Digital power grid attack defense method, device, equipment, medium and program product

Through distributed architecture and tiered modeling of finite state machine, the problem of insufficient applicability of the existing technology in dynamic and complex attack scenarios is solved, real-time and intelligent defense of digital grid systems is realized, and security and protection capabilities are improved.

CN120455078APending Publication Date: 2025-08-08CHINA SOUTHERN POWER GRID COMPANY +1

Patent Information

Application Number
CN202510589591.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

When facing complex and changing network attacks, existing digital grid attack defense methods have problems such as inconsistent description of offensive and defensive behaviors, insufficient dynamics, limited real-time, lack of decision-making support capabilities and insufficient scalability, making it difficult to adapt to dynamic and complex scenarios of digital grids.

Method used

Using a distributed architecture and a hierarchical modeling method based on finite state machines, we use the target system to obtain the status data, build offensive and defensive behavior models, conduct state predictions, and determine defense response strategies to achieve comprehensive modeling and real-time defense of multi-dimensional and multi-stage offensive and defensive behaviors.

Benefits of technology

It improves the security protection capabilities of the digital grid system, enhances real-time and intelligence, and can defend in advance in complex attack environments, improving the applicability and defense effect of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455078A_ABST
    Figure CN120455078A_ABST
Patent Text Reader

Abstract

The invention relates to a digital power grid attack defense method and device, equipment, a medium and a program product. The method comprises the steps that firstly, state data of a target system are obtained, then, the state data are input into an attack and defense behavior model to obtain an initial state set, the attack and defense behavior model is established according to a finite state machine, and the initial state set comprises a plurality of states, features of all the states and transfer rules; and obtaining a state prediction result according to the state data, the initial state set and the state prediction model, and finally determining a defense response strategy of the target system according to the state prediction result. By adopting the method, the defense response strategy can be determined through state prediction, defense can be performed in advance, so that the safety protection capability of the target system is improved, and the real-time performance and the intelligence are better.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of asset security technology, and in particular to a digital power grid attack defense method, device, equipment, medium and program product. Background Art

[0002] The development of next-generation digital technologies has led to the emergence of the digital grid, a new type of power system that integrates advanced information and communication technologies to achieve digitization, intelligence, and internet-based integration of traditional power systems. In today's digital grid scenario, as the level of grid informatization and intelligence increases, the complexity and openness of the grid system continue to increase. This makes the grid system vulnerable to various cyberattacks, including port scanning, vulnerability exploitation, privilege escalation, and distributed denial of service (DDoS) attacks.

[0003] Traditional means of defending against attacks on digital power grids mostly use static rule matching and isolated monitoring methods, which are not applicable to the dynamic and complex attack behaviors in digital power grid scenarios. Summary of the Invention

[0004] Based on this, it is necessary to provide a digital grid attack defense method, device, equipment, medium and program product suitable for digital grids to address the above technical problems.

[0005] In a first aspect, the present application provides a method for defending against digital power grid attacks, comprising:

[0006] Obtain status data of the target system;

[0007] Input the state data into the attack and defense behavior model to obtain the initial state set. The attack and defense behavior model is constructed based on a finite state machine. The initial state set includes multiple states, the characteristics of each state, and the transition rules.

[0008] Obtaining a state prediction result based on the state data, the initial state set, and the state prediction model;

[0009] Determine the defense response strategy of the target system based on the status prediction results.

[0010] In one embodiment, obtaining status data of a target system includes:

[0011] Acquiring initial state data of the target system, the initial state data including at least one of network traffic data, system log data, and attack case data;

[0012] The initial state data is subjected to feature extraction and standardization processing to obtain state data.

[0013] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. State data is input into the attack and defense behavior model to obtain an initial state set, including:

[0014] Input the state data into the first layer to obtain the first output result;

[0015] Input the first output result into the second layer to obtain the second output result;

[0016] The second output result is input into the third layer to obtain the initial state set.

[0017] In one embodiment, a state prediction result is obtained based on the state data, the initial state set, and the state prediction model, including:

[0018] Configure the initial state and state transition rule base of the state prediction model according to the initial state set;

[0019] The state prediction result is obtained based on the state data, the initial state of the state prediction model and the state transition rule base.

[0020] In one embodiment, the method further comprises:

[0021] Defend the target system according to the defense response strategy and obtain the defense response strategy implementation results of the target system;

[0022] The status prediction model is optimized based on the implementation results of the defense response strategy.

[0023] In one embodiment, the state prediction model is optimized based on the results of the defense response strategy implementation, including:

[0024] Establish a multi-objective optimization model based on the implementation results of the defense response strategy;

[0025] According to the results of the multi-objective optimization model, the state prediction model is optimized.

[0026] In a second aspect, the present application further provides a digital power grid attack defense device, the device comprising:

[0027] Acquisition module, used to obtain status data of the target system;

[0028] The input module is used to input state data into the attack and defense behavior model to obtain the initial state set. The attack and defense behavior model is constructed based on a finite state machine. The initial state set includes multiple states, the characteristics of each state, and the transition rules.

[0029] An obtaining module is used to obtain a state prediction result based on the state data, the initial state set and the state prediction model;

[0030] The determination module is used to determine the defense response strategy of the target system according to the state prediction results.

[0031] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the digital power grid attack defense method described in any one of the first aspects above is implemented.

[0032] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the digital power grid attack defense method described in any one of the first aspects above.

[0033] In a fifth aspect, the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the digital power grid attack defense method described in any one of the first aspects above.

[0034] The aforementioned digital power grid attack defense method, apparatus, device, medium, and program product first obtain the target system's state data. The state data is then input into an attack and defense behavior model to obtain an initial state set. The attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules. Next, a state prediction result is obtained based on the state data, the initial state set, and the state prediction model. Finally, a defense response strategy for the target system is determined based on the state prediction result. Thus, using the target system's state data and the attack and defense behavior model constructed based on the finite state machine, an initial state set including multiple states and state transition rules is obtained. Then, based on the target system's real-time state data, the initial state set, and the state prediction model, a state prediction result is performed on the target system to determine the target system's defense response strategy. When faced with dynamic and complex attack behaviors, determining the defense response strategy through state prediction enables proactive defense, thereby improving the target system's security and protection capabilities, and enhancing real-time and intelligent capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0036] Figure 1 A diagram illustrating an application environment of a digital power grid attack defense method according to an embodiment;

[0037] Figure 21 is a flow chart of a method for defending against digital power grid attacks in one embodiment;

[0038] Figure 3 A flowchart of a digital power grid attack defense method according to another embodiment;

[0039] Figure 4 A flowchart of a digital power grid attack defense method according to another embodiment;

[0040] Figure 5 A flowchart of a digital power grid attack defense method according to another embodiment;

[0041] Figure 6 A flowchart of a digital power grid attack defense method according to another embodiment;

[0042] Figure 7 A flowchart of a digital power grid attack defense method according to another embodiment;

[0043] Figure 8 A flowchart of a digital power grid attack defense method according to another embodiment;

[0044] Figure 9 A structural block diagram of a digital power grid attack defense device in one embodiment;

[0045] Figure 10 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0047] While traditional digital grid attack defense products have made significant progress in cybersecurity, they still suffer from significant issues and flaws due to limitations in their architectural design and technical implementation. These issues primarily manifest in inconsistent descriptions of attack and defense behaviors, insufficient dynamism, limited real-time performance, inadequate decision support capabilities, and limited scalability. These issues not only limit the system's applicability in complex digital grid scenarios but also present significant disadvantages in the face of dynamic, complex, and multi-dimensional cyber attacks. These issues are specifically reflected in the following aspects.

[0048] First, existing digital grid attack defense products lack unified standards for describing and modeling attack and defense behaviors. Many systems employ static rule-matching and feature-based attack detection methods. However, these methods are often tailored to specific attack scenarios or types and lack the ability to comprehensively describe complex, multi-stage attack behaviors. For example, rule-matching methods rely on predefined attack signature libraries, making them prone to missing detections when facing unknown attacks and emerging threats.

[0049] Secondly, insufficient dynamism is a major technical bottleneck for existing products. As mentioned above, many systems use statically configured state transition rules or attack detection logic. These rules require manual updates and are difficult to adapt to the rapid evolution of attack behavior.

[0050] Furthermore, existing systems have limited decision-making support capabilities. Targeted decision-making recommendations often rely on fixed response policy templates, lacking intelligent and dynamic policy optimization capabilities. This template-based decision-making approach prevents real-time adjustments to defense measures based on evolving attack behaviors. For example, when attackers circumvent certain rules through multi-path or multi-stage behaviors, existing systems struggle to adjust response strategies in a timely manner, significantly reducing defense effectiveness.

[0051] Finally, existing products also have shortcomings in scalability. As the scale of the network expands and the complexity of the digital power grid increases, the system needs to process data from multiple subnets or nodes at the same time and ensure coordinated defense between subnets. Existing systems often lack unified management capabilities for distributed environments, resulting in data silos and inconsistent defense strategies when deployed in multiple nodes and multiple scenarios. For example, when an attack involves multiple regional subnets, it is difficult for existing systems to unify and integrate the threat information of these subnets and generate collaborative defense strategies. The technical difficulty in overcoming this problem lies in how to design a distributed and scalable architecture that enables the system to share detection information and decision-making strategies between different network nodes while ensuring low latency and high reliability of data transmission.

[0052] In view of this, the present application proposes a digital power grid attack defense method, which obtains an initial state set including multiple states and state transition rules through the state data of the target system and the attack and defense behavior model constructed based on the finite state machine, and then predicts the state of the target system based on the real-time state data of the target system, the initial state set and the state prediction model to obtain the state prediction result, thereby determining the defense response strategy of the target system. When facing dynamic and complex attack behaviors, the defense response strategy is determined through state prediction, which can be defended in advance, thereby improving the security protection capability of the target system, and having better real-time and intelligence.

[0053] The digital power grid attack defense method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. The digital power grid attack defense method of the present application adopts a distributed architecture, including multiple distributed nodes 102 and a global control center node 104, wherein the distributed nodes 102 communicate with the control center node 104 through a network. Each distributed node 102 can independently run its local attack and defense behavior model and state prediction, and at the same time share key threat information with the global control center node 104, such as state transition records and prediction results. The distributed node 102 and the global control center node 104 can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services. Through the distributed architecture and modular design, the deployment capability of the network security method in large-scale digital power grids is significantly enhanced, and information sharing and policy coordination between network nodes in different regions are realized. It can achieve the unity of global optimization and local response in complex power grid scenarios, thereby improving the overall defense effect.

[0054] In an exemplary embodiment, Figure 2 As shown, a digital power grid attack defense method is provided, which is applied to Figure 1 Taking the distributed node 102 in FIG. 1 as an example, the method includes the following steps 201 to 204. Among them:

[0055] Step 201: Acquire status data of the target system.

[0056] The target system may be a digital power grid system, and the state data may be data acquired by distributed sensors arranged at key locations in the target system, such as data from network switching nodes, servers, terminal devices, and firewalls. By acquiring the state data of the target system, accurate and rich input data can be provided for the operation of attack and defense behavior models and state prediction models. It is understandable that the target system may also be various platforms requiring network security management, such as smart manufacturing, industrial Internet, or cloud computing platforms, and the attack and defense methods in the embodiments of the present application may all be used, and the embodiments of the present application do not impose any restrictions on this.

[0057] Step 202: Input the state data into the attack and defense behavior model to obtain an initial state set.

[0058] The attack and defense behavior model is constructed based on a finite state machine. The initial state set includes multiple states, the characteristics of each state, and transition rules. Optionally, the attack and defense behavior model can be a multi-layered model based on the finite state machine, capable of describing complex attack and defense behaviors at three levels: the foundational layer, the correlation layer, and the strategy layer. This hierarchical modeling approach not only accurately captures the characteristics of a single behavior but also establishes correlations between different behaviors, thereby abstracting the attack and defense behavior model. Through a hierarchical modeling design centered around the finite state machine and combined with dynamic state transition rules, comprehensive modeling of multi-dimensional, multi-stage attack and defense behaviors in the target system can be achieved.

[0059] Step 203: Obtain a state prediction result based on the state data, the initial state set, and the state prediction model.

[0060] The state prediction model is built based on a finite state machine. Its initial state set is the same as the initial state set output by the attack and defense behavior model. This initial state set can include normal operating states, potential risk states, and specific attack and defense behavior states (such as "scanning behavior," "vulnerability exploitation," and "privilege escalation"). Leveraging the dynamic characteristics of the finite state machine, the current state is updated based on real-time state data and the state transition rules of the initial state set. The model also predicts the likely next behavior to produce a state prediction result.

[0061] Step 204: Determine a defense response strategy for the target system based on the state prediction result.

[0062] Based on the state prediction results determined above, a defense response strategy for the target system can be determined, and the target system can be defended against possible attacks based on the defense response strategy.

[0063] In this embodiment, first, the state data of the target system is obtained. Then, the state data is input into the attack and defense behavior model to obtain an initial state set. The attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, the characteristics of each state, and transition rules. Next, a state prediction result is obtained based on the state data, the initial state set, and the state prediction model. Finally, the defense response strategy of the target system is determined based on the state prediction result. In this way, the initial state set including multiple states and state transition rules is obtained by using the state data of the target system and the attack and defense behavior model constructed based on the finite state machine. Then, the state of the target system is predicted based on the real-time state data of the target system, the initial state set, and the state prediction model to obtain the state prediction result, thereby determining the defense response strategy of the target system. When facing dynamic and complex attack behaviors, the defense response strategy determined by state prediction can be defended in advance, thereby improving the security protection capability of the target system and improving real-time and intelligent performance.

[0064] In an optional embodiment of the present application, the step of obtaining the status data of the target system in the above step 201 is as follows: Figure 3 Shown, including:

[0065] Step 301: Acquire the initial state data of the target system.

[0066] The initial state data includes at least one of network traffic data, system log data, and attack case data.

[0067] Optionally, network traffic data can be collected in real time through firewalls, IDS (Intrusion Detection System) / IPS (Intrusion Prevention System), and dedicated network traffic monitoring tools. This collected network traffic data can include key information such as traffic patterns, protocol types, session durations, traffic volume, and source / destination IP addresses. Network traffic data reflects communication activity within the target system and is crucial for detecting abnormal traffic behavior, such as port scans or packet flooding attacks.

[0068] System log data can be obtained by directly accessing the log systems of terminal devices and servers in the target system. This data includes login records, command execution records, file modification information, and other security event records. For example, multiple invalid login attempts or abnormal command execution on the remote host in the system log can serve as early signs of attack behavior.

[0069] The attack case library provides training data based on known attack samples, such as the CVE (Common Vulnerabilities and Exposures) vulnerability database and CERT (Computer Emergency Response Team) incident reports. By acquiring attack case library data, we can obtain behavioral descriptions and attack chain information of known attacks, which can be used for rule matching and machine learning model training, supplementing the model's ability to perceive unknown threats.

[0070] Step 302: Perform feature extraction and standardization on the initial state data to obtain state data.

[0071] Among them, the initial state data can be subjected to refined feature extraction and standardization processing based on entropy analysis, rule matching and machine learning methods, thereby obtaining state data and a basic data set for further analysis and modeling.

[0072] Feature extraction is the process of converting the collected raw data into structured and analyzable behavioral feature information. This embodiment can process and extract the initial state data through preliminary screening and fine-grained analysis. Among them, the preliminary screening is to screen abnormal behaviors in large-scale mixed traffic in the preliminary state data using the entropy analysis method. Entropy analysis is to detect abnormal patterns based on the randomness of traffic distribution. For example, when the access frequency of a certain IP address is significantly higher than the average level of background traffic under normal working conditions in the network, and its access distribution shows a centralized trend, its entropy value can be calculated and marked as abnormal traffic. The entropy calculation formula is as follows:

[0073]

[0074] in, is the probability distribution of a specific traffic pattern within the sampling interval.

[0075] Furthermore, fine-grained analysis is used to extract further fine-grained features from the initially screened abnormal traffic and log data. This is primarily achieved through rule matching and machine learning methods. First, rule matching identifies possible abnormal patterns in the data based on predefined attack signature rules. For example, an illegal request matching a specific SQL (Structured Query Language) keyword indicates a possible SQL injection attack. Second, machine learning employs deep learning models, such as long short-term memory (LSTM) networks, to extract complex time series features from the initial state data, such as abnormal packet retransmission rates, IP address access frequency distribution, and abnormal user login behavior patterns. The identified features can be used to identify unknown attack behaviors or infer potential attack paths.

[0076] The state data from the feature extraction described above can be converted into a unified behavior description format through a standardization module, making it compatible with the input rules of subsequent models. Optionally, each behavior is abstracted into standardized state data. The data structure of the state data can be expressed as: state data = {behavior type, target device, time attribute, attacker characteristics}.

[0077] The behavior type is the type of behavior represented by the current state data, such as "scan," "vulnerability exploit," or "data theft." The target device or system is the target of a specific behavior, such as the target IP address or device ID. The time attribute is the time and duration of the behavior, which can be used for subsequent analysis of time series characteristics. Attacker characteristics are key attributes of the attack source, such as the attacker's IP address and the attack tools used.

[0078] To illustrate the above data processing process, if a port scan behavior is detected in the acquired initial state data, the normalized state data is expressed as follows:

[0079] {Behavior type: "scan", target device: "192.168.1.1", time attribute: "2024-12-08 14:35:00", attacker characteristics: "IP: 10.0.0.5"}

[0080] In this embodiment, the process from initial state data collection to feature extraction and standardization processing to obtain state data is implemented, ensuring the accuracy, completeness and uniformity of the input data, and providing a solid foundation for subsequent model operation.

[0081] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. The state data is input into the attack and defense behavior model to obtain the initial state set. Figure 4 Shown, including:

[0082] Step 401: input state data into the first layer to obtain a first output result.

[0083] The first layer can be the base layer, which is used to describe a single, independent attack and defense behavior state of the target system, called an atomic behavior state. Atomic behavior states are typically determined by a single trigger condition and are the smallest building block for layered attack and defense behavior modeling. For example, behaviors such as port scanning, SQL injection attacks, and illegal login attempts can all be described using base layer modeling. At the base layer, each atomic behavior state can be represented as a state node of a finite state machine. Each state in the base layer contains detailed attributes, including the state name, trigger condition, input characteristics, and output results. The base layer provides the foundation for behavioral association and abstraction in the second and third layers. The conditions for entering a state are defined based on specific trigger events, such as determining whether the trigger condition is met by matching characteristics in network traffic or abnormal records in system logs. Optionally, an example of modeling port scanning behavior in the base layer can be shown below.

[0084] Status definition process, the current status is normal operation, the trigger condition is the number of target port accesses from a single IP , the state after the transfer is scanning behavior. The mathematical description is shown in the following formula.

[0085]

[0086] in, Indicates the number of visits to the i-th port.

[0087] For example, when multiple port access behaviors of the IP address 10.0.0.5 to the target device 192.168.1.1 are detected according to the state data, the finite state machine switches from the normal operation state to the scanning behavior to obtain the first output result.

[0088] Step 402: Input the first output result into the second layer to obtain a second output result.

[0089] The second layer can be an association layer. This layer connects multiple base layer states to construct an attack and defense behavior chain, describing the dynamic evolution of multi-stage attack or defense behavior. The second output is derived from the first output of multiple base layers. Each behavior chain consists of a series of state nodes and state transition rules, reflecting the logical relationship between the initial state and the final state.

[0090] Alternatively, a complete network attack might consist of the following chain: "Port Scan → Vulnerability Exploitation → Privilege Escalation → Data Theft." At the correlation layer, the transition rules for each state are dynamically adjusted based on the current state and input features. For example, if the current state is scanning, and the trigger condition is the detection of a vulnerability exploitation request (such as SQL injection) from the same attack source, the subsequent state will be vulnerability exploitation. The state transition rules at the correlation layer are expressed based on logical functions, as shown below.

[0091]

[0092] Step 403: Input the second output result into the third layer to obtain an initial state set.

[0093] The third layer can be the strategy layer, which abstracts the multiple behavioral chains in the second-layer association layer to describe the overall attack and defense strategy model. Based on the second input, the output is the initial state set. The strategy layer modeling focuses on the synergy of multiple attack chains and the formation of a global strategy, such as distributed denial of service (DDoS) attacks or advanced persistent threats (APTs).

[0094] Taking DDoS attacks as an example, the strategy layer model is constructed by integrating multiple scanning behaviors and traffic anomalies into attack subchains. Through state transition rules, the collaborative relationships between different subchains are modeled into an overall attack strategy.

[0095] In the policy layer, each state represents an overall attack and defense strategy, and state transitions are based on subchain trigger conditions. For example, when multiple nodes are simultaneously in the scanning state and detect a large amount of traffic concentrated on the target device, the finite state machine will transition to the DDoS attack state. The mathematical model is shown below.

[0096]

[0097] in, represents the flow of the i-th node.

[0098] The above analysis of the three-layer attack behavior model shows that state transition rules are the core of achieving the dynamic nature of layered modeling. Each state transitions to the target state when specific trigger conditions are met. State transition rules are implemented based on logical judgments of input state data and can include the following scenarios.

[0099] (1) Traffic anomaly: triggered when the entropy value of network traffic is lower than a certain threshold.

[0100] (2) Log event: Triggered when multiple invalid login attempts are detected in the system log.

[0101] (3) Specific pattern matching: Triggered when the traffic contains attack features (such as SQL injection statements).

[0102] The state transition rule is expressed as a logical function as shown below.

[0103]

[0104] Where T is the state transition function, and are the current state and target state respectively, and E is the input state data.

[0105] In this embodiment, hierarchical modeling is used to establish attack and defense behavior models step by step, from single behaviors to overall strategy levels. The foundation layer provides a fine-grained description of atomic behaviors, the association layer constructs the dynamic logic of the behavior chain, and the strategy layer describes the global attack and defense strategy by integrating the behavior chain. The hierarchical models are interconnected, forming an adaptive, dynamic, and standardized description system. Through a structured and modular design, it can adapt to complex and changing attack scenarios, while laying a solid foundation for the dynamic operation and decision support of the subsequent state prediction model. Through the attack and defense behavior model, the system achieves efficient response and accurate description of the complex threat environment of the target system.

[0106] In the embodiment of the present application, the step of obtaining the state prediction result according to the state data, the initial state set and the state prediction model is as follows: Figure 5 Shown, including:

[0107] Step 501: configure the initial state and state transition rule base of the state prediction model according to the initial state set.

[0108] Optionally, configure the initial states and state transition rule base of the state prediction model based on the initial state set output by the attack and defense behavior model. Each state in the initial state set includes a feature description and the definition of a state transition rule. For example, the initial state name is "Normal Operation" and the description is "No abnormalities in network operation and no signs of attack detected." The transition condition is to transition to the next state when an abnormality in network traffic or logs is detected. The state transition rule is based on logical conditions, as shown in the following formula.

[0109]

[0110] in, is the current state, is the input status data, is the state transition function.

[0111] Step 502: Obtain a state prediction result based on the state data, the initial state of the state prediction model, and the state transition rule base.

[0112] Optionally, a state transition rule base is configured based on the logical sequence of historical attack paths during state prediction model initialization and can be dynamically updated through a feedback mechanism while the state prediction model is running. During operation, the state prediction model receives real-time state data and updates the current state based on the state transition rules. Each input state data is considered a trigger condition. When the preset logical judgment is met, the state prediction model transitions from the current state to the target state. For example, when the system detects port scanning behavior from a certain IP address, the state prediction model transitions from the normal operation state to the scanning behavior state, as shown in the following formula.

[0113]

[0114] in, Indicates the number of accesses to the target port.

[0115] After the state transition, in the "scanning behavior" state, if a SQL injection attack pattern match is further detected, the state prediction model transitions to the vulnerability exploitation behavior state, as shown in the following formula.

[0116]

[0117] Whenever new state data is acquired, the state prediction model's finite state machine immediately triggers a state update, ensuring real-time reflection of the current offensive and defensive situation. This real-time nature of dynamic state updates is achieved through an event-driven architecture (EDA).

[0118] After updating the state in real time, the state prediction model can predict the attacker's next possible action based on the current state, providing forward-looking guidance for defense strategies. Optionally, this embodiment combines Markov chains with deep learning models, such as LSTM neural networks, to achieve state prediction.

[0119] The first approach involves state prediction based on a Markov chain. A Markov chain uses a state transition probability matrix to describe the transition relationship between states and predict the likelihood of the next state. The transition probability is derived from historical data, as shown in the following formula.

[0120]

[0121] Based on the current state, the state prediction model predicts the next state by maximizing the transition probability. For example, in the scanning state, if the transition probability matrix indicates that vulnerability exploitation has the highest transition probability, the system will predict the next state as vulnerability exploitation.

[0122] The second approach involves complex time series prediction based on LSTM. In complex, multi-stage attacks, a single-step transition in a Markov chain may not be sufficient to capture the global nature of the behavioral chain. Instead, an LSTM neural network can be used to predict future states by learning from the historical sequence of states, as shown in the following equation.

[0123]

[0124] in, is the hidden state at the current moment, are input features, and W, U, and b are model parameters. LSTM can capture long-term dependencies and has a significant effect on predicting multi-stage attacks.

[0125] By combining the above two methods, the state prediction model can achieve comprehensive prediction of simple single-step behaviors and complex multi-stage behaviors.

[0126] Optionally, based on the status update and prediction results, a corresponding defense response strategy can be determined. The defense response strategy can include two types: active defense and passive mitigation.

[0127] The first, active defense, immediately triggers rules to block the attack source IP address when the state prediction model indicates vulnerability exploitation, preventing further privilege escalation. Alternatively, if the prediction results indicate possible data theft, the target device's access to sensitive data is restricted.

[0128] The second type is passive mitigation. When the state prediction model is in a DDoS attack state, the load pressure of the target device is reduced through traffic regulation.

[0129] In this embodiment, the state prediction model enables real-time tracking, accurate prediction, and efficient response to the target system's attack and defense behaviors, providing strong technical support for the target system's security protection. State prediction significantly enhances the intelligence level of network defense, enabling it to maintain excellent defensive effectiveness in complex and ever-changing attack environments.

[0130] In one embodiment, Figure 6 As shown, the method further includes:

[0131] Step 601: Defend the target system according to the defense response strategy, and obtain the defense response strategy implementation result of the target system.

[0132] Optionally, the defense response strategy can respond in real time to defend the target system. The triggering basis of the real-time response is shown in the following logic function.

[0133] R=f(S,P)

[0134] Among them, S is the current state, P is the predicted state, and R is the response action.

[0135] Optionally, state transition rules and the state prediction model can be dynamically updated through a feedback mechanism to adapt to changes in attack behavior. During operation, the actual state transition paths are recorded in real time and compared with the predicted results to update transition probabilities and state prediction model parameters. If a particular attack path is triggered multiple times, the priority of its key nodes can be increased. In cases where the prediction deviates significantly from the actual state, the state prediction model retrains the LSTM model to optimize its prediction capabilities.

[0136] Optionally, the defense response strategy can include: first, detecting abnormal traffic and transitioning the current state to the scanning state. Then, detecting a SQL injection pattern match and transitioning the current state to the vulnerability exploitation state. Finally, the state prediction model uses a Markov chain to predict that the attacker may attempt privilege escalation, triggering the privilege isolation strategy in advance to prevent further development of the attack chain.

[0137] Furthermore, the step of generating a defense response strategy may also include the following steps.

[0138] (1) State analysis and priority assessment. The state of each finite state machine can be classified according to its threat level. The threat level is determined by the severity of the attack behavior, the importance of the target device, and the possible impact. For example, the threat level of the "vulnerability exploitation behavior" state is higher than that of the "scanning behavior", and the priority of the state involving critical devices will be further increased. The formula for calculating the threat level is shown below.

[0139]

[0140] Where L is the threat level, S is the threat score of the behavior, C is the importance score of the target device, and α and β are weight factors.

[0141] (2) Defense strategy generation: Determine the appropriate defense strategy based on the current state and the predicted next state. For example, if the current state is "scanning behavior" and the next predicted state is "vulnerability exploitation behavior," the access control rules of the target device will be strengthened in advance to prevent the vulnerability from being further exploited. For the predicted "DDoS attack" state, the traffic control strategy will be triggered to reduce the target device load by limiting the traffic of high-risk IP addresses.

[0142] (3) Real-time response: The defense response strategy is directly applied to the target system’s network environment through an event-driven architecture. Specific response actions include blocking IP addresses, adjusting firewall rules, isolating devices, allocating additional resources, etc. This ensures that the target system can take proactive defense measures at the early stages of the attack chain, thereby reducing the impact of potential threats.

[0143] Step 602: Optimize the state prediction model according to the defense response strategy implementation result.

[0144] Optionally, optimize the state prediction model such as Figure 7 As shown, this may include:

[0145] Step 701: Establish a multi-objective optimization model based on the defense response strategy implementation results.

[0146] Step 702: Optimize the state prediction model according to the results of the multi-objective optimization model.

[0147] In order to achieve the optimal balance between defense effect and system performance, defense strategy optimization can be performed based on the actual results of the defense response strategy.

[0148] Optionally, a multi-objective optimization model is established with the goal of improving defense effectiveness and reducing normal business interruption, as shown below.

[0149]

[0150] in, Indicates the effect of intercepting the attack, represents the proportion of normal services affected, α and β are weight coefficients, and the optimization variable x includes the parameter settings of the defense rule, such as the traffic limit threshold and blocking time. Based on the obtained optimization variables, the defense rule parameters of the defense response strategy generated by the state prediction model are optimized.

[0151] Optionally, optimization can also be performed through critical path identification. To improve optimization efficiency, priority protection targets are identified by analyzing the key state nodes in the attack path. The critical path refers to the path in the attack chain that has the greatest impact on the final threat. For example, the attack path is: scanning behavior → vulnerability exploitation → data theft. When the transition frequency of the "vulnerability exploitation" state is detected to be the highest, and its impact on the final state "data theft" is the most significant, it is marked as a critical state node. For critical paths, priority is given to strengthening protection measures when generating defense response strategies, such as improving the detection sensitivity of relevant rules or increasing resource allocation.

[0152] Optionally, optimization results can be continuously evaluated through feedback mechanisms and dynamic adjustments, and defense strategies can be updated based on historical data. For example, if a strategy successfully blocks attack chains multiple times, the system will increase its priority. If a rule triggers a high false alarm rate or significantly impacts normal business operations, its parameter settings will be adjusted or its priority will be downgraded. The implementation of the feedback mechanism relies on the recording and analysis of the finite state machine's operating results. By comparing the actual state transition path with the predicted results, the accuracy and effectiveness of the defense strategy are calculated. If the accuracy and effectiveness fall below a threshold, the state prediction model will be retrained or the optimization parameters will be adjusted.

[0153] In one embodiment, the above optimization process is illustrated by way of example, including the following steps:

[0154] (1) Initial state: The current state is in normal operation.

[0155] (2) When port scanning behavior is detected, the state prediction model shifts to the scanning behavior state, and predicts that the next state may be vulnerability exploitation behavior.

[0156] (3) Generate defense response strategies to restrict access to specific ports of target devices and trigger IDS / IPS rules to monitor potential vulnerability exploitation behaviors.

[0157] (4) Optimize the strategy. Through critical path analysis, it is found that "vulnerability exploitation" is the key node in the attack chain. Therefore, stricter access control is implemented on related devices, and high-risk traffic is isolated in advance.

[0158] (5) Response and adjustment: monitor the implementation results of the defense strategy in real time. If the false alarm rate is too high or the actual status does not develop as predicted, adjust the state transition rules and strategy parameters through the feedback mechanism.

[0159] In this embodiment, decision support and optimization are provided by generating defense response strategies. Combining the current state of the state prediction model with its prediction results, defense strategies can be generated before an attack occurs, improving the real-time nature of defense. Through multi-objective optimization and feedback mechanisms, defense rules can be dynamically adjusted to adapt to complex and changing attack scenarios, enhancing the intelligence and adaptability of defense. Critical path identification optimizes resource allocation, prioritizing the protection of the most critical network nodes, improving defense accuracy, and enhancing resource utilization.

[0160] In an embodiment of the present application, the above-mentioned digital power grid attack defense method can be applied to a digital power grid attack defense system, which can include a data acquisition and feature extraction module, a state prediction module, and a decision support and optimization module. The data acquisition and feature extraction module is used to acquire state data, and the collected state data can be stored in a high-performance database for subsequent analysis. The state prediction module is used to obtain state prediction results, and the decision support and optimization module is used to provide decision suggestions and determine optimization parameters. Figure 8 FIG. 1 is a flow chart of a digital power grid attack defense method. FIG.

[0161] Step 801: Acquire the initial state data of the target system.

[0162] Step 802: Perform feature extraction and standardization on the initial state data to obtain state data.

[0163] Step 803: input the state data into the first layer to obtain a first output result.

[0164] Step 804: input the first output result into the second layer to obtain a second output result.

[0165] Step 805: Input the second output result into the third layer to obtain an initial state set.

[0166] Step 806: configure the initial state and state transition rule base of the state prediction model according to the initial state set.

[0167] Step 807: Obtain a state prediction result based on the state data, the initial state of the state prediction model, and the state transition rule base.

[0168] Step 808: Determine a defense response strategy for the target system based on the state prediction result.

[0169] Step 809: Defend the target system according to the defense response strategy, and obtain the defense response strategy implementation result of the target system.

[0170] Step 810: Optimize the state prediction model according to the defense response strategy implementation result.

[0171] In this embodiment, the digital power grid attack defense system is based on a finite state machine. By introducing a hierarchical modeling method based on a finite state machine, the attack and defense behaviors are modeled step by step from the basic layer, the association layer to the strategy layer, providing a more refined description capability. The advantage of this hierarchical modeling is that it solves the problem of fragmentation and inconsistency in the description of attack and defense behaviors in traditional systems, and at the same time lays the foundation for multi-granularity behavior analysis and the generation of defense strategies. Specifically, the standardized description system can cover all levels from single atomic behavior to complex strategic behavior, ensuring that the system has consistent modeling capabilities when facing different types of attacks. Through hierarchical design, new atomic behavior definitions can be introduced in the basic layer, or new behavior chains and strategy models can be added in the association layer and strategy layer, so as to quickly adapt to the ever-changing threat environment, thereby improving the scalability of the system.

[0172] Furthermore, by combining the dynamic operational characteristics of finite state machines with machine learning algorithms to establish a state prediction model, dynamic updates of the current state and intelligent predictions of future states are achieved, enhancing the system's real-time and intelligent capabilities. Furthermore, through an event-driven architecture (EDA), the system instantly updates the current state of the finite state machine upon each state data input, ensuring dynamic synchronization of attack and defense postures. Based on state prediction, the system can predict the attacker's next move in advance and proactively adjust defense strategies, thereby curbing threats early in the attack chain. Through feedback mechanisms and dynamic rule updates, the system continuously optimizes state transition rules and prediction models, significantly improving its ability to respond to new and unknown attacks and enhancing its adaptability.

[0173] Furthermore, by combining state analysis of finite state machines with a multi-objective optimization algorithm, a dynamic decision support mechanism was designed that can achieve the optimal defense strategy under multi-dimensional constraints. Defense strategies are generated based on a comprehensive assessment of multiple factors, such as threat level and target device importance, to ensure accurate resource allocation. For example, by identifying key nodes in the attack path, the system can prioritize the protection of core devices. Through a feedback mechanism, the system can dynamically adjust policy parameters based on real-time operating data and defense effectiveness, ensuring that defense measures are consistent with actual threats. Through a multi-objective optimization algorithm, a dynamic balance is achieved between attack interception effectiveness and normal business continuity, thereby avoiding the negative impact of excessive defense on business operations. This makes defense more precise and dynamic, achieving a balance among multiple objectives.

[0174] Furthermore, based on the operational characteristics of digital power grids, the system achieves precise adaptation to the power grid environment by designing highly scenario-specific attack and defense behavior modeling and decision rules. For example, the system can effectively identify specific threat behaviors within the SCADA system and dynamically adjust protection strategies. A distributed architecture ensures multi-node coordinated defense capabilities within large-scale digital power grids. A distributed finite state machine model enables sharing of detection information across regional subnets, enabling network-wide coordinated defense. Data flows at different layers (such as the distribution layer, transmission layer, and monitoring layer) can be independently analyzed and uniformly managed, ensuring the security and stability of the entire power grid network. Dedicated behavioral descriptions and response mechanisms are designed to address the specific needs of digital power grids, such as identifying cross-regional tripping events and distributed denial of service (DDoS) attacks. The modular design enables easy integration into other network security platforms and rapid adaptation to the security requirements of diverse network environments.

[0175] Optionally, distributed nodes can incorporate edge computing technology to offload some data processing and analysis tasks to edge nodes, significantly reducing the load on central nodes. At the same time, based on critical path identification and resource allocation optimization, limited computing and network resources can be efficiently utilized. Through edge computing and an event-driven architecture, system latency from data acquisition to response is significantly reduced, ensuring the timeliness of defensive measures. Through critical path analysis, the system prioritizes resource allocation to protect the most important targets, avoiding wasting resources on secondary targets. This enables expansion to larger-scale network environments without significantly increasing hardware resources, meeting the needs of future digital grid development.

[0176] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0177] Based on the same inventive concept, embodiments of the present application also provide a digital power grid attack defense device for implementing the aforementioned digital power grid attack defense method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the digital power grid attack defense device provided below can be found in the above-mentioned limitations of the digital power grid attack defense method and will not be further elaborated here.

[0178] In an exemplary embodiment, Figure 9 As shown, a digital power grid attack defense device 900 is provided, comprising: an acquisition module, an input module, a obtaining module and a determination module, wherein:

[0179] Acquisition module, used to obtain status data of the target system;

[0180] The input module is used to input state data into the attack and defense behavior model to obtain the initial state set. The attack and defense behavior model is constructed based on a finite state machine. The initial state set includes multiple states, the characteristics of each state, and the transition rules.

[0181] An obtaining module is used to obtain a state prediction result based on the state data, the initial state set and the state prediction model;

[0182] The determination module is used to determine the defense response strategy of the target system according to the state prediction results.

[0183] In one embodiment, the acquisition module is specifically used to obtain initial state data of the target system, where the initial state data includes at least one of network traffic data, system log data, and attack case data; and perform feature extraction and standardization processing on the initial state data to obtain state data.

[0184] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. The input module is specifically used to input state data into the first layer to obtain a first output result; input the first output result into the second layer to obtain a second output result; and input the second output result into the third layer to obtain an initial state set.

[0185] In one embodiment, the obtaining module is specifically used to configure the initial state of the state prediction model and the state transition rule base according to the initial state set; and obtain the state prediction result according to the state data, the initial state of the state prediction model and the state transition rule base.

[0186] In one embodiment, the device further includes an optimization module for defending the target system according to the defense response strategy and obtaining the defense response strategy implementation result of the target system; and optimizing the state prediction model according to the defense response strategy implementation result.

[0187] In one embodiment, the optimization module is specifically used to establish a multi-objective optimization model according to the implementation results of the defense response strategy; and optimize the state prediction model according to the results of the multi-objective optimization model.

[0188] Each module in the aforementioned digital power grid attack defense device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor within a computer device in hardware form, or can be stored in a computer device's memory in software form, allowing the processor to call and execute the corresponding operations of each module.

[0189] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 10 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store status data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a digital power grid attack defense method is implemented.

[0190] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0191] In an exemplary embodiment, a computer device is provided, comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the following steps when executing the computer program: obtaining state data of a target system; inputting the state data into an attack and defense behavior model to obtain an initial state set, wherein the attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules; obtaining a state prediction result based on the state data, the initial state set, and the state prediction model; and determining a defense response strategy for the target system based on the state prediction result.

[0192] In one embodiment, the processor implements the following steps when executing a computer program: obtaining initial state data of a target system, the initial state data including at least one of network traffic data, system log data, and attack case data; performing feature extraction and standardization processing on the initial state data to obtain state data.

[0193] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. When the processor executes the computer program, the following steps are implemented: inputting state data into the first layer to obtain a first output result; inputting the first output result into the second layer to obtain a second output result; and inputting the second output result into the third layer to obtain an initial state set.

[0194] In one embodiment, the processor implements the following steps when executing the computer program: configuring the initial state of the state prediction model and the state transition rule base according to the initial state set; obtaining the state prediction result according to the state data, the initial state of the state prediction model and the state transition rule base.

[0195] In one embodiment, the processor implements the following steps when executing the computer program: defending the target system according to the defense response strategy and obtaining the defense response strategy implementation result of the target system; optimizing the state prediction model according to the defense response strategy implementation result.

[0196] In one embodiment, the processor implements the following steps when executing the computer program: establishing a multi-objective optimization model based on the results of the defense response strategy implementation; and optimizing the state prediction model based on the results of the multi-objective optimization model.

[0197] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: obtaining state data of a target system; inputting the state data into an attack and defense behavior model to obtain an initial state set, where the attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules; obtaining a state prediction result based on the state data, the initial state set, and the state prediction model; and determining a defense response strategy for the target system based on the state prediction result.

[0198] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: obtaining initial state data of the target system, the initial state data including at least one of network traffic data, system log data, and attack case data; performing feature extraction and standardization processing on the initial state data to obtain state data.

[0199] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. When the computer program is executed by a processor, the following steps are implemented: inputting state data into the first layer to obtain a first output result; inputting the first output result into the second layer to obtain a second output result; and inputting the second output result into the third layer to obtain an initial state set.

[0200] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: configuring the initial state of the state prediction model and the state transition rule base according to the initial state set; obtaining the state prediction result according to the state data, the initial state of the state prediction model and the state transition rule base.

[0201] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: defending a target system according to a defense response strategy, and obtaining a defense response strategy implementation result of the target system; and optimizing a state prediction model according to the defense response strategy implementation result.

[0202] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: establishing a multi-objective optimization model based on the results of the defense response strategy implementation; and optimizing the state prediction model based on the results of the multi-objective optimization model.

[0203] In one embodiment, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the following steps: obtaining state data of a target system; inputting the state data into an attack and defense behavior model to obtain an initial state set, wherein the attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules; obtaining a state prediction result based on the state data, the initial state set, and the state prediction model; and determining a defense response strategy for the target system based on the state prediction result.

[0204] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: obtaining initial state data of the target system, the initial state data including at least one of network traffic data, system log data, and attack case data; performing feature extraction and standardization processing on the initial state data to obtain state data.

[0205] In one embodiment, the attack and defense behavior model includes a first layer, a second layer, and a third layer. When the computer program is executed by a processor, the following steps are implemented: inputting state data into the first layer to obtain a first output result; inputting the first output result into the second layer to obtain a second output result; and inputting the second output result into the third layer to obtain an initial state set.

[0206] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: configuring the initial state of the state prediction model and the state transition rule base according to the initial state set; obtaining the state prediction result according to the state data, the initial state of the state prediction model and the state transition rule base.

[0207] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: defending a target system according to a defense response strategy, and obtaining a defense response strategy implementation result of the target system; and optimizing a state prediction model according to the defense response strategy implementation result.

[0208] In one embodiment, when the computer program is executed by a processor, the following steps are implemented: establishing a multi-objective optimization model based on the results of the defense response strategy implementation; and optimizing the state prediction model based on the results of the multi-objective optimization model.

[0209] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0210] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0211] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0212] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A digital power grid attack defense method, characterized in that: The method comprises: Obtain status data of the target system; Inputting the state data into an attack and defense behavior model to obtain an initial state set, wherein the attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules; Obtaining a state prediction result according to the state data, the initial state set, and the state prediction model; A defense response strategy for the target system is determined according to the state prediction result.

2. The method according to claim 1, characterized in that The obtaining of the status data of the target system includes: Acquiring initial state data of the target system, the initial state data including at least one of network traffic data, system log data, and attack case data; The initial state data is subjected to feature extraction and standardization processing to obtain the state data.

3. The method according to claim 1, characterized in that The attack and defense behavior model includes a first layer, a second layer, and a third layer. Inputting the state data into the attack and defense behavior model to obtain an initial state set includes: Inputting the state data into the first layer to obtain a first output result; Inputting the first output result into the second layer to obtain a second output result; The second output result is input into the third layer to obtain the initial state set.

4. The method according to claim 1, wherein Obtaining a state prediction result according to the state data, the initial state set, and the state prediction model includes: Configuring the initial state and state transition rule base of the state prediction model according to the initial state set; The state prediction result is obtained according to the state data, the initial state of the state prediction model and the state transition rule base.

5. The method according to claim 1, wherein The method further comprises: Defending the target system according to the defense response strategy, and obtaining the defense response strategy implementation result of the target system; The state prediction model is optimized according to the implementation results of the defense response strategy.

6. The method according to claim 5, characterized in that Optimizing the state prediction model according to the implementation result of the defense response strategy includes: Establishing a multi-objective optimization model based on the implementation results of the defense response strategy; The state prediction model is optimized according to the results of the multi-objective optimization model.

7. A digital power grid attack defense device, characterized in that: The device comprises: Acquisition module, used to obtain status data of the target system; an input module, configured to input the state data into an attack and defense behavior model to obtain an initial state set, wherein the attack and defense behavior model is constructed based on a finite state machine, and the initial state set includes multiple states, characteristics of each state, and transition rules; An obtaining module, configured to obtain a state prediction result based on the state data, the initial state set, and the state prediction model; A determination module is used to determine the defense response strategy of the target system according to the state prediction result.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Network attacker behavior analyzing method based on attack graph

    CN106534195A

  • Network killing chain detection method, prediction method and system

    CN112087420A

  • Null-byte injection detection

    US10044752B1

Cited By

  • Cloud control system highly hidden attack detection method based on hierarchical state machine behavior modeling

    CN120880792A