Source network load system attack path tracking and security protection method

Through infectious disease model and squirt group algorithm, real-time attack monitoring and path tracking of the source network load system are realized, and protection strategies are optimized, which solves the problems of insufficient monitoring and unreasonable protection in the existing technology, and improves the system's security and emergency response capabilities.

CN120409186AActive Publication Date: 2025-08-01NORTHEAST DIANLI UNIVERSITY
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510351802.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-08-01
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

In the prior art, the source network load system has insufficient monitoring of network attacks, making it difficult to detect attacks in real time, insufficient tracking of attack paths, and insufficient protection strategies, resulting in low recognition rate, high cost, low effect, and undynamic adjustment.

Method used

Using methods based on infectious disease model and squid group algorithm, we collect a variety of data to verify physical information, identify attack behavior, build an attack propagation model, reverse track the attack path, and optimize security protection strategies through the squid group algorithm to select the optimal protection measures.

Benefits of technology

It improves the integrity and real-time nature of attack data, improves attack detection accuracy, identify the source and propagation path of the attack, dynamically adjusts protection strategies, reduces costs, and enhances the security and attack resistance of the source network load system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120409186A_ABST
    Figure CN120409186A_ABST
Patent Text Reader

Abstract

The invention discloses a source network load system attack path tracking and security protection method, which comprises the following steps: firstly, proposing a source network load system network attack monitoring and acquisition technology, and acquiring power generation side, energy storage system, load side, power grid operation, environmental factors and network security data; then, whether the instruction or the collected information is subjected to network attack is identified by checking whether the issued instruction and the uploaded power utilization data are reasonable; and secondly, according to the monitored network attack behavior of the source network load system, based on an infectious disease model mechanism, carrying out reverse tracking on an attacked issuing instruction or uploaded data, and giving a network attack path of the source network load system. And finally, key network nodes are selected in the attack path of the source network load system based on the dogvessel squirt group algorithm to configure security protection measures, the deployment cost and the prediction effect are considered at the same time, a protection scheme is finally output, the source network load system is guided to deploy defense measures at the key nodes of the attack path, and the security of the power grid is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system regulation and control, and particularly to a method for tracking attack paths and security protection of a source-network-load system. Background Art

[0002] Tracking the attack paths of the source-network-load system and proposing security protection strategies can accurately identify the attack sources, analyze the attack propagation paths, and take targeted security protection measures (such as firewalls and isolation devices). This helps improve the network security of the power grid, prevent malicious attacks from affecting power dispatching and load management, and ensure the stable operation of the power system. At the same time, by intelligently optimizing the protection strategy, the protection effect can be maximized on the premise of minimizing costs, the overall defense ability of the power grid can be enhanced, and the security and resilience of the energy system can be strengthened.

[0003] However, the existing methods still have the following deficiencies: 1) Insufficient network attack monitoring, passive defense, and lack of active monitoring: The existing methods mostly rely on post-event analysis such as log analysis and anomaly detection, and it is difficult to detect attacks in real time. Limited monitoring scope: Traditional methods mainly focus on the security of communication networks and lack in-depth monitoring of power physical information (such as power flow and load changes), resulting in a low attack recognition rate. Difficulty in detecting data tampering: Attackers may forge load data, generation instructions, etc., and the existing methods are difficult to distinguish data anomalies from equipment failures. 2) Insufficient attack path tracking, difficult to identify the attack propagation path: The existing network log analysis methods lack effective modeling of the attack propagation chain and cannot track the evolution process of attacks. Insufficient ability to handle complex attacks: In the face of multi-point attacks (such as DDoS attacks and data tampering attacks), traditional methods are difficult to trace the attack sources. 3) The protection strategy is not intelligent enough, and the deployment of protection measures is unreasonable: The existing methods often adopt fixed strategies (such as deploying firewalls across the network), but lack intelligent optimization, resulting in high protection costs and low effects. Unable to dynamically adjust the protection strategy: The influence ranges of different attack types are different, and there is a lack of precise protection strategies for different attack paths.

[0004] Therefore, we have designed a method for tracking attack paths and security protection of a source-network-load system to solve the above problems. Summary of the Invention

[0005] The purpose of the present invention is to solve the disadvantages in the prior art, such as the difficulty in using monitoring data for active monitoring, insufficient attack path tracking, difficulty in identifying the attack propagation path, and unreasonable deployment of protection measures. A method for tracking attack paths and security protection of a source-network-load system based on an epidemic model and a salp swarm algorithm is proposed. An attack monitoring and acquisition technology is proposed to enhance the integrity and real-time performance of attack data. A physical information verification method is constructed to improve the attack detection accuracy, identify command tampering and data deception attacks, and select the optimal security defense strategy under a limited budget.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] A method for tracking the attack path and security protection of a source-network-load system, comprising the following steps:

[0008] Step (1), collecting power generation side data, energy storage system data, load side data, power grid operation data, environmental factors, and network security data;

[0009] Step (2), by verifying whether the issued instructions and the uploaded power consumption data are reasonable, identifying whether the instructions or the collected information have been subject to a cyber attack;

[0010] Step (3), according to the cyber attack behavior of the source-network-load system, reversely tracking the issued instructions or the uploaded data that have been attacked, and giving the attack path of the source-network-load system being subject to a cyber attack;

[0011] Step (4), selecting key network nodes in the attack path of the source-network-load system to configure security protection measures, taking into account both the deployment cost and the expected effect, and obtaining the optimal protection strategy.

[0012] As a further preferred solution of the present invention, in step (1), collecting power generation side data, energy storage system data, load side data, power grid operation data, environmental factors, and network security data, including:

[0013] The real-time active power output of the generator, the real-time reactive power of the generator, the system frequency, the generator switch state, the power generation power scheduling instruction of the generator, the charge and discharge power of the energy storage unit, the state of charge of the energy storage unit, the maximum charge and discharge power of the energy storage unit, the minimum charge and discharge power of the energy storage unit, the energy storage power instruction of the energy storage unit, the active power of the load, the load data, the adjustment instruction of the load, the power of the transmission line, the substation / bus voltage, the power grid loss, the outdoor temperature, the air humidity.

[0014] As a further preferred solution of the present invention, in step (2), the operation process of identifying whether the instructions or the collected information have been subject to a cyber attack by verifying whether the issued instructions and the uploaded power consumption data are reasonable is as follows:

[0015] Step (21), in the instruction verification link, calculating the matching degree of the total system output and the total load through the power balance constraint, and checking whether the power generation, energy storage, and load adjustment instructions meet the physical constraints. If the instructions cause the system power imbalance or exceed the equipment operation range, the system is abnormal;

[0016] Step (22), the device operation constraint verification ensures that the generator output, energy storage charge and discharge, and load regulation comply with the device parameter limits. In the data verification part, the historical load data and environmental factors are used to predict the current load, and it is compared with the uploaded data to determine whether the data has been tampered with. If the actual data deviates from the predicted value by more than the set threshold, it is determined that the data has been attacked;

[0017] Step (23), through comprehensive determination of network attacks, combining the instruction verification and data verification results, identify whether an attack has occurred, and take warning and defense measures;

[0018] As a further preferred solution of the present invention, in step (3), according to the network attack behavior of the source-network-load system, the issued instructions or uploaded data that have been attacked are traced backwards, and the process of giving the path of the source-network-load system suffering from network attacks is as follows:

[0019] Based on the cyber-physical information verification technology for monitoring network attacks in the source-network-load system, after detecting abnormal instructions or abnormal data, the attack behavior is regarded as an infection event, and the propagation path of the attack in the system is analyzed based on the epidemic model to trace the source of the attack;

[0020] Step (31), use cyber-physical information verification to identify the attacked nodes, mark them as infected states, and mark the un-attacked nodes as susceptible states;

[0021] Step (32), construct an attack propagation model, assuming that the attack spreads in the topology of the source-network-load system at a certain propagation rate, and at the same time, the protected or repaired nodes enter the recovery state according to the recovery rate, and trace which node the attack spreads from to the current victim node;

[0022] Step (33), identify the attack source node through reverse path tracing.

[0023] As a further preferred solution of the present invention, in step (4), select key network nodes in the attack path of the source-network-load system to configure security protection measures, taking into account both the deployment cost and the expected effect, and the process of obtaining the optimal protection strategy is as follows:

[0024] Step (41), use the attack path tracing technology based on the epidemic model to determine the attack path and its key nodes, and construct a protection optimization model;

[0025] Step (42), define the protection effect and deployment cost of each node, and take maximizing the protection effect and minimizing the cost as the goal, and constrain the total budget for optimization;

[0026] Step (43), during the optimization process, based on the Salp Swarm Algorithm, by simulating the foraging behavior of the salp swarm, the leader-follower mechanism is adopted to iteratively search for the optimal protection scheme. Based on the leader node, the position is adjusted according to the global best solution, and the follower nodes gradually converge to the optimal protection strategy through group collaborative optimization decision-making;

[0027] Step (44), output the key nodes in the attack path, and deploy the optimal protection strategy on these key nodes.

[0028] Compared with the prior art, the beneficial effects of the present invention are as follows: The method for tracking the attack path and securing the source-network-load system based on the infectious disease model and the Salp Swarm Algorithm of the present invention proposes the monitoring and acquisition of attack data parameters, enhancing the integrity and real-time nature of attack data; through the physical information verification method, the attack detection accuracy is improved, the attack source and propagation path are efficiently located, and through the combination of physical constraints and data analysis, the effective monitoring of instruction tampering, data deception, and communication hijacking is realized, enhancing the security and defense capabilities of the source-network-load system; it can effectively cope with network attacks such as instruction tampering and data deception, enhancing the security and emergency response capabilities of the source-network-load system; the attack path is tracked through the infectious disease model to identify the attack propagation process and trace the attack source; the Salp Swarm Algorithm is used to optimize the security protection strategy, which can dynamically adapt to different attack scenarios, select the optimal protection deployment plan under limited resource constraints, achieve the optimal protection configuration and the best security defense strategy, enhance the security and anti-attack capabilities of the source-network-load system, and ensure the stable operation of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 It is a schematic flowchart of a method for tracking the attack path and securing the source-network-load system proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.

[0031] A method for tracking the attack path and securing the source-network-load system based on the infectious disease model and the Salp Swarm Algorithm (SSA) proposed in this embodiment mainly uses: the source-network-load system network attack monitoring and acquisition technology, the source-network-load system network attack monitoring technology based on physical information verification, the source-network-load system attack path tracking technology of the infectious disease model, and the source-network-load system attack path security protection strategy based on SSA.

[0032] Specifically, the above-mentioned source-network-load system attack path tracking and security protection scheme will be described in detail below. Refer to Figure 1, the method includes the following steps:

[0033] Step (1), propose a monitoring and acquisition technology for data parameters of network attacks on the source-network-load system, and collect power generation side data, energy storage system data, load side data, power grid operation data, environmental factors, network security data, etc. The proposal of the data parameter monitoring and acquisition technology enhances the integrity and real-time nature of attack data.

[0034] Specifically, it includes the real-time active power output of the generator, the real-time reactive power of the generator, the system frequency, the generator switch state, the power generation power scheduling instruction of the generator, the charge / discharge power of the energy storage unit, the state of charge of the energy storage unit, the maximum / minimum charge / discharge power of the energy storage unit, the energy storage power instruction of the energy storage unit, the active power of the load, the load data, the regulation instruction of the load, the power of the transmission line, the substation / bus voltage, the power grid loss, the temperature, the humidity, the meteorological conditions, the instruction source, and the communication state.

[0035] For the above-mentioned power generation side data, energy storage system data, load side data, power grid operation data, and environmental factors collected, as shown in formula (1):

[0036]

[0037] Where: X(t) represents the power generation side data, energy storage system data, load side data, power grid operation data, and environmental factors collected, is the real-time active power output of the i-th generator, is the real-time reactive power of the i-th generator, f(t) is the system frequency, is the generator on / off state, is the power generation power scheduling instruction of generator i at time t, is the charge / discharge power of the j-th energy storage unit, SOC j (t) is the state of charge of the j-th energy storage unit, is the maximum charge / discharge power of the energy storage unit, is the minimum charge / discharge power of the energy storage unit, is the energy storage power instruction of the energy storage unit, is the active power of the k-th load, P L (t-n) is the load data at the past n moments, is the regulation instruction of load k, P line,l (t) is the power on transmission line l, V(t) is the substation / bus voltage, P loss (t) is the power grid loss, T(t) is the outdoor temperature, H(t) is the air humidity, W(t) is the weather state (meteorological conditions).

[0038] Step (2): Propose a network attack behavior monitoring technology for the source-grid-load system based on physical information verification. By verifying whether the issued instructions are reasonable and whether the uploaded power consumption data is reasonable, identify whether the instructions or the collected information have been subject to a network attack, and then realize the monitoring of network attack behaviors in the source-grid-load system.

[0039] Specifically, this technology verifies the rationality of dispatching instructions and the authenticity of user-uploaded data to detect possible network attacks. Based on the physical constraints of the source-grid-load system, multi-level verification is carried out on the dispatching instructions and the data parameters collected by real-time monitoring to ensure the security and stability of the system.

[0040] First, in the instruction verification link, calculate the matching degree between the total system output and the total load through the power balance constraint, and check whether the power generation power instruction, energy storage power instruction, and load regulation instruction conform to the physical constraints. If the instruction causes system power imbalance or exceeds the equipment operation range, there may be abnormalities. The expression of the instruction verification power balance constraint for physical information is:

[0041]

[0042] In the formula, E c (t) is the instruction verification error, is the power generation power dispatching instruction of generator i at time t, G represents the total number of generators, is the energy storage power instruction of the energy storage unit, S represents the total number of energy storage units, is the regulation instruction of load k, L represents the set of transmission lines, P loss (t) is the power grid loss, Θ is the power balance tolerance threshold. If δ C = 0, the instruction may be abnormal (tampered or attacked), if δ c = 1, it means the instruction is normal (not tampered or attacked).

[0043] Secondly, the equipment operation constraint verification ensures that the generator output, energy storage charge and discharge, and load regulation conform to their equipment parameter constraints, and avoids abnormal instructions from affecting the system operation.

[0044] The expression of the generator operation constraint for the equipment operation constraint verification of physical information is:

[0045]

[0046] The expression of the energy storage system operation constraint for the equipment operation constraint verification of physical information is:

[0047]

[0048] In the above formula, △t represents the energy storage operation time, represents the maximum charge of the energy storage, respectively represent the maximum and minimum values of the energy storage SOC.

[0049] The expression of the load regulation constraint for the device operation constraint verification of physical information is:

[0050]

[0051] In the above formula, is the minimum charge-discharge power of the energy storage unit, is the maximum charge-discharge power of the energy storage unit; SOC j (t) is the state of charge of the j-th energy storage unit, is the minimum active power of the k-th load, is the maximum active power of the k-th load.

[0052] If any device instruction exceeds the constraint range, it is marked as an abnormal instruction.

[0053] In the data verification section, the historical load data and environmental factors (temperature, humidity, meteorological conditions) are used to predict the real-time load, and it is compared with the uploaded data to determine whether the data has been tampered with. If the actual data deviates from the predicted value by more than the set threshold, the data may be under attack.

[0054] The expression for the load data verification of physical information, predicting the load based on historical load data and environmental factors and detecting the credibility of its data is:

[0055]

[0056] In the formula, is the predicted real-time load, P L (t - n) is the load data at the past n moments, P L (t) is the load data at time t, X = (T(t), H(t), W(t)) is the environmental factor, T(t) is the outdoor temperature, H(t) is the air humidity, W(t) is the weather condition, and f(·) is the trained load prediction model (LightGBM, LSTM, etc. can be used).

[0057] The comprehensive judgment expression for cyber attacks on physical information is:

[0058]

[0059] In the formula, if δ D = 0, it means the load data is abnormal and may be tampered with. If δ attack = 1, the system may be under cyber attack, and δ attack = 0 indicates that the system is not under cyber attack;

[0060] Finally, through comprehensive judgment of network attacks, combined with the results of instruction verification and data verification, it is possible to identify whether an attack has occurred and take warning and defense measures. This technology combines physical constraints and data analysis to effectively monitor instruction tampering, data deception, and communication hijacking, improving the security and defense capabilities of the source-network-load system.

[0061] Step (3), in this step, a technique for tracing the attack path of the source-network-load system based on the epidemic model is proposed. According to the network attack behaviors (instruction tampering, data deception, and communication hijacking) of the source-network-load system detected in the previous step, based on the mechanism of the epidemic model, the issued instructions or uploaded data under attack are traced backward to give the attack path of the source-network-load system under network attack.

[0062] The technique for tracing the attack path of the source-network-load system based on the epidemic model is a method for backward tracing of the network attack path using the mechanism of epidemic transmission. This technology combines the network attack monitoring technology of the source-network-load system based on physical information verification. After detecting abnormal instructions or abnormal data, the attack behavior is regarded as an "infection event", and the propagation path of the attack in the system is analyzed based on the epidemic model (such as the SIR model) to trace the source of the attack. Specifically as follows:

[0063] First, use physical information verification to identify the attacked nodes and mark them as the infected state (Infected), while the un-attacked nodes are marked as the susceptible state (Susceptible).

[0064] Set variables consistent with the network attack detection technology of the source-network-load system based on physical information verification and introduce network attack monitoring variables, variables related to the epidemic model (system node status, transmission parameters, network topology variables), as shown in formula (8); the physical information verification detection attack model is as shown in formula (9), and the initial infection state model is set as shown in formulas (10) and (11). Formula (10) sets the attacked node as the initial infected node, and formula (11) is the formula for the susceptible node state.

[0065]

[0066] S n (0) = 1 - I n (0)(11)

[0067] In the above formula, X attack (t) is the attack monitoring sample data, δ attack represents whether an attack is detected (1: there is an attack, 0: no attack), δ C is the instruction verification result (1: normal, 0: abnormal), δ D is the data verification result (1: normal, 0: abnormal), E C(t) is the instruction verification error, are the power data of power generation, energy storage, and load respectively, S n (t) is the susceptible state: the nodes of the source-network-load system that have not been attacked, indicating the probability that node n is in the susceptible state; I n (t) is the infected state, that is, the nodes of the source-network-load system that have been attacked, indicating the probability that node n is attacked at time t. R n (t) is the recovered state: the repaired nodes, β is the propagation rate, that is, the probability that the attack spreads from one node to another node, γ is the recovery rate, that is, the probability that the attacked node returns to normal, A mn represents the adjacency matrix between node m and node n (1: connected, 0: not connected).

[0068] Then, construct an attack propagation model. Assume that the attack spreads in the topological structure of the source-network-load system at a certain propagation rate (β), and at the same time, the protected or repaired nodes enter the recovered state (Recovered) at the recovery rate (γ). The expression of the attack propagation model is shown in formulas (12)-(14):

[0069]

[0070] In the above formula, the attack propagation rate β depends on the number of attacked neighbor nodes The recovery rate γ depends on the system defense mechanism. If a certain node n becomes infected at a certain time t (that is, I n (t)>0), it means that the attack spreads from the adjacent node m to node n.

[0071] The expression for calculating the propagation attack path model is shown in formula (15). The attack propagation path consists of the infected nodes. The expression for the reverse tracking attack source model is shown in formula (16). Assume that T is the time when the attack is detected, then the attack source node n0 satisfies this condition. From formula (16), it can be obtained that the reverse tracking attack source model can also be shown as formula (17).

[0072]

[0073] P=(n0,n1,n2,...,n T ) (17)

[0074] In the above formula, P attack-path represents the calculated attack path. P=(n0,n1,n2,...,n T ) is the attack path, representing the attack source set; n represents the traced attack source. The initial infection state I of the attack source node n0 n (0)=1, which is the node with the longest infection time and the shortest attack path during the entire infection process.

[0075] Finally, through reverse path tracing, the source node of the attack is identified, and the attack propagation path is reconstructed, providing a basis for attack traceability and defense strategies. This method can effectively cope with network attacks such as instruction tampering and data deception, and improve the security and emergency response capabilities of the source-network-load system.

[0076] Step (4), in this step, a security protection strategy for the attack path of the source-network-load system based on the Salp Swarm Algorithm (SSA) is proposed. Key network nodes are selected in the attack path of the source-network-load system to configure security protection measures, such as installing firewalls and isolation devices, while taking into account the deployment cost and expected effect.

[0077] First, use the attack path tracing technology based on the epidemic model to determine the attack path P and its key nodes, construct a protection optimization model, and define the protection effect E n and deployment cost C n of each node, and with the goal of maximizing the protection effect and minimizing the cost, constrain the total budget B to form an optimization problem; the expression of the protection optimization model is as follows:

[0078]

[0079] In the formula, P=(n0,n1,n2,...,n T ) is the attack path, from the tracking result of the epidemic model, I n (t) is the probability that node n is attacked at time t, S n (t) is the probability that node n is in a susceptible state, A mn is the adjacency matrix (1: connected, 0: not connected), x n is whether to deploy security protection measures at node n (1: deploy, 0: not deploy), C n is the cost of deploying protection measures at node n, E n is the expected protection effect of deploying protection measures at node n, B is the total budget constraint, λ is the protection effect weight coefficient, is the protection strategy of the i-th salp individual at time t (i.e., the selected security protection node for deployment), is the objective function, representing the total protection effect of this strategy, is the current optimal protection strategy.

[0080] Select key nodes in the attack path to deploy security protection measures to maximize the protection effect, and the objective function considering the cost constraint is shown in formula (19), and the constraint conditions are shown in formula (20):

[0081]

[0082] In the above formula: λ is the trade-off between the protection effect and the cost, that is, the protection effect weight coefficient, E n x n represents the protection effect, and C n x n represents the protection cost.

[0083] During the optimization process, the salp swarm algorithm iteratively searches for the optimal protection plan by simulating the foraging behavior of the salp swarm and adopting the leader-follower mechanism. The leader node adjusts its position according to the global best solution, while the follower nodes gradually converge to the optimal protection strategy through group collaborative optimization decisions.

[0084] The initial salp swarm model expression based on the salp swarm algorithm is shown in formula (21), initializing M candidate solutions (individuals), and each individual represents a set of protection strategies.

[0085]

[0086] In the formula: is randomly initialized between [0,1] and undergoes binary processing (such as sigmoid transformation).

[0087] Based on the salp swarm algorithm, the individual positions are updated using formulas (22)-(23), and the leader-follower mechanism is used to update the positions.

[0088]

[0089] In the formula: is the protection strategy of the i-th salp individual at time t (i.e., the selected security protection node to be deployed), c1 is a random factor that controls the search range. is the protection strategy of the 1st salp individual at time t, is the protection strategy of the best salp individual in the current iteration at time t-1, is the protection strategy of the i-th salp individual at time t-1, is the protection strategy of the (i-1)-th salp individual at time t-1.

[0090] The calculation objective function based on the salp swarm algorithm is shown in the following formula:

[0091]

[0092] In the formula: is the protection strategy of the i-th salp individual at time t (i.e., the selected security protection node to be deployed), is the objective function, representing the total protection effect of this strategy, λ is the trade-off between the protection effect and the cost, that is, the protection effect weight coefficient, E nThe expected protection effect of deploying protection measures at node n Whether to deploy security protection measures at node n at time t (1: deploy, 0: not deploy), C n The cost of deploying protection measures at node n

[0093] The optimal solution based on the salp swarm algorithm is shown as follows

[0094]

[0095] In the formula is the current optimal protection strategy is the protection strategy of the i-th salp individual at time t (i.e., the selected security protection node for deployment) is the objective function, representing the total protection effect of this strategy. When the algorithm converges or reaches the maximum number of iterations, the optimal protection strategy is output

[0096] Finally, the key nodes in the attack path are output, and the optimal protection strategy of deploying firewalls, isolation devices or other security measures on these key nodes is used to reduce the risk of attack propagation. This strategy can dynamically adapt to different attack scenarios, achieve the optimal protection configuration under limited resource constraints, improve the security and anti-attack ability of the source-network-load system, and ensure the stable operation of the power grid

[0097] If the attack path is long, the salp swarm algorithm preferentially selects key nodes with greater propagation impact (such as high-degree nodes) to deploy protection measures. If the budget is low, the salp swarm algorithm balances the protection effect and cost and selects the optimal configuration scheme within the limited budget. Finally, the protection scheme is output to guide the source-network-load system to deploy firewalls, isolation devices, etc. at the key nodes of the attack path to improve network security

[0098] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution of the present invention and its inventive concept, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention

Claims

1. A method for tracking attack paths and security protection of a source-network-load system, characterized in that, Including the following steps: Step (1), collect power generation side data, energy storage system data, load side data, power grid operation data, environmental factors, and network security data; Step (2), identify whether the issued instruction or the collected information has been cyber-attacked by verifying whether the issued instruction and the uploaded power consumption data are reasonable; Step (3), according to the cyber-attack behavior of the source-network-load system, reverse-track the attacked issued instruction or uploaded data, and give the path of the source-network-load system being cyber-attacked; Step (4), select key network nodes in the source-network-load system attack path to configure security protection measures, taking into account the deployment cost and expected effect, and obtain the optimal protection strategy.

2. The method for tracing the attack path and security protection of a source-network-load system according to claim 1, wherein In step (1), collecting power generation side data, energy storage system data, load side data, power grid operation data, environmental factors, and network security data includes: The real-time active power output of the generator, the real-time reactive power of the generator, the system frequency, the generator switch state, the power generation power scheduling instruction of the generator, the charge and discharge power of the energy storage unit, the state of charge of the energy storage unit, the maximum charge and discharge power of the energy storage unit, the minimum charge and discharge power of the energy storage unit, the energy storage power instruction of the energy storage unit, the active power of the load, the load data, the regulation instruction of the load, the power of the transmission line, the substation / bus voltage, the power grid loss, the outdoor temperature, and the air humidity.

3. A source-network-load system attack path tracing and security protection method according to claim 1, characterized in that In step (2), the operation process of identifying whether the issued instruction or the collected information has been cyber-attacked by verifying whether the issued instruction and the uploaded power consumption data are reasonable is as follows: Step (21), in the instruction verification link, calculate the matching degree between the total system output and the total load through power balance constraints, and check whether the power generation, energy storage, and load regulation instructions meet the physical constraints. If the instruction causes system power imbalance or exceeds the equipment operation range, the system is abnormal; Step (22), the equipment operation constraint verification ensures that the generator output, energy storage charge and discharge, and load regulation meet the equipment parameter limits. In the data verification part, use historical load data and environmental factors to predict the current load, and compare it with the uploaded data to determine whether the data has been tampered with. If the actual data deviates from the predicted value by more than the set threshold, it is determined that the data has been attacked; Step (23), through comprehensive cyber-attack determination, combine the instruction verification and data verification results, identify whether an attack has occurred, and take warning and defense measures.

4. A method for tracing the attack path and security protection of a source-network-load system according to claim 1, characterized in that, In step (3), the process of reverse-tracking the attacked issued instruction or uploaded data according to the cyber-attack behavior of the source-network-load system and giving the path of the source-network-load system being cyber-attacked is as follows: Based on the cyber-attack monitoring technology of the source-network-load system with physical information verification, after detecting abnormal instructions or abnormal data, regard the attack behavior as an infection event, and analyze the propagation path of the attack in the system based on the infectious disease model to trace the attack source; Step (31), use physical information verification to identify the attacked nodes, mark them as infected states, and mark the non-attacked nodes as susceptible states; Step (32): Construct an attack propagation model. Assume that the attack spreads in the topological structure of the source network-load system at a certain propagation rate, and at the same time, the protected or repaired nodes enter the recovery state at the recovery rate, and trace which node the attack spreads from to the current victim node; Step (33): Identify the attack source node through reverse path tracing.

5. The method for tracing the attack path and security protection of a source-network-load system according to claim 1, characterized in that Step (4): Select key network nodes in the attack path of the source network-load system to configure security protection measures, taking into account both the deployment cost and the expected effect. The process of obtaining the optimal protection strategy is as follows: Step (41): Use the attack path tracing technology based on the epidemic model to determine the attack path and its key nodes, and construct a protection optimization model; Step (42): Define the protection effect and deployment cost of each node, and optimize with the goal of maximizing the protection effect and minimizing the cost, while restricting the total budget; Step (43): In the optimization process, based on the salp swarm algorithm, by simulating the foraging behavior of the salp swarm, adopt the leader-follower mechanism to iteratively search for the optimal protection scheme. Based on the leader node, adjust the position according to the global best solution, and the follower nodes make group collaborative optimization decisions to gradually converge to the optimal protection strategy; Step (44): Output the key nodes in the attack path, and deploy the optimal protection strategy on these key nodes.

Citation Information

Patent Citations

  • Priority-considered multi-level backup blocking method for attack exception of an industrial control system

    CN109756478A

  • Power grid reinforcement method for coping with information physical attack

    CN116646913A

  • Method and system for detecting cross-site attack

    CN117176405A

  • Attack path prediction method and device based on distributed energy system

    CN117579398A

  • Importance sketching of influence dynamics in massive-scale networks

    US20210142424A1