Attack detection method and device of power monitoring system, electronic equipment, medium and product

Through the integrated processing of distributed network traffic acquisition and attention mechanism, the accuracy of APT attack detection of power monitoring systems is improved, the problem of low detection accuracy in the existing technology is solved, and the security and response capabilities of the system are enhanced.

CN120378138APending Publication Date: 2025-07-25GUO JIA DIAN WANG YOU XIAN GONG SI XI NAN FEN BU +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510414606.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The APT attack detection method of the existing power monitoring system has low detection accuracy and cannot effectively detect zero-day attacks and dynamic variant attacks, resulting in the impact of system security.

Method used

The network traffic data is obtained through the distributed network traffic acquisition unit, a basic feature matrix is constructed, and the attention mechanism is used to fusion processing of channel attention and spatial attention, improving the accuracy of the attack detection model.

Benefits of technology

It improves the accuracy of APT attack detection, enhances the security of the power monitoring system, and generates warning information in a timely manner so that managers can take measures to avoid losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378138A_ABST
    Figure CN120378138A_ABST
Patent Text Reader

Abstract

The invention discloses an attack detection method and device for a power monitoring system, electronic equipment, a medium and a product, and relates to the technical field of information security, and the method comprises the steps: obtaining network flow data of the power monitoring system through a distributed network flow collection unit, and converting the network flow data into a feature matrix to obtain a basic feature matrix; inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result; and if the attack detection result represents that the power monitoring system suffers from the advanced persistent threat, generating warning information based on the attack detection result and outputting the warning information. According to the application, the detection accuracy of the APT attack detection method can be improved, the security of the power monitoring system is improved, and reliable guarantee is provided for stable operation of the power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular, to an attack detection method, device, electronic device, medium and product for a power monitoring system. Background Art

[0002] The new power monitoring system has been widely used due to its characteristics such as clean, low-carbon, safe and controllable. Nowadays, with the access of a large number of power electronic devices, the security risks faced by the communication network of the new power monitoring system have risen sharply. Advanced persistent threat (APT) attacks, which are extremely concealed, destructive and have the characteristic of long-term latency, have become a serious problem for the communication network of the new power monitoring system. Such attacks target specific targets. Compared with ordinary network attacks, they have more complex means, longer latency and great harm. Common threats include zero-day attacks and self-developed malware. In the new power monitoring system, APT attacks often target power electronic devices in the data acquisition layer and information management layer, use fishing means, trojans, etc. to steal permissions, and gradually penetrate. Once successful, the power grid will experience large-scale power outages, leakage of sensitive information such as power operation and users, resulting in huge economic losses and even endangering national security. Therefore, the research on APT attack detection for the new power monitoring system is extremely urgent.

[0003] Existing APT attack detection technologies mainly include static detection based on rule matching, anomaly detection methods based on machine learning, and feature extraction and classification methods based on deep learning. Among them, the static detection method based on rule matching matches suspicious behaviors in network traffic through a predefined rule library. However, the update of the rule library highly depends on known attack samples and cannot effectively detect zero-day attacks or dynamic variant attacks, resulting in an impact on the attack detection accuracy; the anomaly detection method based on machine learning distinguishes normal traffic from abnormal traffic by training a shallow model. Although this method can capture some statistical features, it is not sensitive enough to the concealed attack features with low signal-to-noise ratio, resulting in an impact on the attack detection accuracy; the feature extraction and classification based on deep learning uses convolutional neural networks or recurrent neural networks to automatically extract deep features of traffic data. However, traditional convolutional neural networks rely on local features and have insufficient generalization ability for attackers to dynamically adjust strategies, resulting in an impact on the attack detection accuracy. In summary, the current APT attack detection methods have low detection accuracy, resulting in an impact on the security of the power monitoring system.

[0004] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a method, device, electronic device, medium and product for detecting attacks on a power monitoring system, aiming to solve the technical problem that the current APT attack detection method has a low detection accuracy, which affects the security of the power monitoring system.

[0006] To achieve the above object, this application proposes a method for detecting attacks on a power monitoring system, and the method includes:

[0007] Obtain the network traffic data of the power monitoring system through a distributed network traffic collection unit, and convert the network traffic data into a feature matrix to obtain a basic feature matrix;

[0008] Input the basic feature matrix into a preset attack detection model to obtain an attack detection result. Among them, in the process of performing attack detection on the basic feature matrix by the attack detection model, channel attention and spatial attention fusion processing are performed on the basic feature matrix through an attention mechanism. The higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight, and the higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight;

[0009] If the attack detection result indicates that the power monitoring system is suffering from an advanced persistent threat, generate a warning message based on the attack detection result and output it.

[0010] In one embodiment, the attack detection model includes a first convolutional layer, an attention mechanism module, a second convolutional layer, a normalization layer, a pooling layer, a residual connection module and a fully connected layer;

[0011] The step of inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result includes:

[0012] Input the basic feature matrix into the first convolutional layer to obtain an initial feature;

[0013] Input the initial feature into the attention mechanism module for channel attention and spatial attention fusion processing to obtain an enhanced feature;

[0014] Input the enhanced feature into the second convolutional layer for convolution operation to obtain a first processing result;

[0015] Input the first processing result into the normalization layer to obtain a second processing result;

[0016] Input the second processing result into the pooling layer to obtain a third processing result;

[0017] Output the third processing result, add it to the first processing result in the residual connection module to obtain a fourth processing result;

[0018] Input the fourth processing result into the fully connected layer to obtain an attack detection result.

[0019] In one embodiment, the attention mechanism module includes a channel attention mechanism and a spatial attention mechanism;

[0020] The step of inputting the initial feature into the attention mechanism module to perform channel attention and spatial attention fusion processing to obtain an enhanced feature includes:

[0021] Input the initial feature into the channel attention mechanism, generate a channel weight matrix through the channel attention mechanism, and multiply the initial feature by the channel weight matrix to obtain a first output feature;

[0022] Input the initial feature into the spatial attention mechanism, generate a spatial weight matrix through the spatial attention mechanism, and multiply the initial feature by the spatial weight matrix to obtain a second output feature;

[0023] Perform feature fusion on the first output feature and the second output feature to obtain an enhanced feature.

[0024] In one embodiment, the step of generating a channel weight matrix through the channel attention mechanism includes:

[0025] Perform an average pooling operation on the initial feature through the channel attention mechanism to obtain a first output result;

[0026] Perform a max pooling operation on the initial feature through the channel attention mechanism to obtain a second output result;

[0027] Add the first output result and the second output result to obtain a first addition result, and input the first addition result into a first activation function to generate a channel weight matrix.

[0028] In one embodiment, the step of generating a spatial weight matrix through the spatial attention mechanism includes:

[0029] Perform an average pooling operation on the initial feature through the spatial attention mechanism to obtain a third output result;

[0030] Perform a max pooling operation on the initial feature through the spatial attention mechanism to obtain a fourth output result;

[0031] Add the third output result and the fourth output result to obtain a second addition result, and input the second addition result into a second activation function to generate a spatial weight matrix.

[0032] In one embodiment, the step of converting the network traffic data into a feature matrix to obtain a basic feature matrix includes:

[0033] Based on label encoding technology, convert the categorical variable values in the network traffic data into numerical form to obtain a first feature matrix;

[0034] Based on dummy variable encoding, perform label reshaping on the traffic protocol information in the network traffic data to obtain reshaped protocol information, and convert the reshaped protocol information into binary features through one-hot encoding to obtain a second feature matrix;

[0035] Determine the first feature matrix and the second feature matrix as the basic feature matrix.

[0036] In addition, to achieve the above object, the present application also proposes an attack detection device for a power monitoring system, and the attack detection device for the power monitoring system includes:

[0037] A preprocessing module, configured to obtain network traffic data of the power monitoring system through a distributed network traffic collection unit, and convert the network traffic data into a feature matrix to obtain a basic feature matrix;

[0038] A detection module, configured to input the basic feature matrix into a preset attack detection model to obtain an attack detection result. Among them, in the process of performing attack detection on the basic feature matrix through the attack detection model, perform channel attention and spatial attention fusion processing on the basic feature matrix through an attention mechanism. The higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight, and the higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight;

[0039] A warning module, configured to, if the attack detection result indicates that the power monitoring system is suffering from an advanced persistent threat, generate a warning message based on the attack detection result and output it.

[0040] In addition, to achieve the above object, the present application also proposes an electronic device, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the attack detection method for the power monitoring system as described above.

[0041] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the attack detection method of the power monitoring system as described above are implemented.

[0042] In addition, to achieve the above object, the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of the attack detection method of the power monitoring system as described above are implemented.

[0043] One or more technical solutions proposed by the present application have at least the following technical effects:

[0044] The network traffic data of the power monitoring system is obtained through the distributed network traffic collection unit. The distributed collection method can perform data collection simultaneously at multiple key nodes of the power monitoring system, covering a wider network area, collecting richer and more comprehensive network traffic information, enabling the subsequent constructed basic feature matrix to contain more valuable information, and providing a solid data basis for accurately detecting APT attacks.

[0045] Then, convert the network traffic data into a feature matrix to obtain a basic feature matrix; input the basic feature matrix into a preset attack detection model to obtain an attack detection result. In the process of performing attack detection on the basic feature matrix by the attack detection model, channel attention and spatial attention fusion processing are performed on the basic feature matrix through an attention mechanism. The higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight; the higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight. In this application, channel attention can allocate channel attention weights according to the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples. When the features of a certain channel are more similar to the APT samples, the attention weight of this channel is higher, which enables the model to pay more attention to the key channels related to attacks, highlight the feature information in these channels, and avoid being interfered by irrelevant information; spatial attention focuses on the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, and allocates spatial channel attention weights according to the similarity. There may be certain correlations and patterns in the spatial dimension of the network traffic data of the power monitoring system, and attackers may use these spatial features for covert attacks. The spatial attention mechanism can capture these spatial correlations and focus the attention on the spatial regions related to attacks, further improving the ability to identify attack features; the fusion processing of channel attention and spatial attention enables the model to comprehensively consider information in both the channel and spatial dimensions, more comprehensively and accurately identify APT attack features, improve the adaptability of the model to complex attack patterns, and thus effectively improve the accuracy of attack detection.

[0046] If the attack detection result indicates that the power monitoring system is suffering from an advanced persistent threat, a warning message is generated and output based on the attack detection result. A timely feedback mechanism can enable the management personnel of the power monitoring system to quickly learn about the attack situation, take corresponding measures to deal with it, avoid greater losses caused by the attack, and thus further improve the security of the power monitoring system.

[0047] Therefore, this application can improve the detection accuracy of the APT attack detection method, enhance the security of the power monitoring system, and provide a reliable guarantee for the stable operation of the power monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0049] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0050] Figure 1 It is a schematic flowchart provided for the first embodiment of the attack detection method of the power monitoring system of the present application;

[0051] Figure 2 It is a schematic brief flowchart provided for an embodiment of the attack detection method of the power monitoring system of the present application;

[0052] Figure 3 It is a schematic diagram of the convolutional layer structure provided for an embodiment of the attack detection method of the power monitoring system of the present application;

[0053] Figure 4 It is a curve graph of the activation function of the power monitoring system provided for an embodiment of the attack detection method of the power monitoring system of the present application;

[0054] Figure 5 It is a schematic diagram of the module structure of the attack detection device of the power monitoring system in the embodiment of the present application;

[0055] Figure 6 It is a schematic diagram of the device structure of the hardware operating environment involved in the attack detection method of the power monitoring system in the embodiment of the present application.

[0056] The realization of the purpose, functional features and advantages of the present application will be further described with reference to the accompanying drawings in combination with the embodiments. Specific embodiments

[0057] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0058] To better understand the technical solutions of the present application, the following will be described in detail in combination with the accompanying drawings of the specification and specific embodiments.

[0059] The main solution of the embodiment of the present application is as follows: obtaining the network traffic data of the power monitoring system through a distributed network traffic collection unit, and converting the network traffic data into a feature matrix to obtain a basic feature matrix; inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result. Among them, in the process of performing attack detection based on the basic feature matrix by the attack detection model, channel attention and spatial attention fusion processing are performed on the basic feature matrix through an attention mechanism. The higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight. The higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight; if the attack detection result indicates that the power monitoring system is suffering from an advanced persistent threat, a warning message is generated and output based on the attack detection result.

[0060] In this embodiment, for the convenience of description, the following will be described with an electronic device as the execution subject.

[0061] Since the existing APT attack detection technologies mainly include static detection based on rule matching, anomaly detection methods based on machine learning, and feature extraction and classification methods based on deep learning. Among them, the static detection method based on rule matching matches suspicious behaviors in network traffic through a predefined rule library. However, the update of the rule library highly depends on known attack samples and cannot effectively detect zero-day attacks or dynamic variant attacks, resulting in the impact on the attack detection accuracy; the anomaly detection method based on machine learning distinguishes normal traffic from abnormal traffic by training a shallow model. Although this method can capture some statistical features, it is not sensitive enough to the hidden attack features with low signal-to-noise ratio, resulting in the impact on the attack detection accuracy; the feature extraction and classification based on deep learning uses a convolutional neural network or a recurrent neural network to automatically extract the deep features of traffic data. However, the traditional convolutional neural network depends on local features and has insufficient generalization ability for attackers to dynamically adjust strategies, resulting in the impact on the attack detection accuracy. To sum up, the current APT attack detection method has a low detection accuracy, resulting in the impact on the security of the power monitoring system.

[0062] The present application provides a solution. The network traffic data of the power monitoring system is obtained through a distributed network traffic collection unit. The distributed collection method can collect data simultaneously at multiple key nodes of the power monitoring system, covering a wider network area, collecting richer and more comprehensive network traffic information, enabling the subsequent constructed basic feature matrix to contain more valuable information, and providing a solid data foundation for accurately detecting APT attacks. Secondly, channel attention can allocate channel attention weights according to the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples. The higher the similarity between the features of a certain channel and the APT samples, the higher the attention weight of this channel, which enables the model to pay more attention to the key channels related to the attack, highlighting the feature information in these channels and avoiding being interfered by irrelevant information. Spatial attention focuses on the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, and allocates spatial channel attention weights according to the similarity. There may be certain associations and patterns in the spatial dimension of the network traffic data of the power monitoring system, and attackers may use these spatial features for covert attacks. The spatial attention mechanism can capture these spatial associations, focus the attention on the spatial regions related to the attack, and further improve the ability to identify attack features. The fusion processing of channel attention and spatial attention enables the model to comprehensively consider the information in both the channel and spatial dimensions, more comprehensively and accurately identify APT attack features, improve the adaptability of the model to complex attack patterns, and thus effectively improve the accuracy of attack detection. Finally, through a timely feedback mechanism, the management personnel of the power monitoring system can quickly learn about the attack situation, take corresponding measures to deal with it, avoid greater losses caused by the attack, and further improve the security of the power monitoring system.

[0063] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of implementing the above functions. Hereinafter, an electronic device will be taken as an example to illustrate this embodiment and the following embodiments.

[0064] Based on this, the embodiment of the present application provides a method for detecting attacks in a power monitoring system, referring to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the attack detection method for the power monitoring system of the present application.

[0065] In this embodiment, the attack detection method for the power monitoring system includes steps S10 to S30:

[0066] Step S10, obtaining the network traffic data of the power monitoring system through a distributed network traffic collection unit, and converting the network traffic data into a feature matrix to obtain a basic feature matrix;

[0067] The distributed network flow collection unit is a system composed of multiple collection points distributed in different locations of the power monitoring system. These collection points can collect the flow data of each node in the network in real time, ensure the comprehensiveness and diversity of data sources, and avoid data deviation caused by single-point collection. Network flow data refers to various data information transmitted in the power monitoring system network, including the size of the data packet, transmission time, source address, destination address, protocol used, etc. These data reflect the operating status and communication status of the network.

[0068] In this embodiment, the network flow data of the power monitoring system is collected, the collected network flow data is processed, and converted into a feature matrix to obtain a feature matrix (hereinafter referred to as a basic feature matrix) so that the subsequent attack detection model can analyze it. The feature matrix is a data structure in the form of a matrix obtained by sorting and converting the network flow data. Each row of the matrix usually represents a sample, and each column represents a feature. The feature matrix can be used to more conveniently analyze and process the data.

[0069] Step S20, inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result, wherein, in the process of performing attack detection based on the basic feature matrix by the attack detection model, channel attention and spatial attention fusion processing are performed on the basic feature matrix through an attention mechanism, and the higher the similarity between the channel feature of the basic feature matrix and the advanced persistent threat sample, the higher the channel attention weight, and the higher the similarity between the spatial feature of the basic feature matrix and the advanced persistent threat sample, the higher the spatial channel attention weight;

[0070] The preset attack detection model is a pre-trained model used to determine whether the power monitoring system is under attack by advanced persistent threats. The model can be built based on machine learning or deep learning algorithms, such as convolutional neural networks, recurrent neural networks, etc. By learning a large amount of historical data, the characteristic patterns of abnormal traffic under normal and APT attacks are mastered. The specific training process is not limited here. In a feasible implementation, in order to evaluate the classification performance of the attack detection model, the precision and recall evaluation criteria are used, and the formula can be:

[0071]

[0072] In the formula, TP represents the number of positive classes predicted as positive classes, FP represents the number of negative classes predicted as positive classes, and FN represents the number of positive classes predicted as negative classes.

[0073] The attention mechanism can automatically focus on the important parts of the input data and assign different weights to different parts. Channel attention is a specific form of the attention mechanism, which mainly focuses on the channel dimension of the feature matrix. By calculating the similarity between the channel features and the advanced persistent threat samples, different attention weights are assigned to each channel, enabling the model to pay more attention to the channel features related to attacks. Spatial attention focuses on the spatial dimension of the feature matrix. By calculating the similarity between the spatial features and the advanced persistent threat samples, different attention weights are assigned to each spatial region, thereby capturing the spatial correlation information in the data and helping to discover potential attack patterns. Among them, the advanced persistent threat samples are known and labeled APT attack samples, which contain the typical features and patterns of APT attacks. The basic feature matrix is input into a preset attack detection model, and the model analyzes and processes the basic feature matrix to obtain the attack detection result. In this process, the attention mechanism is used to perform channel attention and spatial attention fusion processing on the basic feature matrix. According to the similarity between the channel features and spatial features and the advanced persistent threat samples, different attention weights are assigned to different channels and spatial regions, thereby highlighting the features related to attacks and improving the detection accuracy of the model. Through the fusion processing of channel attention and spatial attention, the model can better capture the feature information and spatial correlation in the data, enhancing the adaptability to different types of APT attacks.

[0074] Step S30, if the attack detection result indicates that the power monitoring system is under an advanced persistent threat, a warning message is generated and output based on the attack detection result.

[0075] The attack detection result is the conclusion obtained by a preset attack detection model after analyzing the basic feature matrix, and is used to determine whether the power monitoring system is under an APT attack. The result can be a binary value (such as being attacked or not being attacked), or a probability value indicating the likelihood of being attacked.

[0076] Based on the attack detection result, if the result shows that the power monitoring system is under an advanced persistent threat, a warning message is generated and output based on this result to send an alarm to the management personnel or relevant personnel of the power monitoring system. The warning message can include key information such as the type of attack, the occurrence time, and the affected nodes, etc. There is no specific limitation here. The warning message can be sent to relevant personnel through various means, such as text messages, emails, system pop-ups, etc., so that they can take measures to deal with the attack in a timely manner.

[0077] In a feasible embodiment, the step S10 of converting the network traffic data into a feature matrix to obtain the basic feature matrix includes:

[0078] Step S101, convert the categorical variable values in the network traffic data into numerical form based on label encoding technology to obtain the first feature matrix;

[0079] Label encoding technology assigns different integer encodings to different values of categorical variables, enabling categorical data originally in text form to be converted into numerical form for subsequent mathematical operations and model processing. Categorical variable values are values with different categorical attributes in network traffic data, such as source IP address types (internal IP, external IP), user identity categories (administrator, ordinary user), etc., which are usually presented in text form. After being processed by label encoding technology, the categorical variable values in the network traffic data are converted into numerical form to form a matrix, that is, the first feature matrix. Since many machine learning and deep learning models can only process numerical data, and there are a large number of categorical variables in network traffic data, these categorical variables are converted into numerical form through label encoding technology, enabling categorical data that could not directly participate in model operations to be effectively utilized by the model, thus constructing the first feature matrix.

[0080] Step S102, perform label reshaping on the traffic protocol information in the network traffic data based on dummy variable encoding to obtain reshaped protocol information, and convert the reshaped protocol information into binary features through one-hot encoding to obtain the second feature matrix;

[0081] Dummy variable encoding is a way of encoding categorical variables into a set of binary variables. For a categorical variable with multiple different values, dummy variable encoding will create multiple new binary variables to represent its different states. Traffic protocol information is various protocol types involved in network traffic data, and protocol information usually exists in string form.

[0082] In this embodiment, label reshaping is performed on the traffic protocol information to convert it into a label form that is more convenient for subsequent encoding operations to obtain reshaped protocol information. For example, the protocol name is converted into a corresponding number or identifier, and then the reshaped protocol information is converted into binary features through one-hot encoding to obtain the second feature matrix. For a categorical variable with n different values, one-hot encoding will create n binary features, each feature corresponding to a possible value. In a certain sample, the feature corresponding to the actual value of the sample is 1, and the remaining features are all 0.

[0083] Step S103, determine the first feature matrix and the second feature matrix as the basic feature matrix.

[0084] The basic feature matrix obtained by concatenating the first feature matrix and the second feature matrix integrates the features after the conversion of categorical variables and traffic protocol information in the network traffic data, and can be used as the input data for the subsequent attack detection model. The specific concatenation method is not limited here. It can be horizontal concatenation along the column direction (that is, connecting the two matrices in the column direction. For example, if the first feature matrix has m rows and n1 columns, and the second feature matrix has m rows and n2 columns, the resulting basic feature matrix after horizontal concatenation has m rows and n1 + n2 columns), vertical concatenation along the row direction (that is, connecting the two matrices in the row direction. If the first feature matrix has m1 rows and n columns, and the second feature matrix has m2 rows and n columns, the resulting basic feature matrix after vertical concatenation has m1 + m2 rows and n columns), etc.

[0085] In a feasible implementation manner, an edge-cloud collaborative detection architecture can be adopted. A lightweight detection model is deployed on the edge devices of the power monitoring system, and the lightweight detection model is used to quickly check the collected network traffic data. According to the preset simple rules or feature patterns, the traffic data that may be abnormal is identified and marked as suspected attack data; the suspected attack data marked by the edge devices is uploaded to the attack detection model in the cloud for attack detection. Compared with directly detecting through the attack detection model, by performing preliminary anomaly screening on the edge devices and only uploading the suspected attack data to the cloud, the speed of attack detection is improved, and the response speed of the system is increased. The edge devices can detect the network traffic data in real time, discover anomalies in a timely manner, and at the same time, when anomalies are discovered, they are detected by an attack detection model with high accuracy, which can ensure the accuracy of anomaly detection and the overall security of the power monitoring system.

[0086] Based on the first embodiment of the present application, in the second embodiment of the present application, the content that is the same as or similar to the above-mentioned embodiment one can be referred to the above introduction and will not be elaborated hereinafter. On this basis, please refer to Figure 2 , the attack detection model includes a first convolutional layer, an attention mechanism module, a second convolutional layer, a normalization layer, a pooling layer, a residual connection module, and a fully connected layer; the step S20: the step of inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result includes:

[0087] Step S201, inputting the basic feature matrix into the first convolutional layer to obtain initial features;

[0088] The first convolutional layer is the first convolutional operation layer in the attack detection model. It scans the input data through a convolutional kernel to extract local features in the data, providing preliminary feature information for subsequent analysis. The attention mechanism module performs channel attention and spatial attention fusion processing on the input features, highlighting the key features related to attacks and enhancing the model's ability to capture attack features. Second convolutional layer: After the attention mechanism module, it performs another convolutional operation on the enhanced features to further extract and mine more complex and deep-level features, enabling the model to understand the data more deeply. The normalization layer is used to normalize the data. By adjusting the distribution of the data, the data has a unified scale and features, which helps to accelerate the training process of the model and improve the stability and generalization ability of the model. The pooling layer downsamples the data. While retaining the main features, it reduces the amount of data, lowers the computational complexity of the model, and can also prevent overfitting to a certain extent, improving the robustness of the model. The residual connection module directly connects the input of the previous layer to the output of the subsequent layer, enabling the model to more easily learn the residual information of the data during the training process, alleviating the vanishing gradient problem, and helping the model to be trained deeper and more accurately. Fully connected layer: The last layer of the model integrates the feature vectors output by the previous layer and makes a classification judgment based on the feature patterns learned before, finally outputting the attack detection result.

[0089] Specifically, the basic feature matrix is input into the first convolutional layer, and the convolutional kernel of the convolutional layer slides on the basic feature matrix for convolutional operations to extract the local features in the basic feature matrix, providing a basis for subsequent more in-depth feature analysis. In this embodiment, the size of the convolutional kernel and the convolutional stride are not limited here and can be set according to actual needs.

[0090] Step S202: Input the initial features into the attention mechanism module for channel attention and spatial attention fusion processing to obtain enhanced features;

[0091] Input the initial features obtained from the first convolutional layer into the attention mechanism module. In this module, the initial features are analyzed from two dimensions: channel and spatial, calculating the channel attention weight and the spatial attention weight. After fusing the two, the initial features are weighted processed to highlight the key features related to attacks and obtain enhanced features, enabling the model to focus more on attack features.

[0092] Step S203: Input the enhanced features into the second convolutional layer for convolutional operations to obtain a first processing result;

[0093] Input the enhanced features into the second convolutional layer. The second convolutional layer again uses a convolutional kernel to perform a convolution operation on the enhanced features, mining more complex and representative features in the enhanced features to obtain a first processing result containing richer information. In this embodiment, the number of convolutional layers, the type of convolutional kernel, etc. can be set according to actual needs and are not limited here.

[0094] Step S204: Input the first processing result into the normalization layer to obtain a second processing result;

[0095] Input the first processing result into the normalization layer. The normalization layer performs standardization processing on the first processing result, adjusts the distribution of the data, enables the data to have unified characteristics in terms of mean, variance, etc., and improves the efficiency and stability of model training to obtain a second processing result. The normalization method can be methods such as Batch Normalization, Layer Normalization, Instance Normalization, etc., and is not limited here.

[0096] Step S205: Input the second processing result into the pooling layer to obtain a third processing result;

[0097] Input the second processing result into the pooling layer. The pooling layer performs downsampling on the data according to a preset pooling strategy, reduces the data volume while retaining the main features, and reduces the complexity of subsequent calculations to obtain a third processing result. The pooling method selection can be methods such as max pooling, average pooling, adaptive pooling, and random pooling, etc., and is not limited here.

[0098] Step S206: Output the third processing result to the residual connection module and add it to the first processing result to obtain a fourth processing result;

[0099] Input the third processing result into the residual connection module. The residual connection module adds the third processing result to the first processing result. This can enable the model to learn the residual information of the data, alleviate the gradient disappearance problem during the training process, and help the model converge better to obtain a fourth processing result.

[0100] Step S207: Input the fourth processing result into the fully connected layer to obtain an attack detection result.

[0101] Input the fourth processing result into the fully connected layer. The fully connected layer comprehensively analyzes all the features in the fourth processing result, judges whether there is an attack in the current data according to the feature patterns learned by the model, and finally outputs an attack detection result. The number of layers of the fully connected layer and the number of neurons in the fully connected layer can be set according to actual needs and are not limited here.

[0102] In a feasible embodiment, the attention mechanism module includes a channel attention mechanism and a spatial attention mechanism; the step S202: inputting the initial features into the attention mechanism module for channel attention and spatial attention fusion processing to obtain enhanced features includes:

[0103] Step S2021, input the initial features into the channel attention mechanism, generate a channel weight matrix through the channel attention mechanism, and multiply the initial features by the channel weight matrix to obtain a first output feature;

[0104] The channel attention mechanism is a mechanism used in neural networks to focus on the importance of different channels of input features. In image or feature matrix data, channels can be different types of feature information. The channel attention mechanism summarizes and analyzes the features at all spatial positions. The channel attention mechanism automatically identifies the channels that are most important for attack detection, assigns higher weights to these channels, enhances the expression ability of key channel features, enables the model to focus more on valuable feature information, improves the accuracy of attack detection, and reduces interference from irrelevant information: for those channels that contribute less to attack detection, the channel attention mechanism reduces their weights, reduces the interference of these irrelevant information to the model, and improves the efficiency and robustness of the model.

[0105] In this embodiment, the channel attention mechanism summarizes the information of the initial features in the spatial dimension, generates a channel weight matrix through calculation. The channel weight matrix is a matrix generated by the channel attention mechanism, and its dimension is the same as the number of channels of the input features. Each element in the matrix corresponds to a channel of the input features and represents the importance of that channel. The larger the weight value, the more important the features of that channel are in subsequent processing. Then, the channel weight matrix and the initial features are multiplied element by element by channel, so that the feature values of important channels are amplified and the feature values of unimportant channels are relatively reduced, thereby obtaining a first output feature and highlighting the important feature information in the channel dimension.

[0106] Step S2022, input the initial features into the spatial attention mechanism, generate a spatial weight matrix through the spatial attention mechanism, and multiply the initial features by the spatial weight matrix to obtain a second output feature;

[0107] The spatial attention mechanism focuses on the importance of input features in the spatial dimension. It analyzes the features across all channels to assign a weight to each spatial position, highlighting the feature information in important spatial regions. The spatial attention mechanism can locate important spatial regions in the input features. By enhancing the features in these regions, the model can better capture the spatial distribution characteristics of attacks and improve the ability to recognize attack patterns. In network traffic data, the features at certain spatial positions may be of great significance for attack detection. The spatial attention mechanism can fully exploit these spatial features, enabling the model to analyze the data more comprehensively and improve the performance of attack detection.

[0108] In this embodiment, the spatial attention mechanism aggregates information in the channel dimension for the initial features and generates a spatial weight matrix through calculation. The spatial weight matrix is generated by the spatial attention mechanism and has the same dimension as the spatial dimension of the input features. Each element in the matrix corresponds to a spatial position of the input features and represents the importance of that position. The larger the weight value, the more important the features at that spatial position are in subsequent processing. Then, the spatial weight matrix is multiplied element-wise with the initial features according to the spatial positions, enhancing the features at important spatial positions and suppressing the features at unimportant spatial positions, thereby obtaining the second output feature and highlighting the important feature information in the spatial dimension.

[0109] Step S2023: Fuse the first output feature and the second output feature to obtain an enhanced feature.

[0110] Fusing the first output feature and the second output feature integrates the important information in both the channel dimension and the spatial dimension to obtain a more comprehensive and representative enhanced feature. The enhanced feature comprehensively considers the importance of both channels and space and can better reflect the attack-related features in the input data, providing more effective information for subsequent attack detection. In this embodiment, the feature fusion method is not limited and can be set according to actual needs. For example, it can be the element-wise addition of the corresponding positions of the first output feature and the second output feature to simply and directly fuse the feature information; it can be the multiplication of the elements at the corresponding positions of the two output features to emphasize the features that are important in both the channel and spatial dimensions; it can also be the concatenation of the first output feature and the second output feature in the channel dimension and then performing feature fusion and dimension adjustment through a convolutional layer.

[0111] It can be understood that through feature fusion, the processing results of channel attention and spatial attention are combined, enabling the enhanced feature to contain important information in both the channel and spatial dimensions simultaneously. Thus, it can more comprehensively reflect the features of the input data, provide richer and more accurate information for attack detection, and improve the performance and reliability of the entire attack detection model.

[0112] In a feasible implementation, a dynamic adaptive attention mechanism can be adopted, which specifically includes: constructing a lightweight sub-network that takes the statistics of the current network traffic characteristics as input. The lightweight sub-network analyzes and processes these statistics, and generates dynamic weight coefficients through a series of calculations. Among them, the statistics of the network traffic characteristics are numerical values obtained by statistically analyzing network traffic data, reflecting the overall characteristics and distribution of network traffic, and can include the mean and variance. The mean represents the average level of network traffic, and the variance measures the degree of dispersion of traffic data relative to the mean; processing the enhanced features with the dynamic weight coefficients to generate an adaptive attention matrix. The specific processing method can be weighted summation, element-wise multiplication, etc., which are not limited here. The adaptive attention matrix can enhance the model's perception ability of network traffic mutations. When the traffic changes sharply, the model can adjust its attention in a timely manner, capture possible attack signs, and improve the timeliness of attack detection. By adaptively adjusting the attention, the model can more comprehensively focus on the input features, which helps to discover the feature information hidden in unknown attack patterns and improve the recognition ability of new attacks, enhancing the security of the power monitoring system network.

[0113] In a feasible embodiment, the step S2021: the step of generating the channel weight matrix through the channel attention mechanism includes:

[0114] Step S20211, performing an average pooling operation on the initial features through the channel attention mechanism to obtain a first output result;

[0115] In the channel attention mechanism, first, an average pooling operation is performed on the initial features. The average pooling traverses each channel of the initial features, divides each channel into several regions in the spatial dimension, and then calculates the average value of the feature values in each region to obtain the average feature information of each channel, forming a first output result. The pooling window size and pooling stride are not limited here and can be set according to actual needs.

[0116] Average pooling can extract the overall features of each channel, reduce the influence of the spatial dimension, and provide a basis for subsequent channel importance analysis. By average pooling, the spatial dimension of the features can be reduced while retaining the average feature information of each channel, which helps to more efficiently analyze the importance of channels in subsequent processing and reduce the interference of redundant information. By calculating the average value of each channel, average pooling can extract the overall features of each channel, reflecting the feature distribution of the channel in the entire spatial range, and providing comprehensive information for channel importance analysis.

[0117] Step S20212, performing a max pooling operation on the initial features through the channel attention mechanism to obtain a second output result;

[0118] Perform a max - pooling operation on the initial features. The max - pooling traverses each channel of the initial features, divides each channel into several regions in the spatial dimension, and selects the maximum value in each region as the output of that region, thereby highlighting the important features in each channel, obtaining the maximum feature information of each channel, and forming the second output result.

[0119] Max - pooling can highlight the important features in each channel, reduce the spatial dimension of the features, focus the attention on the regions with larger feature values. For tasks such as attack detection, it can more accurately capture the features related to attacks, making the extracted features more stable and reliable.

[0120] Step S20213: Add the first output result and the second output result to obtain a first addition result, and input the first addition result into a first activation function to generate a channel weight matrix.

[0121] Add the corresponding elements of the first output result and the second output result to obtain a first addition result. The addition operation fuses the feature information obtained by average - pooling and max - pooling, integrating the average features and max features of each channel. Then, input the first addition result into the first activation function. The activation function performs a non - linear transformation on the input, maps it to a suitable range, and finally generates a channel weight matrix. Each element in the channel weight matrix represents the importance degree of the corresponding channel, and can be used for weighted processing of the initial features later to highlight the features of important channels. The activation function can be Sigmoid, ReLU, etc., and the activation function can be selected according to the specific application scenario, which is not limited here. The fusion method can be direct addition or weighted addition, which is not limited here.

[0122] In a feasible embodiment, the step S2022: The step of generating a spatial weight matrix through the spatial attention mechanism includes:

[0123] Step S20221: Perform an average - pooling operation on the initial features through the spatial attention mechanism to obtain a third output result;

[0124] In the spatial attention mechanism, first perform an average - pooling operation on the initial features, traverse each spatial position of the initial features, divide the feature values corresponding to each spatial position into several regions in the channel dimension, and then calculate the average value of the feature values in each region to obtain the average feature information of each spatial position, and form the third output result.

[0125] Step S20222: Perform a max - pooling operation on the initial features through the spatial attention mechanism to obtain a fourth output result;

[0126] Perform a max pooling operation on the initial features. Max pooling divides the feature values corresponding to each spatial position in the channel dimension, selects the maximum value in each divided region as the output of that region, obtains the maximum feature information for each spatial position, and forms the fourth output result.

[0127] In step S2023, add the third output result and the fourth output result to obtain a second addition result, and input the second addition result into a second activation function to generate a spatial weight matrix.

[0128] Add the corresponding elements of the third output result and the fourth output result to obtain a second addition result. The addition operation fuses the spatial feature information obtained from average pooling and max pooling, integrating the average feature and the maximum feature of each spatial position. Then, input the second addition result into the second activation function. The activation function performs a non-linear transformation on the input, maps it to a suitable range, and finally generates a spatial weight matrix. Each element in the spatial weight matrix represents the importance degree of the corresponding spatial position, and can be used for weighted processing of the initial features in the subsequent steps to highlight the features of important spatial positions.

[0129] Exemplarily, to help understand the implementation process of the attack detection method for the power monitoring system obtained by combining the above embodiment 1, please refer to Figure 2 , Figure 2 A brief flow schematic diagram of an attack detection method for a power monitoring system is provided. Specifically:

[0130] Step S1: Data collection and data preprocessing. Use a distributed network traffic collection unit to quickly collect network traffic data and organize the collected data into a vector matrix form as the input for the next step. At the information-side device port, continuously collect network traffic information over a relatively long time span. These data, like fine clues, comprehensively reflect the network dynamics during system operation. Subsequently, according to different process stages of an attack, finely classify the massive network traffic data, sort and integrate it, and transform it into a well-organized dataset for in-depth analysis, laying a solid foundation for accurately understanding the information security status of the system.

[0131] Step S2: For the network traffic data that has been collected, implement a series of refined preprocessing processes. First, use the professional technical means of label encoding to cleverly convert the variable values originally presented in a categorical form into corresponding numerical forms, making the data more convenient for subsequent operations during analysis (that is, convert the categorical variable values in the network traffic data into numerical forms based on the label encoding technology to obtain the first feature matrix). Second, focus on various protocols involved in network traffic, introduce the dummy variable encoding method, reshape the categorical information existing in the form of strings into labels, and then further transform it through one-hot encoding to streamline and refine the complex protocol information, and finally successfully convert it into clear binary features, laying a foundation for subsequent in-depth data mining and analysis work (that is, reshape the traffic protocol information in the network traffic data into reshaped protocol information based on the dummy variable encoding, and convert the reshaped protocol information into binary features through one-hot encoding to obtain the second feature matrix).

[0132] Step S3: The convolutional layer extracts features from the preprocessed data, and passes the collected and processed feature vector matrix to three convolutional layers for preliminary feature extraction (that is, input the basic feature matrix into the first convolutional layer to obtain the initial features). Organize the collected network data into a vector matrix form and send it to three convolutional layers, allowing them to fully mine and refine the key features. Each convolutional layer includes convolutional, batch normalization, and activation function operations. The operation process of each convolutional layer is as Figure 3 shown.

[0133] S3.1. Convolutional operation: Use a convolutional kernel of size 3×3 to extract features from the input data. S3.2. Batch normalization operation: Perform batch normalization operation (Batch Normalization, BN) on the data of each batch. S3.3. Activation function operation: Use the ReLu activation function to process the data after the batch normalization operation, which can accelerate the convergence speed of the network and, at the same time, alleviate the problem of network overfitting. The mathematical expression of the ReLu activation function is: y = max(0, x), where the curve of the ReLu activation function is as Figure 4 shown.

[0134] Step S4: Perform feature enhancement through the attention mechanism module (that is, input the initial features into the attention mechanism module for channel attention and spatial attention fusion processing to obtain enhanced features), propose an attention mechanism that fuses channels and spaces, capture the correlation between data, and highlight the key information of APT attack data. The attention mechanism module includes channel attention and spatial attention, propose an attention mechanism that fuses channels and spaces, capture the correlation between data, and highlight the key information of APT attack data.

[0135] S4.1. Channel attention: The data processed by three convolutional layers is used as the input of channel attention. In the process of accurately calculating channel attention, it is crucial to compress the spatial dimension of the input feature map. When aggregating spatial information, average pooling and max pooling are combined and applied to the calculation process of channel attention (that is, the initial features are input into the channel attention mechanism, a channel weight matrix is generated through the channel attention mechanism, and the first output features are obtained by multiplying the channel weight matrix with the initial features). The input data is processed using average pooling and max pooling respectively, the feature maps obtained by the two pooling methods are added with the corresponding channel eigenvalues, and then processed using the sigmoid function, thus obtaining the weight of each channel (that is, the first output result is obtained by performing average pooling on the initial features through the channel attention mechanism; the second output result is obtained by performing max pooling on the initial features through the channel attention mechanism; the first addition result is obtained by adding the first output result and the second output result, and the first addition result is input into the first activation function to generate the channel weight matrix). Then, the weight is multiplied by the input of channel attention, and the output of channel attention is obtained. The formula can be:

[0136]

[0137] Among them, formula (1) and formula (2) respectively represent average pooling and max pooling on the feature map of the input channel attention, formula (3) represents adding the corresponding channel eigenvalues of the feature maps obtained by the two pooling methods and then processing using the sigmoid function, σ represents the sigmoid function, represents the output of channel attention.

[0138] S4.2. Spatial attention: As a powerful supplement to channel attention, spatial attention can comprehensively expand the difference between normal traffic and abnormal traffic in the network (that is, the initial features are input into the spatial attention mechanism, a spatial weight matrix is generated through the spatial attention mechanism, and the second output features are obtained by multiplying the spatial weight matrix with the initial features). In the process of calculating spatial attention, a combination of average pooling and max pooling is adopted to achieve in-depth mining and utilization of feature information. The feature maps obtained by the two pooling methods are added with the corresponding position eigenvalues, and then processed using the sigmoid function, thus obtaining the weight of each spatial position (that is, the third output result is obtained by performing average pooling on the initial features through the spatial attention mechanism; the fourth output result is obtained by performing max pooling on the initial features through the spatial attention mechanism; the second addition result is obtained by adding the third output result and the fourth output result, and the second addition result is input into the second activation function to generate the spatial weight matrix). Then, the weight is multiplied by the input of spatial attention, and the output of spatial attention is obtained. The formula can be:

[0139]

[0140] Formula (4) and formula (5) respectively represent the average pooling and maximum pooling of the feature map of the input spatial attention. Formula (6) represents the addition of the feature values of the corresponding positions of the feature maps obtained by the two pooling methods, and then the sigmoid function is used to process them to obtain the weight of each spatial position. σ represents the sigmoid function. represents the output of spatial attention, and formula (7) indicates that the input of channel attention and spatial attention are the same.

[0141] S4.3 Feature fusion: The feature maps output by channel attention and spatial attention are concatenated, and then 1×1 convolution is used to fuse features between different channels and reduce the dimension of feature map channels. The expression is formula (8).

[0142]

[0143] In formula (8), concat() represents the channel concatenation operation of the feature maps output by the channel attention and spatial attention, and conv() represents the execution of a 1×1 convolution operation. Represents the final output of the attention mechanism module.

[0144] Step S5: Input the enhanced features into the convolutional neural network model to obtain the attack detection result (that is, input the enhanced features into the second convolutional layer for convolution operation to obtain the first processing result; input the first processing result into the normalization layer to obtain the second processing result; input the second processing result into the pooling layer to obtain the third processing result; output the third processing result to the residual connection module and add it to the first processing result to obtain the fourth processing result; input the fourth processing result into the fully connected layer to obtain the attack detection result), the output of the attention mechanism module is used as the input of the convolutional neural network model, and the data input into the convolutional neural network model is subjected to convolution operation, batch normalization operation, pooling operation, etc., to finally realize the detection function of APT attack. The feature vector output by the attention mechanism module is used as the input of the convolutional neural network model, and the feature vector matrix is subjected to convolution, batch normalization, ReLu function activation, pooling, residual connection, fully connected layer, sigmoid function and other operations, to finally realize the detection function of APT attack.

[0145] Step S6: issuing a warning based on the attack detection result (ie, if the attack detection result indicates that the electric power monitoring system is subject to a high-level persistent threat, generating and outputting a warning message based on the attack detection result).

[0146] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the attack detection method of the power monitoring system of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0147] This application also provides an attack detection device for a power monitoring system, please refer to Figure 5 , the attack detection device of the power monitoring system comprises:

[0148] A preprocessing module 10 is used to obtain network flow data of the power monitoring system through a distributed network flow acquisition unit, and convert the network flow data into a feature matrix to obtain a basic feature matrix;

[0149] A detection module 20 is used to input the basic feature matrix into a preset attack detection model to obtain an attack detection result, wherein, in the process of performing attack detection based on the basic feature matrix by the attack detection model, the basic feature matrix is subjected to channel attention and spatial attention fusion processing by an attention mechanism, and the higher the similarity between the channel feature of the basic feature matrix and the advanced persistent threat sample, the higher the channel attention weight, and the higher the similarity between the spatial feature of the basic feature matrix and the advanced persistent threat sample, the higher the spatial channel attention weight;

[0150] The warning module 30 is configured to generate and output warning information based on the attack detection result if the attack detection result indicates that the power monitoring system is subject to an advanced persistent threat.

[0151] Optionally, the attack detection model includes a first convolution layer, an attention mechanism module, a second convolution layer, a normalization layer, a pooling layer, a residual connection module and a fully connected layer; the detection module 20 is used to:

[0152] Inputting the basic feature matrix into the first convolutional layer to obtain initial features;

[0153] Inputting the initial features into the attention mechanism module to perform channel attention and spatial attention fusion processing to obtain enhanced features;

[0154] Inputting the enhanced feature into the second convolutional layer for convolution operation to obtain a first processing result;

[0155] Inputting the first processing result into the normalization layer to obtain a second processing result;

[0156] Inputting the second processing result into the pooling layer to obtain a third processing result;

[0157] Output the third processing result to the residual connection module and add it to the first processing result to obtain a fourth processing result;

[0158] Input the fourth processing result into the fully connected layer to obtain an attack detection result.

[0159] Optionally, the attention mechanism module includes a channel attention mechanism and a spatial attention mechanism; the detection module 20 is configured to:

[0160] Input the initial feature into the channel attention mechanism, generate a channel weight matrix through the channel attention mechanism, and multiply the initial feature by the channel weight matrix to obtain a first output feature;

[0161] Input the initial feature into the spatial attention mechanism, generate a spatial weight matrix through the spatial attention mechanism, and multiply the initial feature by the spatial weight matrix to obtain a second output feature;

[0162] Perform feature fusion on the first output feature and the second output feature to obtain an enhanced feature.

[0163] Optionally, the detection module 20 is configured to:

[0164] Perform average pooling on the initial feature through the channel attention mechanism to obtain a first output result;

[0165] Perform max pooling on the initial feature through the channel attention mechanism to obtain a second output result;

[0166] Add the first output result and the second output result to obtain a first addition result, and input the first addition result into a first activation function to generate a channel weight matrix.

[0167] Optionally, the detection module 20 is configured to:

[0168] Perform average pooling on the initial feature through the spatial attention mechanism to obtain a third output result;

[0169] Perform max pooling on the initial feature through the spatial attention mechanism to obtain a fourth output result;

[0170] Add the third output result and the fourth output result to obtain a second addition result, and input the second addition result into a second activation function to generate a spatial weight matrix.

[0171] Optionally, the preprocessing module 10 is configured to:

[0172] Based on label encoding technology, convert the categorical variable values in the network traffic data into numerical form to obtain a first feature matrix;

[0173] Based on dummy variable encoding, the traffic protocol information in the network traffic data is reshaped into reshaped protocol information, and the reshaped protocol information is converted into binary features through one-hot encoding to obtain a second feature matrix;

[0174] The first feature matrix and the second feature matrix are determined as the basic feature matrix.

[0175] The attack detection device of the power monitoring system provided by this application adopts the attack detection method of the power monitoring system in the above embodiment, which can solve the technical problem that the detection accuracy of the current APT attack detection method is relatively low, resulting in the security of the power monitoring system being affected. Compared with the prior art, the beneficial effects of the attack detection device of the power monitoring system provided by this application are the same as those of the attack detection method of the power monitoring system provided by the above embodiment, and other technical features in the attack detection device of the power monitoring system are the same as the features disclosed in the above embodiment method, and will not be elaborated here.

[0176] This application provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the attack detection method of the power monitoring system in the first embodiment above.

[0177] Refer to the following Figure 6 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present application. The electronic device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description), PMPs (Portable Media Player), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0178] As Figure 6As shown, the electronic device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory 1002 or the program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the electronic device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems may be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.

[0179] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0180] The electronic device provided by the present application adopts the attack detection method of the power monitoring system in the above embodiments, and can solve the technical problem that the current APT attack detection method has a low detection accuracy, resulting in the security of the power monitoring system being affected. Compared with the prior art, the beneficial effects of the electronic device provided by the present application are the same as those of the attack detection method of the power monitoring system provided by the above embodiments, and other technical features in the electronic device are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.

[0181] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0182] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0183] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the attack detection method of the power monitoring system in the above embodiments.

[0184] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0185] The above computer-readable storage medium can be included in an electronic device; or it can exist separately without being assembled into the electronic device.

[0186] The above computer-readable storage medium stores one or more programs, which, when executed by an electronic device, cause the electronic device to: obtain network traffic data of a power monitoring system through a distributed network traffic collection unit, and convert the network traffic data into a feature matrix to obtain a basic feature matrix; input the basic feature matrix into a preset attack detection model to obtain an attack detection result, wherein, in the process of performing attack detection on the basic feature matrix by the attack detection model, channel attention and spatial attention fusion processing is performed on the basic feature matrix through an attention mechanism, the higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight, and the higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight; if the attack detection result indicates that the power monitoring system is under an advanced persistent threat, a warning message is generated and output based on the attack detection result.

[0187] Computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via an Internet service provider through the Internet).

[0188] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the boxes may occur in a different order than that marked in the accompanying drawings. For example, two consecutive boxes shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and combinations of boxes in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0189] The modules described in the embodiments of the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0190] The readable storage medium provided by the present application is a computer-readable storage medium that stores computer-readable program instructions (i.e., computer programs) for executing the attack detection method of the above-mentioned power monitoring system, and can solve the technical problem that the detection accuracy of the current APT attack detection method is relatively low, resulting in the security of the power monitoring system being affected. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the attack detection method of the power monitoring system provided by the above embodiments, and will not be elaborated here.

[0191] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the attack detection method of the power monitoring system as described above.

[0192] The computer program product provided by the present application can solve the technical problem that the detection accuracy of the current APT attack detection method is relatively low, resulting in the security of the power monitoring system being affected. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the attack detection method of the power monitoring system provided by the above embodiments, and will not be elaborated here.

[0193] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. All equivalent structural transformations made under the technical concept of the present application by using the content of the specification and drawings of the present application, or directly / indirectly applied in other related technical fields, are included in the patent protection scope of the present application.

Claims

1. An attack detection method for a power monitoring system, characterized in that The attack detection method of the power monitoring system includes: Obtaining the network traffic data of the power monitoring system through a distributed network traffic acquisition unit, and converting the network traffic data into a feature matrix to obtain a basic feature matrix; Inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result. Among them, in the process of performing attack detection based on the basic feature matrix by the attack detection model, the basic feature matrix is processed by fusing channel attention and spatial attention through an attention mechanism. The higher the similarity between the channel features of the basic feature matrix and the advanced persistent threat samples, the higher the channel attention weight. The higher the similarity between the spatial features of the basic feature matrix and the advanced persistent threat samples, the higher the spatial channel attention weight; If the attack detection result indicates that the power monitoring system is suffering from an advanced persistent threat, a warning message is generated and output based on the attack detection result.

2. The attack detection method for the power monitoring system according to claim 1, characterized in that, The attack detection model includes a first convolutional layer, an attention mechanism module, a second convolutional layer, a normalization layer, a pooling layer, a residual connection module, and a fully connected layer; The step of inputting the basic feature matrix into a preset attack detection model to obtain an attack detection result includes: Inputting the basic feature matrix into the first convolutional layer to obtain an initial feature; Inputting the initial feature into the attention mechanism module for channel attention and spatial attention fusion processing to obtain an enhanced feature; Inputting the enhanced feature into the second convolutional layer for convolution operation to obtain a first processing result; Inputting the first processing result into the normalization layer to obtain a second processing result; Inputting the second processing result into the pooling layer to obtain a third processing result; Outputting the third processing result to the residual connection module and adding it to the first processing result to obtain a fourth processing result; Inputting the fourth processing result into the fully connected layer to obtain an attack detection result.

3. The attack detection method for the power monitoring system according to claim 2, wherein The attention mechanism module includes a channel attention mechanism and a spatial attention mechanism; The step of inputting the initial feature into the attention mechanism module for channel attention and spatial attention fusion processing to obtain an enhanced feature includes: Inputting the initial feature into the channel attention mechanism, generating a channel weight matrix through the channel attention mechanism, and multiplying the initial feature by the channel weight matrix to obtain a first output feature; Inputting the initial feature into the spatial attention mechanism, generating a spatial weight matrix through the spatial attention mechanism, and multiplying the initial feature by the spatial weight matrix to obtain a second output feature; Performing feature fusion on the first output feature and the second output feature to obtain an enhanced feature.

4. The attack detection method for the power monitoring system according to claim 3, characterized in that, The step of generating a channel weight matrix through the channel attention mechanism includes: Performing average pooling operation on the initial feature through the channel attention mechanism to obtain a first output result; Performing max pooling operation on the initial feature through the channel attention mechanism to obtain a second output result; The first output result and the second output result are added to obtain a first addition result, and the first addition result is input into a first activation function to generate a channel weight matrix.

5. The attack detection method of the power monitoring system according to claim 3, characterized in that The step of generating a spatial weight matrix by the spatial attention mechanism comprises: Performing an average pooling operation on the initial features through the spatial attention mechanism to obtain a third output result; Performing a maximum pooling operation on the initial features through the spatial attention mechanism to obtain a fourth output result; The third output result and the fourth output result are added to obtain a second addition result, and the second addition result is input into a second activation function to generate a spatial weight matrix.

6. The attack detection method for the power monitoring system according to any one of claims 1 to 5, characterized in that, The step of converting the network traffic data into a feature matrix to obtain a basic feature matrix comprises: Based on the label encoding technology, the categorical variable values in the network traffic data are converted into numerical form to obtain a first feature matrix; Based on dummy variable coding, the flow protocol information in the network flow data is labeled and reshaped to obtain reshaped protocol information, and the reshaped protocol information is converted into binary features through one-hot encoding to obtain a second feature matrix; The first characteristic matrix and the second characteristic matrix are determined as basic characteristic matrices.

7. An attack detection device for a power monitoring system, characterized in that, The attack detection device of the power monitoring system comprises: A preprocessing module, used for acquiring network flow data of the power monitoring system through a distributed network flow acquisition unit, and converting the network flow data into a feature matrix to obtain a basic feature matrix; A detection module, configured to input the basic feature matrix into a preset attack detection model to obtain an attack detection result, wherein, in the process of performing attack detection based on the basic feature matrix by the attack detection model, the basic feature matrix is subjected to channel attention and spatial attention fusion processing by an attention mechanism, and the higher the similarity between the channel feature of the basic feature matrix and the advanced persistent threat sample, the higher the channel attention weight, and the higher the similarity between the spatial feature of the basic feature matrix and the advanced persistent threat sample, the higher the spatial channel attention weight; The warning module is used to generate and output warning information based on the attack detection result if the attack detection result indicates that the power monitoring system is subject to an advanced persistent threat.

8. An electronic device, characterized in that, The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the attack detection method for the power monitoring system according to any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the attack detection method for the power monitoring system according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that, The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the attack detection method for the power monitoring system according to any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • Network attack detection method and device, computer equipment and program product

    CN121217486A

  • Network attack detection method, apparatus, computer device, and program product

    CN121217486B