Power system fault identification method under network attack and terminal equipment
By constructing a power system fault identification method and combining network attack criteria and correction mechanisms, it can identify and correct faults caused by network attacks, and solve the security and stability problems of the power system in complex network environments, and achieve rapid response and fault correction for network attacks.
Patent Information
- Application Number
- CN202510165979.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-08-05
AI Technical Summary
The existing power system security and stability control systems are difficult to effectively identify and deal with complex and changeable network attacks, resulting in increased risk of power grid instability or even large-scale power outages.
A power system fault identification method is constructed under network attacks. By collecting power system voltage, current and switching signals, combining the fault criterion and correction mechanism under network attacks, it can identify single-phase instantaneous faults, single-phase permanent faults, three-phase short-circuit faults, etc., to achieve rapid response and fault correction to network attacks.
It improves the protection capabilities of the stable system in complex network environments, ensures the safe and stable operation of the power system, can quickly identify and respond to network attacks, and reduces extreme risks.
Smart Images

Figure CN120433951A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system security and stability control, and in particular to a method and terminal equipment for identifying power system faults under network attacks. Background Art
[0002] Due to the deep integration of power systems and information networks, power infrastructure faces complex and diverse cybersecurity threats. Cyberattack methods are constantly evolving. Malicious actors not only pose threats to power systems by stealing data and tampering with information, but can also physically damage them by controlling, interfering with, or disrupting the normal operation of power equipment. Methods such as forged data injection, denial of service attacks, and remote control can cause serious failures in key grid equipment such as lines and transformers, leading to grid instability and even large-scale power outages. Faced with the huge challenges posed by cyberattacks, traditional safety and stability control systems mainly rely on preset criteria and failure modes, making it difficult to effectively identify and respond to complex and changing cyberattack scenarios. Therefore, there is an urgent need to construct a cyberattack fault identification method for safety and stability systems to enhance their ability to protect against cyberattacks and ensure the safe and stable operation of power systems in complex network environments. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a method and terminal equipment for identifying power system faults under network attacks in response to the shortcomings of the existing technology, thereby improving the protection capability of the security system against network attacks and ensuring the safe and stable operation of the power system in a complex network environment.
[0004] To solve the above technical problems, the technical solution adopted by the present invention is: a method for identifying power system faults under network attacks, comprising the following steps:
[0005] S1, collect power system voltage, current and switch signal;
[0006] If at least one phase current increases, at least one phase voltage decreases, there is a phase trip signal, and within the specified waiting time T d If there is no other phase tripping signal, it is determined that a single-phase instantaneous fault occurs in the power system;
[0007] If at least one phase current increases, at least one phase voltage decreases, there are two phase trip signals, and the time difference between the two phase trip signals is greater than the reclosing time T c , it is determined that a single-phase permanent fault occurs in the power system;
[0008] Based on the determination of single-phase instantaneous fault of the safety device, if the reclosing time T c If a three-phase trip signal appears, it is determined that a conversion fault has occurred in the power system, that is, a single-phase to phase fault;
[0009] If a three-phase trip signal or a change in the position contacts of the three-phase circuit breaker appears simultaneously after the safety device is activated, and the three-phase voltages all decrease by the set thresholds and the three-phase currents all increase by the set thresholds, it is determined that a three-phase short circuit fault has occurred in the power system;
[0010] S2. Perform fault correction under network attack;
[0011]
[0012]
[0013]
[0014]
[0015] Among them, X(t) is the output result of the attack behavior, IJA is the information blocking attack, N Ir is the number of phases of current rise, N Ud is the number of phases with voltage drop, P(t) is the correction result, SPTF is a single-phase instantaneous fault, SPPF is a single-phase permanent fault, 3TWJ is a three-phase trip signal, CF is a conversion fault, T is the delay time, T C is the reclosing time, IDA is the information delay attack, TWJ is the single-phase tripping signal, T(i) twj -T(i-1) twj is the time difference between single-phase tripping signals, TPSCF is a two-phase short-circuit fault, Represents existence.
[0016] The method of the present invention not only enables the stability device to determine normal fault conditions, but also can identify network attacks and respond quickly and accurately when the system is attacked by a network attack, thereby improving the extreme risk early warning capability of the power system and ensuring the safe and stable operation of the power system in a complex network environment.
[0017] The information delay attack meets the following conditions:
[0018] or
[0019] Among them, M T and M T-1 is the time between adjacent states of SV message, η is the system delay coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and It is the time between adjacent frames of the GOOSE message, and M represents the type of the message itself.
[0020] The information blocking attack meets the following conditions:
[0021] or
[0022] Among them, M T and M T-1 is the time between adjacent states of SV messages, κ is the system congestion coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and It is the time between adjacent frames of the GOOSE message.
[0023] The set threshold is 10%.
[0024] Power system fault types also include:
[0025] If the main transformer or unit is shut down more than twice, and the interval between shut-downs is within the scheduled shut-down time range; or the unit is shut down more than twice by remote control, and the interval between shut-downs exceeds the reclosing time; or the line shut-down signal or line blocking signal is detected more than twice, and the shut-down time exceeds the reclosing time, and there is no sudden change in current or voltage before the first shut-down, then the power system is judged to have a frequent breaking fault;
[0026] If the change in the three-phase negative sequence voltage component of the transformer exceeds the threshold or the transformer power change exceeds the threshold, and there is no circuit breaker trip signal for the transformer, it is determined that a controllable load attack fault has occurred in the power system;
[0027] If a traditional fault occurs within 1 second and a malicious remote control attack occurs at the same time, the power system is determined to have a reclosing refusal attack fault; the traditional faults include instantaneous faults, permanent faults, three-phase faults, two-phase faults, single-phase faults, and conversion faults.
[0028] As an inventive concept, the present invention also provides a terminal device, including a memory, a processor, and a computer program stored in the memory; the processor executes the computer program to implement the steps of the above method.
[0029] As an inventive concept, the present invention also provides a computer-readable storage medium having a computer program / instruction stored thereon; the computer program / instruction implements the steps of the above method when executed by a processor.
[0030] As an inventive concept, the present invention also provides a computer program product, comprising a computer program / instruction; when the computer program / instruction is executed by a processor, the steps of the above method are implemented.
[0031] Compared with the existing technology, the beneficial effects of the present invention are: the fault identification method of the present invention makes up for the shortcomings of the security system in identifying network attacks, can effectively combine the specific business of the security system for personalized settings, has good closed-loop processing capabilities in the face of network attacks, and realizes the identification of network attack faults, which is of great significance to the safe, stable and reliable operation of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 This is the overall flow chart of the power system fault identification method under cyber attack;
[0033] Figure 2 It is a flowchart of the fault correction procedure under network attack;
[0034] Figure 3 It is a diagram of the network attack fault identification system;
[0035] Figure 4 It is the structure diagram of the startup judgment module;
[0036] Figure 5 This is the structure diagram of the logic judgment module. DETAILED DESCRIPTION
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0038] Example 1
[0039] Figure 1 The network attack fault identification method and system overall flow chart provided by the embodiment of the present invention are as follows:
[0040] Step S1: Construct the basic fault types to achieve preliminary fault diagnosis.
[0041] Step S2: Construct a new type of network attack fault criterion to achieve intelligent fault identification.
[0042] Step S3: Build a malicious attack behavior detection model to perform high-precision identification and early warning, use the identification results as input conditions for network attack faults, and achieve in-depth diagnosis of network attack faults.
[0043] Step S4: Based on the normal fault in step S1, driven by the fault event and combined with the malicious attack behavior detection model in step S3, perform reliability assessment and correction of stable faults under network attacks.
[0044] Furthermore, the specific execution method of step S1 is as follows:
[0045] Step S1-1: Construct a basic fault identification model for the safety and stability device, and perform basic fault type judgment on the safety and stability device.
[0046] Specific basic faults include: instantaneous faults, permanent faults, three-phase faults, two-phase faults, single-phase faults, and conversion faults.
[0047] The targets can be divided into three categories: lines, main transformers, and generator sets. Each of these types of faults can cause basic phase-to-phase faults. Main transformers and generator sets do not distinguish between phases. For lines, for example, the following basic faults are present: single-phase instantaneous ground fault, single-phase permanent fault, conversion fault, two-phase short circuit fault, three-phase short circuit fault, instantaneous fault on the same phase of a double-circuit line, permanent fault on the same phase of a double-circuit line, permanent fault on the opposite phase of a double-circuit line, and instantaneous fault on the opposite phase of a double-circuit line. The safety and stability device identifies these basic faults by collecting voltage, current, and switching signals through its acquisition unit.
[0048] Furthermore, the specific execution method of step S2 is as follows:
[0049] Step S2-1: Add new fault criteria, including frequent breaking fault type criteria, controllable load attack fault criteria, and reclosing refusal attack fault criteria.
[0050] The specific criteria are as follows:
[0051] (1) Frequent interruption fault type judgment: There are multiple criteria for frequent interruption fault type judgment. The first is that the main transformer or unit is detected to be shut down for 2 or more times, and the shut-down interval is within the shut-down time range of the maintenance plan. The second is that remote control shut-down is detected for more than 2 times, and the shut-down interval exceeds the reclosing time. The third is that line shut-down signals or line locking signals are detected for more than 2 times, and the shut-down time exceeds the reclosing time, and there is no sudden change in current and voltage before the first shut-down.
[0052] (2) Controllable load attack fault judgment criteria: If a large number of loads are maliciously controlled and switched on and off simultaneously or frequently, or if there is malicious peak load regulation by reverse control, it will cause an impact on the power grid. For this type of controllable load attack, the judgment criteria are that the change in the three-phase negative sequence voltage component of the transformer exceeds the threshold or the change in the transformer power exceeds the threshold, and at the same time, there is no transformer circuit breaker trip signal.
[0053] (3) Reclosing refusal attack fault criterion: a traditional fault occurs within 1 second and a malicious remote control attack occurs at the same time.
[0054] Furthermore, the specific execution method of step S3 is as follows:
[0055] Step S3-1: Based on the network detection results, network attack types are pre-classified into information delay, information jam, data tampering, and malicious remote control. Data tampering and malicious remote control are common attacks in power systems. Information delay and information jam can be used directly to determine faults caused by these attacks, while data tampering and malicious remote control are themselves faults.
[0056] Step S3-2: Construct a malicious attack behavior detection model to detect whether there is a network attack and the type of attack. The specific detection model is as follows:
[0057] (1) Information delay attack behavior occurs when the following conditions are met:
[0058] or
[0059] Among them, M T and M T-1 is the time between adjacent states of SV message, η is the system delay coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and The value of K depends on the type of message.
[0060] (2) Information blocking attacks are those that meet the following requirements:
[0061] or
[0062] Among them, M T and M T-1 is the time between adjacent states of SV messages, κ is the system congestion coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and The value of K depends on the type of message.
[0063] (3) An information tampering attack occurs when the following abnormal conditions are met:
[0064]
[0065] Where P is 104 message, L real (P) is the theoretical length of the message, F TYP (P) is the value of the type identification field of the message, F COT The reason for the telemetry message transmission (the reasons are 01, 02, 03, 20), F IOA (P) is the information body address of the telemetry message, FSPI (P) is the single-point telesignaling status bit of the telesignaling message, F SRS (P) is the dual-point telesignaling status bit of the telesignaling message.
[0066] (3) Malicious remote control attacks occur when the following conditions are met:
[0067]
[0068] A(P) is the remote control logic timing, P rk1 ,P rk2 ,P rk3 ,P rk4 They are remote control selection, remote control selection confirmation, remote control execution, and remote control execution confirmation. T is the statistical time, M RCV is the remote control command flag value, M RTV is the telemetry message flag value, M RIV is the remote signal message flag value, η CMAX is the maximum value of remote control ratio within the statistical time, λ is the remote control frequency coefficient, N S is the number of circuit breakers.
[0069] Step S3-3: Based on the detection result of step S3-2, further match the corresponding network attack fault and output alarm information.
[0070] Furthermore, the specific execution method of step S4 is as follows:
[0071] Step S4-1: Collect analog and switch quantities to determine basic faults.
[0072] The specific basic fault judgment is as follows:
[0073] S4-1-1: Collect voltage, current and switch signals. If at least one phase current increases, at least one phase voltage decreases, or there is a phase trip signal, and within the specified waiting time T d If there is no other phase tripping signal, the safety device will judge it as a single-phase instantaneous fault if the above conditions are met.
[0074] S4-1-2: Collect voltage, current and switch signals. If at least one phase current increases, at least one phase voltage decreases, there are two phase trip signals, and the time difference between the two phase trip signals is greater than the reclosing time T c If the above conditions are met, the safety device will judge it as a single-phase permanent fault.
[0075] S4-1-3: Collect voltage, current and switch signals, and judge the single momentary fault as the fault that does not exceed the reclosing time T c A three-phase tripping signal appears again, which satisfies the above safety device's judgment that it is a conversion fault (single-phase to phase fault).
[0076] S4-1-4: Collect voltage, current and switch signals. After the device is started, three-phase trip signals or three-phase circuit breaker position contacts change simultaneously, and the three-phase voltages suddenly drop and the three-phase currents suddenly increase. If the above conditions are met, the safety device will determine that it is a three-phase short circuit fault.
[0077] Step S4-2: Collect analog and switch quantities, read the malicious attack behavior detection model results to evaluate the reliability of the fault, and then perform fault correction under network attacks.
[0078] Fault correction block diagram as follows Figure 2 , the specific reliability assessment and correction model is as follows:
[0079] (1)
[0080] Where X(t) is the output result of the attack behavior, IJA is the information blocking attack, N Ir Current rising phase number, N Ud is the phase number of voltage drop, P(t) is the correction result, and SPTF is the single-phase transient fault.
[0081] To further explain, for a single-phase instantaneous fault, if a network attack causes the trip signal to be lost, the safety device will determine that there is no fault. In this case, a misjudgment will occur. That is, if a network attack causes the trip signal to be lost, a single-phase instantaneous fault will be misjudged, and the safety device will then determine that there is no fault.
[0082] (2)
[0083] Where X(t) is the output result of the attack behavior, IJA is the information blocking attack, N Ir Current rising phase number, N Ud is the number of phases with voltage drop, P(t) is the correction result, SPTF is the single-phase transient fault, and SPPF is the single-phase permanent fault.
[0084] To further explain, for a single-phase permanent fault, if a cyberattack causes the tripping signal to be lost, resulting in the loss of the tripping signal on one phase, or even the loss of the tripping signals on both phases, the safety device will identify it as a single-phase transient fault, or even fail to identify the fault. In this case, a misjudgment will occur.
[0085] (3)
[0086] Where X(t) is the attack behavior output result, IDA is the information delay attack, P(t) is the correction result, SPTF is the single-phase instantaneous fault, 3TWJ is the three-phase tripping signal, CF is the conversion fault, T is the delay time, T C is the reclosing time.
[0087] To further explain, for conversion faults, network attacks can block the tripping signal, causing the three-phase tripping signal to appear outside the reclosing time. At this time, the safety device will identify it as a single-momentary fault, which will lead to a misjudgment.
[0088] (4)
[0089] Where X(t) is the attack behavior output, IDA is the information delay attack, P(t) is the correction result, TWJ is the single-phase tripping signal, T(i) twj -T(i-1) twj is the time difference between single-phase trip signals, T C is the reclosing time, and TPSCF is a two-phase short circuit fault.
[0090] Further explanation: for a two-phase short-circuit fault, the network attack delays the tripping signal time, making the time difference between the two-phase tripping signals greater than the reclosing time T c , the safety device will judge it as a single-phase permanent fault. In this case, it will be a misjudgment.
[0091] Figure 3 This schematic diagram shows the structure of a network attack fault identification system provided by an embodiment of the present invention. The system primarily includes a voltage and current detection module, a switch value acquisition module, a startup judgment module, and a logic judgment module. The voltage and current detection module serves as input to the startup judgment module, while the startup judgment module and the switch value acquisition module serve as input to the logic judgment module. The logic judgment module also receives output from the malicious attack behavior detection model within the network detection device.
[0092] The voltage and current detection module is used to collect multiple three-phase voltages and currents and transmit the sampling signals to the start judgment module.
[0093] The switch quantity acquisition module is used to collect various switch quantity signals, including line trip signals, contact position signals, etc. In addition, the switch quantity signal, as a state quantity, can also be used to indicate a special state in the system.
[0094] The startup judgment module is used to calculate the collected three-phase voltage, current effective value and power, and monitor in real time whether the voltage, current and power are over-limit.
[0095] The logic judgment module is used to process the information transmitted by the startup judgment module, and at the same time comprehensively judge the network attack information of the network detection device to give a logic judgment result.
[0096] like Figure 4Furthermore, the startup judgment module includes: an analog quantity calculation unit, a voltage startup judgment unit, a current startup judgment unit, and a power startup judgment unit.
[0097] The output end of the analog quantity calculation unit is connected to the input ends of the voltage start judgment unit, the current start judgment unit and the power start judgment unit, and is used to calculate the effective value of voltage, current and power.
[0098] In one embodiment, the analog quantity calculation unit collects three-phase voltage and current from the line and calculates their effective value and power, and transmits the calculated information to the voltage start judgment unit, the current start judgment unit and the power start judgment unit.
[0099] The voltage start judgment unit receives the output of the analog quantity calculation unit and monitors in real time whether the voltage effective value exceeds the limit.
[0100] The current start judgment unit receives the output of the analog quantity calculation unit and monitors in real time whether the effective value of the current exceeds the limit.
[0101] The power start judgment unit receives the output of the analog quantity calculation unit and monitors in real time whether the power exceeds the limit.
[0102] In one embodiment, the voltage start judgment unit receives the voltage effective value from the analog calculation unit in real time and monitors whether the voltage effective value exceeds the set threshold value U s , if it exceeds, it will pass the voltage start signal to the logic judgment module. Similarly, the current start judgment unit and the power start judgment unit will receive the current effective value and power from the analog calculation unit in real time, and monitor whether the current effective value and power exceed the set threshold value I s and P s If it exceeds the limit, the current start signal and power will be transmitted to the logic judgment module.
[0103] like Figure 5 Furthermore, the logic judgment module shown includes: a data acquisition unit, a first judgment unit, a second judgment unit, and a third judgment unit.
[0104] The output end of the data acquisition unit is connected to the input end of the first judgment unit for inputting the startup information of the startup judgment module and the network attack information of the external network detection device.
[0105] The output end of the first judgment unit is connected to the input end of the second judgment unit, and the output end of the second judgment unit is connected to the input end of the third judgment unit.
[0106] The first judgment unit is used to judge whether the stabilization device has a normal fault.
[0107] The second judgment unit is used to judge a new type of fault of the stabilization device.
[0108] The third judgment unit is used to judge the correctness of the fault determined by the stabilization device and then make corrections.
[0109] In one embodiment, the data acquisition unit reads the startup information of the startup judgment module and the information of the network detection device, and performs a fault judgment based on the stability fault judgment criteria. It also considers the information of the network detection device to determine whether the new criteria for network attacks are met. After the fault is determined, the fault correction steps for network attacks are used to determine whether the fault misjudgment needs to be corrected, thus completing the identification and handling of the network attack.
[0110] Example 2
[0111] Embodiment 2 of the present invention provides a terminal device corresponding to the above-mentioned embodiment 1. The terminal device can be a processing device for a client, such as a mobile phone, a laptop computer, a tablet computer, a desktop computer, etc., to execute the method of the above-mentioned embodiment.
[0112] The terminal device of this embodiment includes a memory, a processor, and a computer program stored in the memory; the processor executes the computer program in the memory to implement the steps of the method in the above-mentioned embodiment 1.
[0113] In some implementations, the memory may be a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage.
[0114] In other implementations, the processor may be a central processing unit (CPU), a digital signal processor (DSP), or other general-purpose processors, which are not limited herein.
[0115] Example 3
[0116] Embodiment 3 of the present invention provides a computer-readable storage medium corresponding to the above-mentioned embodiment 1, on which a computer program / instruction is stored. When the computer program / instruction is executed by a processor, the steps of the method of the above-mentioned embodiment 1 are implemented.
[0117] Computer readable storage media can be tangible devices that hold and store instructions used by instruction execution devices. Computer readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any combination thereof.
[0118] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The scheme in the embodiment of the present application can be implemented in various computer languages, for example, object-oriented programming language Java and literal translation scripting language JavaScript, etc.
[0119] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0120] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0121] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0122] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for identifying power system faults under network attacks, characterized in that: The following steps are involved: S1, collect power system voltage, current and switch signal; If at least one phase current increases, at least one phase voltage decreases, there is a phase trip signal, and within the specified waiting time T d If there is no other phase tripping signal, it is determined that a single-phase instantaneous fault occurs in the power system; If at least one phase current increases, at least one phase voltage decreases, there are two phase trip signals, and the time difference between the two phase trip signals is greater than the reclosing time T c , it is determined that a single-phase permanent fault occurs in the power system; Based on the determination of single-phase instantaneous fault of the safety device, if the reclosing time T c If a three-phase trip signal appears, it is determined that a conversion fault has occurred in the power system, that is, a single-phase to phase fault; If a three-phase trip signal or a change in the position contacts of the three-phase circuit breaker appears simultaneously after the safety device is activated, and the three-phase voltages all decrease by the set thresholds and the three-phase currents all increase by the set thresholds, it is determined that a three-phase short circuit fault has occurred in the power system; S2. Perform fault correction under network attack; Among them, X(t) is the output result of the attack behavior, IJA is the information blocking attack, N Ir is the number of phases of current rise, N Ud is the number of phases with voltage drop, P(t) is the correction result, SPTF is a single-phase instantaneous fault, SPPF is a single-phase permanent fault, 3TWJ is a three-phase trip signal, CF is a conversion fault, T is the delay time, T C is the reclosing time, IDA is the information delay attack, TWJ is the single-phase tripping signal, T(i) twj -T(i-1) twj is the time difference between single-phase tripping signals, TPSCF is a two-phase short-circuit fault, Represents existence.
2. The method for identifying power system faults under network attacks according to claim 1, characterized in that: The information delay attack meets the following conditions: or Among them, M T and M T-1 is the time between adjacent states of SV message, η is the system delay coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and It is the time between adjacent frames of the GOOSE message, and M represents the type of the message itself.
3. The method for identifying power system faults under network attacks according to claim 1, characterized in that: The information blocking attack meets the following conditions: or Among them, M T and M T-1 is the time between adjacent states of SV messages, κ is the system congestion coefficient, L is the channel length coefficient, S is the message length coefficient, K is the message type, and It is the time between adjacent frames of the GOOSE message.
4. The method for identifying power system faults under network attacks according to claim 1, characterized in that: The set threshold is 10%.
5. The method for identifying power system faults under network attacks according to any one of claims 1 to 4, characterized in that: Power system fault types also include: If the main transformer or unit is shut down more than twice, and the shut-down interval is within the shut-down time range in the maintenance plan; or the unit is shut down more than twice by remote control, and the shut-down interval exceeds the reclosing time; or the line shut-down signal is detected more than twice or the line has a locking signal, and the shut-down time exceeds the reclosing time, and at the same time, there is no sudden change in current and voltage before the first shut-down, then it is determined that the power system has a frequent breaking fault; if the change in the three-phase negative sequence voltage component of the transformer exceeds the threshold or the transformer power change exceeds the threshold, and at the same time, there is no circuit breaker tripping signal of the transformer, then it is determined that the power system has a controllable load attack fault; If a traditional fault occurs within 1 second and a malicious remote control attack occurs at the same time, the power system is determined to have a reclosing refusal attack fault; the traditional faults include instantaneous faults, permanent faults, three-phase faults, two-phase faults, single-phase faults, and conversion faults.
6. A terminal device comprising a memory, a processor, and a computer program stored in the memory; characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 5.
7. A computer-readable storage medium having a computer program / instruction stored thereon; characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
8. A computer program product comprising a computer program / instructions; characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.