Digital twin-driven power network security situation awareness method
Through the combination of the digital twin model and the power network security event library, sample data is obtained for situation analysis, which solves the problem of untimely awareness of power network security situation, realizes real-time risk identification and early warning of power network, and improves the accuracy and response efficiency of security situation awareness.
Patent Information
- Application Number
- CN202510846654.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-24
AI Technical Summary
The security situation of the power network is not aware of in time, making it difficult to accurately identify potential security risks. Traditional monitoring methods cannot adapt to the complex and changeable power system environment, making it difficult to deal with security threats in a timely manner.
By establishing a digital twin model, accessing the power network security event library, obtaining network traffic and user behavior sample data, conducting data conflict situation analysis and redundant situation analysis, identifying potential security risks and issuing early warning signals.
Real-time safety status monitoring of the power network is realized, potential risks are identified in a timely manner and early warning are issued, improving the accuracy and response efficiency of safety situation awareness.
Smart Images

Figure CN120358094A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of power engineering, specifically to the technical field of power security, and particularly to a method for power network security situation awareness driven by digital twins. Background Art
[0002] With the increasing scale and complexity of modern power systems, the security and stability of power networks face huge challenges. There are a large number of device nodes and communication links in the power network, and the operating states of each node are complex and interrelated, making it significantly more difficult to identify and warn of potential security risks in the power network. Traditional power network security monitoring means usually rely on a single data source or static security rules, which cannot adapt to the complex and changing power system environment and lack an overall understanding of the overall situation of the power network. Therefore, it is difficult for traditional security monitoring means to detect and warn of potential security risks in a timely manner, resulting in the power system being difficult to respond in a timely manner when attacked or malfunction occurs, affecting the stable operation of the power network. Summary of the Invention
[0003] This application provides a method for power network security situation awareness driven by digital twins, aiming to solve the technical problems of untimely power network security situation awareness and difficulty in accurately identifying security risks.
[0004] In view of the above problems, this application provides a method for power network security situation awareness driven by digital twins.
[0005] This application provides a method for power network security situation awareness driven by digital twins, and the method includes: setting a digital twin model according to the power grid topology structure and each power device; accessing a power network security event library, and writing multiple power network security maintenance tasks into the power network security event library; performing power device group mining based on the first power network security maintenance task among the multiple power network security maintenance tasks to obtain a first sample data set, where the first sample data set includes network traffic sample data and user behavior sample data, and the first power network security maintenance task is any one of the multiple power network security maintenance tasks; based on the digital twin model, introducing the first sample data set, performing data conflict situation analysis with the user behavior sample data, and setting a data conflict network layer; performing data redundancy situation analysis with the network traffic sample data, and setting a data redundancy network layer; coupling and connecting the data conflict network layer and the data redundancy network layer based on the multiple power network security maintenance tasks in the power network security event library, identifying potential security risks, and sending out security warning signals.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: The above digital twin-driven power network security situation awareness method is based on the topological structure of the power grid and various power equipment to establish a digital twin model to completely map the operation of the actual power network. Subsequently, the power network security event library is accessed, which records the security maintenance tasks of multiple power networks to ensure that the security maintenance task information can be transmitted to the digital twin model in real time. After that, based on any specific maintenance task in the event library, data mining is performed on relevant power equipment to extract a sample data set including network traffic and user behavior. This process ensures that accurate status information can be obtained from multiple dimensions, which helps to identify specific security situations related to the task. After importing the sample data into the digital twin model, data conflict analysis is performed using the user behavior sample data to establish a data conflict network layer, thereby identifying potential risks caused by abnormal or inconsistent behaviors. At the same time, the network traffic sample data is used for data redundancy analysis to establish a data redundancy network layer, which helps to identify redundancy hazards brought by duplicate or abnormal traffic. Based on these two network layers, the data conflict layer and the data redundancy layer are coupled and connected, and a comprehensive assessment of potential security risks is achieved through association analysis. When any abnormal trend or risk signal is detected, a warning will be issued to ensure that security issues can be quickly identified and responded to.
[0007] The above description is only an overview of the technical solution of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specific embodiments of this application are specifically given. Brief Description of the Drawings
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0009] Figure 1 It is a schematic flowchart of the digital twin-driven power network security situation awareness method in an embodiment; Figure 2 It is a schematic flowchart of obtaining the first sample data set of the digital twin-driven power network security situation awareness method in an embodiment. Detailed Embodiments
[0010] The embodiments of this application provide a digital twin-driven power network security situation awareness method to solve the technical problems of untimely power network security situation awareness and difficult to accurately identify security risks.
[0011] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0012] It should be noted that the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products or devices.
[0013] Embodiments, such as Figure 1 As shown, the present application provides a method for power grid security situation awareness driven by digital twins. The method includes: Set up a digital twin model according to the power grid topology structure and each power device.
[0014] In the embodiments of the present application, the system terminal collects detailed topology structure data of the power grid, including each line, node position, and connection relationship between nodes. The topology data usually comes from power grid management systems such as GIS (Geographic Information System) and SCADA (Supervisory Control and Data Acquisition). In addition, the specific positions of power devices (such as transformers, circuit breakers, distribution cabinets, etc.) in the topology and their connection information are also collected. Subsequently, the operation data and physical and electrical characteristic information of each power device in the power grid are obtained, such as real-time monitoring data such as the voltage, current, power, and temperature of the device, as well as basic information such as the model, capacity, rated power, and health status of the device. Sensors and monitoring devices collect this data through Internet of Things technology and converge it into the system terminal to ensure the real-time and accuracy of the data. Then, based on the collected topology structure and device data, a digital twin model is constructed using 3D modeling software or a digital twin platform. The actual power grid structure and power device positions in the model are mapped correspondingly to ensure that the digital twin model can truly reflect the physical structure and connection relationship of the actual power grid. In this model, not only the physical positions and connection relationships of each device are included, but also the state parameters and operation conditions of each device are recorded. Through this digital twin model, the system terminal can monitor the overall operation status of the power grid and the state changes of each device in real time, providing basic data for subsequent risk detection.
[0015] Access the power grid security event library, and the power grid security event library writes multiple power grid security maintenance tasks.
[0016] In one embodiment, the system terminal accesses a power network security event library, which is an information library dedicated to storing and managing power network security events, risk records, and maintenance tasks. Multiple power network security maintenance tasks are written into it to support the security situation awareness and risk management of the power network. By accessing the event library, detailed information about power network historical events and current maintenance tasks can be obtained. These tasks include possible network security events, risk handling requirements, and equipment status checks, etc. Each task contains information such as the target device of the task and the task handling method. The security maintenance task information stored in the power network security event library provides a basis for subsequent situation analysis, enabling the system terminal to call these task data, timely understand the potential risks and security maintenance requirements of the power network, and thus more efficiently conduct security monitoring and early warning management of the power network.
[0017] Based on the first power network security maintenance task among the multiple power network security maintenance tasks, power equipment group mining is performed to obtain a first sample data set, which includes network traffic sample data and user behavior sample data. The first power network security maintenance task is any one of the multiple power network security maintenance tasks.
[0018] In one embodiment, the system terminal randomly selects a power network security maintenance task from the multiple power network security maintenance tasks stored in the power network security event library as the first power network security maintenance task. Based on this task, combined with the constructed digital twin model, correlation analysis and mining are carried out on the power equipment group to identify the power equipment related to this task, so as to better focus on the key equipment and data required for this task, and obtain the network traffic sample data and user behavior sample data of these power equipment, forming a first sample data set, providing a basis for further security situation analysis. Among them, the network traffic sample data can reflect the communication mode and data transmission situation between power equipment, and the user behavior sample data helps to analyze the access and operation situation of users in power equipment. By extracting these data, the system terminal can conduct a more in-depth situation awareness and risk analysis on the power equipment involved in the first power network security maintenance task, laying a data foundation for subsequent conflict detection and redundancy analysis.
[0019] Further, as Figure 2 shown, based on the first power network security maintenance task among the multiple power network security maintenance tasks, power equipment group mining is performed to obtain a first sample data set, including: Collect the operation data of power equipment associated with the first power network security maintenance task, and set up a network security scenario; based on the digital twin model, mark the abnormal conflict nodes and abnormal traffic nodes in the network security scenario; use the abnormal conflict nodes and abnormal traffic nodes as starting points to conduct power equipment group mining to obtain the first sample data set.
[0020] Preferably, the system terminal identifies power equipment related to the first power network security maintenance task, and these devices usually include transformers, circuit breakers, power distribution cabinets, etc. Through sensors and monitoring systems installed on the power equipment, the operation data of the power equipment are collected in real time. These data include key parameters such as voltage, current, power, frequency, temperature, and equipment status. Subsequently, based on the collected equipment operation data and the topology of the power network, a network security scenario is constructed. This scenario includes the connection relationships between devices, the network traffic patterns and their load conditions under normal operation. When constructing the scenario, the key parameters in the scenario are defined, for example, network topology, device location, traffic flow direction, and load distribution, etc. These parameters will help simulate the behavior and state of the power network under normal circumstances. After that, based on the digital twin model, in the set network security scenario, the operation data of the power equipment are analyzed in real time. Abnormal conflict nodes and abnormal traffic nodes existing in the network are identified by means of threshold detection, and these nodes are marked. Among them, the abnormal conflict nodes are determined by comparing parameters such as device load and device temperature with the corresponding thresholds, and the abnormal traffic nodes are determined by comparing parameters such as network traffic and traffic fluctuation amplitude with the corresponding thresholds. As long as there is one item of abnormality, it will be marked. After marking the abnormal conflict nodes and abnormal traffic nodes, the system terminal uses the marked abnormal conflict nodes and abnormal traffic nodes as starting points to conduct power equipment group mining. By analyzing the connection relationships between these nodes and other power equipment, the device groups associated with them are identified, and from the mined power equipment groups, the first sample data set is extracted. This data set contains various data related to the first power network security maintenance task, including network traffic sample data and user behavior sample data. These sample data will provide an important basis for subsequent security situation analysis and risk assessment.
[0021] Furthermore, the present application provides using the abnormal conflict nodes and abnormal traffic nodes as starting points to conduct power equipment group mining to obtain the first sample data set, including: Obtain the Internet of Things communication protocols of each power equipment and set up communication links; use the abnormal conflict nodes as starting points and determine the first connection relationship along the propagation paths corresponding to the communication links; use the abnormal traffic nodes as starting points and determine the second connection relationship along the propagation paths corresponding to the communication links; based on the first connection relationship and the second connection relationship, obtain the first sample data set.
[0022] Optionally, the system terminal identifies all power equipment in the power grid, including transformers, circuit breakers, distribution cabinets, etc., and ensures that they have been registered in the network. Then, query and collect the Internet of Things communication protocols used by these devices, such as MQTT, CoAP, Modbus, DNP3, etc. Each protocol may have different data formats and communication methods. Obtaining these protocols is of great significance for subsequent data exchange and communication link setup. Subsequently, according to the collected communication protocols, set up the communication links between each power equipment. This process includes defining the data transmission path, network topology, and communication delay between devices to ensure that each power equipment can effectively conduct data communication through the specified communication protocol. After that, take the marked abnormal conflict node as the starting point and analyze its position in the communication link. The system terminal will trace the data propagation path starting from the abnormal conflict node along the set communication link, identify other devices directly or indirectly connected to this node and their connection relationships, and record the device connection relationships related to the abnormal conflict node to form a mapping of the first connection relationship. Similarly, take the marked abnormal traffic node as the starting point, analyze its position in the communication link in the same way, trace the data propagation path starting from the abnormal traffic node along the set communication link, identify other devices directly connected to this node and their connection relationships, and record the device connection relationships related to the abnormal traffic node to form a mapping of the second connection relationship. Then, based on the first connection relationship and the second connection relationship, extract data from the relevant devices to form the first sample data set, providing important data support for subsequent security situation analysis.
[0023] Based on the digital twin model, introduce the first sample data set, conduct a data conflict situation analysis with the user behavior sample data, and set up a data conflict network layer.
[0024] In one embodiment, the user behavior sample data in the first sample dataset is introduced into the digital twin model. This data includes information such as the operation records and access frequencies of users on power equipment. In the digital twin model, a new data conflict network layer is constructed, which is used for data conflict situation analysis and generates the conflict risk values of nodes. The construction method of the data conflict network layer includes graph neural network (GNN), long short-term memory network, etc. Taking the long short-term memory network as an example, the system terminal cleans and standardizes the user behavior sample data in the first sample dataset. Ensure that the data has no missing values and convert it into a format suitable for input to the network layer to form a training set. For example, encode categorical variables (such as user roles or operation types) into numerical forms for easy processing by the network layer. Subsequently, design the model structure of the data conflict network layer, including an input layer, an LSTM layer (multiple LSTM layers can be set to enhance the model's ability), and an output layer. Input the training set into the data conflict network layer for forward propagation, calculate the conflict risk value of the network layer, and then calculate the loss between the conflict risk value output by the network layer and the true conflict risk value marked in the training set according to the mean squared error (MSE). Then, calculate the gradient of the loss with respect to the network layer parameters through the backpropagation algorithm, and use an optimization algorithm (such as Adam or SGD) to update the weights and biases of the network layer to minimize the loss value. Repeat multiple training epochs, with multiple forward propagations and backpropagations in each epoch, until the preset number of training rounds is reached or the loss converges. By setting the data conflict network layer, the system terminal can dynamically calculate and optimize the conflict risk value during the processing of user behavior data, thereby enhancing the security management ability of the power network.
[0025] Perform data redundancy situation analysis with the network traffic sample data and set up a data redundancy network layer.
[0026] In one embodiment, the system terminal uses the network traffic sample data in the first sample dataset to set up a data redundancy network layer in the digital twin model in the same manner as described above. This data redundancy network layer is used for data redundancy situation analysis and generates the redundancy risk values of nodes. The specific construction process is the same as described above. By setting up the data redundancy network layer, the redundancy risk value can be dynamically calculated and optimized during the processing of network traffic data, thereby enhancing the security management ability of the power network.
[0027] Based on multiple power network security maintenance tasks in the power network security event library, couple and connect the data conflict network layer and the data redundancy network layer to identify potential security risks and issue security warning signals.
[0028] In one embodiment, after the data conflict network layer and the data redundancy network layer are set up, the system terminal couples and connects these two network layers based on multiple power network security maintenance tasks in the power network security event library. The coupling connection process enables these two network layers to share information. After the coupling connection is completed, the system terminal comprehensively analyzes the outputs of the two network layers through a security risk value calculation formula and sets up a propagation situation map based on the analysis results. Subsequently, security warning signals are generated according to the nodes in the set propagation situation map to notify maintenance personnel to take necessary preventive measures to maintain the security and stability of the power network. This process ensures that in a dynamic power network environment, security maintenance can respond in a timely manner, improving the overall security management ability.
[0029] Further, the present application provides for obtaining a first sample data set based on the first connection relationship and the second connection relationship, including: With sudden disasters as the limitation, generate an emergency security maintenance mark, where the emergency security maintenance mark includes a fault impact area; based on the emergency security maintenance mark, use the data conflict network layer to evaluate the conflict risk level under the mapping of the fault impact area, and combine with the first connection relationship to add a first priority sequence; based on the emergency security maintenance mark, use the data redundancy network layer to evaluate the redundancy risk level under the mapping of the fault impact area, and combine with the second connection relationship to add a second priority sequence.
[0030] Optionally, the system terminal identifies the affected fault areas centered on abnormal nodes according to the type of sudden disaster and historical experience. These areas may include power equipment, lines or network nodes. The system terminal generates an emergency security maintenance mark with the determined fault impact area. Subsequently, based on the emergency security maintenance mark, use the data conflict network layer to analyze the status of each node in the fault impact area, calculate the conflict risk value according to the user behavior data of each node, and compare it with a preset conflict risk level table to determine the conflict risk level of each node. Use the data redundancy network layer to analyze the status of each node in the fault impact area, calculate the redundancy risk value according to the network traffic data of each node, and compare it with a preset redundancy risk level table to determine the redundancy risk level of each node. Then, calculate the security risk value of each node according to the security risk value calculation formula by combining the conflict risk value and the redundancy risk value, and add the calculation result to the first priority sequence in combination with the first connection relationship, and add the calculation result to the second priority sequence in combination with the second connection relationship. Through the above steps, it can be ensured that after a sudden disaster occurs, the power network can quickly identify and respond to potential security risks, providing data support and decision-making basis for implementing effective maintenance and protection measures.
[0031] Further, the present application provides, based on the emergency security maintenance mark, using the data conflict network layer to evaluate the conflict risk level under the mapping of the fault impact area, and combining the first connection relationship, adding a first priority sequence, including: Using the data conflict network layer, performing conflict risk analysis on N nodes under the mapping of the fault impact area, calculating the security risk values corresponding to the N nodes, where N is the total number of nodes; sorting the security risk values corresponding to the N nodes to obtain the first priority sequence; based on the first connection relationship, performing a propagation situation access on the propagation path corresponding to the communication link of the first priority sequence, and setting a first propagation situation map.
[0032] Optionally, the system terminal identifies and selects N nodes related to the fault according to the fault impact area in the emergency security maintenance mark. Subsequently, analyze the status and behavior of each node through the data conflict network layer, and perform conflict risk analysis on each node to calculate the conflict risk value corresponding to each node. Analyze the status and behavior of each node through the data redundancy network layer, and perform redundancy risk analysis on each node to calculate the redundancy risk value corresponding to each node. Then, fuse the conflict risk value and redundancy risk value of each node through the security risk value calculation formula to calculate the security risk values corresponding to the N nodes. After calculating the security risk values of the N nodes, the system terminal sorts the security risk values calculated for the N nodes according to the priority score to identify the nodes that need to be processed first. According to the sorting result, form a first priority sequence to determine the nodes that should be given priority attention in case of a fault. Then, based on the first connection relationship, perform a propagation situation access on the communication link between the nodes in these priority sequences to determine the information transfer path between the nodes. These paths show how to effectively monitor and share information through the network. According to the propagation path identified by the propagation situation intensity, construct a first propagation situation map. This map shows the connection relationship and data flow between each node, enabling maintenance personnel to intuitively understand the propagation dynamics and potential risks of the fault impact area.
[0033] Further, the present application provides a security risk value calculation formula, including: Security risk value calculation formula: , where is used to represent the security risk value of the i-th node, is the conflict risk value of the i-th node, is the redundancy risk value of the i-th node, is the weight coefficient, used to balance the conflict risk and redundancy risk; based on the security risk values corresponding to the N nodes, calculate the priority score , and determine the first priority sequence.
[0034] Optionally, the calculation formula of the security risk value is used to evaluate the security risk level of each node in the power network. For each node i, the specific calculation formula of the security risk value is as follows: , where is used to represent the security risk value of the i-th node, indicating the comprehensive security risk level of this node under the current situation. is the weight coefficient, which ranges between 0 and 1 and is used to balance the importance of conflict risk and redundancy risk. The larger the value, the higher the degree of emphasis on conflict risk. is the conflict risk value of the i-th node, indicating the degree of risk caused by equipment failures, operation conflicts, etc. is the redundancy risk value of the i-th node, indicating the degree of risk caused by data redundancy, abnormal network traffic, etc. The system terminal will use the conflict risk value of the i-th node weighted according to the weight , and then add the redundancy risk value of the i-th node multiplied by 1− . This calculation method ensures that when evaluating security risks, potential risks caused by equipment conflicts and redundancies can be taken into account simultaneously. After calculating the security risk values of all nodes, the system terminal calculates the priority score of each node based on these security risk values. The specific calculation method is as follows: ; where is the priority score of the i-th node, indicating the relative importance of this node among all nodes. The higher the score, the higher the priority. N is the total number of nodes. The system terminal calculates the priority score of each node, arranges them according to these priority scores, and then adds the arrangement results to the first priority sequence to help the system terminal identify and handle high-risk nodes in case of failures, thereby enhancing the security and stability of the power network.
[0035] Furthermore, the present application provides the setting of the first propagation situation map, including: Denote the communication link distance from node i to node j as , and calculate the propagation situation intensity from node i to node j ; Set the first propagation situation map , where V is the set corresponding to N nodes under the fault impact area mapping.
[0036] Optionally, when performing propagation situation analysis, the system terminal first determines the communication link distance from node i to node j, denoted as , and then calculates the propagation situation intensity from node i to node j based on the determined communication link distance. The specific calculation formula of the propagation situation intensity is as follows: ; where is the priority score of node i. The intensity of the propagation situation is directly proportional to the priority scores between nodes and inversely proportional to the communication link distance, that is, the shorter the distance, the greater the propagation intensity. Subsequently, the first propagation situation graph is set according to the risk propagation path iteration formula , which shows the propagation relationship between nodes and specifically includes the edge set , where V is the set corresponding to N nodes under the fault impact area mapping. This first propagation situation graph will provide intuitive information for maintenance personnel to facilitate understanding of the information flow between nodes and potential risk propagation paths under specific fault conditions, and provide decision-making support for subsequent emergency response and safety management
[0037] Furthermore, the present application provides an adjustment to the initialized output impedance, including Risk propagation path iteration formula: ; where and are the security risk values of node i and node j respectively, is the optimal path for isolating risk propagation, and Path is the path of risk propagation
[0038] Optionally, when selecting the risk propagation path, the system terminal uses the following objective function to determine the best path ; in this formula, the goal is to find a path that minimizes the risk propagation of the entire path. Specifically, represents the propagation intensity from node i to node j, which is obtained from the previous analysis. The propagation risk of each segment in the path is affected by the security risk values of the connected nodes, that is, and are the security risk values of node i and node j respectively. When selecting the path, the system terminal will consider the propagation intensity of each connection in the path and the security risk values of the nodes. By taking the product of the maximum risk values in the path, the system terminal can ensure that even in the most unfavorable situation, the selected path can withstand potential risks. Finally, represents the optimal path for isolating risk propagation, which can effectively reduce the security risk of the entire network. And Path represents the actual risk propagation path, which provides an important basis for subsequent decision-making and emergency response. Through this process, not only is the selection of the risk propagation path optimized, but also the management ability of potential risks is enhanced, enabling the power network to respond more effectively when facing security threats
[0039] In summary, the embodiments of the present application at least have the following technical effects Embodiments of the present application set up a digital twin model according to the power grid topology and power equipment, and access a power network security event library to write multiple maintenance tasks. Subsequently, through the analysis of power network security maintenance tasks, a first sample data set containing network traffic and user behavior sample data is obtained, and based on this data set, data conflict situation analysis and data redundancy situation analysis are carried out, and a data conflict network layer and a data redundancy network layer are respectively set. By coupling and connecting these two network layers, potential security risks are identified and security warning signals are issued. In addition, under the background of emergencies, emergency security maintenance marks are generated, and the conflict risks and redundancy risks of the fault-affected area are evaluated, and a priority sequence is generated in combination with the connection relationship. Finally, by calculating the security risk value, propagation situation intensity and iterative formula between nodes, the risk propagation path is optimized to ensure timely and effective response and decision support in power network security management. These technical effects together solve the technical problems of untimely power network security situation awareness and difficulty in accurately identifying security risks, and achieve the effect of real-time monitoring of the power network security status through a digital twin model, identifying potential risks and issuing warning signals, and improving the accuracy and response efficiency of power network security situation awareness.
[0040] It should be noted that the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of this specification have been described. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0041] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
[0042] This specification and the drawings are only exemplary descriptions of the present application and are considered to have covered any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.
Claims
1. A digital twin-driven power grid security situation awareness method, characterized in that, The method includes: Setting up a digital twin model according to the power grid topology and each power equipment; Accessing a power network security event library, which writes multiple power network security maintenance tasks; Based on the first power network security maintenance task among the multiple power network security maintenance tasks, performing power equipment group mining to obtain a first sample data set, where the first sample data set includes network traffic sample data and user behavior sample data, and the first power network security maintenance task is any one of the multiple power network security maintenance tasks; Based on the digital twin model, introducing the first sample data set, performing data conflict situation analysis with the user behavior sample data, and setting up a data conflict network layer; Performing data redundancy situation analysis with the network traffic sample data, and setting up a data redundancy network layer; Based on the multiple power network security maintenance tasks in the power network security event library, performing coupled connection on the data conflict network layer and the data redundancy network layer, identifying potential security risks and sending out security warning signals.
2. The digital twin-driven power grid security situation awareness method according to claim 1, wherein Based on the first power network security maintenance task among the multiple power network security maintenance tasks, performing power equipment group mining to obtain a first sample data set, the method includes: Collecting the operation data of the power equipment associated with the first power network security maintenance task, and setting up a network security scenario; Based on the digital twin model, marking abnormal conflict nodes and abnormal traffic nodes in the network security scenario; Taking the abnormal conflict nodes and abnormal traffic nodes as starting points, performing power equipment group mining to obtain a first sample data set.
3. The digital twin-driven power network security situation awareness method according to claim 2, wherein Taking the abnormal conflict nodes and abnormal traffic nodes as starting points, performing power equipment group mining to obtain a first sample data set, the method includes: Obtaining the Internet of Things communication protocols of each power equipment and setting up communication links; Taking the abnormal conflict nodes as starting points, and determining a first connection relationship along the propagation path corresponding to the communication link; Taking the abnormal traffic nodes as starting points, and determining a second connection relationship along the propagation path corresponding to the communication link; Based on the first connection relationship and the second connection relationship, obtaining a first sample data set.
4. The digital twin-driven power network security situation awareness method according to claim 3, characterized in that, Based on the first connection relationship and the second connection relationship, obtaining a first sample data set, the method further includes: Generating an emergency security maintenance mark with a sudden disaster as a limit, where the emergency security maintenance mark includes a fault impact area; Based on the emergency security maintenance mark, using the data conflict network layer to evaluate the conflict risk level under the mapping of the fault impact area, and combining with the first connection relationship, adding a first priority sequence; Based on the emergency security maintenance mark, using the data redundancy network layer to evaluate the redundancy risk level under the mapping of the fault impact area, and combining with the second connection relationship, adding a second priority sequence.
5. The digital twin-driven power grid security situation awareness method according to claim 4, characterized in that, Based on the emergency security maintenance mark, using the data conflict network layer to evaluate the conflict risk level under the mapping of the fault impact area, and combining with the first connection relationship, adding a first priority sequence, the method further includes: Using the data conflict network layer, perform conflict risk analysis on N nodes under the mapping of the fault impact area, and calculate the security risk values corresponding to the N nodes, where N is the total number of nodes; Sort the security risk values corresponding to the N nodes to obtain the first priority sequence; Based on the first connection relationship, perform a propagation situation access on the first priority sequence along the propagation path corresponding to the communication link, and set a first propagation situation map.
6. The digital twin-driven power grid security situation awareness method according to claim 5, wherein Safety risk value calculation formula: , where is used to represent the safety risk value of the i-th node, is the conflict risk value of the i-th node, is the redundancy risk value of the i-th node, is the weight coefficient, which is used to balance the conflict risk and the redundancy risk; Calculate the priority score based on the security risk values corresponding to N nodes , and determine the first priority sequence 7. The digital twin-driven power network security situation awareness method according to claim 6, characterized in that, Denote the communication link distance from node i to node j as , and calculate the propagation situation intensity from node i to node j ; Set the first propagation situation map , where V is the set corresponding to N nodes under the fault influence area mapping.
8. The digital twin-driven power grid security situation awareness method according to claim 7, characterized in that The method further includes: Iterative formula for the risk propagation path: ; Among them, and are the security risk values of node i and node j respectively, is the optimal path for isolating risk propagation, and Path is the path of risk propagation.
Citation Information
Patent Citations
6G digital twin network autonomous system based on intention driving
CN118138476A
Network security analysis method and system based on digital twinning
CN119276611A
Network operation and maintenance method and system based on digital twin technology
CN120110893A
Cybersecurity and threat assessment platform for computing environments
US10868825B1
System and method for data breach protection
US20220263843A1
Cited By
Thermal heat supply system defense collaborative protection method and system based on digital twinning
CN120639516A