A satellite telemetry data injection attack anomaly detection method and system

By building a satellite ecological stability model and a multi-source data screening mechanism, the detection accuracy and real-time problems of satellite telemetry data under complex attacks are solved, and efficient and accurate attack abnormality detection and cleaning are achieved.

CN120408609BActive Publication Date: 2025-09-02SHANGHAI SHIYAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510907943.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-09-02
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

Existing satellite telemetry data security protection technology is inadequate detection accuracy, poor real-time performance and weak adaptability when facing complex and concealed injection attacks, and cannot effectively deal with increasingly complex threats.

Method used

By collecting and preprocessing satellite telemetry data through multi-source data, a satellite ecological stability model is built, and an initial ecological early warning group is generated using the primary and secondary screening mechanisms, and ecological damage scores are obtained through ecological stability calculation and intrusion verification, and finally an intrusion cleaning decision is generated for data cleaning and recovery.

Benefits of technology

It improves the efficiency and accuracy of attack anomaly detection in satellite telemetry data, can quickly identify and clean high-risk targets, and enhances the ability to identify complex attack patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408609B_ABST
    Figure CN120408609B_ABST
Patent Text Reader

Abstract

The present invention provides a satellite telemetry data injection attack anomaly detection method and system. The method comprises the following steps: performing multi-source data acquisition on each satellite subsystem to obtain satellite telemetry data, obtaining a preset satellite telemetry data physical constraint library, and constructing a satellite ecological stability model in combination with the satellite telemetry data. The satellite telemetry data is initially screened based on a primary satellite data screening mechanism to generate an initial satellite ecological warning group. The ecological stability of the initial satellite ecological warning group is calculated based on the satellite ecological stability model to obtain an ecological stability result. The initial satellite ecological warning group is secondary screened based on a secondary satellite data screening mechanism and the ecological stability result to obtain a satellite ecological warning group. The satellite ecological warning group is then subjected to ecological invasion verification to obtain a satellite ecological damage score. An invasion cleaning decision is generated based on the satellite ecological damage score to obtain an invasion cleaning decision. The method can improve the efficiency and accuracy of attack anomaly detection in satellite telemetry data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of satellite detection technology, and in particular to a satellite telemetry data injection attack anomaly detection method and system. Background Art

[0002] With the rapid development of aerospace technology, satellite systems are playing an increasingly important role in communications, navigation, remote sensing, and other fields. However, satellite telemetry data may be exposed to malicious injection attacks during transmission and processing. Attackers can forge or tamper with data, disrupting the normal operation of satellites and even causing serious security incidents.

[0003] Currently, anomaly detection in satellite telemetry data primarily relies on traditional data validation, statistical analysis, and machine learning methods. However, these methods have significant shortcomings when facing complex and covert injection attacks: on the one hand, traditional validation techniques struggle to identify carefully constructed malicious data; on the other hand, existing machine learning models rely on large amounts of labeled data and have limited generalization capabilities for new attack patterns.

[0004] In summary, the existing satellite telemetry data security protection technology still has problems such as insufficient detection accuracy, poor real-time performance and weak adaptability, and cannot effectively deal with the increasingly complex injection attack threats. Summary of the Invention

[0005] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a method for detecting anomalies in satellite telemetry data injection attacks, the method comprising:

[0006] Perform multi-source data collection on each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data;

[0007] Obtaining a preset satellite telemetry data physical constraint library, and building a satellite ecological stability model based on the satellite telemetry data physical constraint library and the satellite telemetry data;

[0008] Performing a preliminary screening of satellite telemetry data based on the initial satellite data screening mechanism to generate an initial satellite ecological early warning group, and calculating the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain the ecological stability results;

[0009] Based on the secondary satellite data screening mechanism and combined with the ecological stability results, the initial satellite ecological warning group is screened again to obtain the satellite ecological warning group. The satellite ecological warning group is then verified for ecological invasion to obtain the satellite ecological damage score.

[0010] An invasion cleaning decision is generated based on the satellite ecological damage score, and an invasion cleaning decision is obtained. Users can clean and restore satellite telemetry data based on the invasion cleaning decision.

[0011] As a further solution of the present invention, the initial screening of satellite telemetry data based on the initial satellite data screening mechanism to generate an initial satellite ecological warning group includes:

[0012] Randomly extracting 2 to 5 associated data from the satellite telemetry data based on Latin hypercube sampling, where the associated data represents satellite telemetry data with physical associations between the satellite telemetry data, and combining the 2 to 5 associated data into a randomly combined data set;

[0013] The randomly combined data set is combined with a hypergraph structure contained in the satellite ecological stability model to generate an initial satellite ecological early warning group.

[0014] As a further solution of the present invention, the step of calculating the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model and obtaining the ecological stability result includes:

[0015] Calculating theoretical values ​​of physical constraint functions contained in each data combination in the initial satellite ecological warning group based on a satellite ecological stability model;

[0016] Based on the theoretical value of the physical constraint function and the local ecological stability function, local ecological stability calculation is performed on each data combination in the initial satellite ecological warning group to obtain a local ecological stability result, and the ecological stability of the data combination is calculated based on the local ecological stability result.

[0017] As a further embodiment of the present invention, the method further comprises:

[0018] The local ecological stability function is expressed as:

[0019] ;

[0020] in, It is expressed as the local ecological stability corresponding to the j-th physical constraint function in the data combination, Expressed as ecological stability sensitivity factor and is an integer in [1, 10], It is expressed as the relative deviation between the measured value and the theoretical value of the j-th physical constraint function in the data combination.

[0021] As a further solution of the present invention, the secondary satellite data screening mechanism is used to perform secondary screening on the initial satellite ecological warning group in combination with the ecological stability results to obtain the satellite ecological warning group, and the satellite ecological warning group is subjected to ecological invasion verification to obtain the satellite ecological damage score, including:

[0022] The secondary satellite data screening mechanism includes high-risk combination initial screening and high-risk combination fusion screening;

[0023] The high-risk combination initial screening is to eliminate the data combinations whose ecological stability exceeds the preset ecological stability threshold in the initial satellite ecological warning group, and to ensure the minimum number of combinations in the initial satellite ecological warning group after the elimination operation based on the screening guarantee mechanism;

[0024] The high-risk combination fusion screening is represented by randomly cross-fusing the data combinations in the high-risk combination set based on the fusion constraint strategy to generate a satellite ecological warning candidate set, iteratively optimizing the satellite ecological warning candidate set based on the fusion optimization strategy to obtain iterative optimization results, and generating a satellite ecological warning group based on the iterative optimization results;

[0025] Based on the ecological invasion stress test, the satellite ecological early warning group was verified for ecological invasion, and the satellite ecological damage score of the satellite ecological early warning group was calculated according to the satellite ecological damage scoring function.

[0026] As a further embodiment of the present invention, the ecological invasion stress test includes:

[0027] Inject bionic attack signals with energy density greater than a preset threshold into sensitive frequency bands of satellite telemetry data, monitor the number of cross-layer conflicts in the satellite network protocol stack, and record the duration of inter-satellite link bit error rate exceeding the limit;

[0028] Embedding parasitic parameters in the satellite's attitude control system to quantify the stability decay gradient, which is expressed as the rate of ecological stability decline per unit time;

[0029] The equalization circuits of each satellite subsystem are cut off and 10% of the charge and discharge power is redirected to measure the harmonic distortion rate of the multi-power bus.

[0030] As a further solution of the present invention, the generation of an invasion cleaning decision based on the satellite ecological damage score and the acquisition of the invasion cleaning decision, wherein the user can perform data cleaning and recovery on the satellite telemetry data based on the invasion cleaning decision, include:

[0031] Anomaly classification is performed on the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined to be a highly dangerous anomaly, and a high-risk anomaly cleaning decision is generated;

[0032] When the satellite ecological damage score is between [0.6, 0.85], it is determined to be a moderately dangerous anomaly, and a medium-dangerous anomaly repair decision is generated;

[0033] When the satellite ecological damage score is lower than 0.6, it is judged as no dangerous anomaly and a routine maintenance decision is generated.

[0034] As a further solution of the present invention, the step of obtaining a preset physical constraint library of satellite telemetry data and constructing a satellite ecological stability model based on the physical constraint library of satellite telemetry data and satellite telemetry data includes:

[0035] Physical constraint relationships are loaded from a preset satellite telemetry data physical constraint library, and the physical constraint relationships are organized through a hypergraph structure. A satellite ecological stability model is constructed based on the hypergraph structure. The hypergraph structure includes vertices and hyperedges. The vertices of the hypergraph structure are represented by satellite telemetry data, and the hyperedges of the hypergraph structure are represented by physical constraint relationships between satellite telemetry data.

[0036] As a further solution of the present invention, the multi-source data acquisition for each satellite subsystem to obtain satellite telemetry data and the data preprocessing for the satellite telemetry data include:

[0037] Acquire the operating data of each satellite subsystem in real time, synchronize the time base of the operating data of each satellite subsystem using a unified timestamp protocol, and balance the relationship between high-precision monitoring and resource consumption through an adaptive sampling frequency adjustment mechanism. Use a noise reduction algorithm to eliminate physical layer interference during the signal acquisition process.

[0038] The data preprocessing includes outlier detection and elimination and time axis calibration. The time axis calibration is performed by performing cubic spline interpolation on the time axis of the operating data of each satellite subsystem, normalizing the operating data of each satellite subsystem after data preprocessing, and combining the operating data of each satellite subsystem after data preprocessing and data normalization to generate satellite telemetry data.

[0039] In another aspect, an embodiment of the present invention further provides a satellite telemetry data injection attack anomaly detection system, comprising:

[0040] A data acquisition module, the data acquisition module is used to collect multi-source data from each satellite subsystem, obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data;

[0041] A model construction module, the model construction module is used to obtain a preset satellite telemetry data physical constraint library and construct a satellite ecological stability model based on the satellite telemetry data physical constraint library and satellite telemetry data;

[0042] An ecological early warning module, which is used to perform an initial screening of satellite telemetry data to generate an initial satellite ecological early warning group, and calculate the ecological stability of the initial satellite ecological early warning group based on a satellite ecological stability model to obtain an ecological stability result;

[0043] An invasion verification module, which is used to perform a secondary screening of the initial satellite ecological warning group based on the ecological stability results to obtain a satellite ecological warning group, and perform ecological invasion verification on the satellite ecological warning group to obtain a satellite ecological damage score;

[0044] A decision generation module is used to generate an invasion cleaning decision based on the satellite ecological damage score and obtain an invasion cleaning decision. Users can clean and restore satellite telemetry data based on the invasion cleaning decision.

[0045] Based on the above aspects, the embodiment of the present application collects multi-source data from each satellite subsystem, obtains satellite telemetry data, and performs data preprocessing on the satellite telemetry data, obtains a preset satellite telemetry data physical constraint library, establishes a multi-parameter coupling evaluation system based on the physical constraint library, shortens the delay of subsequent evaluation and screening operations, constructs a satellite ecological stability model based on the satellite telemetry data physical constraint library and satellite telemetry data, performs initial screening on the satellite telemetry data based on the initial satellite data screening mechanism, generates an initial satellite ecological early warning group, quickly eliminates invalid low-risk combinations, focuses computing power on remaining suspicious targets, reduces invalid computing power, and ensures the efficiency of high-risk target identification, and calculates the initial satellite ecological stability model based on the satellite ecological stability model. The ecological stability of the early warning group is determined, and the ecological stability results are obtained. The initial satellite ecological early warning group is screened again based on the secondary satellite data screening mechanism and combined with the ecological stability results to obtain the satellite ecological early warning group. Through hypergraph association screening and dynamic sorting of ecological stability, cross-system high-risk targets are accurately captured from a large number of data combinations. The satellite ecological early warning group is verified for ecological invasion to obtain a satellite ecological damage score, thereby improving the accuracy of capturing cross-system high-risk targets. Intrusion cleaning decisions are generated based on the satellite ecological damage score to obtain intrusion cleaning decisions. Users can clean and recover satellite telemetry data based on the intrusion cleaning decisions. This method can improve the efficiency and accuracy of attack anomaly detection in satellite telemetry data. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 The present invention provides a method for detecting anomalies in satellite telemetry data injection attacks.

[0047] Figure 2 Schematic diagram of a satellite telemetry data injection attack anomaly detection system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0048] The present invention will be described in detail below with reference to the accompanying drawings. Figure 1The following is a schematic diagram of the execution flow of a satellite telemetry data injection attack anomaly detection method provided by an embodiment of the present invention. The satellite telemetry data injection attack anomaly detection method is introduced in detail below.

[0049] Step S1: collect multi-source data from each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data.

[0050] Specifically, the operating data of each satellite subsystem is obtained in real time. For example, the operating parameters of satellite core subsystems such as power supply, attitude control, thermal management, and communication are obtained in real time through a distributed sensor network, including key indicators such as battery voltage and current, solar panel output power, gyroscope angular velocity, reaction wheel speed, star sensor data, temperature distribution of key components, signal strength and bit error rate.

[0051] It can be understood that a unified timestamp protocol is used to synchronize the time base of the operating data of each satellite subsystem, and an adaptive sampling frequency adjustment mechanism is used to balance the relationship between high-precision monitoring and resource consumption. The adaptive sampling frequency adjustment mechanism is expressed as dynamically adjusting the sampling rate based on the change gradient of the operating data of each satellite subsystem and the criticality of the mission. When the change rate exceeds the preset threshold or the mission is in a critical stage, the sampling frequency is increased. When resources are tight, the satellite subsystems are coordinated to perform hierarchical frequency reduction. A noise reduction algorithm is used to eliminate the physical layer interference in the signal acquisition process. For example, a noise reduction algorithm based on wavelet transform is applied to remove the high-frequency noise part in the operating data of each satellite subsystem.

[0052] Furthermore, the collected operating data of each satellite subsystem is subjected to outlier detection and elimination, a sliding window algorithm is used to identify and remove outlier data that exceeds the physical constraint range, and the operating data of each satellite subsystem is time-calibrated through a cubic spline interpolation mechanism. The time-axis calibration is represented by dynamically compensating for the clock drift of each sensor to uniformly align the multi-source data to the reference time axis. The operating data of each satellite subsystem after data preprocessing is normalized so that data of different dimensions are converted into a unified dimensionless value in the [0,1] interval. The operating data of each satellite subsystem after data preprocessing and data normalization are combined to generate satellite telemetry data.

[0053] Step S2: obtaining a preset satellite telemetry data physical constraint library, and constructing a satellite ecological stability model based on the satellite telemetry data physical constraint library and the satellite telemetry data.

[0054] It can be understood that the preset satellite telemetry data physical constraint library is a set of mathematical rules based on the principles of satellite dynamics and the physical characteristics of the equipment. It describes the physical coupling laws between the satellite subsystems through predefined physical constraint functions.

[0055] Specifically, physical constraint relationships are loaded from a preset satellite telemetry data physical constraint library, and the physical constraint relationships are organized through a hypergraph structure. A satellite ecological stability model is constructed based on the hypergraph structure. The vertices of the hypergraph structure represent satellite telemetry data, and the hyperedges of the hypergraph structure represent physical constraint relationships between satellite telemetry data. For example, in the coupling relationship between the power supply and thermal control subsystems, a nonlinear functional relationship between battery temperature and charging current is defined; in the attitude control system, a differential equation model of reaction wheel energy consumption and angular acceleration is established.

[0056] It can be understood that a dynamic weight allocation strategy is implemented in the model construction process to adjust the importance weight of each subsystem according to different mission stages. The dynamic weight allocation strategy is expressed as giving the attitude control system the highest weight coefficient in the orbital maneuvering stage, increasing the weight of the communication system in the data transmission stage, and strengthening the monitoring level of the energy system in the shadow period.

[0057] It can be understood that the dynamic weight calculation adopts the eigenvalue analysis method, combining the current task objectives with historical fault data to obtain the optimal allocation plan. For example, for special working conditions such as space radiation and thermal cycle, the allocation weight is dynamically corrected based on the model's built-in environmental compensation module combined with the real-time acquired space environment parameters.

[0058] Step S3: Performing a primary screening of the satellite telemetry data based on the primary satellite data screening mechanism to generate an initial satellite ecological warning group, and calculating the ecological stability of the initial satellite ecological warning group based on the satellite ecological stability model to obtain an ecological stability result.

[0059] In this embodiment, step S3 includes:

[0060] Step S31 : performing a primary screening of satellite telemetry data based on a primary satellite data screening mechanism to generate an initial satellite ecological warning group.

[0061] Specifically, the satellite telemetry data are randomly combined based on a stratified random sampling operation to obtain a randomly combined data set. The stratified random sampling strategy is represented by randomly extracting 2 to 5 associated data through the Latin hypercube sampling technology. The associated data are satellite telemetry data with physical associations between the satellite telemetry data. The random combined data set is combined with the hypergraph structure contained in the satellite ecological stability model to generate an initial satellite ecological warning group.

[0062] It can be understood that the initial satellite ecological warning group generation process implements a triple verification mechanism to constrain the spatial distribution of the initial satellite ecological warning group. The triple verification mechanism is expressed as a mandatory constraint that there is at least one physical constraint path for the data in the initial satellite ecological warning group. The physical constraint path is expressed as a physical constraint function contained in the physical constraint library of satellite telemetry data, and the difference in data magnitude within the initial satellite ecological warning group is limited to within three orders of magnitude to avoid calculation errors due to excessive differences in data magnitude, and at the same time eliminate invalid combinations where the proportion of data from the same subsystem is too high.

[0063] It can be understood that the generation scale of the initial satellite ecological warning group is constrained based on the generation scale adaptive mechanism. The generation scale adaptive mechanism is expressed as the basic generation amount of each batch is 20% of the total amount of associated parameters. When the effective combination rate is lower than 70%, the negative feedback expansion mechanism is triggered to increase the generation amount. The effective combination rate is expressed as the proportion of the number of qualified data combinations that pass the triple verification mechanism in the generated random combination data set, until the physical constraint edge coverage reaches the preset threshold for three consecutive times.

[0064] Step S32: Calculate the ecological stability of the initial satellite ecological warning group based on the satellite ecological stability model to obtain an ecological stability result.

[0065] In this embodiment, step S32 includes:

[0066] Step S32-1: Calculate the local ecological stability of the physical constraint function corresponding to each data combination in the initial satellite ecological warning group based on the satellite ecological stability model.

[0067] Specifically, a physical correlation assessment is performed on the initial satellite ecological warning group based on the satellite ecological stability model. The physical correlation assessment is expressed as calculating the theoretical value of the physical constraint function contained in each data combination in the initial satellite ecological warning group, and performing local ecological stability calculation on the data combination based on the theoretical value of the physical constraint function to obtain a local ecological stability result. The local ecological stability calculation is expressed as calculating the relative deviation between the measured value and the theoretical value of the physical constraint function, and calculating the local ecological stability based on the local ecological stability function. The local ecological stability function can be expressed as:

[0068] ;

[0069] in, It is expressed as the local ecological stability corresponding to the j-th physical constraint function in the data combination, Expressed as ecological stability sensitivity factor and is an integer in [1, 10], It is expressed as the relative deviation between the measured value and the theoretical value of the j-th physical constraint function in the data combination.

[0070] It can be understood that the distribution of the ecological stability sensitivity factor is represented by the distribution of the highly sensitive physical constraint function. In the range of [8, 10], the sensitive physical constraint function is assigned In the range of [4, 7], the allocation of low-sensitivity physical constraint functions Within the range of [1, 3], the highly sensitive physical constraint function is expressed as the physical laws related to core safety, such as the conservation of angular momentum between the attitude control gyroscope and the reaction wheel; the medium-sensitive physical constraint function is expressed as the operating constraints of key equipment, such as the temperature-current relationship of lithium battery charging and discharging; the low-sensitivity physical constraint function is expressed as the influence of environmental factors on satellite telemetry data, such as the coupling relationship between solar radiation intensity and sailboard temperature.

[0071] For example, a data combination is {battery temperature T, charging current I}. The physical constraint function matched to this data combination in the satellite telemetry data physical constraint library is T=f(I)=0.2I²+25, and the measured data of I is 5A. Then the theoretical value of the function of this data combination is expressed as =30℃.

[0072] Step S32-2: Calculate the ecological stability of the data combination based on the local ecological stability of the physical constraint function corresponding to the data combination.

[0073] Specifically, the ecological stability of the data combination within the initial satellite ecological warning group is calculated based on the ecological stability function, which can be expressed as:

[0074] ;

[0075] in, Represents the initial satellite ecological warning group data combination ecological stability, Expressed as ecological stability weight, Represented as a combination of data The local ecological stability corresponding to the j-th physical constraint function in .

[0076] It can be understood that the physical constraint function is assigned an ecological stability weight based on the triple benchmark strategy, which includes a basic weight, a state coefficient, and a historical correction coefficient. The basic weight benchmark is expressed as dividing the physical constraint function into three basic physical constraints: physical laws, device models, and statistical relationships, and assigning basic weights of 1.0, 0.8, and 0.3 to the physical laws, the device models, and the statistical relationships, respectively.

[0077] The state coefficient benchmark is expressed as setting a state coefficient for the basic weight corresponding to the data combination when the device abnormality occurs, for example, multiplying the weight by 0.5, and setting a state coefficient for the basic weight corresponding to the data combination that has just completed data calibration, for example, multiplying the weight by 1.2;

[0078] The historical correction coefficient benchmark indicates that no historical correction coefficient is set for a data combination consisting of data within one month or the historical correction coefficient is set to 1.0, and a historical correction coefficient is set for a data combination consisting of data exceeding one month, for example, a historical correction coefficient of 0.85 is set for a data combination consisting of data from two months ago;

[0079] An ecological stability weight is generated by combining the basic weight, the state coefficient, and the historical correction coefficient. For example, if the physical constraint function matched by a certain data combination corresponds to a battery temperature-current mechanism model, the basic weight of the data combination is 0.8, and a battery alarm occurs at this time, the state coefficient of the data combination is 0.5, and the constituent data of the data combination is data within one month, then the historical correction coefficient of the data combination is 1.0. The basic weight, state coefficient, and historical correction coefficient corresponding to the data combination constitute an ecological stability weight of 0.4.

[0080] Step S4: Based on the secondary satellite data screening mechanism and in combination with the ecological stability results, the initial satellite ecological warning group is screened for the second time to obtain a satellite ecological warning group, and the satellite ecological warning group is verified for ecological invasion to obtain a satellite ecological damage score.

[0081] In this embodiment, step S4 includes:

[0082] Step S41 : performing a secondary screening on the initial satellite ecological warning group based on the secondary satellite data screening mechanism and in combination with the ecological stability result to obtain a satellite ecological warning group.

[0083] Specifically, the secondary satellite data screening mechanism includes initial screening of high-risk combinations and fusion screening of high-risk combinations. The initial screening of high-risk combinations is performed by eliminating data combinations in the initial satellite ecological warning group whose ecological stability exceeds a preset ecological stability threshold. After the data elimination operation, the data combinations in the initial satellite ecological warning group are sorted in ascending order according to ecological stability, and the top 15 percent of the data combinations are output as the high-risk combination set. The minimum number of combinations in the high-risk combination set is guaranteed based on the screening guarantee mechanism.

[0084] It can be understood that the screening and bottom-line guarantee mechanism is expressed as comparing the number of data combinations in the high-risk combination set with the preset bottom-line guarantee threshold. If the number of data combinations in the high-risk combination set is lower than the preset bottom-line guarantee threshold, and the number of remaining data combinations in the initial satellite ecological warning group after data removal and initial screening of high-risk combinations exceeds the difference between the preset bottom-line guarantee threshold and the number of data combinations in the high-risk combination set, then the remaining data combinations in the initial satellite ecological warning group are added to the high-risk combination set; if the number of data combinations in the high-risk combination set is lower than the preset bottom-line guarantee threshold, and the number of remaining data combinations in the initial satellite ecological warning group after data removal and initial screening of high-risk combinations does not exceed the difference between the preset bottom-line guarantee threshold and the number of data combinations in the high-risk combination set, then all remaining data combinations in the initial satellite ecological warning group are added to the high-risk combination set, and the data combinations in the initial satellite ecological warning group that have not undergone data removal and have a sudden drop in ecological stability greater than 30% are forcibly added to the high-risk combination set as high-risk combinations.

[0085] Furthermore, the high-risk combination fusion screening is represented by randomly cross-fusing the data combinations in the high-risk combination set based on the fusion constraint strategy, calculating the ecological stability of the data combination after random cross-fusion, combining the data combination after random cross-fusion with the corresponding ecological stability, generating a satellite ecological warning candidate set, iteratively optimizing the satellite ecological warning candidate set based on the fusion optimization strategy, obtaining the iterative optimization result, and generating a satellite ecological warning group based on the iterative optimization result.

[0086] It can be understood that the fusion constraint strategy is expressed as limiting data exchange to data combinations that belong to the same physical constraint type. For example, if data combinations with physical constraint types of energy and posture are mutually exclusive, then data exchange is prohibited between the two, and the exchangeable parameter set is filtered according to the hyperedges contained in the hypergraph structure.

[0087] It can be understood that the random cross-fusion operation includes three fusion modes: replacement fusion, expansion fusion and splitting fusion. The replacement fusion mode is represented by replacing the data combination with the ecological stability continuously higher than 0.5 with the same-level parameters of the top 10 historical failure rates. The historical failure rate is represented by the proportion of historical failures of the same type as the data combination in the preset historical failure library; expansion fusion adds cross-system parameters to the data combination with no more than 3 types of satellite telemetry data in the data combination and the ecological stability lower than 0.4. The cross-system parameters are represented by satellite telemetry data that are associated with the current data combination. For example, a data combination is {reaction wheel speed, power supply bus current} and the ecological stability is 0.39. The data combination In accordance with the requirements of the expansion fusion mode, bearing temperature data is added to the data combination, and the data combination after expansion fusion is {reaction wheel speed, power supply bus current, bearing temperature}; cracking fusion means splitting the combination judged as having multiple constraint failures into multiple independent sub-units, and performing fusion optimization for each of the multiple sub-units. For example, a data combination is judged as having multiple constraint failures because it violates the attitude maneuvering stability constraint and the thermal control power constraint at the same time. At this time, the cracking fusion mode is triggered, and the data combination is decoupled and split into a maneuvering control sub-unit and a thermal management sub-unit. The corresponding data of similar failure cases in the historical fault library are injected into the maneuvering control sub-unit, and the expansion fusion mode is implemented for the thermal management sub-unit to fuse cross-system parameters.

[0088] It can be understood that the fusion optimization strategy is expressed as always maintaining the five data combinations with the lowest ecological stability unchanged, and at the same time implementing stress testing on the medium-risk combinations. For example, the data combinations with ecological stability within [0.35, 0.45) are divided into medium-risk combinations, and the medium-risk combinations are injected with three simulated attacks of timing delay, magnitude offset and constraint cutoff for stress testing. At the same time, the iterative optimization convergence coefficient is continuously monitored during the iterative optimization process. The iterative optimization convergence coefficient is expressed as the relative value of the ecological stability extremes of the top ten combinations for three consecutive generations. When the iterative optimization convergence coefficient is lower than 0.05 for three consecutive generations, it is judged as strong convergence, and the top 30 data combinations with the lowest ecological stability are output at this time; if the iterative optimization convergence coefficient is lower than 0.08 for five consecutive generations, it is treated as weak convergence, and the top 50 data combinations with the lowest ecological stability are output at this time.

[0089] Step S42: Perform ecological invasion verification on the satellite ecological early warning group to obtain a satellite ecological damage score.

[0090] Specifically, the satellite ecological warning group is verified for ecological invasion based on the ecological invasion stress test. The ecological invasion stress test includes three stress test stages: heterogeneous signal injection, ecological niche erosion test, and energy flow hijacking verification. Heterogeneous signal injection is represented by injecting a bionic attack signal with an energy density greater than a preset threshold in the sensitive frequency band, monitoring the number of cross-layer conflicts in the satellite network protocol stack, and recording the duration of the inter-satellite link bit error rate exceeding the limit; the ecological niche erosion test is represented by embedding parasitic parameters in the attitude control system, such as forging a solar vector angle θ offset of 0.5°, quantifying the stability attenuation gradient of the infected subsystem, and the stability attenuation gradient is represented by the rate of decrease of ecological stability per unit time; the energy flow hijacking verification is represented by cutting off the battery balancing circuit and redirecting 10% of the charging and discharging power, and measuring the harmonic distortion rate of the multi-power bus.

[0091] Furthermore, the satellite ecological damage score of the satellite ecological warning group is calculated according to the satellite ecological damage score function, which can be expressed as:

[0092] ;

[0093] in Expressed as the satellite ecological damage score, Expressed as ES deviation weight, Expressed as the offset of the ecological stability of the current data combination, Expressed as the ecological stability benchmark, Expressed as the subsystem association breadth weight, Expressed as subsystem association breadth, Expressed as the attack feature matching rate weight, Expressed as attack signature matching rate.

[0094] For example, an anomaly is detected during the iterative optimization of a data combination, and the current ES=0.41. =0.65, at this time The normalized ES deviation is |0.41-0.65|=0.24. The hypergraph analysis shows that this combination affects the attitude control, energy, thermal control and data transmission four cross-system links. Therefore, the subsystem association breadth is , and the parameter momentum wheel speed is abnormal. After DTW matching the historical fault library, the highest similarity matched is 0.89. Because the satellite is in the orbit change maneuvering stage, the weight of the satellite ecological damage scoring function is set to =0.7, =0.1, =0.2, then at this time It is 0.4965.

[0095] Step S5: Generate an invasion cleaning decision based on the satellite ecological damage score and obtain the invasion cleaning decision. The user can clean and restore the satellite telemetry data based on the invasion cleaning decision.

[0096] Specifically, an anomaly classification is implemented for the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined that a highly dangerous anomaly has occurred, and a high-risk anomaly cleaning decision is generated, for example, isolating the infected subsystem, reconstructing the safe instruction set through instruction redundancy verification, and loading the onboard backup parameter image; when the satellite ecological damage score is between [0.6, 0.85], it is determined that a moderately dangerous anomaly has occurred, and a medium-risk anomaly repair decision is generated, for example, deploying a harmonic filter on the energy bus and implementing mutual information verification on cross-system related parameters; when the satellite ecological damage score is lower than 0.6, it is determined that there is no dangerous anomaly, and a daily maintenance decision is generated.

[0097] Figure 2 A schematic diagram of a satellite telemetry data injection attack anomaly detection system provided by some embodiments of the present application and capable of implementing the concept of the present application is shown.

[0098] Specifically, a satellite telemetry data injection attack anomaly detection system includes:

[0099] The data acquisition module is used to collect multi-source data from each satellite subsystem, obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data.

[0100] The model construction module is used to obtain a preset satellite telemetry data physical constraint library and construct a satellite ecological stability model based on the satellite telemetry data physical constraint library and satellite telemetry data.

[0101] The ecological early warning module is used to randomly combine satellite telemetry data to generate an initial satellite ecological early warning group, and calculate the ecological stability of the initial satellite ecological early warning group based on a satellite ecological stability model to obtain an ecological stability result.

[0102] The invasion verification module is used to iteratively reorganize the initial satellite ecological warning group according to the ecological stability result to obtain the satellite ecological warning group, and perform ecological invasion verification on the satellite ecological warning group to obtain the satellite ecological damage score.

[0103] A decision generation module is used to generate an invasion cleaning decision based on the satellite ecological damage score and obtain an invasion cleaning decision. Users can clean and restore satellite telemetry data based on the invasion cleaning decision.

[0104] The specific usage and function of this embodiment are described below:

[0105] First, multi-source data collection is performed on each satellite subsystem to obtain satellite telemetry data, and the satellite telemetry data is preprocessed. Then, a preset satellite telemetry data physical constraint library is obtained, and a satellite ecological stability model is constructed based on the satellite telemetry data physical constraint library and the satellite telemetry data. Then, the satellite telemetry data is initially screened based on the primary satellite data screening mechanism to generate an initial satellite ecological early warning group. The ecological stability of the initial satellite ecological early warning group is calculated based on the satellite ecological stability model to obtain the ecological stability result. Then, the initial satellite ecological early warning group is secondary screened based on the secondary satellite data screening mechanism and combined with the ecological stability result to obtain A satellite ecological early warning group is obtained, and ecological invasion verification is performed on the satellite ecological early warning group to obtain a satellite ecological damage score. Finally, an invasion cleaning decision is generated based on the satellite ecological damage score to obtain an invasion cleaning decision. Users can clean and restore satellite telemetry data based on the invasion cleaning decision. By combining ecological stability with hypergraph screening to capture hidden threats in satellite telemetry data, the threat retrieval efficiency is improved while ensuring coverage of key risk targets. The ecological invasion verification and satellite ecological damage score are used to enhance the ability to identify complex attack patterns. This method can improve the efficiency and accuracy of attack anomaly detection in satellite telemetry data.

[0106] In addition, an embodiment of the present invention further provides an electronic device, including:

[0107] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method proposed in the first embodiment of the present invention.

[0108] The following is a detailed introduction to the various components of electronic equipment:

[0109] The term "processor" is the control center of an electronic device and can be a single processor or a collective term for multiple processing elements. For example, the processor can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the first embodiment of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0110] The processor can execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.

[0111] The memory is used to store the software program for executing the solution of the present invention, and the execution is controlled by the processor. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0112] The memory may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory may be integrated with the processor or exist independently and be coupled to the processor via an interface circuit of the electronic device, and this is not specifically limited in the embodiments of the present invention.

[0113] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wireless communication (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer, or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0114] It should be understood that the term "and / or" as used herein simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent the existence of A alone, the existence of both A and B, or the existence of B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the related objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0115] It should be understood that in the embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0116] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A satellite telemetry data injection attack anomaly detection method, characterized in that: The method comprises: Perform multi-source data collection on each satellite subsystem to obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data; Obtaining a preset satellite telemetry data physical constraint library, and building a satellite ecological stability model based on the satellite telemetry data physical constraint library and the satellite telemetry data; Performing a preliminary screening of satellite telemetry data based on the preliminary satellite data screening mechanism to generate an initial satellite ecological early warning group, and calculating the ecological stability of the initial satellite ecological early warning group based on the satellite ecological stability model to obtain the ecological stability results; Calculating theoretical values ​​of physical constraint functions contained in each data combination in the initial satellite ecological warning group based on a satellite ecological stability model; performing local ecological stability calculations on each data combination in the initial satellite ecological early warning group based on the theoretical value of the physical constraint function and the local ecological stability function, obtaining local ecological stability results, and calculating the ecological stability of the data combination based on the local ecological stability results; The local ecological stability function is expressed as: ; in, It is expressed as the local ecological stability corresponding to the j-th physical constraint function in the data combination, Expressed as ecological stability sensitivity factor and is an integer in [1, 10], It is expressed as the relative deviation between the measured value and the theoretical value of the jth physical constraint function in the data combination; Based on the secondary satellite data screening mechanism and combined with the ecological stability results, the initial satellite ecological warning group is screened again to obtain the satellite ecological warning group. The satellite ecological warning group is then verified for ecological invasion to obtain the satellite ecological damage score. An invasion cleaning decision is generated based on the satellite ecological damage score, and an invasion cleaning decision is obtained. Users can clean and restore satellite telemetry data based on the invasion cleaning decision.

2. The satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that: The initial satellite data screening mechanism is used to screen the satellite telemetry data to generate an initial satellite ecological warning group, including: Randomly extracting 2 to 5 associated data from the satellite telemetry data based on Latin hypercube sampling, where the associated data represents satellite telemetry data with physical associations between the satellite telemetry data, and combining the 2 to 5 associated data into a randomly combined data set; The randomly combined data set is combined with a hypergraph structure contained in the satellite ecological stability model to generate an initial satellite ecological early warning group.

3. The satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that: The secondary satellite data screening mechanism is used to screen the initial satellite ecological warning group in combination with the ecological stability results to obtain a satellite ecological warning group, and the satellite ecological warning group is verified for ecological invasion to obtain a satellite ecological damage score, including: The secondary satellite data screening mechanism includes high-risk combination initial screening and high-risk combination fusion screening; The high-risk combination initial screening is to eliminate the data combinations whose ecological stability exceeds the preset ecological stability threshold in the initial satellite ecological warning group, and to ensure the minimum number of combinations in the initial satellite ecological warning group after the elimination operation based on the screening guarantee mechanism; The high-risk combination fusion screening is represented by randomly cross-fusing the data combinations in the high-risk combination set based on the fusion constraint strategy to generate a satellite ecological warning candidate set, iteratively optimizing the satellite ecological warning candidate set based on the fusion optimization strategy to obtain iterative optimization results, and generating a satellite ecological warning group based on the iterative optimization results; Based on the ecological invasion stress test, the satellite ecological early warning group was verified for ecological invasion, and the satellite ecological damage score of the satellite ecological early warning group was calculated according to the satellite ecological damage scoring function.

4. The satellite telemetry data injection attack anomaly detection method according to claim 3, characterized in that: The ecological invasion stress test includes: Inject bionic attack signals with energy density greater than a preset threshold into sensitive frequency bands of satellite telemetry data, monitor the number of cross-layer conflicts in the satellite network protocol stack, and record the duration of inter-satellite link bit error rate exceeding the limit; Embedding parasitic parameters in the satellite's attitude control system to quantify the stability decay gradient, which is expressed as the rate of ecological stability decline per unit time; The equalization circuits of each satellite subsystem are cut off and 10% of the charge and discharge power is redirected to measure the harmonic distortion rate of the multi-power bus.

5. The satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that: The generation of an invasion cleaning decision based on the satellite ecological damage score and the acquisition of the invasion cleaning decision are performed. The user can perform data cleaning and recovery on the satellite telemetry data based on the invasion cleaning decision, including: Anomaly classification is performed on the satellite ecological damage score. When the satellite ecological damage score exceeds 0.85, it is determined to be a highly dangerous anomaly, and a high-risk anomaly cleaning decision is generated; When the satellite ecological damage score is between [0.6, 0.85], it is determined to be a moderately dangerous anomaly, and a medium-dangerous anomaly repair decision is generated; When the satellite ecological damage score is lower than 0.6, it is judged to be non-hazardous anomaly.

6. The satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that: The step of obtaining a preset satellite telemetry data physical constraint library and constructing a satellite ecological stability model based on the satellite telemetry data physical constraint library and the satellite telemetry data includes: Loading physical constraint relationships from a preset satellite telemetry data physical constraint library, and organizing the physical constraint relationships through a hypergraph structure; A satellite ecological stability model is constructed based on the hypergraph structure, wherein the hypergraph structure includes vertices and hyperedges, the vertices of the hypergraph structure are represented as satellite telemetry data, and the hyperedges of the hypergraph structure are represented as physical constraint relationships between satellite telemetry data.

7. The satellite telemetry data injection attack anomaly detection method according to claim 1, characterized in that: The multi-source data acquisition for each satellite subsystem to obtain satellite telemetry data and the data preprocessing for the satellite telemetry data include: Acquire the operating data of each satellite subsystem in real time, synchronize the time base of the operating data of each satellite subsystem using a unified timestamp protocol, and balance the relationship between high-precision monitoring and resource consumption through an adaptive sampling frequency adjustment mechanism. Use a noise reduction algorithm to eliminate physical layer interference during the signal acquisition process. The data preprocessing includes outlier detection and elimination and time axis calibration. The time axis calibration is performed by performing cubic spline interpolation on the time axis of the operating data of each satellite subsystem, normalizing the operating data of each satellite subsystem after data preprocessing, and combining the operating data of each satellite subsystem after data preprocessing and data normalization to generate satellite telemetry data.

8. A satellite telemetry data injection attack anomaly detection system, characterized in that: include: A data acquisition module, the data acquisition module is used to collect multi-source data from each satellite subsystem, obtain satellite telemetry data, and perform data preprocessing on the satellite telemetry data; A model construction module, the model construction module is used to obtain a preset satellite telemetry data physical constraint library and construct a satellite ecological stability model based on the satellite telemetry data physical constraint library and satellite telemetry data; An ecological early warning module, which is used to perform an initial screening of satellite telemetry data to generate an initial satellite ecological early warning group, and calculate the ecological stability of the initial satellite ecological early warning group based on a satellite ecological stability model to obtain an ecological stability result; Calculating theoretical values ​​of physical constraint functions contained in each data combination in the initial satellite ecological warning group based on a satellite ecological stability model; performing local ecological stability calculations on each data combination in the initial satellite ecological early warning group based on the theoretical value of the physical constraint function and the local ecological stability function, obtaining local ecological stability results, and calculating the ecological stability of the data combination based on the local ecological stability results; The local ecological stability function is expressed as: ; in, It is expressed as the local ecological stability corresponding to the j-th physical constraint function in the data combination, Expressed as ecological stability sensitivity factor and is an integer in [1, 10], It is expressed as the relative deviation between the measured value and the theoretical value of the jth physical constraint function in the data combination; An invasion verification module, which is used to perform a secondary screening of the initial satellite ecological warning group based on the ecological stability results to obtain a satellite ecological warning group, and perform ecological invasion verification on the satellite ecological warning group to obtain a satellite ecological damage score; A decision generation module is used to generate an invasion cleaning decision based on the satellite ecological damage score and obtain an invasion cleaning decision. Users can clean and restore satellite telemetry data based on the invasion cleaning decision.

Citation Information

Patent Citations

  • Abnormity detection method and device for satellite telemetering multi-dimensional time series data, medium and product

    CN118094425A

  • Whole-process monitoring method and system for meteorological satellite data

    CN118820218A