fused features, converting the high - dimensional time - series feature maps into low - dimensional embedding vectors. During the compression process, the auto - encoder retains the key relationships between the features through non - linear transformation and feature aggregation, while discarding redundant information. This low - dimensional embedding vector is not only convenient for subsequent dynamic pattern analysis and threat classification modules to process, but also significantly improves the computational efficiency of the model.
[0138] Through this multi - scale feature extraction mechanism, the time - series feature embedding module can extract rich and diverse feature expressions from the original data, which not only enhances the model's perception ability of information at different time granularities, but also provides high - quality inputs for subsequent deep - learning models. This mechanism can effectively adapt to the complex and changeable power system network environment and provide strong support for precise coordinated defense.
[0139] In a possible implementation, the dynamic pattern analysis module further includes a historical buffer mechanism based on node behavior for dynamically adjusting the calculation accuracy of the interaction weights between nodes. The historical buffer mechanism is specifically used for:
[0140] When generating the interaction weight matrix between nodes, a behavior historical buffer is established for each node to store the operating state data, link traffic data, and interaction features of the node within a preset time window;
[0141] The dynamic pattern analysis module extracts the time - series behavior data of the nodes from the historical buffer through a sliding window mechanism, and combines it with the hidden state sequence of the current time slice to calculate the short - term trend of the node behavior;
[0142] According to the calculated short - term trend, the interaction weights between the node and its neighbor nodes are dynamically adjusted to highlight the identification of abnormal interaction behaviors. The weight adjustment includes enhancing the weights of abnormal interactions and suppressing the influence of normal interactions;
[0143] The adjusted interaction weight matrix is used for the calculation of subsequent node dynamic feature characterization.
[0144] The dynamic mode analysis module enhances the dynamic adaptability of the calculation of interaction weights between nodes by introducing a historical buffer mechanism based on node behavior. It can effectively identify and highlight abnormal interaction behaviors, especially in complex network environments. This mechanism is based on the storage, analysis, and dynamic adjustment of node historical behavior data, achieving precise calculation of node interaction weights and providing high-quality input for subsequent dynamic feature characterization.
[0145] During the process of generating the interaction weight matrix between nodes, a behavior historical buffer is established for each node. The role of this buffer is to store the running state data, link traffic data, and interaction characteristics of the node within a preset time window. The running state data includes the performance metrics of the node, such as CPU utilization rate, memory occupancy rate, and task queue length, which can directly reflect the current load and health status of the node. The link traffic data records the communication characteristics between nodes, such as packet transmission rate and network bandwidth utilization rate, reflecting the real-time usage of the link. The interaction characteristics describe the interaction intensity and pattern between the node and other nodes, such as communication frequency, data transmission direction, and specific protocol usage. The storage of these data is recorded in a time series form, which can retain the dynamic change information of node behavior.
[0146] To extract valuable information from the historical buffer, the dynamic mode analysis module adopts a sliding window mechanism to gradually process the time series behavior data of nodes. The sliding window mechanism extracts the data within the current time window at each time step and combines it with the hidden state sequence of the current time slice to analyze the short-term behavior trend of the node. The hidden state sequence is generated by the previous feature extraction module and contains the comprehensive features of the node in the current time slice. By combining the hidden state sequence with the historical behavior data, the module can capture the behavior changes of the node in a short period, such as sudden traffic increase, abnormal state fluctuations, or abnormal communication patterns.
[0147] Based on the extracted short-term trends, the dynamic mode analysis module dynamically adjusts the interaction weights between the node and its neighbor nodes. The core of the weight adjustment lies in highlighting the identification of abnormal interaction behaviors, which is usually achieved by non-linearly amplifying or suppressing the interaction weights. For example, when the short-term trend of a node shows an abnormal communication pattern (such as high-frequency packet transmission or access behavior that does not conform to normal operations), the associated interaction weight will be amplified, so that the abnormal behavior is more prominently displayed in the weight matrix. On the contrary, for nodes that have been in a stable state for a long time, their interaction weights will be appropriately suppressed to reduce the interference of normal interactions on subsequent analysis. Through this dynamic adjustment, the weight matrix can more accurately reflect the actual interaction state between nodes.
[0148] The adjusted interaction weight matrix is directly used for the calculation of subsequent node dynamic feature characterization. In the dynamic feature characterization process, the characteristics of each node include not only its own state, but also the characteristics and interaction weights of its neighboring nodes. Through this process, the characteristics of abnormal nodes or key nodes are further strengthened in the feature characterization, providing an important basis for subsequent threat classification.
[0149] The historical buffer mechanism effectively captures the short-term dynamic characteristics of node behavior by storing and analyzing node behavior data, and achieves real-time response to abnormal behavior through sliding windows and dynamic weight adjustment. Compared with existing technologies, this mechanism not only enhances the calculation accuracy of the interaction weights between nodes, but also significantly improves the system's sensitivity and response capabilities to network anomalies. Through this design, the dynamic pattern analysis module can handle node behavior in complex network environments more efficiently and accurately, providing solid technical support for the linkage defense capabilities of the entire system.
[0150] It should be understood that the order of execution of the steps in the above embodiment does not necessarily mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention.
[0151] The following is an embodiment of the device of the present invention. For details not described in detail therein, reference may be made to the corresponding method embodiment described above.
[0152] Figure 2 The structural diagram of the power system cyberspace precision linkage defense control device provided by an embodiment of the present invention is shown. For the convenience of explanation, only the part related to the embodiment of the present invention is shown, which is described in detail as follows:
[0153] like Figure 2 As shown, the power system cyberspace precision linkage defense control device 2 includes:
[0154] The network space mapping unit 201 is used to perform real-time dynamic mapping of the power system network space based on space mapping technology, generate a network topology structure and a key asset distribution map, and extract the operating status data and potential risk information of the network nodes in the network topology structure and the key asset distribution map.
[0155] The fusion and threat identification unit 202 is used to integrate data sources at different levels of the power system according to the operating status data and potential risk information of the network nodes and use deep learning algorithms to perform correlation analysis to obtain network threat classification results.
[0156] The defense strategy generation unit 203 is used to generate a dynamic defense strategy based on the network threat classification result and the network operation status; wherein the strategy includes defense path selection, response node scheduling and risk isolation measures.
[0157] The execution and feedback unit 204 is used to execute the generated dynamic defense strategy, obtain real-time monitoring results, and evaluate the effectiveness of defense measures according to the feedback mechanism of real-time monitoring results.
[0158] The analysis and update unit 205 is used to collect historical defense records, threat characteristics, and response effects, and update the threat knowledge base and defense rule base based on data analysis techniques.
[0159] The cyber space mapping unit 201 is used to perform real-time dynamic mapping of the power system cyber space. Its implementation is based on space mapping technology, and specifically includes the following technical solutions. First, the cyber space mapping unit 201 collects the operation status data of key nodes in the network in real time through a variety of sensor devices deployed in the power system network, including but not limited to information such as traffic, connection status, latency, and device configuration. To ensure the comprehensiveness of mapping, the cyber space mapping unit 201 also integrates two methods: passive listening and active detection. The passive listening method is used to capture the real-time communication data of devices and links in the network, while the active detection method obtains information about unknown parts of the network topology by sending specific detection data packets.
[0160] The collected data is processed through a preprocessing module for cleaning, denoising, and formatting to ensure the accuracy and consistency of the data. Subsequently, the processed data enters the mapping algorithm module, which combines the topology discovery algorithm and the path calculation algorithm to generate the topology structure diagram of the power system network. The topology discovery algorithm can identify the nodes, links, and their connection relationships in the network, while the path calculation algorithm determines the communication paths between different nodes according to the network routing rules. Through these processes, the cyber space mapping unit 201 can generate an accurate network topology structure.
[0161] In addition, the cyber space mapping unit 201 further identifies and classifies key assets in the cyber space. Key assets include but not limited to substation monitoring equipment, dispatching center servers, distribution terminals, etc. This unit forms a key asset distribution map by matching the identification information and attribute data of nodes through the interface with the asset management database.
[0162] To extract operation status data and potential risk information, the cyber space mapping unit 201 is also equipped with an operation status analysis module and a risk assessment module. The operation status analysis module performs statistical and trend analysis on the real-time data of nodes and links, such as monitoring traffic changes, frequencies of abnormal connections, etc. The risk assessment module combines preset security policies and risk assessment models to evaluate the risk levels of each node and link, such as detecting whether there are abnormal communication behaviors, unauthorized access attempts, or potential security configuration vulnerabilities.
[0163] The generated network topology structure, critical asset distribution map, and the operating status data and potential risk information of the nodes are transmitted to the fusion and threat identification unit 202 through the internal data interface. These data not only provide accurate basic information for subsequent threat identification and defense strategy generation but also ensure that the system can respond quickly and adjust when facing complex network threats through real-time dynamic updates.
[0164] In a possible implementation, the cyber space mapping unit 201 is specifically used for:
[0165] Obtain the real-time operating data of the power system network, including the performance level data of each node, link traffic, historical failure times, and node correlation;
[0166] Calculate the weight w of the link between nodes through space mapping technology ij ;
[0167] According to the calculated weight w ij , construct the link weight matrix W;
[0168] Based on the link weight matrix W, construct the network topology structure G(V,E); where the node set V is all the devices in the power system, and the edge set E is all the connections between nodes;
[0169] Calculate the importance index C of node i i :
[0170] Sort all nodes according to the importance index, and select the specified number of nodes with the highest importance index as critical assets to generate a critical asset distribution map.
[0171] By sorting the importance indices of all nodes in descending order, the most important nodes in the network can be identified as critical assets. The number of critical assets is determined by user requirements, such as selecting the top 5% of the nodes.
[0172] Among them,
[0173] In a possible implementation, the weight w of the link between nodes ij The calculation formula is:
[0174]
[0175] where w ij is the link weight between node i and node j; α1, α2, and α3 are weight adjustment factors; T ij is the link traffic between node i and node j; R ij is the node correlation between node i and node j, calculated through the historical interaction frequency between nodes; S iThe current performance level data of node i, including CPU utilization; F i (τ) is the number of times node i fails at time τ; t start is the start time of the time window, t is the current time; t1 is the total length of the time window.
[0176] In a possible implementation, the importance index C of node i i is calculated as follows:
[0177] C i = ∑ j∈V w ij
[0178] where w ij is the link weight between node i and node j.
[0179] In a possible implementation, the cyber space mapping unit 201 is specifically used for:
[0180] Based on the network topology structure, determine the communication relationship and link attributes of nodes and their neighbor nodes, and extract the interaction characteristics between nodes as operation state correlation data;
[0181] According to the critical asset distribution map, locate the critical asset nodes, and combine with the operation state correlation data to extract the node operation state and link load information related to the critical assets;
[0182] Based on the extracted node operation state and link load information related to the critical assets, analyze the link anomaly trend, node interaction anomaly and topology change, and generate potential risk information of the critical asset nodes.
[0183] The cyber space mapping unit 201 plays a key role in the power system cyber space precision linkage defense device. Its function is to comprehensively analyze the communication relationship and operation state between nodes based on the network topology structure and the critical asset distribution map, so as to accurately evaluate the potential risks of critical assets. Its specific implementation includes a series of operation processes from data collection to risk analysis, and these processes are interrelated to form a systematic technical solution.
[0184] First, based on the network topology of the power system, the cyber space mapping unit 201 determines the communication relationships and link attributes between nodes and their neighbor nodes. The implementation of this step requires collecting communication data between nodes through real-time network monitoring tools, including but not limited to parameters such as data transmission rate, packet loss rate, and latency. For the extraction of link attributes, not only the static attributes of the link (such as bandwidth and link type) need to be concerned, but also the changes in the link state (such as congestion and abnormal fluctuations) need to be dynamically tracked. These data can be analyzed to extract the interaction characteristics between nodes, such as the frequency of data interaction, communication direction, and interaction intensity. The interaction characteristics are then normalized and used as the basis for operation status correlation data.
[0185] Next, according to the critical asset distribution map, the cyber space mapping unit 201 locates the critical asset nodes and extracts the operation status and link load information related to these critical assets in combination with the operation status correlation data. The location of critical asset nodes depends on the predefined asset categories, the importance ranking of nodes, and the upstream and downstream dependencies in the critical asset distribution map. For example, high-priority critical asset nodes may include control centers, data aggregation nodes, or key sensor nodes. After locating the critical asset nodes, the mapping unit needs to extract the operation status data related to each critical asset node, such as CPU utilization, memory occupancy, and real-time task load, and at the same time pay attention to the load information of its related links, such as the real-time traffic of the link, load balancing situation, and the health status of the link. These data need to be uniformly aligned in space and time to ensure that the dynamic relationship between the critical asset nodes and their surrounding environment can be accurately reflected.
[0186] Based on the extracted operation status and link load information of the critical asset nodes, the cyber space mapping unit 201 further analyzes the link anomaly trend, node interaction anomaly, and dynamic changes in the network topology. The link anomaly trend analysis is achieved by performing anomaly detection on the time-series data of link traffic and health status, and historical baseline comparison or pattern recognition methods can be used to identify sudden anomalies in the link, such as sudden increase in traffic, long-term latency, or frequent link interruptions. Node interaction anomaly analysis needs to combine the interaction characteristic data to identify possible abnormal behaviors between nodes, such as abnormal repetition of packets, increase in unauthorized access requests, or abnormal reversal of communication direction. In addition, the network topology change analysis evaluates the dynamic characteristics of the network by monitoring the addition and deletion of nodes and links in the network, changes in the connections between nodes, or changes in the overall topology structure.
[0187] Finally, through comprehensive processing of the above analysis results, the cyberspace mapping unit 201 generates potential risk information of key asset nodes. Such risk information includes, but is not limited to: performance bottlenecks that may exist in a key asset node, potential congestion points of the link, and the risk of abnormal communication attacks that may be suffered. Potential risk information is output in the form of structured data, which may include risk levels (high, medium, and low), impact ranges (the associated ranges of nodes and links), and corresponding trigger conditions (such as abnormal thresholds or time periods). These risk information not only provides accurate input for subsequent threat classification and defense strategy generation, but also provides network managers with intuitive decision-making basis.
[0188] The network space mapping unit 201 can further expand its functions. For example, for the extraction of link attributes, the weight analysis of multi-path communication can be added to identify the backup channel performance of key links. For the extraction of operation status data, by introducing a time weighting mechanism, priority can be given to recent operation data changes, so as to respond to emergencies more quickly. In addition, for topology change analysis, the regional granularity of the analysis can be dynamically adjusted in combination with the communication mode of each area in the network to adapt to network environments of different scales and complexities.
[0189] Through the above technical solution, the cyberspace mapping unit 201 can not only comprehensively monitor and analyze the key nodes and link status in the power system network, but also generate high-value risk information based on the specific needs of key assets, providing a solid foundation for achieving precise linkage defense.
[0190] The fusion and threat identification unit 202 is a key module for receiving the data provided by the cyberspace mapping unit 201 and performing in-depth analysis on the data to achieve intelligent threat identification. Its main function is to fully perceive the network status by integrating data from different levels and sources in the power system network, including network traffic data, node logs, equipment status information and historical attack records, and use deep learning algorithms to perform intelligent correlation analysis on these data.
[0191] The fusion and threat identification unit 202 standardizes and unifies heterogeneous data from multiple data sources through a data integration module. This module uses a specific cleaning and conversion algorithm to remove redundant and noisy information in the data, and uses a format conversion method to convert data in different formats into a unified input format. For example, log files are parsed into structured data tables, and traffic features are extracted as quantitative indicators. Through this data fusion method, the quality and consistency of the input data can be ensured.
[0192] Based on the standardized data, this unit conducts threat identification through a deep learning analysis module. This module utilizes a deep neural network structure, such as the combination of a convolutional neural network (CNN) and a long short-term memory network (LSTM), to design a specific model for network threats. The CNN part is used to extract static features, such as the spatial distribution characteristics in network traffic patterns; the LSTM part captures the dynamic changes in time series data, such as the evolution trend of abnormal behaviors. This joint model can effectively process complex multi-dimensional data in the power system network, especially when facing advanced persistent threats (APT), and can identify potential attack patterns.
[0193] To improve the accuracy of threat identification, the fusion and threat identification unit 202 also introduces a feature correlation analysis algorithm based on the multi-head attention mechanism. This algorithm assigns different weights to the features of each data source, focusing on threat features with high correlation, such as abnormally high-frequency network connections or recurring unauthorized access requests. This can significantly improve the detection ability for key threats and reduce the false alarm rate.
[0194] After completing the in-depth analysis, this unit generates threat identification results, including threat type, occurrence location, potential attack path, and risk level. These results are transmitted to the defense strategy generation unit 203 through an internal data interface for subsequent defense strategy formulation. At the same time, to support real-time defense response, the fusion and threat identification unit 202 designs a low-latency processing architecture, which significantly reduces the latency time of threat identification through asynchronous processing and batch computing technologies.
[0195] In a possible implementation, the fusion and threat identification unit 202 is specifically used for:
[0196] Preprocess the operation status data and potential risk information of network nodes to obtain time series features; among them, the preprocessing includes formatting and normalization processing; the time series features include node operation status, link traffic, historical fault records, and communication abnormal behaviors;
[0197] Based on the time series features, use a pre-trained deep learning model to obtain the probability distribution and classification labels of each network threat type; among them, network threats include denial-of-service attacks, unauthorized access, and data tampering.
[0198] The fusion and threat identification unit 202 is an important part of the precise linkage defense device for the power system network space. Its core function is to accurately identify and classify network threats through multi-level data processing and threat analysis of deep learning models. The entire process of this unit from data reception to threat identification is interconnected, forming an efficient and dynamic technical solution.
[0199] First, the Fusion and Threat Recognition Unit 202 receives the operating status data and potential risk information of network nodes. The operating status data is derived from the performance metrics monitored in real time by the nodes, including but not limited to CPU utilization, memory occupancy, and task queue length. These data can directly reflect the current workload and operating health status of the nodes. The potential risk information is the analysis result transferred from the Cyberspace Mapping Unit 201, which may include link anomaly trends, abnormal interactions between nodes, and changes in the topological structure. These data not only provide the static node status but also incorporate the dynamic characteristics of the network, laying a rich data foundation for subsequent threat analysis.
[0200] After receiving these data, the Fusion and Threat Recognition Unit 202 preprocesses them to ensure the consistency of data format and the standardization of features. During the preprocessing, the data is first formatted to align the data from different sources in chronological order and fill in the possible missing values. The missing values can be processed using time series interpolation methods, such as linear interpolation or polynomial interpolation, to reduce the bias caused by incomplete data. Subsequently, the data enters the normalization process, where the feature values are scaled to a fixed range (such as 0 to 1) to eliminate the differences between different feature dimensions. Normalization not only improves the convergence speed of the deep learning model but also reduces the negative impact of extreme values on model training.
[0201] After preprocessing, the time series features generated by the Fusion and Threat Recognition Unit 202 include node operating status, link traffic, historical fault records, and communication abnormal behaviors. The selection of these features has a clear functional orientation: the node operating status is used to evaluate the health of the nodes, the link traffic reflects the load distribution of the network and possible abnormal behaviors, the historical fault records provide a long-term evaluation basis for node stability, and the communication abnormal behaviors directly point to network attacks or potential security threats. The time series features are segmented in units of fixed time windows, and the data within each window is organized into multi-dimensional vectors to capture the time correlation of the features.
[0202] After generating the time series features, the Fusion and Threat Recognition Unit 202 inputs them into a pre-trained deep learning model to identify network threats. The deep learning model is designed to combine the characteristics of time series analysis and feature interaction, usually including a two-layer structure: the first layer is a recurrent neural network (such as LSTM or GRU) used to capture the long-term dependencies in the time series features; the second layer is a fully connected network to further integrate the global information of the time series and generate a classification output for threats. A large number of real and simulated network data, including various scenarios of normal behavior and attack behavior, are used during model training to ensure the adaptability of the model to the actual environment.
[0203] Through the deep learning model, the fusion and threat recognition unit 202 can perform real-time analysis on the received feature data and output the probabilities of various network threats. These threats include, but are not limited to, denial of service attacks (DoS), unauthorized access, and data tampering. Denial of service attacks are usually manifested by excessive loads on nodes and links, while unauthorized access may have specific patterns in abnormal communication behaviors (such as abnormal source IP addresses or high-frequency access requests). Data tampering may be indirectly reflected through historical fault records and sudden changes in link loads. Through the probability output, the fusion and threat recognition unit 202 can effectively map complex network behaviors into intuitive threat assessment results for use by the subsequent defense strategy generation unit 203.
[0204] To further enhance the robustness and applicability of the fusion and threat recognition unit 202, the unit can expand the following functions. For example, in the time series feature generation stage, a feature importance evaluation module can be added to dynamically adjust the weights of features, making the model more sensitive to key features. In the deep learning model, an attention mechanism can be introduced to focus on the data of high-risk nodes and their associated links, thereby further improving the accuracy of threat recognition. In addition, the unit can also compare the recognition results with the historical threat knowledge base to generate a confidence analysis of threat types, providing more decision-making support for network managers.
[0205] Through the above implementation, the fusion and threat recognition unit 202 achieves full-chain coverage from data to threats in the security analysis of the power system network.
[0206] In a possible implementation, the deep learning model includes a time series feature embedding module, a dynamic pattern analysis module, and a threat classification module;
[0207] Among them, the time series feature embedding module is used to receive the preprocessed time series feature data; input the received data into a one-dimensional convolutional neural network to extract the local feature patterns of each time slice and generate a feature map tensor; input the feature map tensor into the encoding part of the autoencoder to further compress the feature dimension and generate a low-dimensional embedding matrix;
[0208] The dynamic pattern analysis module is used to receive the low-dimensional embedding matrix generated by the time series feature embedding module; process the received data through a long short-term memory network to obtain a hidden state sequence; input the hidden state sequence into the graph attention network, and combine the network topology structure and the communication relationship matrix between nodes, and calculate the interaction weights for each pair of nodes through the attention mechanism to generate an inter-node interaction weight matrix; according to the hidden state sequence and the inter-node interaction weight matrix, through a weighted aggregation operation, fuse the own features of each node with the features of its neighbor nodes to generate a dynamic feature representation matrix of the nodes;
[0209] The threat classification module is used to receive the dynamic feature representation matrix and the interaction weight matrix provided by the dynamic pattern analysis module; generate the threat feature representation of each node according to the dynamic feature representation matrix and the interaction weight matrix; extract the feature patterns of threat types including denial-of-service attacks, unauthorized access, and data tampering layer by layer through a fully connected neural network according to the threat feature representation, and achieve classification through the Softmax layer, outputting the probability distribution and classification labels of each threat type.
[0210] The deep learning model undertakes the core tasks from feature extraction to threat recognition in the precise linkage defense device for the power system cyberspace. It is specifically composed of a time series feature embedding module, a dynamic pattern analysis module, and a threat classification module. These three modules cooperate closely and through a series of ordered calculation steps, transform complex network operation data into clear threat assessment results, providing important support for the formulation of subsequent defense strategies.
[0211] First, the time series feature embedding module is used to receive the preprocessed time series feature data. These feature data include but are not limited to node operation status, link traffic, historical fault records, and communication abnormal behaviors. The received feature data are input into a one-dimensional convolutional neural network to extract the local feature patterns in each time slice. The one-dimensional convolutional neural network uses the method of sliding convolutional kernels to gradually extract high-frequency and low-frequency features in the time dimension, thereby capturing the short-term change rules in the time series. Through this convolutional operation, the network generates a feature map tensor, which retains the key patterns of the original data while significantly reducing redundant information.
[0212] Subsequently, the feature map tensor is input into the encoding part of the autoencoder. The autoencoder compresses the high-dimensional feature map into a low-dimensional embedding matrix through multiple non-linear transformations. This compression process not only greatly reduces the storage requirements of the data but also retains the key correlation information between features. During the encoding process, the autoencoder aggregates the important patterns in the feature space through weight sharing and hierarchical feature extraction, thereby generating globally representative embedding vectors. These embedding vectors, as the condensed representation of the time series features, are transmitted to the dynamic pattern analysis module.
[0213] After receiving the low-dimensional embedding matrix, the dynamic pattern analysis module first uses the long short-term memory network (LSTM) to perform time series modeling on the embedding vectors. The LSTM network captures the long-term and short-term dependencies in the time series through its unique gating mechanism. During the processing, the LSTM performs non-linear transformations on the input embedding vectors at each time step and combines the information of historical time steps to generate a hidden state sequence. These hidden state sequences encode the dynamic change features of the node operation status in the time dimension and are the comprehensive embodiment of the global patterns of the time series.
[0214] The generated hidden state sequence is input into the Graph Attention Network (GAT). GAT combines the network topology structure and the communication relationship matrix between nodes, and calculates the interaction weights for each pair of nodes through the attention mechanism. Specifically, the attention mechanism assigns a weight value to each edge according to the similarity of node hidden states and the importance of communication relationships. These weight values can dynamically reflect the importance of interactions between nodes, thereby constructing an interaction weight matrix between nodes. The weight matrix is then used for the weighted aggregation operation of node features. In the weighted aggregation process, the dynamic feature representation of a node is obtained by weighted summing its own features and the features of neighboring nodes according to the weights. This process ensures that the final representation of each node includes not only its own characteristics but also the information of its neighborhood, fully reflecting the global position and role of the node in the network.
[0215] The outputs of the dynamic pattern analysis module, including the dynamic feature representation matrix of nodes and the interaction weight matrix, are passed to the threat classification module. The threat classification module maps the dynamic features of nodes to the feature space of threat categories through the fully connected network structure of deep learning. Specifically, the dynamic feature representation matrix first undergoes feature transformation through a multi-layer fully connected neural network, and each layer of the network gradually extracts higher-order threat patterns. Subsequently, the extracted threat features are classified through the Softmax layer, and the probability distribution of each threat type and the corresponding classification labels are output. The classification results cover various common threat types such as Denial of Service (DoS) attacks, unauthorized access, and data tampering, and the probability values reflect the likelihood and severity of threats.
[0216] The design of this deep learning model not only covers the complete process from time series feature extraction to threat classification but also is optimized for the complexity of the power system network. For example, in the time series modeling stage, the module combines the advantages of convolutional networks and recurrent networks, capturing both the short-term fluctuations and long-term evolution trends of time series; in the Graph Attention Network, the attention mechanism dynamically adjusts the weight distribution between nodes, significantly improving the sensitivity to network abnormal behaviors; in the classification stage, the multi-layer fully connected network deeply mines the threat features, making the classification results more accurate and comprehensive.
[0217] Through the above technical solutions, this model can efficiently process complex time series and topological data in the power system network, providing comprehensive and accurate support for threat identification and classification.
[0218] In a possible implementation, the defense strategy generation unit 203 is one of the core modules of the entire defense device. It is responsible for dynamically formulating specific defense strategies based on the threat type, threat location, and risk level information output by the fusion and threat recognition unit 202, in combination with the current operating state of the power system network. To achieve efficient and accurate defense strategy generation, this unit integrates a series of algorithm modules and optimization mechanisms, and its design fully considers the complexity and real-time requirements of the power system network.
[0219] The first step of the defense strategy generation unit 203 is to receive and parse the input data from the fusion and threat recognition unit 202. The input data usually includes information such as threat type (e.g., denial of service attack, unauthorized access, data tampering, etc.), attack path, affected nodes, and their importance levels. The parsing module structures this data to form a standardized threat description file to ensure that subsequent modules can directly utilize it.
[0220] During the process of defense strategy generation, the unit generates a defense path suitable for the current threat through the defense path optimization module. The defense path optimization module uses a shortest path algorithm based on graph theory and introduces a multi-objective optimization model, taking the threat isolation effect, minimizing response time, and maximizing resource utilization efficiency as optimization goals. Specifically, the defense path optimization module calculates the pros and cons of each possible defense path through a weighted cost function. For example:
[0221] Cost = α·T + β·R - γ·I
[0222] Where T is the response time, R is the resource consumption, I is the threat isolation effect, and the weight parameters α, β, γ are dynamically adjusted according to the actual scenario.
[0223] At the same time, the defense strategy generation unit 203 is also equipped with a response node scheduling module for selecting and allocating response nodes in the power system network. The scheduling module comprehensively considers the availability, current load, and response capabilities of each node, and uses linear programming or integer programming algorithms to generate a scheduling plan. To improve the robustness of the scheduling, the module also introduces a fault tolerance mechanism that can automatically adjust the strategy when some nodes are unavailable to ensure the defense effect.
[0224] For some high-risk threats, the defense strategy generation unit 203 includes a risk isolation strategy module for designing targeted isolation measures. This module combines the attack path and the distribution of key nodes, calculates the minimum isolation cost, and generates a specific isolation plan, such as blocking a specific communication path or restricting the access rights of certain nodes. The generation of the isolation strategy makes full use of the current network topology and node attributes to ensure that while minimizing the impact of the threat to the greatest extent, the interference to normal services is minimized.
[0225] Another key design of the defense strategy generation unit 203 is the dynamic adjustment ability of the strategy. After generating the initial defense strategy, the unit can combine the real-time data provided by the execution and feedback unit 204 and optimize the strategy through the feedback adjustment module. For example, when it is found that the effect of a certain defense path is not good or the resource consumption is too high, the module can re-evaluate and generate an optimized strategy version. This closed-loop feedback mechanism ensures that the defense strategy always matches the current network state and threat characteristics.
[0226] Through the close cooperation of these modules, the defense strategy generation unit 203 can quickly respond to complex and dynamically changing power system network threats and provide accurate and efficient defense strategies.
[0227] The execution and feedback unit 204 is a key module for implementing the execution and optimization of the defense strategy. Its core functions include the execution of the defense strategy, the real-time monitoring of the defense effect, and the implementation of the feedback mechanism to ensure the effectiveness and dynamic adjustment ability of the defense measures. This unit works closely with the defense strategy generation unit 203 and can achieve efficient threat response and coordinated defense in a complex power system network environment.
[0228] First of all, the execution and feedback unit 204 receives the dynamic defense strategy provided by the defense strategy generation unit 203. This strategy includes defense path selection, response node scheduling, and risk isolation measures. To accurately execute these strategies, this unit designs a strategy parsing module, which decomposes the strategy into specific operation instructions, such as modifying network traffic routing, adjusting node permissions, activating isolation measures, etc. The parsing module ensures that the instructions can be directly applied to the relevant devices of the power system network by calling the control interfaces of network devices (such as the APIs of routers, switches, and firewalls).
[0229] During the execution process, the execution and feedback unit 204 monitors the effect of the defense operation in real time through a distributed sensor network. The sensor network includes traffic monitors, status recording devices, and log collectors installed at key nodes, which can capture the changes in network traffic, node performance, and system operating status in real time. The collected data is processed by the data aggregation module, which uses a time window-based aggregation algorithm to compress the real-time data into statistical information that is easy to analyze, such as threat interception rate, node response time, and coverage of isolation measures.
[0230] To evaluate the effectiveness of defense measures, a multi-dimensional defense effect evaluation model is built into this unit. The evaluation model takes real-time data as input and combines predefined defense effect metrics (such as threat blocking rate, system resource occupancy rate, and the degree of impact on normal operations) to calculate the comprehensive score of defense operations. For example, when a certain defense path successfully blocks a threat but causes a resource bottleneck, the model will prompt that this path needs to be optimized. The scoring result not only provides a basis for subsequent policy adjustments but also helps select higher-priority defense measures when multiple policies are executed.
[0231] The feedback mechanism is an important part of the execution and feedback unit 204. This unit sends the evaluation results of defense effects and real-time monitoring data back to the defense policy generation unit 203 through a feedback channel. The feedback information includes the effectiveness of the current policy, potential problems, and parts that need to be optimized. For example, when it is detected that the resource usage of some nodes is overloaded, the feedback mechanism will prompt to generate a new scheduling plan. To ensure the real-time nature of feedback, this unit adopts a low-latency communication protocol and an asynchronous transmission architecture, which can complete the information backhaul within milliseconds.
[0232] The execution and feedback unit 204 is also equipped with an adaptive optimization module. This module automatically adjusts some defense parameters according to the feedback information, such as dynamically adjusting the traffic limit threshold, optimizing the isolation range, or reallocating the task load of response nodes, so as to achieve the immediate optimization of defense measures. The adaptive optimization module adopts an incremental update algorithm to reduce the impact of the adjustment process on network operation, and at the same time gradually improves the overall defense efficiency through progressive optimization.
[0233] The analysis and update unit 205 is an important module for achieving continuous optimization and knowledge accumulation in the entire device. Its main function is to deeply analyze the historical data, threat characteristics, and response effects collected during the system operation, and use this data to dynamically update the threat knowledge base and defense rule base to provide more accurate support for future threat identification and response.
[0234] This unit first collects multi-dimensional historical data through interfaces with other units, including topology change information and critical asset distribution from the cyber space mapping unit 201, the threat classification results of the threat identification unit 202, the policy output of the defense policy generation unit 203, and the defense effect evaluation data provided by the execution and feedback unit 204. These data are uniformly stored in a distributed database for subsequent analysis and processing. To ensure the quality of the data, the analysis and update unit 205 includes a data preprocessing module, which eliminates redundant or abnormal data through denoising, formatting, and consistency verification, thereby improving the reliability of the analysis results.
[0235] In the data analysis phase, this unit uses techniques such as clustering analysis, association rule mining, and time series analysis to extract potential threat patterns and attack behavior characteristics from a large amount of historical data. For example, by using clustering algorithms to identify threat events with similar attributes, the patterns of specific types of attacks can be summarized; through association rule mining, the key behaviors and possible paths in the attack chain can be discovered; through time series analysis, the occurrence probabilities of certain threats at different time periods can be predicted. These analysis results are used to enrich the threat knowledge base, enabling it to cover more attack types and scenarios.
[0236] The threat knowledge base is one of the core components of the analysis and update unit 205. It stores threat-related information in a structured manner, including threat types, attack paths, impact scopes, characteristic values, countermeasures, etc. The update of the knowledge base is carried out based on incremental learning. Each analysis result will expand or revise the existing knowledge entries. For example, if the frequency of a certain type of threat increases significantly, the knowledge base will dynamically adjust its weight to enhance the priority of this type of threat in subsequent threat identification processes. In addition, this unit also supports knowledge version control and backtracking functions to ensure that the knowledge state at a specific time period can be queried and verified when needed.
[0237] At the same time, this unit is responsible for maintaining the defense rule base, which is the basis for formulating strategies by the defense strategy generation unit 203. The defense rule base stores the conditions, trigger mechanisms, and optimization parameters related to defense strategies, such as the priority response nodes for specific threats, resource allocation limits, and the applicable scopes of isolation strategies. The analysis and update unit 205 continuously optimizes the parameters in the rule base by analyzing the deviation between the defense execution results and the actual effects. For example, when a certain rule causes resource waste, the rule base will reduce the priority of this strategy; when a certain rule has a significant blocking effect on threats, its applicable scope will be increased.
[0238] To support real-time updates, the analysis and update unit 205 is also equipped with an efficient streaming data processing architecture, enabling it to perform analysis and updates while data is flowing in. In addition, the unit introduces deep learning models to automatically extract complex threat characteristics and derive new defense rules, thereby enhancing the system's autonomous optimization ability.
[0239] In the above embodiments, the descriptions of each embodiment have their own focuses. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0240] Those of ordinary skill in the art can realize that the templates, units, and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware or in combination with computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0241] If the module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-mentioned method embodiments of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned embodiments of the precise linkage defense control method for each power system network space. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory, random access memory, electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0242] The above-mentioned embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A precise linkage defense control method for the cyber space of a power system, characterized in that, Including: Based on spatial mapping technology, a real-time dynamic mapping of the cyber space of the power system is carried out to generate a network topology structure and a distribution map of key assets, and the operation status data and potential risk information of network nodes in the network topology structure and the distribution map of key assets are extracted; According to the operation status data and potential risk information of network nodes, data sources at different levels of the power system are integrated and correlation analysis is carried out using deep learning algorithms to obtain network threat classification results; Generate dynamic defense strategies based on network threat classification results and network operation status; among them, the strategies include defense path selection, response node scheduling and risk isolation measures; Execute the generated dynamic defense strategies, obtain real-time monitoring results, evaluate the effectiveness of defense measures according to the feedback mechanism of real-time monitoring results, and collect historical defense records, threat characteristics and response effects, and update the threat knowledge base and defense rule base based on data analysis technology.
2. The precise linkage defense control method for the cyber space of the power system according to claim 1, wherein, The real-time dynamic mapping of the cyber space of the power system based on spatial mapping technology to generate a network topology structure and a distribution map of key assets includes: Obtain the real-time operation data of the power system network, including the performance level data of each node, link traffic, historical failure times, and node correlation degree; Calculate the weight w of the link between nodes through spatial mapping technology ij ; According to the calculated weight w ij , construct the link weight matrix W; Based on the link weight matrix W, construct a network topology structure G(V,E); where the node set V is all devices in the power system, and the edge set E is the connection between all nodes; Importance index C of computing node i i : Sort all nodes according to the importance index, select a specified number of nodes with the highest importance index as key assets, and generate a distribution map of key assets.
3. The precise linkage defense control method for the power system cyberspace according to claim 2, wherein The weight w of the link between nodes ij The calculation formula is as follows: Among them, w ij is the link weight between node i and node j; α1, α2, and α3 are weight adjustment factors; T ij is the link traffic between node i and node j; R ij is the node correlation degree between node i and node j, calculated through the historical interaction frequency between nodes; S i is the current performance level data of node i, including CPU utilization; F i (τ) is the number of failures of node i at time τ; t start is the start time of the time window, t is the current time; t1 is the total length of the time window.
4. The precise linkage defense control method for the power system cyberspace according to claim 3, characterized in that The importance index C of node i i The calculation formula is as follows: C i = ∑ j∈V w ij where w ij is the link weight between node i and node j.
5. The precise linkage defense control method for the cyber space of the power system according to claim 1, characterized in that The extraction of the operation status data and potential risk information of network nodes in the network topology structure and the distribution map of key assets includes: Based on the network topology structure, determine the communication relationship and link attributes between nodes and their neighbor nodes, and extract the interaction characteristics between nodes as operation status correlation data; According to the distribution map of key assets, locate key asset nodes, and combine with operation status correlation data to extract the operation status of nodes related to key assets and link load information; Based on the extracted operation status of nodes related to key assets and link load information, analyze link anomaly trends, node interaction anomalies and topology changes, and generate potential risk information of key asset nodes.
6. The precise and coordinated defense control method for the power system cyberspace according to claim 1, wherein The integration of data sources at different levels of the power system and the use of deep learning algorithms for correlation analysis according to the operation status data and potential risk information of network nodes to obtain network threat classification results include: Preprocess the operation status data and potential risk information of network nodes to obtain time series features; among them, the preprocessing includes formatting and normalization processing; the time series features include node operation status, link traffic, historical failure records and communication abnormal behaviors; According to the time series features, use a pre-trained deep learning model to obtain the probability distribution and classification labels of each network threat type; among them, the network threats include denial of service attacks, unauthorized access, and data tampering.
7. The power system cyber space precise linkage defense control method according to claim 6, characterized in that, The deep learning model includes a time series feature embedding module, a dynamic pattern analysis module and a threat classification module; Obtaining the probabilities of various network threats based on the time series features using a pre-trained deep learning model, including: The time series feature embedding module receives the preprocessed time series feature data; inputs the received data into a one-dimensional convolutional neural network to extract the local feature patterns of each time slice, generating a feature map tensor; inputs the feature map tensor into the encoding part of an autoencoder to further compress the feature dimension, generating a low-dimensional embedding matrix; The dynamic pattern analysis module receives the low-dimensional embedding matrix generated by the time series feature embedding module; processes the received data through a long short-term memory network to obtain a hidden state sequence; inputs the hidden state sequence into a graph attention network, and combines the network topology structure and the communication relationship matrix between nodes, and calculates the interaction weights for each pair of nodes through an attention mechanism, generating an interaction weight matrix between nodes; according to the hidden state sequence and the interaction weight matrix, through a weighted aggregation operation, fuses the own features of each node with the features of its neighbor nodes, generating a dynamic feature representation matrix of the nodes; The threat classification module receives the dynamic feature representation matrix and the interaction weight matrix provided by the dynamic pattern analysis module; generates the threat feature representation of each node according to the dynamic feature representation matrix and the interaction weight matrix; according to the threat feature representation, extracts the feature patterns of threat types including denial-of-service attacks, unauthorized access, and data tampering layer by layer through a fully connected neural network, and realizes classification through a Softmax layer, outputting the probability distribution and classification labels of each threat type.
8. The power system cyber space precise linkage defense control method according to claim 7, characterized in that The step of fusing the own features of each node with the features of its neighbor nodes through a weighted aggregation operation according to the hidden state sequence and the interaction weight matrix to generate a dynamic feature representation matrix of the nodes includes: Calculate the initial weighted value z between computing node i and its neighbor node j ij : where, w ij is the weight value in the interaction weight matrix, reflecting the interaction intensity between nodes i and j; h i is the hidden state feature vector of node i; h j is the hidden state feature vector of node j; M is a trainable weight matrix; b ij is the bias term; σ is the activation function; Neighbor feature representation of computing node i where N(i) is the set of neighbor nodes of node i; The dynamic feature representation h of computing node i i ′ : where α4 is a fusion coefficient; W1 and W2 are trainable weight matrices; b1 and b2 are bias terms.
9. The power system cyber space precise linkage defense control method according to claim 7, characterized in that When processing the input feature map tensor X, the autoencoder introduces a time slice weight calculation sub-module that assigns weights to different time steps; The time slice weight calculation sub-module calculates the time slice weights: where α t is the importance weight of time slice t; ΔS(t) is the difference between the node running state at time slice t and the node running state at time slice t-1, and the node running state includes the utilization rate of the node CPU; ΔT(t) is the difference between the link traffic at time slice t and the link traffic at time slice t-1, and the link traffic includes the data packet transmission rate or the network bandwidth utilization rate; N is the total number of time slices.
10. A precise linkage defense control device for the cyber space of a power system, characterized in that, including: A cyber space mapping unit for real-time dynamic mapping of the cyber space of the power system based on space mapping technology, generating a network topology structure and a critical asset distribution map, and extracting the operation status data and potential risk information of network nodes in the network topology structure and the critical asset distribution map; A fusion and threat recognition unit for integrating data sources at different levels of the power system and performing correlation analysis using deep learning algorithms according to the operation status data and potential risk information of network nodes to obtain a network threat classification result; A defense strategy generation unit for generating a dynamic defense strategy based on the network threat classification result and the network operation status; where the strategy includes defense path selection, response node scheduling, and risk isolation measures; An execution and feedback unit for executing the generated dynamic defense strategy, obtaining real-time monitoring results, and evaluating the effectiveness of the defense measures according to the feedback mechanism of the real-time monitoring results; An analysis and update unit, which is used to collect historical defense records, threat characteristics and response effects, and update the threat knowledge base and the defense rule base based on data analysis techniques.
Citation Information
Cited By
Computer network security data processing method and system based on artificial intelligence
CN120934905A
Cloud security multi-level depth defense system construction method and system
CN121396667A
AI security agent automatic defense system and method
CN121509114A
An ai security agent automated defense system and method
CN121509114B