Satellite telemetry data injection attack anomaly detection method and system
By building a satellite ecological stability model and ecological intrusion verification, the detection accuracy and real-time problems of satellite telemetry data under complex attacks are solved, and efficient attack abnormality detection and data recovery are achieved.
Patent Information
- Application Number
- CN202510907943.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-02
AI Technical Summary
Existing satellite telemetry data security protection technology is inadequate detection accuracy, poor real-time performance and weak adaptability when facing complex and hidden injection attacks, and cannot effectively deal with the increasingly complex injection attack threats.
By collecting and preprocessing satellite telemetry data multi-source data, a satellite ecological stability model is built, and the ultra-graph structure and ecological stability calculation are used to perform primary and secondary screening, combining ecological intrusion verification and destruction scores, intrusion cleaning decisions are generated, and data is restored.
It improves the efficiency and accuracy of attack anomaly detection in satellite telemetry data, can quickly identify and clean up complex attacks, and ensures the stable operation of the satellite system.
Smart Images

Figure CN120408609A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite detection, and in particular, to a method and system for detecting anomalies in satellite telemetry data injection attacks. Background Art
[0002] With the rapid development of space technology, satellite systems play an increasingly important role in fields such as communication, navigation, and remote sensing. However, satellite telemetry data may face the threat of malicious injection attacks during the transmission and processing process. Attackers can interfere with the normal operation of satellites or even cause serious security accidents by forging or tampering with data.
[0003] Currently, the anomaly detection of satellite telemetry data mainly relies on traditional data verification, statistical analysis, and machine learning methods. However, these methods have obvious deficiencies when facing complex and hidden injection attacks: on the one hand, traditional verification technologies are difficult to identify carefully constructed malicious data; on the other hand, existing machine learning models rely on a large amount of labeled data and have limited generalization ability for new attack patterns.
[0004] In summary, the existing satellite telemetry data security protection technologies still have problems such as insufficient detection accuracy, poor real-time performance, and weak adaptability, and cannot effectively cope with the increasingly complex threat of injection attacks. Summary of the Invention
[0005] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a method for detecting anomalies in satellite telemetry data injection attacks, and the method includes: Collect multi-source data for each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data; Obtain a preset physical constraint library of satellite telemetry data, and construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and satellite telemetry data; Based on the initial satellite data screening mechanism, perform an initial screening on the satellite telemetry data to generate an initial satellite ecological early warning group, calculate the ecological stability degree of the initial satellite ecological early warning group based on the satellite ecological stability model, and obtain the ecological stability degree result; Based on the secondary satellite data screening mechanism and combined with the ecological stability degree result, perform a secondary screening on the initial satellite ecological early warning group to obtain a satellite ecological early warning group, and perform ecological intrusion verification on the satellite ecological early warning group to obtain a satellite ecological damage score; Generate an intrusion cleaning decision based on the satellite ecological damage score to obtain an intrusion cleaning decision, and a user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision.
[0006] As a further solution of the present invention, the initial screening of the satellite telemetry data is performed based on the initial satellite data screening mechanism to generate an initial satellite ecological early warning group, including: Randomly extract 2 to 5 associated data from the satellite telemetry data based on Latin hypercube sampling. The associated data represents satellite telemetry data with physical associations between satellite telemetry data, and combine the 2 to 5 associated data into a random combination data set; Combine the random combination data set with the hypergraph structure included in the satellite ecological stability model to generate an initial satellite ecological early warning group.
[0007] As a further solution of the present invention, calculating the ecological stability degree of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain the ecological stability degree result, including: Calculate the theoretical values of the physical constraint functions included in each data combination in the initial satellite ecological early warning group based on the satellite ecological stability model; Perform local ecological stability calculation on each data combination in the initial satellite ecological early warning group based on the theoretical values of the physical constraint functions and the local ecological stability function to obtain the local ecological stability result, and calculate the ecological stability degree of the data combination based on the local ecological stability result.
[0008] As a further solution of the present invention, the method further includes: The local ecological stability function is expressed as: ; Wherein, represents the local ecological stability corresponding to the jth physical constraint function in the data combination, represents the ecological stability sensitivity factor and is an integer in [1, 10], represents the relative deviation between the measured value and the theoretical value of the jth physical constraint function in the data combination.
[0009] As a further solution of the present invention, performing a secondary screening on the initial satellite ecological early warning group based on the secondary satellite data screening mechanism and combining the ecological stability degree result to obtain a satellite ecological early warning group, and performing ecological invasion verification on the satellite ecological early warning group to obtain a satellite ecological damage score, including: The secondary satellite data screening mechanism includes a high-risk combination initial screening and a high-risk combination fusion screening; The high-risk combination initial screening means removing the data combinations in the initial satellite ecological early warning group whose ecological stability exceeds the preset ecological stability threshold, and performing a guaranteed combination quantity on the initial satellite ecological early warning group after the removal operation based on the screening guarantee mechanism; The high-risk combination fusion screening is expressed as randomly cross-fusing the data combinations in the high-risk combination set based on the fusion constraint strategy to generate a satellite ecological early warning candidate set, iteratively optimizing the satellite ecological early warning candidate set based on the fusion optimization strategy to obtain the iterative optimization result, and generating a satellite ecological early warning group based on the iterative optimization result; Based on the ecological invasion stress test, verify the ecological invasion of the satellite ecological early warning group, and calculate the satellite ecological damage score of the satellite ecological early warning group according to the satellite ecological damage scoring function.
[0010] As a further solution of the present invention, the ecological invasion stress test includes: Inject a bionic attack signal with an energy density greater than a preset threshold in the sensitive frequency band of the satellite telemetry data, monitor the number of cross-layer conflicts in the satellite network protocol stack, and record the duration of the satellite link bit error rate exceeding the limit; Embed parasitic parameters in the attitude control system of the satellite to quantify the stability decay gradient, and the stability decay gradient is expressed as the rate of decrease in ecological stability per unit time; Truncate the balance circuit of each subsystem of the satellite and redirect 10% of the charge-discharge power, and measure the harmonic distortion rate of the multi-power bus.
[0011] As a further solution of the present invention, generate an intrusion cleaning decision based on the satellite ecological damage score to obtain the intrusion cleaning decision, and the user can perform data cleaning and recovery on the satellite telemetry data based on the intrusion cleaning decision, including: Perform anomaly grading on the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined that a highly dangerous anomaly has occurred, and a high-risk anomaly cleaning decision is generated; When the satellite ecological damage score is in the range of [0.6, 0.85], it is determined that a moderately dangerous anomaly has occurred, and a medium-risk anomaly repair decision is generated; When the satellite ecological damage score is less than 0.6, it is determined that there is no dangerous anomaly, and a daily maintenance decision is generated.
[0012] As a further solution of the present invention, obtain a preset physical constraint library of satellite telemetry data, and construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and satellite telemetry data, including: Load the physical constraint relationship from the preset physical constraint library of satellite telemetry data, organize the physical constraint relationship through a hypergraph structure, and construct a satellite ecological stability model based on the hypergraph structure. The hypergraph structure includes vertices and hyperedges. The vertices of the hypergraph structure represent satellite telemetry data, and the hyperedges of the hypergraph structure represent the physical constraint relationships between satellite telemetry data.
[0013] As a further solution of the present invention, the multi-source data collection of each satellite subsystem is performed to obtain satellite telemetry data, and the data preprocessing of the satellite telemetry data includes: The operation data of each satellite subsystem is obtained in real time, the time base of the operation data of each satellite subsystem is synchronized by using the timestamp unified protocol, and the relationship between high-precision monitoring and resource consumption is balanced through the adaptive sampling frequency adjustment mechanism. For the physical layer interference in the signal acquisition process, a noise reduction algorithm is used to eliminate the physical layer interference; The data preprocessing includes anomaly detection and elimination and time axis calibration. The time axis calibration is expressed as performing cubic spline interpolation on the operation data of each satellite subsystem for time axis calibration, normalizing the operation data of each satellite subsystem after data preprocessing, and combining the operation data of each satellite subsystem after data preprocessing and data normalization to generate satellite telemetry data.
[0014] On the other hand, an embodiment of the present invention further provides a satellite telemetry data injection attack anomaly detection system, including: A data collection module, which is used to perform multi-source data collection on each satellite subsystem, obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data; A model construction module, which is used to obtain a preset satellite telemetry data physical constraint library and construct a satellite ecological stability model according to the satellite telemetry data physical constraint library and the satellite telemetry data; An ecological early warning module, which is used to initially screen the satellite telemetry data to generate an initial satellite ecological early warning group, and calculate the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain an ecological stability result; An intrusion verification module, which is used to perform secondary screening on the initial satellite ecological early warning group according to the ecological stability result to obtain a satellite ecological early warning group, and perform ecological intrusion verification on the satellite ecological early warning group to obtain a satellite ecological damage score; A decision generation module, which is used to generate an intrusion cleaning decision according to the satellite ecological damage score to obtain an intrusion cleaning decision, and the user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision.
[0015] Based on the above aspects, embodiments of the present application perform multi-source data collection on each satellite subsystem to obtain satellite telemetry data, perform data preprocessing on the satellite telemetry data to obtain a preset physical constraint library of satellite telemetry data, establish a multi-parameter coupling evaluation system based on the physical constraint library to shorten the latency of subsequent evaluation and screening operations, construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and the satellite telemetry data, perform an initial screening on the satellite telemetry data based on the initial satellite data screening mechanism to generate an initial satellite ecological warning group, quickly eliminate invalid low-risk combinations, focus computing power on the remaining suspicious targets, reduce the amount of invalid calculations, and ensure the identification efficiency of high-risk targets. Calculate the ecological stability degree of the initial satellite ecological warning group based on the satellite ecological stability model to obtain the ecological stability degree result, perform a secondary screening on the initial satellite ecological warning group based on the secondary satellite data screening mechanism and in combination with the ecological stability degree result to obtain the satellite ecological warning group, accurately capture cross-system high-risk targets from a large number of data combinations through hypergraph association screening and dynamic ranking of ecological stability degrees, and perform ecological invasion verification on the satellite ecological warning group to obtain the satellite ecological damage score, improve the accuracy of capturing cross-system high-risk targets, generate an intrusion cleaning decision based on the satellite ecological damage score to obtain the intrusion cleaning decision, and the user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision. Through this method, the efficiency and accuracy of attack anomaly detection in satellite telemetry data can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 FIG. is a schematic execution flowchart of a method for detecting anomalies in satellite telemetry data injection attacks provided by an embodiment of the present invention.
[0017] Figure 2 FIG. is a schematic diagram of a system for detecting anomalies in satellite telemetry data injection attacks provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The present invention will be specifically described below in conjunction with the accompanying drawings of the specification. Figure 1 FIG. is a schematic execution flowchart of a method for detecting anomalies in satellite telemetry data injection attacks provided by an embodiment of the present invention. The method for detecting anomalies in satellite telemetry data injection attacks will be introduced in detail below.
[0019] Step S1: Perform multi-source data collection on each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data.
[0020] Specifically, the operating data of each satellite subsystem is obtained in real time. For example, the operating parameters of the core satellite subsystems such as power supply, attitude control, thermal management, and communication are obtained in real time through a distributed sensor network, specifically including key indicators such as battery voltage and current, solar panel output power, gyroscope angular velocity, reaction wheel speed, star sensor data, temperature distribution of key components, signal strength, and bit error rate.
[0021] It can be understood that the time reference of the operating data of each satellite subsystem is synchronized using a timestamp unification protocol, and the relationship between high-precision monitoring and resource consumption is balanced through an adaptive sampling frequency adjustment mechanism. The adaptive sampling frequency adjustment mechanism is expressed as dynamically adjusting the sampling rate based on the change gradient of the operating data of each satellite subsystem and the criticality of the task. When the change rate exceeds a preset threshold or the task is in a critical stage, the sampling frequency is increased. When resources are scarce, each satellite subsystem is coordinated to perform hierarchical frequency reduction. For the physical layer interference during the signal acquisition process, a noise reduction algorithm is used to eliminate the physical layer interference. For example, a noise reduction algorithm based on wavelet transform is applied to remove the high-frequency noise part in the operating data of each satellite subsystem.
[0022] Furthermore, anomaly detection and elimination are performed on the collected operating data of each satellite subsystem. The sliding window algorithm is used to identify and remove abnormal data that exceeds the physical constraint range, and the time axis of the operating data of each satellite subsystem is calibrated through a cubic spline interpolation mechanism. The time axis calibration is expressed as unifying multi-source data to a reference time axis by dynamically compensating for the clock drift of each sensor. Data normalization is performed on the operating data of each satellite subsystem after data preprocessing, so that data with different dimensions is converted into dimensionless numerical values in a unified [0, 1] interval. The operating data of each satellite subsystem after data preprocessing and data normalization is combined to generate satellite telemetry data.
[0023] Step S2: Obtain a preset physical constraint library for satellite telemetry data, and construct a satellite ecological stability model based on the physical constraint library for satellite telemetry data and the satellite telemetry data.
[0024] It can be understood that the preset physical constraint library for satellite telemetry data is a mathematical rule system constructed based on satellite dynamics principles and equipment physical characteristics, and the physical coupling rules between each satellite subsystem are described through predefined physical constraint functions.
[0025] Specifically, load the physical constraint relationships from the preset physical constraint library of satellite telemetry data, organize the physical constraint relationships through a hypergraph structure, and construct a satellite ecological stability model based on the hypergraph structure. The vertices of the hypergraph structure represent satellite telemetry data, and the hyperedges of the hypergraph structure represent the physical constraint relationships between satellite telemetry data. For example, in the coupling relationship between the power supply and the thermal control subsystem, define the nonlinear function relationship between the battery temperature and the charging current; in the attitude control system, establish the differential equation model of the reaction wheel energy consumption and the angular acceleration.
[0026] It can be understood that during the model construction process, a dynamic weight allocation strategy is implemented to adjust the importance weights of each subsystem according to different mission phases. The dynamic weight allocation strategy is expressed as assigning the highest weight coefficient to the attitude control system during the orbital maneuver phase, increasing the weight ratio of the communication system during the data transmission phase, and strengthening the monitoring level of the energy system during the shadow period.
[0027] It can be understood that the dynamic weight calculation uses the eigenvalue analysis method to obtain the optimal allocation scheme by combining the current mission objectives and historical fault data. For example, for special working conditions such as space radiation and thermal cycling, the allocated weights are dynamically corrected based on the built-in environment compensation module of the model and the space environment parameters obtained in real time.
[0028] Step S3: Based on the initial satellite data screening mechanism, conduct the initial screening of satellite telemetry data to generate an initial satellite ecological warning group, calculate the ecological stability degree of the initial satellite ecological warning group based on the satellite ecological stability model, and obtain the ecological stability degree result.
[0029] In this embodiment, step S3 includes: Step S31: Based on the initial satellite data screening mechanism, conduct the initial screening of satellite telemetry data to generate an initial satellite ecological warning group.
[0030] Specifically, perform random data combination on satellite telemetry data based on the stratified random sampling operation to obtain a random combination data set. The stratified random sampling strategy is expressed as randomly extracting 2 to 5 associated data through the Latin hypercube sampling technique. The associated data refers to satellite telemetry data with physical associations between satellite telemetry data, and the random combination data set is combined with the hypergraph structure included in the satellite ecological stability model to generate an initial satellite ecological warning group.
[0031] It is understandable that the initial satellite ecological early warning group generation process implements a triple verification mechanism to restrict the spatial distribution of the generated initial satellite ecological early warning group. The triple verification mechanism means that there is at least one physical constraint path for the data within the initial satellite ecological early warning group. The physical constraint path is represented by the physical constraint functions included in the satellite telemetry data physical constraint library, and the data magnitude difference within the initial satellite ecological early warning group is restricted within three magnitudes to avoid calculation errors caused by excessive data magnitude differences. At the same time, invalid combinations with too high a proportion of data from the same subsystem are excluded.
[0032] It is understandable that the generation scale of the initial satellite ecological early warning group is restricted based on the generation scale adaptive mechanism. The generation scale adaptive mechanism means that the basic generation quantity for each batch is 20% of the total associated parameters. When the effective combination rate is lower than 70%, a negative feedback expansion mechanism is triggered to increase the generation quantity. The effective combination rate is represented by the proportion of the number of qualified data combinations passing through the triple verification mechanism in the generated random combination data set until the physical constraint edge coverage rate reaches the preset threshold for three consecutive times.
[0033] Step S32: Calculate the ecological stability degree of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain the ecological stability degree result.
[0034] In this embodiment, step S32 includes: Step S32-1: Calculate the local ecological stability degree of the physical constraint functions corresponding to each data combination within the initial satellite ecological early warning group based on the satellite ecological stability model.
[0035] Specifically, perform a physical association evaluation on the initial satellite ecological early warning group based on the satellite ecological stability model. The physical association evaluation means calculating the theoretical values of the physical constraint functions included in each data combination within the initial satellite ecological early warning group, and calculating the local ecological stability degree of the data combination based on the theoretical values of the physical constraint functions to obtain the local ecological stability degree result. The local ecological stability degree calculation means calculating the relative deviation between the measured value and the theoretical value of the physical constraint function, and calculating the local ecological stability degree according to the local ecological stability degree function. The local ecological stability degree function can be expressed as: ; Among them, represents the local ecological stability degree corresponding to the j-th physical constraint function within the data combination, represents the ecological stability sensitivity factor and is an integer in [1, 10], represents the relative deviation between the measured value and the theoretical value of the j-th physical constraint function within the data combination.
[0036] It is understandable that the allocation of the ecological stability sensitivity factors is expressed as the allocation to the high-sensitivity physical constraint function within the range of [8, 10], the allocation to the medium-sensitivity physical constraint function within the range of [4, 7], the allocation to the low-sensitivity physical constraint function within the range of [1, 3]. The high-sensitivity physical constraint function is expressed as the physical laws related to core security, such as the conservation of angular momentum between the attitude control gyroscope and the reaction wheel. The medium-sensitivity physical constraint function is expressed as the operation constraints of key equipment, such as the temperature-current relationship during the charge and discharge of lithium batteries. The low-sensitivity physical constraint function is expressed as the influence relationship of environmental factors on satellite telemetry data, such as the coupling relationship between the solar radiation intensity and the temperature of the solar panel.
[0037] For example, a certain data combination is {battery temperature T, charging current I}. The physical constraint function matched by this data combination in the physical constraint library of satellite telemetry data is T = f(I) = 0.2I² + 25, and the measured data of I is 5A. Then the theoretical value of the function of this data combination is expressed as = 30°C.
[0038] Step S32-2, calculate the ecological stability of the data combination based on the local ecological stability of the physical constraint function corresponding to the data combination.
[0039] Specifically, calculate the ecological stability of the data combination within the initial satellite ecological warning group based on the ecological stability function. The ecological stability function can be expressed as: ; Among them, represents the ecological stability of the data combination within the initial satellite ecological warning group, represents the ecological stability weight, represents the data combination the local ecological stability corresponding to the j-th physical constraint function in.
[0040] It is understandable that the ecological stability weight is assigned to the physical constraint function based on the triple benchmark strategy. The triple benchmark strategy includes three benchmarks: the basic weight, the state coefficient, and the historical correction coefficient. The basic weight benchmark is expressed as dividing the physical constraint function into three basic physical constraints: physical laws, equipment models, and statistical relationships, and respectively assigning basic weights of 1.0, 0.8, and 0.3 to the physical laws, the equipment models, and the statistical relationship basic physical constraints; The state coefficient benchmark is expressed as setting the state coefficient for the basic weight corresponding to the data combination when equipment anomalies occur. For example, multiplying the weight by 0.5, and setting the state coefficient for the basic weight corresponding to the data combination that has just completed data calibration. For example, multiplying the weight by 1.2; The historical correction coefficient benchmark is expressed as not setting the historical correction coefficient or setting the historical correction coefficient to 1.0 for the data combination composed of data within one month, and setting the historical correction coefficient for the data combination composed of data exceeding one month. For example, setting a historical correction coefficient of 0.85 for the data combination composed of data two months ago; Combining the basic weight, the state coefficient, and the historical correction coefficient to generate the ecological stability weight. For example, if the physical constraint function matched by a certain data combination corresponds to the battery temperature - current mechanism model, the basic weight of this data combination is 0.8, and at this time, a battery alarm occurs, so the state coefficient of this data combination is 0.5, and the component data of this data combination is data within one month, then the historical correction coefficient of this data combination is 1.0, and the ecological stability weight 0.4 is composed of the basic weight, state coefficient, and historical correction coefficient corresponding to this data combination.
[0041] Step S4, based on the secondary satellite data screening mechanism and combined with the ecological stability result, perform secondary screening on the initial satellite ecological early warning group to obtain the satellite ecological early warning group, and conduct ecological invasion verification on the satellite ecological early warning group to obtain the satellite ecological damage score.
[0042] In this embodiment, step S4 includes: Step S41, based on the secondary satellite data screening mechanism and combined with the ecological stability result, perform secondary screening on the initial satellite ecological early warning group to obtain the satellite ecological early warning group.
[0043] Specifically, the secondary satellite data screening mechanism includes preliminary screening of high - risk combinations and fusion screening of high - risk combinations. The preliminary screening of high - risk combinations means excluding the data combinations in the initial satellite ecological early warning group whose ecological stability exceeds the preset ecological stability threshold, arranging the data combinations in the initial satellite ecological early warning group after the data exclusion operation in ascending order of ecological stability, and outputting the top 15% of the data combinations as the high - risk combination set, and ensuring the number of combinations in the high - risk combination set based on the screening guarantee mechanism.
[0044] It can be understood that the screening guarantee mechanism is expressed as comparing the number of data combinations in the high-risk combination set with a preset guarantee threshold. If the number of data combinations in the high-risk combination set is lower than the preset guarantee threshold, and after the data elimination operation and the preliminary screening of high-risk combinations, the number of remaining data combinations in the initial satellite ecological warning group exceeds the difference between the preset guarantee threshold and the number of data combinations in the high-risk combination set, then the remaining data combinations in the initial satellite ecological warning group are filled into the high-risk combination set; if the number of data combinations in the high-risk combination set is lower than the preset guarantee threshold, and after the data elimination operation and the preliminary screening of high-risk combinations, the number of remaining data combinations in the initial satellite ecological warning group does not exceed the difference between the preset guarantee threshold and the number of data combinations in the high-risk combination set, then all the remaining data combinations in the initial satellite ecological warning group are filled into the high-risk combination set, and the data combinations with a sudden drop in ecological stability greater than 30% in the initial satellite ecological warning group that have not undergone the data elimination operation are forcibly filled into the high-risk combination set as high-risk combinations.
[0045] Furthermore, the high-risk combination fusion screening is expressed as randomly cross-fusing the data combinations in the high-risk combination set based on the fusion constraint strategy, calculating the ecological stability of the data combinations after the random cross-fusion, combining the data combinations after the random cross-fusion with the corresponding ecological stability to generate a satellite ecological warning candidate set, iteratively optimizing the satellite ecological warning candidate set based on the fusion optimization strategy to obtain the iterative optimization result, and generating a satellite ecological warning group based on the iterative optimization result.
[0046] It can be understood that the fusion constraint strategy is expressed as restricting data exchange only between data combinations belonging to the same physical constraint type. For example, if the physical constraint types of two data combinations are energy type and attitude type respectively and they are mutually exclusive, then data exchange between them is restricted, and the exchangeable parameter set is screened according to the hyperedges contained in the hypergraph structure.
[0047] It can be understood that the random cross-fusion operation includes three fusion modes: replacement fusion, expansion fusion and splitting fusion. The replacement fusion mode is represented by replacing the data combination with the ecological stability continuously higher than 0.5 with the same-level parameters of the top 10 historical failure rates. The historical failure rate is represented by the proportion of historical failures of the same type as the data combination in the preset historical failure library; expansion fusion adds cross-system parameters to the data combination with no more than 3 types of satellite telemetry data in the data combination and the ecological stability lower than 0.4. The cross-system parameters are represented by satellite telemetry data that are associated with the current data combination. For example, a data combination is {reaction wheel speed, power supply bus current} and the ecological stability is 0.39. The data combination In accordance with the requirements of the expansion fusion mode, bearing temperature data is added to the data combination, and the data combination after expansion fusion is {reaction wheel speed, power supply bus current, bearing temperature}; cracking fusion means splitting the combination judged as having multiple constraint failures into multiple independent sub-units, and performing fusion optimization for each of the multiple sub-units. For example, a data combination is judged as having multiple constraint failures because it violates the attitude maneuvering stability constraint and the thermal control power constraint at the same time. At this time, the cracking fusion mode is triggered, and the data combination is decoupled and split into a maneuvering control sub-unit and a thermal management sub-unit. The corresponding data of similar failure cases in the historical fault library are injected into the maneuvering control sub-unit, and the expansion fusion mode is implemented for the thermal management sub-unit to fuse cross-system parameters.
[0048] It can be understood that the fusion optimization strategy is expressed as always maintaining the five data combinations with the lowest ecological stability unchanged, and at the same time implementing stress testing on the medium-risk combinations. For example, the data combinations with ecological stability within [0.35, 0.45) are divided into medium-risk combinations, and the medium-risk combinations are injected with three simulated attacks of timing delay, magnitude offset and constraint cutoff for stress testing. At the same time, the iterative optimization convergence coefficient is continuously monitored during the iterative optimization process. The iterative optimization convergence coefficient is expressed as the relative value of the ecological stability extremes of the top ten combinations for three consecutive generations. When the iterative optimization convergence coefficient is lower than 0.05 for three consecutive generations, it is judged as strong convergence, and the top 30 data combinations with the lowest ecological stability are output at this time; if the iterative optimization convergence coefficient is lower than 0.08 for five consecutive generations, it is treated as weak convergence, and the top 50 data combinations with the lowest ecological stability are output at this time.
[0049] Step S42: Perform ecological invasion verification on the satellite ecological early warning group to obtain a satellite ecological damage score.
[0050] Specifically, ecological invasion verification is carried out on the satellite ecological early warning group based on ecological invasion stress testing. The ecological invasion stress testing includes three stress testing stages: heterogeneous signal injection, niche erosion testing, and energy flow hijacking verification. Heterogeneous signal injection means injecting a bionic attack signal with an energy density greater than a preset threshold in a sensitive frequency band, monitoring the number of cross-layer conflicts in the satellite network protocol stack, and recording the duration of the bit error rate exceeding the limit in the inter-satellite link; niche erosion testing means embedding parasitic parameters in the attitude control system, such as forging the sun vector angle θ to deviate by 0.5°, and quantifying the stability decay gradient of the infected subsystem. The stability decay gradient is expressed as the rate of decrease in ecological stability per unit time; energy flow hijacking verification means truncating the battery equalization circuit and redirecting 10% of the charge and discharge power, and measuring the harmonic distortion rate of the multi-power bus.
[0051] Further, the satellite ecological damage score of the satellite ecological early warning group is calculated according to the satellite ecological damage score function, and the satellite ecological damage score function can be expressed as: ; Where represents the satellite ecological damage score, represents the ES deviation weight, represents the offset of the ecological stability of the current data combination, represents the ecological stability benchmark, represents the subsystem association breadth weight, represents the subsystem association breadth, represents the attack feature matching rate weight, represents the attack feature matching rate.
[0052] For example, during the iterative optimization process of a certain data combination, an anomaly is detected. The current ES = 0.41, = 0.65. At this time, is |0.41 - 0.65| = 0.24. The normalized ES deviation is 0.24 / 0.65 ≈ 0.369. Hypergraph analysis shows that this combination affects 4 cross-system links including attitude control, energy, thermal control, and data transmission. Therefore, the subsystem association breadth is , and the parameter momentum wheel speed is abnormal. After DTW matching the historical fault library, the highest similarity is 0.89. Since the satellite is in the orbit transfer maneuver stage, the weights of the satellite ecological damage score function are set as = 0.7, = 0.1, = 0.2. Then at this time, is 0.4965.
[0053] Step S5, generate an intrusion cleaning decision based on the satellite ecological damage score, obtain the intrusion cleaning decision, and the user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision.
[0054] Specifically, perform anomaly grading on the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined that a highly dangerous anomaly has occurred, and a high-risk anomaly cleaning decision is generated. For example, isolate the infected subsystem, reconstruct the security instruction set through instruction redundancy verification, and load the on-board backup parameter image; when the satellite ecological damage score is in the range of [0.6, 0.85], it is determined that a moderately dangerous anomaly has occurred, and a medium-risk anomaly repair decision is generated. For example, deploy a harmonic filter on the power bus and perform mutual information verification on the cross-system correlation parameters; when the satellite ecological damage score is lower than 0.6, it is determined that there is no dangerous anomaly, and a daily maintenance decision is generated.
[0055] Figure 2 The schematic diagram of a satellite telemetry data injection attack anomaly detection system provided by some embodiments of the present application that can implement the idea of the present application is shown.
[0056] Specifically, a satellite telemetry data injection attack anomaly detection system includes: A data acquisition module, which is used to perform multi-source data acquisition on each satellite subsystem, obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data.
[0057] A model construction module, which is used to obtain a preset physical constraint library of satellite telemetry data and construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and the satellite telemetry data.
[0058] An ecological early warning module, which is used to randomly combine the satellite telemetry data to generate an initial satellite ecological early warning group, and calculate the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain the ecological stability result.
[0059] An intrusion verification module, which is used to iteratively reorganize the initial satellite ecological early warning group according to the ecological stability result to obtain a satellite ecological early warning group, and perform ecological intrusion verification on the satellite ecological early warning group to obtain a satellite ecological damage score.
[0060] A decision generation module, which is used to generate an intrusion cleaning decision based on the satellite ecological damage score, obtain the intrusion cleaning decision, and the user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision.
[0061] The specific usage method and function of this embodiment will be described below: First, multi-source data collection is performed on each satellite subsystem to obtain satellite telemetry data, and the satellite telemetry data is preprocessed. Then, a preset physical constraint library of satellite telemetry data is obtained, and a satellite ecological stability model is constructed based on the physical constraint library of satellite telemetry data and the satellite telemetry data. Next, an initial screening of the satellite telemetry data is performed based on the initial satellite data screening mechanism to generate an initial satellite ecological early warning group. The ecological stability of the initial satellite ecological early warning group is calculated based on the satellite ecological stability model to obtain the ecological stability result. Immediately afterwards, a secondary screening of the initial satellite ecological early warning group is performed based on the secondary satellite data screening mechanism and in combination with the ecological stability result to obtain the satellite ecological early warning group, and an ecological invasion verification is performed on the satellite ecological early warning group to obtain the satellite ecological damage score. Finally, an intrusion cleaning decision generation is performed based on the satellite ecological damage score to obtain the intrusion cleaning decision. The user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision. By combining ecological stability with hypergraph screening to capture hidden threats in satellite telemetry data, the threat retrieval efficiency is improved on the premise of ensuring coverage of key risk targets, and the discrimination ability for complex attack patterns is enhanced through ecological invasion verification and satellite ecological damage scoring. Through this method, the efficiency and accuracy of attack anomaly detection in satellite telemetry data can be improved.
[0062] In addition, an embodiment of the present invention also provides an electronic device, including: At least one processor; and a memory communicatively connected to at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method proposed in Embodiment 1 of the present invention.
[0063] The following is a specific introduction to the components of the electronic device: Among them, the processor is the control center of the electronic device, which can be a single processor or a collective term for multiple processing elements. For example, the processor is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement Embodiment 1 of the present invention, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0064] Among them, the processor can execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.
[0065] The memory is used to store the software program for implementing the solution of the present invention and is controlled by a processor for execution. The specific implementation manner can refer to the above method embodiments and will not be elaborated here.
[0066] The memory can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can be integrated with the processor or exist independently and be coupled to the processor through the interface circuit of the electronic device. The embodiments of the present invention do not make specific limitations on this.
[0067] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a limited way (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0068] It should be understood that the term "and / or" in this text is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this text generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship. The specific meaning can be understood by referring to the context before and after.
[0069] It should be understood that in the embodiments of the present invention, the magnitudes of the serial numbers of the above processes do not mean the sequence of execution. The execution sequence of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0070] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for detecting anomalies in satellite telemetry data injection attacks, characterized in that, The method includes: Performing multi-source data collection on each satellite subsystem to obtain satellite telemetry data, and performing data preprocessing on the satellite telemetry data; Obtaining a preset physical constraint library of satellite telemetry data, and constructing a satellite ecological stability model based on the physical constraint library of satellite telemetry data and the satellite telemetry data; Performing a primary screening on the satellite telemetry data based on a primary satellite data screening mechanism to generate an initial satellite ecological warning group, calculating the ecological stability degree of the initial satellite ecological warning group based on the satellite ecological stability model, and obtaining an ecological stability degree result; Performing a secondary screening on the initial satellite ecological warning group based on a secondary satellite data screening mechanism and combining the ecological stability degree result to obtain a satellite ecological warning group, and performing ecological invasion verification on the satellite ecological warning group to obtain a satellite ecological damage score; Generating an intrusion cleaning decision based on the satellite ecological damage score to obtain an intrusion cleaning decision, and a user can perform data cleaning and recovery on the satellite telemetry data based on the intrusion cleaning decision.
2. The anomaly detection method for satellite telemetry data injection attack according to claim 1, characterized in that, The performing a primary screening on the satellite telemetry data based on a primary satellite data screening mechanism to generate an initial satellite ecological warning group includes: Randomly extracting 2 to 5 associated data from the satellite telemetry data based on Latin hypercube sampling, where the associated data represents satellite telemetry data with physical associations among the satellite telemetry data, and combining the 2 to 5 associated data into a random combination data set; Combining the random combination data set with the hypergraph structure included in the satellite ecological stability model to generate an initial satellite ecological warning group.
3. The anomaly detection method for satellite telemetry data injection attack according to claim 1, characterized in that, The calculating the ecological stability degree of the initial satellite ecological warning group based on the satellite ecological stability model and obtaining an ecological stability degree result includes: Calculating the theoretical values of the physical constraint functions included in each data combination in the initial satellite ecological warning group based on the satellite ecological stability model; Performing local ecological stability calculation on each data combination in the initial satellite ecological warning group based on the theoretical values of the physical constraint functions and a local ecological stability function to obtain local ecological stability results, and calculating the ecological stability degree of the data combination based on the local ecological stability results.
4. The anomaly detection method for satellite telemetry data injection attacks according to claim 3, wherein The method further includes: The local ecological stability function is expressed as: ; Among them, represents the local ecological stability corresponding to the j-th physical constraint function in the data combination, represents the ecological stability sensitivity factor and is an integer in [1, 10], represents the relative deviation between the measured value and the theoretical value of the j-th physical constraint function in the data combination.
5. A satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that The performing a secondary screening on the initial satellite ecological warning group based on a secondary satellite data screening mechanism and combining the ecological stability degree result to obtain a satellite ecological warning group, and performing ecological invasion verification on the satellite ecological warning group to obtain a satellite ecological damage score includes: The secondary satellite data screening mechanism includes a high-risk combination primary screening and a high-risk combination fusion screening; The high-risk combination primary screening means excluding the data combinations in the initial satellite ecological warning group whose ecological stability degree exceeds a preset ecological stability threshold, and performing combination quantity guarantee on the initial satellite ecological warning group after the exclusion operation based on a screening guarantee mechanism; The high-risk combination fusion screening means randomly cross-fusing the data combinations in the high-risk combination set based on a fusion constraint strategy to generate a satellite ecological warning candidate set, iteratively optimizing the satellite ecological warning candidate set based on a fusion optimization strategy to obtain an iterative optimization result, and generating a satellite ecological warning group based on the iterative optimization result; Verify the ecological invasion of the satellite ecological early warning group based on the ecological invasion stress test, and calculate the satellite ecological damage score of the satellite ecological early warning group according to the satellite ecological damage scoring function.
6. The anomaly detection method for satellite telemetry data injection attack according to claim 5, wherein The ecological invasion stress test includes: Inject a bionic attack signal with an energy density greater than a preset threshold in the sensitive frequency band of the satellite telemetry data, monitor the number of cross-layer conflicts in the satellite network protocol stack, and record the duration of the bit error rate exceeding the limit in the inter-satellite link; Embed parasitic parameters in the satellite's attitude control system to quantify the stability attenuation gradient, where the stability attenuation gradient is expressed as the rate of decrease in ecological stability per unit time; Truncate the equalization circuit of each satellite subsystem and redirect 10% of the charge-discharge power to measure the harmonic distortion rate of the multi-power bus.
7. The anomaly detection method for satellite telemetry data injection attacks according to claim 1, characterized in that, Generate an intrusion cleaning decision based on the satellite ecological damage score, obtain the intrusion cleaning decision, and the user can perform data cleaning and recovery on the satellite telemetry data based on the intrusion cleaning decision, including: Perform anomaly grading on the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined that a highly dangerous anomaly has occurred, and a high-risk anomaly cleaning decision is generated; When the satellite ecological damage score is in the range of [0.6, 0.85], it is determined that a moderately dangerous anomaly has occurred, and a medium-risk anomaly repair decision is generated; When the satellite ecological damage score is less than 0.6, it is determined that there is no dangerous anomaly.
8. The anomaly detection method for satellite telemetry data injection attack according to claim 1, wherein Obtain the preset physical constraint library of satellite telemetry data, and construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and satellite telemetry data, including: Load the physical constraint relationship from the preset physical constraint library of satellite telemetry data, and organize the physical constraint relationship through a hypergraph structure; Construct a satellite ecological stability model based on the hypergraph structure. The hypergraph structure includes vertices and hyperedges. The vertices of the hypergraph structure represent satellite telemetry data, and the hyperedges of the hypergraph structure represent the physical constraint relationships between satellite telemetry data.
9. The anomaly detection method for satellite telemetry data injection attack according to claim 1, wherein Collect multi-source data for each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data, including: Obtain the operation data of each satellite subsystem in real time, synchronize the time reference of the operation data of each satellite subsystem using the timestamp unification protocol, and balance the relationship between high-precision monitoring and resource consumption through an adaptive sampling frequency adjustment mechanism. Use a noise reduction algorithm to eliminate the physical layer interference during the signal acquisition process; The data preprocessing includes anomaly point detection and elimination and time axis calibration. The time axis calibration is expressed as performing cubic spline interpolation on the operation data of each satellite subsystem for time axis calibration, normalizing the operation data of each satellite subsystem after data preprocessing, and combining the operation data of each satellite subsystem after data preprocessing and data normalization to generate satellite telemetry data.
10. A satellite telemetry data injection attack anomaly detection system, characterized in that, Including: A data acquisition module, which is used to collect multi-source data for each satellite subsystem to obtain satellite telemetry data and perform data preprocessing on the satellite telemetry data; A model construction module, which is used to obtain a preset physical constraint library of satellite telemetry data and construct a satellite ecological stability model based on the physical constraint library of satellite telemetry data and satellite telemetry data; An ecological early warning module, which is used to initially screen satellite telemetry data to generate an initial satellite ecological early warning group, calculate the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model, and obtain the ecological stability result; An intrusion verification module, which is used to perform secondary screening on the initial satellite ecological early warning group according to the ecological stability result to obtain a satellite ecological early warning group, and perform ecological intrusion verification on the satellite ecological early warning group to obtain a satellite ecological damage score; A decision generation module, which is used to generate an intrusion cleaning decision based on the satellite ecological damage score to obtain an intrusion cleaning decision, and the user can perform data cleaning and restoration on the satellite telemetry data based on the intrusion cleaning decision.
Citation Information
Patent Citations
Abnormity detection method and device for satellite telemetering multi-dimensional time series data, medium and product
CN118094425A
Whole-process monitoring method and system for meteorological satellite data
CN118820218A
Satellite measurement and control data anomaly detection and intelligent diagnosis early warning method and system
CN119646586A
Monitoring and alarming method and system for on-orbit abnormity of remote sensing satellite instrument
CN120150795A
Wildfire ignition prediction with swarm neural network ensemble
US20220383102A1
Cited By
Satellite laser communication coarse tracking scene reproduction method and system
CN122119752A