Power monitoring system network anomaly detection method, device, equipment, medium and product
By combining model-driven and data-driven abnormality detection models, using the network operation data of the power monitoring system, the problem of low accuracy in network abnormality detection of power monitoring system is solved, efficient identification and timely response to known and unknown attack patterns is achieved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202510411728.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-18
AI Technical Summary
The current power monitoring system has low accuracy in network abnormality detection, the model-driven method has limited ability to detect new attack modes, while the data-driven method has reduced detection accuracy in the case of unbalanced data distribution.
The abnormality detection model combined with model-driven and data-driven is adopted to detect abnormalities on the network operation data of the power monitoring system through the pre-trained model-driven sub-model and the data-driven sub-model. The known attack mode is detected using the prior knowledge and rules of the model-driven sub-model. The data-driven sub-model captures unknown attack modes through deep learning and obtains comprehensive anomaly detection scores through weighted summing processing.
It improves the accuracy of network abnormality detection of power monitoring system, can timely identify known and unknown network abnormalities, reduce missed and false alarms, and ensure the stability and security of power monitoring system.
Smart Images

Figure CN120342669A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technologies, and in particular, to a method, device, equipment, medium, and product for detecting network anomalies in a power monitoring system. Background Art
[0002] The power monitoring system plays a crucial role in the operation of the power monitoring system, and its network security is directly related to the stability and reliability of power supply. Currently, the power monitoring system faces complex and ever-changing network security threats. In the field of network anomaly detection, the model-driven method and the data-driven method each have their own advantages and disadvantages. The model-driven method usually detects anomalies based on predefined models and rules, and its detection ability for new and unknown attack patterns is limited, resulting in the accuracy of the detection results of network anomaly detection in the power monitoring system being affected. The data-driven method relies on a large amount of historical data for training, and learns the normal patterns and anomaly patterns in the data through machine learning algorithms. In the power monitoring system, there is a problem of unbalanced data distribution, where the amount of normal data is greater than the amount of abnormal data, resulting in the machine learning model being prone to bias towards normal data during the training process, thereby reducing the detection accuracy for abnormal data and affecting the accuracy of the detection results of network anomaly detection in the power monitoring system. In summary, the accuracy of current network anomaly detection in the power monitoring system is relatively low.
[0003] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention
[0004] The main objective of the present application is to provide a method, device, equipment, medium, and product for detecting network anomalies in a power monitoring system, aiming to solve the technical problem of relatively low accuracy of current network anomaly detection in the power monitoring system.
[0005] To achieve the above objective, the present application proposes a method for detecting network anomalies in a power monitoring system, the method comprising:
[0006] Obtain the network operation data of the power monitoring system collected by a data collection probe, and preprocess the network operation data to obtain standardized operation data, wherein the network operation data is used to characterize the network operation state of the power monitoring system;
[0007] Input the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data through the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score;
[0008] When the anomaly detection score meets a preset anomaly condition, trigger an alarm and execute a preset emergency measure.
[0009] In one embodiment, the anomaly detection model includes the model-driven sub-model and the data-driven sub-model;
[0010] The step of inputting the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score includes:
[0011] Input the standardized operation data into the model-driven sub-model to obtain the model-driven detection score;
[0012] Input the standardized operation data into the data-driven sub-model to obtain the data-driven detection score;
[0013] Perform weighted summation processing on the model-driven detection score and the data-driven detection score through a preset weight set to obtain the anomaly detection score.
[0014] In one embodiment, the model-driven sub-model includes an expert system sub-model and a power flow statistics sub-model;
[0015] The step of inputting the standardized operation data into the model-driven sub-model to obtain the model-driven detection score includes:
[0016] Input the communication protocol data in the standardized operation data into the expert system sub-model to obtain a rule matching score;
[0017] Input the network traffic data in the standardized operation data into the power flow statistics sub-model to obtain a traffic statistics score;
[0018] Perform weighted summation processing on the rule matching score and the traffic statistics score through a preset model-driven weight set to obtain the model-driven detection score.
[0019] In one embodiment, the data-driven sub-model includes a feature extraction layer and an LSTM layer;
[0020] The step of inputting the standardized operation data into the data-driven sub-model to obtain the data-driven detection score includes:
[0021] Input the standardized operation data into the feature extraction layer to obtain a time series feature vector;
[0022] Input the time series feature vector into the LSTM layer to obtain the data-driven detection score.
[0023] In one embodiment, the network operation data includes network traffic data, device operation parameters, and system log data;
[0024] The step of preprocessing the network operation data to obtain standardized operation data includes:
[0025] Delete the noise data, incomplete data, and duplicate data in the network traffic data, and perform standardization processing on the network traffic data after deletion to obtain standardized traffic data;
[0026] Fill in the missing values in the device operation parameters and mark the outliers to obtain the marked device operation parameters, and perform standardization processing on the processed device operation parameters to obtain standardized operation parameters;
[0027] Delete the duplicate data in the system log data, and perform standardization processing on the system log data after deletion to obtain standardized log data;
[0028] Determine the standardized traffic data, the standardized operation parameters, and the standardized log data as the standardized operation data.
[0029] In one embodiment, the anomaly detection score includes a model-driven detection score and a data-driven detection score;
[0030] Before the step of triggering an alarm and executing a preset emergency measure when the anomaly detection score meets a preset anomaly condition, the method further includes:
[0031] If the model-driven detection score is greater than a preset first threshold and the data-driven detection score is greater than a preset second threshold, it is determined that the anomaly detection score meets the preset anomaly condition;
[0032] If the model-driven detection score is less than or equal to the first threshold and the data-driven detection score is greater than the second threshold, or, the model-driven detection score is greater than the first threshold and the data-driven detection score is less than or equal to the second threshold, then a weighted sum processing is performed on the model-driven detection score and the data-driven detection score based on a preset fusion weight set to obtain an anomaly detection score. When the anomaly detection score is greater than a preset anomaly index, it is determined that the anomaly detection score meets the preset anomaly condition.
[0033] In addition, to achieve the above object, the present application further provides a power monitoring system network anomaly detection device, and the power monitoring system network anomaly detection device includes:
[0034] A preprocessing module, configured to obtain network operation data of the power monitoring system collected by a data collection probe, and preprocess the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system;
[0035] A detection module, configured to input the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data by the anomaly detection model, an anomaly detection is performed on the standardized operation data by a model-driven sub-model in the anomaly detection model to obtain the model-driven detection score in the anomaly detection score, and an anomaly detection is performed on the standardized operation data by a data-driven sub-model in the anomaly detection model to obtain the data-driven detection score in the anomaly detection score;
[0036] A warning module, configured to trigger an alarm and execute a preset emergency measure when the anomaly detection score meets the preset anomaly condition.
[0037] In addition, to achieve the above object, the present application further provides a power monitoring system network anomaly detection device, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the computer program is configured to implement the steps of the power monitoring system network anomaly detection method as described above.
[0038] In addition, to achieve the above object, the present application further provides a storage medium, and the storage medium is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the power monitoring system network anomaly detection method as described above are implemented.
[0039] In addition, to achieve the above object, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of the power monitoring system network anomaly detection method described above are implemented.
[0040] One or more technical solutions proposed by the present application have at least the following technical effects:
[0041] Obtain the network operation data of the power monitoring system collected by the data collection probe, and preprocess the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system; input the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data by the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score; when the anomaly detection score meets the preset anomaly condition, trigger an alarm and execute a preset emergency measure.
[0042] In the present application, the model-driven sub-model and the data-driven sub-model in the pre-trained anomaly detection model perform anomaly detection based on the standardized operation data respectively to obtain the model-driven detection score and the data-driven detection score that constitute the anomaly detection score. The model-driven sub-model performs detection based on the predefined model and rules, and the data-driven sub-model is trained based on a large amount of historical data. The two complement each other's advantages and make up for the deficiencies of a single method. The model-driven sub-model can detect known attack patterns, and the data-driven sub-model can handle new and unknown attack patterns. For the problem of unbalanced data distribution, during the training process of a large amount of historical data, the data-driven sub-model reduces the bias towards normal data by combining the results of the model-driven sub-model, improves the detection accuracy of abnormal data, and thus improves the accuracy of power monitoring system network anomaly detection and ensures the network security of the power monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0044] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0045] Figure 1 This is a schematic flowchart provided for the first embodiment of the method for detecting network anomalies in the power monitoring system of the present application;
[0046] Figure 2 This is a schematic flowchart provided for the second embodiment of the method for detecting network anomalies in the power monitoring system of the present application;
[0047] Figure 3 This is a schematic flowchart of the brief process of the method for detecting network anomalies in the power monitoring system provided for an embodiment of the present application;
[0048] Figure 4 This is a schematic diagram of the brief feature extraction provided for an embodiment of the present application;
[0049] Figure 5 This is a schematic diagram for comparing the model effects of the anomaly detection model and the single model-driven model provided for an embodiment of the present application;
[0050] Figure 6 This is a schematic diagram for comparing the model effects of the anomaly detection model and the single data-driven sub-model provided for an embodiment of the present application;
[0051] Figure 7 This is a schematic diagram of the module structure of the device for detecting network anomalies in the power monitoring system according to the embodiment of the present application;
[0052] Figure 8 This is a schematic diagram of the device structure of the hardware operating environment involved in the method for detecting network anomalies in the power monitoring system according to the embodiment of the present application.
[0053] The implementation, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners
[0054] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0055] For a better understanding of the technical solutions of the present application, the following will be described in detail with reference to the accompanying drawings of the specification and the specific implementation manners.
[0056] The main solution of the embodiment of this application is: obtaining the network operation data of the power monitoring system collected by a data collection probe, and preprocessing the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system; inputting the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score, where in the process of processing the standardized operation data by the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score; when the anomaly detection score meets a preset anomaly condition, triggering an alarm and executing a preset emergency measure.
[0057] In this embodiment, for the convenience of description, the following takes a power monitoring system network anomaly detection device (hereinafter referred to as the detection device) as the execution subject for elaboration.
[0058] Since the current power monitoring system faces complex and changeable network security threats, in the field of network anomaly detection, the model-driven method and the data-driven method have their own advantages and disadvantages. The model-driven method usually detects anomalies based on pre-defined models and rules, and its detection ability for new and unknown attack patterns is limited, resulting in the accuracy of the detection results of the power monitoring system network anomaly detection being affected; while the data-driven method relies on a large amount of historical data for training, and uses machine learning algorithms to learn the normal patterns and abnormal patterns in the data. In the power monitoring system, there is a problem of unbalanced data distribution, where the amount of normal data is greater than the amount of abnormal data, resulting in the machine learning model being prone to bias towards normal data during the training process, thereby reducing the detection accuracy of abnormal data and affecting the accuracy of the detection results of the power monitoring system network anomaly detection.
[0059] This application provides a solution. The model-driven sub-model and the data-driven sub-model in the pre-trained anomaly detection model perform anomaly detection based on the standardized operation data respectively, and obtain the anomaly detection score composed of the model-driven detection score and the data-driven detection score. The model-driven sub-model performs detection based on the predefined model and rules, and the data-driven sub-model is trained based on a large amount of historical data. The two complement each other's advantages and make up for the deficiencies of a single method. The model-driven sub-model can detect known attack patterns, and the data-driven sub-model can handle new and unknown attack patterns. For the problem of unbalanced data distribution, during the training process of a large amount of historical data, the data-driven sub-model reduces the bias towards normal data and improves the detection accuracy of abnormal data by combining the results of the model-driven sub-model, thereby improving the accuracy of network anomaly detection in the power monitoring system and ensuring the network security of the power monitoring system.
[0060] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of implementing the above functions. Hereinafter, an electronic device will be taken as an example to illustrate this embodiment and the following embodiments.
[0061] Based on this, the embodiment of this application provides a method for network anomaly detection in a power monitoring system, referring to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the method for network anomaly detection in the power monitoring system of this application.
[0062] In this embodiment, the method for network anomaly detection in the power monitoring system includes steps S10 to S30:
[0063] Step S10, obtain the network operation data of the power monitoring system collected by the data acquisition probe, and preprocess the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system;
[0064] Pre - deploy data collection probes at key network nodes of the power monitoring system (such as substation communication gateways, dispatching center server interfaces, etc.) to collect network operation data. The network operation data covers various types of data in the power monitoring system network, such as network traffic data (for example, it can include source address, destination address, port number, protocol type, number of bytes, timestamp, etc.) of data packets, device operation parameters (such as CPU (Central Processing Unit) usage rate, memory occupancy rate, disk I / O (Input / Output) rate of devices such as monitoring terminals, servers, switches, etc.), and system log data (for example, it can include operation logs, device alarm logs, authentication and authorization logs), which are used to comprehensively reflect the network operation status of the power monitoring system.
[0065] First, deploy data collection probes at key network nodes of the power monitoring system to continuously collect network operation data. After collection, pre - process the original data, which can specifically include cleaning to remove invalid, duplicate, and incorrect data, and then perform standardization processing to scale data of different magnitudes to a unified interval. For example, scale the number of network traffic bytes, device performance metrics, etc. proportionally to the 0 - 1 interval. Finally, extract key features from various types of data, such as extracting traffic rate change features, protocol distribution features, etc. from network traffic, and finally obtain standardized operation data.
[0066] Through data pre - processing, the interference of noise and redundant data on subsequent analysis is reduced. Standardized data makes different types of data comparable, improves the accuracy of subsequent model training and analysis, and the extracted key features can more prominently show the characteristics of the data, which helps to more accurately detect network anomalies.
[0067] Step S20: Input the standardized operation data into a pre - trained anomaly detection model to obtain an anomaly detection score. Among them, during the process of processing the standardized operation data by the anomaly detection model, the model - driven sub - model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model - driven detection score in the anomaly detection score, and the data - driven sub - model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data - driven detection score in the anomaly detection score;
[0068] The anomaly detection model combines model-driven and data-driven approaches and is used to detect network anomalies in a power monitoring system. Among them, the model-driven sub-model is a model constructed based on the power network topology, communication protocol specifications, and expert experience, such as an expert system model and a power flow statistics model. By setting knowledge rules such as normal communication paths, device interaction rules, data flow patterns, and flow thresholds, it detects whether the data deviates from the normal pattern. The data-driven sub-model is obtained by using deep learning algorithms to learn a large amount of historical data. The data-driven sub-model can capture the dynamic change rules of power network traffic and device parameters over time, thereby identifying abnormal fluctuations that deviate from the normal pattern.
[0069] The standardized operation data obtained through preprocessing is input into the pre-trained anomaly detection model. Inside the model, the model-driven sub-model judges the standardized operation data according to the pre-set rules and thresholds, and obtains the model-driven detection score. The model-driven detection score reflects the degree of data anomaly, and the higher the value, the greater the possibility of anomaly; the data-driven sub-model uses the normal pattern and dynamic change rules it has learned to analyze the input data and obtains the data-driven detection score. The data-driven detection score is a value that can measure the degree of data anomaly and is used to judge whether the data deviates from the normal dynamic change pattern.
[0070] It can be understood that the model-driven sub-model can quickly detect data that conforms to the known anomaly pattern by using prior knowledge and rules. The data-driven sub-model can discover potential and unknown anomaly patterns through learning a large amount of data. Combining the detection results of the two improves the comprehensiveness and accuracy of anomaly detection and reduces false negatives and false positives.
[0071] Step S30, when the anomaly detection score meets the preset anomaly condition, trigger an alarm and execute the preset emergency measures.
[0072] It should be noted that the preset anomaly condition is a standard for judging whether the anomaly detection score indicates that there is an anomaly in the network set according to actual needs and experience, and it can be based on the comparison of the model-driven detection score, the data-driven detection score, and the comprehensive calculation result with the corresponding thresholds.
[0073] Compare the model-driven detection score and the data-driven detection score in the anomaly detection score with the preset anomaly conditions. If the preset anomaly conditions are met, for example, both the model-driven detection score and the data-driven detection score exceed their respective preset thresholds, or the anomaly detection score obtained through weighted calculation exceeds the preset anomaly index, the system will immediately trigger an alarm, send anomaly information to the operation and maintenance personnel, and automatically execute the preset emergency measures to reduce the impact of the anomaly on the power monitoring system. In the specific implementation, triggering the alarm can be sending a text message alarm to the operation and maintenance personnel's mobile phones through the text message platform interface; popping up a prominent prompt window on the operation interface of the power monitoring system to display the anomaly information; sending a detailed anomaly report email to the operation and maintenance personnel using the email system, which is not limited here. The emergency measures are not limited here. For example, it can be automatically performing network node isolation operations; or through the system configuration tool, adjusting the device resource allocation according to the preset policy, such as restricting the network bandwidth of the abnormal device, adjusting the resource allocation of the server, etc.
[0074] Timely alarm notifications can enable the operation and maintenance personnel to respond quickly. Taking automated emergency measures can limit the scope of influence of the anomaly in the first time, ensure the stable operation of the power monitoring system, reduce serious consequences such as power supply interruption caused by network anomalies, and improve the reliability and security of the power monitoring system.
[0075] In a feasible implementation, the network operation data includes network traffic data, device operation parameters, and system log data; the step S10: the step of preprocessing the network operation data to obtain standardized operation data includes:
[0076] Step S101, delete the noise data, incomplete data, and duplicate data in the network traffic data, and perform standardization processing on the network traffic data after the deletion processing to obtain standardized traffic data;
[0077] Network traffic data refers to the information related to data packets transmitted in the power monitoring system network, including the source address, destination address, port number, protocol type, number of bytes, and timestamp of the data packets, etc., which is used to reflect the situation of network data transmission. Device operation parameters refer to the operation status indicators of devices such as monitoring terminals, servers, and switches, such as CPU usage rate, memory occupancy rate, disk I / O rate, etc., which can reflect the working conditions of the devices in real time. System log data is various logs generated by the power monitoring software, including operation logs, device alarm logs, authentication and authorization logs, etc., from which event clues related to system operation can be extracted.
[0078] In network traffic data, noise data refers to data that does not conform to the normal traffic pattern and interferes with data analysis. For example, extremely high or low traffic values that appear instantaneously may be abnormal traffic caused by network failures or malicious attacks. Incomplete data is a data packet in network traffic data that lacks key information. For example, data lacking key fields such as source address, destination address, and protocol type cannot fully describe the basic characteristics of network traffic and will affect subsequent analysis. Duplicate data refers to data records with exactly the same content. In network traffic data, it can be exactly the same data packet records that appear within a preset time interval, and the preset time interval is less than the preset interval threshold.
[0079] First, clean the network traffic data, identify and delete the noise data, incomplete data, and duplicate data in it. Noise data may be abnormal traffic records caused by network fluctuations or interference. Incomplete data cannot accurately reflect the network traffic situation due to the lack of key information. Duplicate data will interfere with the accuracy of data analysis, so they all need to be deleted. After completing the deletion process, perform standardization processing on the remaining network traffic data, convert traffic data of different magnitudes (such as the number of bytes, the number of data packets, etc.) into data on a unified scale to obtain standardized traffic data.
[0080] Step S102: Fill in the missing values in the device operation parameters and mark the outlier values to obtain the marked device operation parameters, and perform standardization processing on the processed device operation parameters to obtain standardized operation parameters;
[0081] In device operation parameters, a missing value refers to a device parameter value collected at a certain time point that is a null value or an invalid symbol, which may be caused by reasons such as data acquisition device failures or loss during transmission. An outlier value is a value in the device operation parameters that deviates from the normal range and may indicate that the device has a failure or is under abnormal interference. For example, if the CPU usage rate of the device continuously exceeds the upper limit of the normal working range, it belongs to an outlier value.
[0082] For the missing values in the device operation parameters, use appropriate methods for data filling, such as linear interpolation filling using valid data at adjacent time points. For outlier values, mark them for subsequent analysis. After completing the missing value filling and outlier value marking, perform standardization processing on the processed device operation parameters, convert device operation parameters of different magnitudes into data on a unified scale to obtain standardized operation parameters.
[0083] Step S103: Delete the duplicate data in the system log data, and perform standardization processing on the system log data after the deletion process to obtain standardized log data;
[0084] In system log data, duplicate data refers to log records whose other key information is exactly the same except for the timestamp. When performing deduplication operations on system log data, based on key information such as the unique identifier of the log event, the event occurrence time, the event source, and the event description, it is determined whether the logs are duplicates. If the other key information of two logs is exactly the same except for the timestamp, and the time interval is within a certain range, they are determined to be duplicate logs and deleted. After completing the deduplication, the remaining system log data is standardized. The event types in the logs are converted into digital codes. For example, an event type dictionary is constructed, and different types of events are assigned unique integer encodings. The severity of the events is quantified. For example, a severity level scale is established to obtain standardized log data.
[0085] Step S104, determine the standardized traffic data, the standardized operating parameters, and the standardized log data as the standardized operating data.
[0086] Integrate the standardized traffic data, the standardized operating parameters, and the standardized log data obtained through processing to form standardized operating data. The standardized data reflects the network operating status of the power monitoring system from different aspects. After integration, it provides a comprehensive and high-quality data basis for the subsequent anomaly detection model, enabling the model to analyze the network operating status from multiple dimensions and improving the accuracy and reliability of anomaly detection.
[0087] In a feasible implementation, the anomaly detection score includes a model-driven detection score and a data-driven detection score; before the step S30: triggering an alarm and executing a preset emergency measure when the anomaly detection score meets the preset anomaly condition, the method further includes:
[0088] Step S40, if the model-driven detection score is greater than a preset first threshold and the data-driven detection score is greater than a preset second threshold, determine that the anomaly detection score meets the preset anomaly condition;
[0089] The model-driven detection score is a value output by the model-driven submodel in the anomaly detection model after performing anomaly detection on the standardized operating data based on prior knowledge such as the power network topology and communication protocol specifications. It is used to measure the degree to which the data deviates from the normal rule pattern. The larger the value, the higher the possibility of anomaly. The data-driven detection score is a value output by the data-driven submodel that reflects the degree of its anomaly for the input standardized operating data by learning a large amount of historical data and mining the normal and abnormal patterns in the data. Similarly, the larger the value, the higher the possibility of anomaly.
[0090] A preset critical value for determining whether the model-driven detection score reaches the abnormal level, that is, a preset first threshold. The critical value set for the data-driven detection score, that is, a preset second threshold, is used to determine whether the detection result of the data-driven sub-model reaches the abnormal standard. The first threshold and the second threshold can be specifically determined based on historical data, expert experience or a large number of tests, and are not limited here.
[0091] After obtaining the model-driven detection score and the data-driven detection score in the abnormal detection score, compare the model-driven detection score with the preset first threshold, and at the same time compare the data-driven detection score with the preset second threshold. If the model-driven detection score is greater than the preset first threshold and the data-driven detection score is also greater than the preset second threshold, it indicates that both sub-models strongly indicate that there is an abnormal situation in the network, and it can be determined that the abnormal detection score meets the preset abnormal conditions, that is, it is determined that the network is abnormal. Further, a dynamic threshold method can be adopted to dynamically adjust the threshold according to factors such as the real-time operating state of the network and different business periods. For example, during the peak power consumption period of the power monitoring system, the network traffic and equipment load change greatly, and the threshold can be appropriately increased to avoid misjudgment; during the low power consumption period, the threshold is reduced to improve the detection sensitivity.
[0092] It can be understood that when both sub-models detect abnormalities and are determined to meet the abnormal conditions, the accuracy and credibility of the abnormality judgment are greatly improved, the possibility of false alarms is reduced, and the accuracy of the abnormality detection is improved.
[0093] Step S50, if the model-driven detection score is less than or equal to the first threshold and the data-driven detection score is greater than the second threshold, or the model-driven detection score is greater than the first threshold and the data-driven detection score is less than or equal to the second threshold, then perform a weighted summation process on the model-driven detection score and the data-driven detection score based on a preset fusion weight set, and determine that the abnormal detection score meets the preset abnormal conditions when the abnormal detection score is greater than a preset abnormal index.
[0094] The preset fusion weight set is a set of preset weight values used to perform weighted summation calculations on the model-driven detection score and the data-driven detection score. The weight values can be determined according to factors such as the reliability and importance of the model-driven and data-driven sub-models in different scenarios. For example, [α, 1-α], where α is the weight of the model-driven detection score and 1-α is the weight of the data-driven detection score. The preset abnormal index is a critical value used to determine whether the abnormal detection score reaches the abnormal standard, and can be specifically determined after comprehensively considering factors such as the fluctuation range under the normal operating state of the system and historical abnormal data.
[0095] When the comparison result of the model-driven detection score and the data-driven detection score shows that: the model-driven detection score is less than or equal to a preset first threshold, but the data-driven detection score is greater than a preset second threshold; the model-driven detection score is greater than the preset first threshold, while the data-driven detection score is less than or equal to the preset second threshold, it indicates that only one sub-model detects an anomaly. At this time, it is not possible to directly determine that the network has an anomaly. Use the preset fusion weight set to perform a weighted sum calculation on the model-driven detection score and the data-driven detection score to obtain an anomaly detection score, and then compare the anomaly detection score with a preset anomaly index. If the anomaly detection score is greater than the preset anomaly index, then it is determined that the anomaly detection score meets the preset anomaly condition, that is, it is determined that the network has an anomaly. The calculation formula for the anomaly detection score can be: anomaly detection score = α × model-driven detection score + (1 - α) × data-driven detection score.
[0096] This embodiment avoids the problem of false negatives caused by the limitations of a single sub-model by considering the situation where a single sub-model detects an anomaly. Even if a single sub-model emits an anomaly signal, it is possible to accurately determine that the network has an anomaly through comprehensive calculation, improving the comprehensiveness of anomaly detection.
[0097] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 2 , the anomaly detection model includes the model-driven sub-model and the data-driven sub-model; the step S20: the step of inputting the standardized operation data into the pre-trained anomaly detection model to obtain an anomaly detection score includes:
[0098] Step S201, input the standardized operation data into the model-driven sub-model to obtain the model-driven detection score;
[0099] Input the standardized operation data obtained after preprocessing into the model-driven sub-model. The model-driven sub-model matches and judges the input standardized operation data based on pre-set knowledge rules such as the power network topology structure and communication protocol specifications, as well as normal communication paths, device interaction rules, data flow patterns, etc. For example, check whether the communication path in the data conforms to the regulations, whether the data format is correct, whether each index is within the normal threshold range, etc. According to the judgment, the model-driven sub-model outputs a model-driven detection score to indicate the degree of anomaly of the data.
[0100] Step S202, input the standardized operation data into the data-driven sub-model to obtain the data-driven detection score;
[0101] Input the standardized operation data into the data-driven sub-model. The data-driven sub-model uses deep learning or machine learning algorithms to establish the patterns and characteristics of normal data through learning a large amount of historical power monitoring data. When the standardized operation data is input, the sub-model compares it with the learned normal patterns, analyzes the data change trends, feature distributions, etc., and thus outputs a data-driven detection score to reflect the degree to which the input data deviates from the normal pattern.
[0102] Step S203: Perform weighted summation processing on the model-driven detection score and the data-driven detection score through a preset weight group to obtain an anomaly detection score.
[0103] After obtaining the model-driven detection score and the data-driven detection score, perform weighted summation calculation on these two scores according to the preset weight group, and fuse the results of the two different detection methods to obtain a comprehensive index reflecting the degree of data anomaly.
[0104] In this embodiment, by combining the advantages of the model-driven and data-driven detection methods. The model-driven detection is good at detecting anomalies of known rules, and the data-driven detection is good at discovering unknown anomalies. Through weighted summation, the two can complement each other, improving the accuracy and reliability of anomaly detection.
[0105] In a feasible implementation manner, the model-driven sub-model includes an expert system sub-model and a power flow statistics sub-model; the step S201 of inputting the standardized operation data into the model-driven sub-model to obtain the model-driven detection score includes:
[0106] Step S2011: Input the communication protocol data in the standardized operation data into the expert system sub-model to obtain a rule matching score.
[0107] Construct a model-driven sub-model based on the prior knowledge, rules, and statistical characteristics of the power monitoring system, specifically including an expert system sub-model and a power flow statistics sub-model, which can use information such as known network structures and communication protocols for anomaly judgment. The expert system sub-model is an intelligent system based on knowledge and inference rules. In the power monitoring system, it is constructed based on the power network topology, communication protocol specifications, etc., and contains a large amount of knowledge rules about the communication patterns and data interaction processes during the normal operation of the power monitoring network, and is used to judge whether the input data conforms to the normal rule pattern. The power flow statistics sub-model is a flow model established by statistically analyzing a large amount of historical normal network flow data in the power monitoring network, which can calculate the flow mean, variance, and threshold range of different business time periods and regions, and use this to detect whether there are anomalies in the current network flow.
[0108] Extract communication protocol data from the standardized operation data, and input the communication protocol data into the expert system sub-model. A large number of knowledge rules formulated according to the power network topology, communication protocol specifications, etc. are stored inside the expert system sub-model. Match the input communication protocol data with the rules one by one. For example, check whether the protocol type of the data packet meets the requirements of a specific service, whether the interaction process of the protocol is correct, etc. According to the matching result, output a rule matching score, which is used to represent the degree of compliance of the input data with the normal communication rules. The higher the value, the more it conforms to the normal rules, and the lower the value, the farther it deviates from the normal rules and the greater the possibility of abnormality.
[0109] Step S2012, input the network traffic data in the standardized operation data into the power flow statistics sub-model to obtain a flow statistics score;
[0110] Select network traffic data from the standardized operation data and input it into the power flow statistics sub-model. The power flow statistics sub-model will compare the currently input network traffic data with this flow model, calculate the deviation degree of the current flow from the normal flow, and thus output a flow statistics score. For example, if the network traffic in a certain period is higher than the average value in the same period of history and exceeds the set threshold range, then the flow statistics score will be higher, indicating that the current flow may be abnormal.
[0111] Step S2013, perform a weighted summation process on the rule matching score and the flow statistics score through a preset model-driven weight set to obtain the model-driven detection score.
[0112] Obtain the rule matching score and the flow statistics score, and perform a weighted summation calculation on these two scores according to the preset model-driven weight set. For example, if the preset weight set is [α, 1-α], the rule matching score is A, and the flow statistics score is B, then the model-driven detection score = α×A+(1-α)×B. Through weighted summation, the detection results of the expert system sub-model and the power flow statistics sub-model are fused to obtain a model-driven detection score that can comprehensively reflect the abnormality degree of the network operation data.
[0113] By fusing the detection results of the two sub-models through weighted summation, information from both aspects of communication protocol and flow statistics can be comprehensively considered. The obtained model-driven detection score can more comprehensively and accurately reflect the abnormality degree of the network operation data, improving the overall abnormality detection ability and reliability of the model-driven sub-model.
[0114] In a feasible implementation manner, the data-driven sub-model includes a feature extraction layer and an LSTM layer; the step S202: the step of inputting the standardized operation data into the data-driven sub-model to obtain the data-driven detection score includes:
[0115] In step S2021, input the standardized operation data into the feature extraction layer to obtain a time series feature vector.
[0116] The feature extraction layer is used to extract valuable features for subsequent analysis and prediction from the input standardized operation data. The extracted features can represent the original data more concisely, highlighting the key information and patterns of the data. The LSTM (Long Short-Term Memory) layer is a type of recurrent neural network layer that can process sequence data and effectively solve the problems of gradient vanishing or gradient explosion that occur in traditional recurrent neural networks when processing long sequences. It is good at capturing long-term dependencies in sequence data.
[0117] Input the standardized operation data into the feature extraction layer. The feature extraction layer will process and transform the standardized operation data, mine the time-related feature information from the data, and combine it into a time series feature vector. For example, for network traffic data, the feature extraction layer may extract the traffic change rate in different time periods, the periodic characteristics of the traffic, etc.; for device operation parameters, it may extract features such as the fluctuation trend of the parameters. By converting the original high-dimensional standardized operation data into a low-dimensional time series feature vector, the extracted data features can more clearly reflect the change laws and patterns of the data in the time dimension, which helps the subsequent LSTM layer better learn and identify abnormal situations.
[0118] In step S2022, input the time series feature vector into the LSTM layer to obtain a data-driven detection score.
[0119] Input the time series feature vector into the LSTM layer. The LSTM layer will process the time series data, utilize its internal memory units and gating mechanisms to learn the long-term dependencies in the data. During the processing, the LSTM layer will continuously update its own state according to the historical data and the current input, and finally output a data-driven detection score, which reflects the degree of deviation of the current network operation state from the normal state.
[0120] It can be understood that the LSTM layer can effectively handle the long-term dependencies in time series data. For network operation data with complex time patterns, it can better learn and remember the historical information of the data, thereby improving the accuracy of anomaly detection. Moreover, the LSTM model can adaptively adjust its own parameters to adapt to different types and patterns of network operation data, and has strong generalization ability.
[0121] Exemplarily, to help understand the implementation process of the power monitoring system network anomaly detection method obtained by combining the above-mentioned embodiment one with this embodiment, please refer to Figure 3 ,Figure 3 A brief process schematic diagram of a method for detecting network anomalies in a power monitoring system is provided. Specifically:
[0122] Step S1: Data collection. At key network nodes of the power monitoring system, such as substation communication gateways and dispatching center server interfaces, highly sensitive data collection probes are deployed. First, complete the full-network deployment of the data collection probes, debug them to stable operation, ensure the complete collection of various types of data, and continuously accumulate one month of normal operation data as the initial data set. The collected data includes: 1. Network traffic data: Accurately record information such as the source address, destination address, port number, protocol type, number of bytes, and timestamp of data packets to ensure the complete tracking of the power data transmission process. 2. Device operation parameters: Include the CPU usage rate, memory occupancy rate, and disk I / O rate of devices such as monitoring terminals, servers, and switches, which reflect the working status of the devices in real time. 3. System log data: Collect operation logs, device alarm logs, and authentication and authorization logs of the power monitoring software, and extract clues to abnormal events from them.
[0123] Step S2: Data preprocessing. Specifically, it includes: 1. Cleaning module: Preprocess the collected data to eliminate invalid, duplicate, and obviously incorrect data items. 2. Standardization module: Normalize data with different magnitudes. Scale the network traffic byte count, device performance metrics, etc. proportionally to the 0-1 interval to balance the weights of various data in subsequent analyses. 3. Feature extraction module: Extract features such as traffic rate change features and protocol distribution features from network traffic; extract features such as resource utilization change rate and abnormal fluctuation frequency from device parameters; extract key features such as event type, occurrence frequency, and association relationship from log data. For data preprocessing, check the integrity of each data packet in the network traffic data. For packets missing key information, such as any one of the source address, destination address, and protocol type, directly delete them. For device operation parameter data, if the device parameter value collected at a certain time point is a null value or an invalid symbol, linearly interpolate and fill it using the valid data of adjacent time points. If the values are invalid for 5 consecutive collection cycles, mark the device parameter data for that period as abnormal and perform separate analysis or directly discard the data for that period to prevent introducing error information that affects the overall device performance assessment. In network traffic data, determine duplicate data based on the five-tuple (source address, destination address, source port, destination port, protocol type) of the data packet and the timestamp information. When exactly the same five-tuple data packet records appear within a very short time interval, retain the first record and delete subsequent duplicates. For system log data, check for duplicates based on key information such as the unique identifier of the log event, event occurrence time, event source, and event description. If two logs have exactly the same key information except for the timestamp and the time interval is within a certain range, they are determined to be duplicate logs, and redundant records are deleted to avoid masking the clues of real abnormal events due to the accumulation of duplicate logs. For the traffic rate in network traffic data, set a reasonable rate threshold range. Based on the statistical analysis of historical traffic data, determine the normal traffic rate interval for a certain power data transmission link. If the traffic rate collected at a certain moment exceeds this range and the duration is extremely short, it is determined as noise data and eliminated. For numerical features such as the byte count and packet count in traffic data, use the min-max standardization method. Let a traffic feature value be x, and its standardized result x std The calculation formula is:
[0124] where x max and x min are the maximum and minimum values of this traffic feature in the historical dataset respectively, ensuring that the traffic data of each link has balanced weights in subsequent model analyses and avoiding the dominant influence of overly large traffic values on some links on model judgment. For traffic rate data, considering the time dynamics of the rate, use the Z-score standardization method. First, calculate the mean μ and standard deviation σ of the traffic rate of a certain link. The standardized rate value xz is as follows: This standardization method makes the rate data normally distributed with the mean as the center, which is conducive to the identification of outliers, and enhances the comparability of rate data of different links. Parameters in the form of percentages such as the CPU usage rate and memory occupancy rate of the device are directly linearly scaled to the range of 0 - 1. For parameters such as the device disk I / O rate with large differences and no fixed reasonable range, Z-score standardization is also used. For the event types in the log, an event type dictionary is constructed, and different types of events are assigned unique integer encodings. For example, "device normal startup" is encoded as 0, "abnormal disconnection of network connection" is encoded as 1, "illegal user login attempt" is encoded as 2, etc. The text-based event types are converted into digital codes for subsequent data analysis model processing. The event types after digital encoding can participate in operations such as abnormal frequency statistics and association rule mining based on statistical or machine learning models. For the severity level of log events, a severity level scale is established. For example, events at the "information" level are set to 0, "warning" level to 1, "error" level to 2, and "critical error" level to 3. Through this quantization method, the impact of different log events on the overall abnormal state of the system can be weighted and considered based on the severity level in subsequent analysis, so that the log data and other numerical network and device data have a unified quantization evaluation standard in the anomaly detection model.
[0125] Step S3: Data feature extraction. Please refer to Figure 4 , specifically including network traffic features, device operation features, and system log features. Among them, network traffic features include the short-term fluctuation coefficient where σ short is the standard deviation of the traffic rate within a short time window, and μ short is the corresponding mean; the long-term trend indicator k long , k long is obtained by using the linear regression analysis method to fit the change trend line of the network traffic rate over a long period of time and extracting the slope of the trend line; the proportion P protocol of the traffic within a unit time to the total traffic; the traffic change rate where F t1 and F t2 are the protocol traffic values of the previous and subsequent time windows respectively. Device operation features include the resource utilization change rate where U t1 and U t2 are the resource utilization values of the previous and subsequent periods respectively; the abnormal fluctuation frequency, that is, the number of times NF abnormal that the device parameters exceed the normal fluctuation range per unit time. System log features include the event type distribution, that is, the frequency distribution FDevent ; Event correlation features. For example, if a certain originally low-frequency abnormal event type (such as a specific device hardware failure alarm) appears frequently, or key business process-related events are missing, it may indicate that the system is in an abnormal state. For example, if the power protection device frequently issues false action alarm logs, it may be a device failure or external interference.
[0126] Step S4: Model construction and fusion components, including a model-driven sub-model and a data-driven sub-model.
[0127] 4.1 Training and construction of the fusion model. The model-driven and data-driven sub-models are trained separately. The expert system model calculates multi-dimensional traffic thresholds based on power industry standards and local network planning entry rules. The LSTM model learns the traffic time series features through multiple rounds of iterative learning, and the clustering algorithm completes the modeling of the data spatial distribution. The parameters of each model are optimized through cross-validation.
[0128] 4.1.1 Model-driven sub-model construction. (1) Expert system model construction: Based on the standard specifications widely followed in the power industry, define the communication architecture, data model, and service interfaces of the substation automation system, and sort out the communication patterns, data interaction processes, and instruction response rules among various devices during the normal operation of the power monitoring network. Clearly define the transmission path, triggering conditions, and format requirements of specific protection action signals between the master station and the slave station, and convert the rules into knowledge base entries of the expert system. Conduct in-depth research on the unique planning details of the power monitoring network, covering information such as network topology structure, device models and configuration differences, and business partition characteristics. Enter the unique device interconnection methods and data flow restrictions of the local network into the expert system as local reasoning rules to ensure that the model closely fits the actual network operation scenario. Organize power domain experts and network security engineers to work together, and continuously improve and verify the expert system rule base through case discussions, on-site fault reviews, etc., so that it can accurately cover common network anomaly situations and corresponding handling logics. (2) Statistical model training: Collect network traffic data with a long time span from all key links of the power monitoring network, and record the multiple attributes of each data packet in detail, such as the source and destination IP subnets, port numbers, protocol types, byte counts, and time stamps accurate to milliseconds, to form an original traffic data set. Conduct in-depth analysis of the traffic data in different dimensions according to business types, time periods, and network regions, and use statistical methods to calculate the core characteristic values of the traffic in each dimension. The mean value is used to measure the normal traffic level, the standard deviation highlights the traffic fluctuation degree, and the skewness and kurtosis describe whether the traffic distribution form deviates from the normal distribution, so as to identify potential abnormal form characteristics. Based on the statistical results, set a multi-level threshold system for each traffic dimension. The initial threshold uses classical statistical methods to initially delimit the normal traffic range, and introduce dynamic adjustment factors in combination with the characteristics of power business time periods, seasonal electricity consumption pattern fluctuations, and network upgrade and maintenance plans. Continuously track the update of traffic data and optimize the threshold to ensure that it closely follows the real-time dynamics of network traffic and accurately captures the starting point of abnormal traffic.
[0129] 4.1.2 Data-driven sub-model training. (1) LSTM model training: Arrange the collected network traffic data in chronological order to construct continuous time series samples, ensuring that the traffic data within each time step is complete and ordered, covering multiple traffic features (number of bytes, packet rate, protocol ratio). Standardize the time series to eliminate interference between features of different magnitudes. Use Z-score standardization to make each feature reasonably distributed around 0, which is conducive to the optimization and convergence of the model's gradient descent. At the same time, divide the training set, validation set, and test set with a ratio of approximately 7:2:1 to ensure the independence of the data and the effectiveness of evaluating the model's generalization ability. Build a long short-term memory network neural network architecture (LSTM), configure the number of hidden layers, and select 2 - 3 layers through experimental comparison to balance the computational complexity and feature learning ability. Initially set the number of hidden units to 64 - 128 units, and use a combination of tanh and sigmoid as the activation function to adapt to the non-linear transformation requirements of time series data. Introduce a recurrent dropout mechanism to randomly mask some neuron connections to prevent overfitting, set the dropout rate in the range of 0.2 - 0.3, and traverse the hyperparameter combination space through a grid search combined with a random search strategy. Select the optimal hyperparameter set based on the principle of minimizing the loss function of the validation set. For example, in a specific network scenario, determine the combination of 2 hidden layers, 96 hidden units, and a dropout rate of 0.25 to achieve the best performance. Use the Adam optimizer of the mini-batch gradient descent algorithm to conduct multiple rounds of training. Set the initial learning rate to 0.001, which decays with the number of training rounds. Reasonably select the number of samples in each batch according to the scale of the dataset and the hardware memory. When the loss value no longer significantly decreases for multiple consecutive rounds or the accuracy tends to be stable, determine that the model has converged and complete the preliminary training.
[0130] 4.2 Generating test datasets and model evaluation based on simulated anomalies. (1) Simulated attack and fault injection strategies: Design simulated attack vectors according to the classification of common power network attack methods, covering various complex attack modes such as denial-of-service attacks, man-in-the-middle attacks, and malware implantation. Replicate the attack process through network security testing tools to ensure that the attack characteristics realistically simulate actual combat situations. Conduct simulations for the types of faults that are likely to occur during the entire life cycle of power monitoring devices, including hardware faults, software faults, and configuration errors, to realistically reproduce the fault phenomena and comprehensively cover the causes of network anomalies caused by device faults. Deeply integrate the abnormal network traffic data generated by simulated attacks with the abnormal operating parameters and system log data caused by device faults to ensure the co-presentation of multi-dimensional anomalies in the same time series or event stream. (2) Construction of the model performance evaluation index system: Draw the receiver operating characteristic (ROC) curve of each model, with the false positive rate (FPR) as the horizontal axis and the true positive rate (TPR) as the vertical axis, to present the performance trade-off situation of the model under different decision thresholds. Please refer to Figure 5 and Figure 6, Figure 5 and Figure 6 On the horizontal axis, FalsePositiveRate (False Positive Rate, FPR) represents the proportion of negative samples that are actually negative but are mispredicted as positive samples. The calculation formula is FPR = number of false positive examples / total number of negative samples. On the vertical axis, TruePositiveRate (True Positive Rate, TPR) represents the proportion of positive samples that are actually positive and are correctly predicted as positive samples. The calculation formula is TPR = number of true positive examples / total number of positive samples. Model1 (red curve) and Model2 (blue curve) show the changes in the true positive rate and false positive rate of the two models under different classification thresholds. The closer the ROC curve is to the upper left corner, the better the performance of the model. Because the upper left corner corresponds to the ideal situation where the true positive rate is 1 and the false positive rate is 0. The steeper the curve, the stronger the ability of the model to distinguish between positive and negative samples. Specifically, Figure 5 is a schematic diagram comparing the model effects of the anomaly detection model (Model1) and the single model-driven model (Model2). The curve of Model1 is entirely above that of Model2, indicating that at the same false positive rate, the true positive rate of Model1 is higher, that is, Model1 can more effectively classify positive samples correctly and has relatively better performance. Figure 6 is a schematic diagram comparing the model effects of the anomaly detection model (Model1) and the single data-driven model (Model2). Figure 6 In it, the curve of Model1 is above that of Model1 in most regions, indicating that in this case, the performance of Model1 is better than that of Model2, and it can obtain a higher true positive rate at a lower false positive rate.
[0131] Step S5: Anomaly detection and response. 1. Real-time detection: The preprocessed real-time data is input into the fusion model in parallel. Each sub-model independently judges and outputs an anomaly score, and the anomaly detection score is obtained through fusion calculation. When the index exceeds the preset threshold, it is determined that the current network state is abnormal. 2. Response mechanism: Once an anomaly is detected, a multi-level response is immediately initiated. On the one hand, detailed alarm information is sent to the power monitoring and maintenance personnel, including the type of anomaly, location of occurrence, scope of influence, etc.; on the other hand, preliminary emergency measures are automatically executed to temporarily isolate the abnormal network nodes and adjust the device resource allocation strategy to prevent the spread of the anomaly and ensure the continuous operation of the core functions of the power monitoring system, so as to gain time for subsequent troubleshooting and repair. Specifically, let the anomaly probability output by the model-driven sub-model be Pm, and the anomaly probability output by the data-driven sub-model be Pd. When Pm ≥ Tm and PD ≥ Td, where Tm and Td are the anomaly thresholds preset by the model-driven and data-driven methods respectively, and the value ranges are between, it is determined as a high-confidence anomaly. When Pm ≥ Tm and Pd < Td, calculate the comprehensive anomaly probability P combined = α × Pm +(1 - α)×P d Make a judgment, where α is the evaluation weight. When Pm < Tm and Pd ≥ Td, calculate the comprehensive anomaly probability P combined = α×P m +(1 - α)×P d Make a judgment, where α is the evaluation weight. When Pm < Tm and Pd < Td, it is determined as normal.
[0132] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the network anomaly detection method of the power monitoring system of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0133] This application also provides a network anomaly detection device for a power monitoring system. Please refer to Figure 7 , the network anomaly detection device for the power monitoring system includes:
[0134] A preprocessing module 10, configured to obtain the network operation data of the power monitoring system collected by a data collection probe, and preprocess the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system;
[0135] A detection module 20, configured to input the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data through the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score;
[0136] A warning module 30, configured to trigger an alarm and execute a preset emergency measure when the anomaly detection score meets a preset anomaly condition.
[0137] Optionally, the anomaly detection model includes the model-driven sub-model and the data-driven sub-model; the detection module 20 is further configured to:
[0138] Input the standardized operation data into the model-driven sub-model to obtain the model-driven detection score;
[0139] Input the standardized operation data into the data-driven sub-model to obtain the data-driven detection score;
[0140] Performing a weighted summation process on the model-driven detection score and the data-driven detection score through a preset weight combination to obtain an anomaly detection score.
[0141] Optionally, the model-driven sub-model includes an expert system sub-model and a power flow statistics sub-model; the detection module 20 is further configured to:
[0142] The step of inputting the standardized operation data into the model-driven sub-model to obtain the model-driven detection score includes:
[0143] Inputting the communication protocol data in the standardized operation data into the expert system sub-model to obtain a rule matching score;
[0144] Inputting the network traffic data in the standardized operation data into the power flow statistics sub-model to obtain a traffic statistics score;
[0145] Performing a weighted summation process on the rule matching score and the traffic statistics score through a preset model-driven weight combination to obtain the model-driven detection score.
[0146] Optionally, the data-driven sub-model includes a feature extraction layer and an LSTM layer; the detection module 20 is further configured to:
[0147] Inputting the standardized operation data into the feature extraction layer to obtain a time series feature vector;
[0148] Inputting the time series feature vector into the LSTM layer to obtain a data-driven detection score.
[0149] Optionally, the network operation data includes network traffic data, device operation parameters, and system log data; the preprocessing module 10 is further configured to:
[0150] Deleting noise data, incomplete data, and duplicate data in the network traffic data, and performing standardization processing on the network traffic data after deletion to obtain standardized traffic data;
[0151] Filling in missing values in the device operation parameters and marking outliers to obtain marked device operation parameters, and performing standardization processing on the processed device operation parameters to obtain standardized operation parameters;
[0152] Deleting duplicate data in the system log data, and performing standardization processing on the system log data after deletion to obtain standardized log data;
[0153] Determining the standardized traffic data, the standardized operation parameters, and the standardized log data as the standardized operation data.
[0154] Optionally, the anomaly detection score includes a model-driven detection score and a data-driven detection score; the warning module 30 is further configured to:
[0155] If the model-driven detection score is greater than a preset first threshold and the data-driven detection score is greater than a preset second threshold, it is determined that the anomaly detection score meets the preset anomaly condition;
[0156] If the model-driven detection score is less than or equal to the first threshold and the data-driven detection score is greater than the second threshold, or the model-driven detection score is greater than the first threshold and the data-driven detection score is less than or equal to the second threshold, then a weighted sum processing is performed on the model-driven detection score and the data-driven detection score based on a preset fusion weight group, and when the anomaly detection score is greater than a preset anomaly index, it is determined that the anomaly detection score meets the preset anomaly condition.
[0157] The power monitoring system network anomaly detection device provided by this application adopts the power monitoring system network anomaly detection method in the above embodiment, and can solve the technical problem of low accuracy in current power monitoring system network anomaly detection. Compared with the prior art, the beneficial effects of the power monitoring system network anomaly detection device provided by this application are the same as those of the power monitoring system network anomaly detection method provided by the above embodiment, and other technical features in the power monitoring system network anomaly detection device are the same as the features disclosed in the method of the above embodiment, and will not be elaborated here.
[0158] This application provides a power monitoring system network anomaly detection device. The power monitoring system network anomaly detection device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the power monitoring system network anomaly detection method in the first embodiment above.
[0159] Next, refer to Figure 8, which shows a schematic structural diagram of a power monitoring system network anomaly detection device suitable for implementing the embodiments of the present application. The power monitoring system network anomaly detection device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The shown power monitoring system network anomaly detection device is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.
[0160] As Figure 8 shown, the power monitoring system network anomaly detection device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in the read-only memory 1002 or a program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the power monitoring system network anomaly detection device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems may be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the power monitoring system network anomaly detection device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a power monitoring system network anomaly detection device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.
[0161] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by a processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0162] The power monitoring system network anomaly detection device provided by the present application adopts the power monitoring system network anomaly detection method in the above-mentioned embodiment, and can solve the technical problem of low accuracy in current power monitoring system network anomaly detection. Compared with the prior art, the beneficial effects of the power monitoring system network anomaly detection device provided by the present application are the same as those of the power monitoring system network anomaly detection method provided by the above-mentioned embodiment, and other technical features in the power monitoring system network anomaly detection device are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.
[0163] It should be understood that the various parts disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0164] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0165] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the power monitoring system network anomaly detection method in the above-mentioned embodiment.
[0166] The computer-readable storage medium provided by this application can, for example, be a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0167] The above computer-readable storage medium can be included in the power monitoring system network anomaly detection device; it can also exist independently without being assembled into the power monitoring system network anomaly detection device.
[0168] The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed by the power monitoring system network anomaly detection device, the power monitoring system network anomaly detection device implements the solutions of the above various embodiments.
[0169] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by connecting through the Internet using an Internet service provider).
[0170] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0171] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0172] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned power monitoring system network anomaly detection method, and can solve the technical problem of low accuracy in current power monitoring system network anomaly detection. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the power monitoring system network anomaly detection method provided by the above embodiments, and will not be elaborated here.
[0173] The present application also provides a computer program product, including a computer program which, when executed by a processor, implements the steps of the power monitoring system network anomaly detection method as described above.
[0174] The computer program product provided by the present application can solve the technical problem of low accuracy in current power monitoring system network anomaly detection. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the power monitoring system network anomaly detection method provided in the above embodiments, and will not be elaborated here.
[0175] The above are only partial embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or direct / indirect application in other relevant technical fields, is included in the patent protection scope of the present application.
Claims
1. A method for detecting network anomalies in a power monitoring system, characterized in that, The power monitoring system network anomaly detection method includes: Obtain the network operation data of the power monitoring system collected by the data acquisition probe, and preprocess the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation status of the power monitoring system; Input the standardized operation data into the pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data by the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score; When the anomaly detection score meets the preset anomaly condition, trigger an alarm and execute the preset emergency measures.
2. The power monitoring system network anomaly detection method according to claim 1, wherein The anomaly detection model includes the model-driven sub-model and the data-driven sub-model; The step of inputting the standardized operation data into the pre-trained anomaly detection model to obtain an anomaly detection score includes: Input the standardized operation data into the model-driven sub-model to obtain the model-driven detection score; Input the standardized operation data into the data-driven sub-model to obtain the data-driven detection score; Perform weighted summation processing on the model-driven detection score and the data-driven detection score through a preset weight group to obtain an anomaly detection score.
3. The power monitoring system network anomaly detection method according to claim 2, wherein, The model-driven sub-model includes an expert system sub-model and a power flow statistics sub-model; The step of inputting the standardized operation data into the model-driven sub-model to obtain the model-driven detection score includes: Input the communication protocol data in the standardized operation data into the expert system sub-model to obtain a rule matching score; Input the network flow data in the standardized operation data into the power flow statistics sub-model to obtain a flow statistics score; Perform weighted summation processing on the rule matching score and the flow statistics score through a preset model-driven weight group to obtain the model-driven detection score.
4. The power monitoring system network anomaly detection method according to claim 2, characterized in that The data-driven sub-model includes a feature extraction layer and an LSTM layer; The step of inputting the standardized operation data into the data-driven sub-model to obtain the data-driven detection score includes: Input the standardized operation data into the feature extraction layer to obtain a time series feature vector; Input the time series feature vector into the LSTM layer to obtain a data-driven detection score.
5. The power monitoring system network anomaly detection method according to claim 1, characterized in that, The network operation data includes network flow data, device operation parameters, and system log data; The step of preprocessing the network operation data to obtain standardized operation data includes: Delete the noise data, incomplete data, and duplicate data in the network flow data, and perform standardization processing on the network flow data after deletion processing to obtain standardized flow data; Fill in the missing values in the device operation parameters and mark the outliers to obtain the marked device operation parameters, and perform standardization processing on the processed device operation parameters to obtain standardized operation parameters; Delete the duplicate data in the system log data, and perform standardization processing on the system log data after deletion processing to obtain standardized log data; Determine the standardized traffic data, the standardized operation parameters, and the standardized log data as standardized operation data.
6. The power monitoring system network anomaly detection method according to any one of claims 1 to 5, characterized in that, The anomaly detection score includes a model-driven detection score and a data-driven detection score; Before the step of triggering an alarm and executing a preset emergency measure when the anomaly detection score meets a preset anomaly condition, the method further includes: If the model-driven detection score is greater than a preset first threshold and the data-driven detection score is greater than a preset second threshold, it is determined that the anomaly detection score meets the preset anomaly condition; If the model-driven detection score is less than or equal to the first threshold and the data-driven detection score is greater than the second threshold, or the model-driven detection score is greater than the first threshold and the data-driven detection score is less than or equal to the second threshold, perform weighted summation processing on the model-driven detection score and the data-driven detection score based on a preset fusion weight set to obtain an anomaly detection score. When the anomaly detection score is greater than a preset anomaly index, it is determined that the anomaly detection score meets the preset anomaly condition.
7. A network anomaly detection device for a power monitoring system, characterized in that, The power monitoring system network anomaly detection device includes: A preprocessing module for acquiring the network operation data of the power monitoring system collected by a data acquisition probe, and preprocessing the network operation data to obtain standardized operation data, where the network operation data is used to characterize the network operation state of the power monitoring system; A detection module for inputting the standardized operation data into a pre-trained anomaly detection model to obtain an anomaly detection score. During the process of processing the standardized operation data by the anomaly detection model, the model-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the model-driven detection score in the anomaly detection score, and the data-driven sub-model in the anomaly detection model performs anomaly detection based on the standardized operation data to obtain the data-driven detection score in the anomaly detection score; A warning module for triggering an alarm and executing a preset emergency measure when the anomaly detection score meets a preset anomaly condition.
8. An abnormal network detection device for a power monitoring system, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. The computer program is configured to implement the steps of the power monitoring system network anomaly detection method according to any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the power monitoring system network anomaly detection method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that, The computer program product includes a computer program which, when executed by a processor, implements the steps of the method for detecting network anomalies in the power monitoring system according to any one of claims 1 to 6.
Citation Information
Cited By
Power monitoring system anomaly detection method based on multi-model voting mechanism
CN120710908A