Thermal power plant auxiliary control system network security threat classification method and system

By extracting time series data of access records and system resource usage information in the auxiliary control system of thermal power plants, and using deep learning for cross-modal correlation learning, the problem of difficulty in identifying complex attacks in traditional methods is solved, and more efficient network security threat classification and real-time protection are achieved.

CN120474729AInactive Publication Date: 2025-08-12HUANENG LINYI POWER GENERATION CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510339082.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional network security protection methods are difficult to effectively identify and prevent modern complex attack behaviors, especially in thermal power plant auxiliary control systems. Due to its high complexity and multi-stage and low-frequency attack methods, traditional methods lack context perception and long-term behavior tracking capabilities, making it difficult to capture complex attack processes.

Method used

By extracting time series data of access records and system resource usage information from the network log data of the auxiliary control system of the thermal power plant, time series analysis is performed using deep learning-based data analysis technology, and fine-grained cross-modal correlation learning is carried out to reveal the intrinsic correlation characteristics between network access behavior and system resource usage status, so as to realize intelligent identification and classification of network security threats.

Benefits of technology

It significantly improves the detection ability of complex attack behaviors, improves the accuracy and real-time nature of network security protection, and can identify and respond to potential threats earlier, ensuring the stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474729A_ABST
    Figure CN120474729A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and particularly discloses a thermal power plant auxiliary control system network security threat classification method and system.The thermal power plant auxiliary control system network security threat classification method comprises the steps that firstly, access records and time sequence data of system resource use information are extracted from weblog data of a thermal power plant auxiliary control system; further introducing a data analysis technology based on deep learning to carry out time sequence analysis on the access record and the system resource use information respectively so as to mine time sequence correlation change modes of the system access behavior and the system resource use state respectively, and carrying out fine-grained cross-modal correlation learning on the system access behavior and the system resource use state; therefore, the internal correlation characteristics between the network access behavior and the system resource use state can be revealed, and the intelligent identification and classification of the network security threats in the auxiliary control system of the thermal power plant can be realized on the basis. Through the mode, the detection capability of complex attack behaviors can be remarkably improved, and the accuracy and the real-time performance of network security protection are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a network security threat classification method and system for an auxiliary control system of a thermal power plant. Background Art

[0002] As a crucial component of the power generation process, the auxiliary control system of a thermal power plant undertakes the critical task of monitoring, controlling, and regulating auxiliary equipment. Its stable operation is directly related to the safety and efficiency of the entire power plant. With the rapid development of information technology, auxiliary control systems in thermal power plants have increasingly relied on advanced computer network technologies, enabling functions such as remote monitoring, automated control, and real-time data transmission. However, this trend towards increased informatization has also exposed auxiliary control systems to unprecedented cybersecurity threats. Due to the high system complexity, numerous devices, and frequent data exchange within thermal power plant auxiliary control systems, cybersecurity concerns not only include common issues such as information leakage and data tampering, but also the risk of malicious manipulation of control commands that could affect the operation of physical equipment. If this occurs, it could lead to power interruption or equipment damage, posing a significant threat to grid stability and public safety.

[0003] Traditional network security protection methods primarily rely on signature libraries and rule sets based on known threats to identify and prevent attacks. However, this approach has significant limitations. For example, modern attacks often employ multi-stage, low-frequency methods, gradually infiltrating target systems through discrete behavioral patterns. In these cases, a single event may not possess obvious malicious characteristics; only when all related activities are viewed coherently does the attack intent become apparent. Traditional signature or rule-matching methods typically focus only on individual packets or events, lacking contextual awareness and the ability to track long-term behavior. Therefore, they struggle to effectively capture these complex attack processes.

[0004] Therefore, an optimized network security threat classification method and system for the auxiliary control system of a thermal power plant is expected. Summary of the Invention

[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a method and system for classifying network security threats in the auxiliary control system of a thermal power plant, which first extracts time series data of access records and system resource usage information from the network log data of the auxiliary control system of the thermal power plant, and then further introduces data analysis technology based on deep learning to perform time series analysis on the access records and system resource usage information, respectively, so as to respectively mine the time series correlation change patterns of system access behavior and system resource usage status, and through fine-grained cross-modal correlation learning of the two, to reveal the inherent correlation characteristics between network access behavior and system resource usage status, so as to realize intelligent identification and classification of network security threats existing in the auxiliary control system of the thermal power plant on this basis. In this way, the detection capability of complex attack behaviors can be significantly improved, thereby improving the accuracy and real-time performance of network security protection.

[0006] According to one aspect of the present application, a method for classifying network security threats of an auxiliary control system of a thermal power plant is provided, which includes:

[0007] Obtain network log data from the auxiliary control system of a thermal power plant;

[0008] extracting a time series of access records and a time series of system resource usage information from the network log data;

[0009] Extracting access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature encoding vector;

[0010] Extracting resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph;

[0011] Performing cross-domain fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature coding vector and the system resource usage state feature graph to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector;

[0012] Based on the access behavior-system resource, a cross-modal fine-grained aggregated encoding feature vector is used to determine the type label of the network security threat.

[0013] According to another aspect of the present application, a network security threat classification system for an auxiliary control system of a thermal power plant is provided, comprising:

[0014] Network log data collection module, used to obtain network log data of the auxiliary control system of the thermal power plant;

[0015] A time series extraction module, configured to extract the time series of access records and the time series of system resource usage information from the network log data;

[0016] An access behavior feature encoding module, configured to extract access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature encoding vector;

[0017] a resource usage status feature extraction module, configured to extract resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph;

[0018] An aggregation analysis module is used to perform cross-domain fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature coding vector and the system resource usage state feature graph to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector;

[0019] The threat identification module is used to determine the type label of the network security threat based on the access behavior-system resource using a cross-modal fine-grained aggregated encoding feature vector.

[0020] Compared with the existing technology, the network security threat classification method and system for the auxiliary control system of a thermal power plant provided in this application first extracts the time series data of access records and system resource usage information from the network log data of the auxiliary control system of the thermal power plant, and then further introduces the data analysis technology based on deep learning to perform time series analysis on the access records and system resource usage information respectively, so as to respectively mine the time series correlation change patterns of system access behavior and system resource usage status, and through fine-grained cross-modal correlation learning of the two, to reveal the inherent correlation characteristics between network access behavior and system resource usage status, so as to realize the intelligent identification and classification of network security threats existing in the auxiliary control system of the thermal power plant on this basis. In this way, the detection capability of complex attack behaviors can be significantly improved, thereby improving the accuracy and real-time performance of network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0022] Figure 1 This is a flowchart of a method for classifying network security threats in a thermal power plant auxiliary control system according to an embodiment of the present application.

[0023] Figure 2 This is a data flow diagram of a network security threat classification method for a thermal power plant auxiliary control system according to an embodiment of the present application.

[0024] Figure 3This is a flowchart of sub-step S3 of the method for classifying network security threats of a thermal power plant auxiliary control system according to an embodiment of the present application.

[0025] Figure 4 This is a flowchart of sub-step S4 of the method for classifying network security threats of a thermal power plant auxiliary control system according to an embodiment of the present application.

[0026] Figure 5 This is a flowchart of sub-step S5 of the method for classifying network security threats of a thermal power plant auxiliary control system according to an embodiment of the present application.

[0027] Figure 6 This is a block diagram of a network security threat classification system for a thermal power plant auxiliary control system according to an embodiment of the present application. DETAILED DESCRIPTION

[0028] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.

[0029] Although the present application makes various references to certain modules in the system according to embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are illustrative only, and different aspects of the system and method can use different modules.

[0030] Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, the various steps may be processed in reverse order or simultaneously, as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.

[0031] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.

[0032] It is worth noting that in this application, all actions to obtain data are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.

[0033] In response to the technical problems described in the above background technology, this application proposes an optimized network security threat classification method for the auxiliary control system of a thermal power plant. It first extracts the time series data of access records and system resource usage information from the network log data of the auxiliary control system of the thermal power plant. Then, it further introduces data analysis technology based on deep learning to perform time series analysis on the access records and system resource usage information respectively, so as to respectively mine the time series correlation change patterns of system access behavior and system resource usage status, and through fine-grained cross-modal correlation learning of the two, to reveal the inherent correlation characteristics between network access behavior and system resource usage status, so as to realize the intelligent identification and classification of network security threats existing in the auxiliary control system of the thermal power plant on this basis. In this way, the detection capability of complex attack behaviors can be significantly improved, thereby improving the accuracy and real-time performance of network security protection.

[0034] Figure 1 This is a flowchart of a method for classifying network security threats in a thermal power plant auxiliary control system according to an embodiment of the present application. Figure 2 Schematic diagram of data flow of the network security threat classification method of the auxiliary control system of a thermal power plant according to an embodiment of the present application. Figure 1 and Figure 2 As shown, the network security threat classification method for the auxiliary control system of a thermal power plant includes the following steps: S1, obtaining network log data of the auxiliary control system of a thermal power plant; S2, extracting the time series of access records and the time series of system resource usage information from the network log data; S3, extracting the access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature coding vector; S4, extracting the resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph; S5, performing cross-domain fine-grained aggregation analysis on the access behavior temporal pattern feature coding vector and the system resource usage status feature graph based on clustering centers to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector; S6, determining the type label of the network security threat based on the access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector.

[0035] In the aforementioned method for classifying network security threats for a thermal power plant auxiliary control system, step S1 involves obtaining network log data from the thermal power plant auxiliary control system. It should be understood that during operation, the thermal power plant auxiliary control system records various network activities according to specific formats and rules, such as detailed information such as internal network access behaviors, resource requests, and operational instructions, forming a network log. Therefore, by obtaining network log data from the thermal power plant auxiliary control system as the basic data source for network security threat analysis, this application can comprehensively understand system access, resource usage, and possible abnormal behaviors, thereby providing rich information support for subsequent security threat classification.

[0036] Specifically, first, it's necessary to identify all log sources that can generate useful log data. This requires a detailed inventory of the entire thermal power plant's auxiliary control systems to clearly identify which devices and systems generate log information that can aid in network security analysis. For example, network devices typically provide data on traffic statistics, access control list (ACL) matches, and security events; servers and workstations may contain application logs, operating system events, user activity records, and other information. Logs from control systems and auxiliary facilities are equally important, reflecting the operational status and security posture of critical physical processes. This comprehensive inventory allows for the creation of a comprehensive list of log sources to guide subsequent work.

[0037] Next, for each identified log source, the logging settings need to be adjusted for each identified source. This involves modifying the configuration parameters of various devices and software applications to ensure that they can capture sufficiently detailed information to support in-depth security analysis. This means that it may be necessary to increase the log level and enable specific types of logging functions (such as operation auditing and failed login attempt logging), and also consider the impact of these settings on system performance. Excessive logging may consume a lot of computing resources and cause the system to respond more slowly, so it is necessary to find a balance between ensuring the amount of information required for security analysis and not affecting normal business operations. In addition, for those devices or systems that do not directly support standard logging protocols, it is necessary to explore customized solutions, such as writing scripts or using third-party tools to capture the necessary data.

[0038] Next, establish a centralized log management platform that can receive log data from various sources, whether through standard protocols (such as Syslog, SNMP) or proprietary APIs. To improve efficiency and reduce latency, the platform should ideally be deployed at the core of the network architecture to facilitate the rapid collection of log information distributed throughout the factory. Furthermore, ensure that the platform has sufficient storage capacity and processing power to handle the influx of massive log data.

[0039] Considering the security of log data, it needs to be encrypted during transmission. Using encrypted communication methods such as SSL / TLS can effectively prevent sensitive information from being stolen or tampered with during transmission, ensuring the authenticity and confidentiality of log data. It is also crucial to implement strict access control policies on the centralized log management platform. Only authorized administrators and technicians can view and manipulate this data, further enhancing security. This can be achieved through role-based access control (RBAC) or other authentication and authorization mechanisms. Additionally, access rights should be regularly reviewed and updated to ensure they remain compliant with current security requirements and organizational policies.

[0040] After all log data enters the centralized management platform, it is standardized. Since the log formats generated by different devices and systems may vary greatly, converting them into a unified standard format can make cross-platform comparison and correlation analysis easier. In this process, adding timestamps and other metadata is also very helpful, which provides additional contextual information for each log record, helping to more accurately track the timeline and development of events. For example, combining geographic location information can help identify whether abnormal behavior is related to a specific location; and additional operator identification can reveal potential human factors. By standardizing log data, not only the quality of data analysis is improved, but also a solid foundation is laid for future automated analysis and machine learning model training.

[0041] In the aforementioned method for classifying network security threats for a thermal power plant auxiliary control system, step S2 extracts the time series of access records and system resource usage information from the network log data. It should be understood that this application considers that access records and system resource usage information are two important aspects reflecting the system's operating status and network activity. These two are interrelated and together describe the overall behavior of the system. Therefore, this application further extracts access records and system resource usage information from the network log data and presents them in the form of time series to facilitate analysis of system behavior patterns and resource usage changes at different time points, thereby identifying potential security threats. Specifically, the access record information includes the source IP address, target IP address, port, time of access, target resource, and access operation type. Access violations that do not conform to normal access patterns, such as access from abnormal IP addresses, unauthorized port access, or a large number of accesses during non-working hours, may indicate external attacks or internal violations. Therefore, the threat category can be determined based on the characteristics of these abnormal behaviors and the potential attack intent. The system resource usage information includes CPU usage, memory utilization, network bandwidth utilization, and disk I / O rate. If the resource usage of a device or system suddenly increases abnormally, it may be due to malicious programs such as viruses and Trojans running in the background, or it may have suffered a DDoS attack. Therefore, the type of security threat that may exist can be inferred based on the abnormal changes in resource usage.

[0042] For different types of log sources, appropriate parsing tools and techniques need to be developed or selected. For log files in standard formats (such as Syslog), you can use ready-made log parsing libraries or frameworks (such as Logstash, Fluentd) to quickly extract the required fields. However, when faced with logs in non-standard or custom formats, you may need to write special parsing scripts and use regular expressions or other text processing methods to accurately extract specific information. In addition, considering that some advanced applications may generate log data in binary format, corresponding decoders are also needed to restore its original content. It is very important to maintain flexibility and scalability throughout the parsing process, because the log format and content may change over time, and the parsing logic also needs to be adjusted accordingly to adapt to new situations.

[0043] After parsing is complete, the next step is to construct a time series. This requires sorting the events scattered across the various log entries according to timestamps and organizing them into a continuous data stream. To achieve this, a unified time base is usually introduced to ensure that log records from different sources can be compared on the same timeline. On this basis, different time windows or sampling frequencies can be further set according to specific analysis needs. For example, if you want to study transient behavior in the short term, you can choose a smaller time interval (such as seconds or minutes); for observing long-term trends, you can use a larger time unit (such as hours or days). In this way, more refined and targeted time series data can be obtained, providing support for subsequent in-depth analysis.

[0044] For the time series of access records, the focus is on capturing the user's interactive behavior and its changing patterns over time. This involves more than just simple event counting, but also a comprehensive consideration of factors such as user identity, access target, and operation type. For example, by counting the number of requests initiated by different users in each time period, an activity curve can be drawn; or a user behavior graph can be constructed based on the access path and command sequence. At the same time, special attention should be paid to uncommon or abnormal behavior patterns, such as a large number of failed login attempts in a short period of time, frequent access to sensitive resources, etc. Such behavior patterns may be signs of malicious activity. By paying attention to these details, a more comprehensive understanding of the normal behavior range can be achieved, making it easier to detect deviations from the norm.

[0045] The time series of system resource usage information focuses on reflecting the dynamic changes in device performance and load status. This part of the work aims to establish a comprehensive performance indicator system that covers all aspects, from the hardware level to the software application. For example, for servers, key parameters such as CPU utilization, memory usage, disk read / write speed, and network bandwidth can be monitored; in control systems, physical quantities such as temperature, pressure, and flow can also be monitored. By continuously tracking the changing trends of these indicators, not only can the health of the system be assessed, but also potential problems can be warned in advance. It is worth noting that in complex networks composed of multiple devices, the impact of cross-device interactions must also be considered. For example, whether the high load of one server will lead to a decline in the service quality of other connected devices. Therefore, when constructing time series of system resource usage, in addition to the data within individual devices, the interactions within the overall network environment should also be considered.

[0046] Finally, to improve the quality and usability of time series data, a series of data cleaning and preprocessing tasks are required. This includes removing duplicate records, filling missing values, and correcting erroneous data. Especially when dealing with large-scale log data sets, effective data cleaning strategies can significantly reduce noise interference and improve the reliability of subsequent analysis results. For example, obviously unreasonable or impossible values (such as negative CPU utilization) can be directly excluded. For accidentally missing timestamps, reasonable inferences can be made based on the time difference between the previous and next records to complete the missing timestamps.

[0047] In the above-mentioned network security threat classification method for the auxiliary control system of a thermal power plant, the step S3 extracts the access behavior temporal pattern features from the time series of the access records to obtain the access behavior temporal pattern feature encoding vector. Figure 3 Flowchart of sub-step S3 of the method for classifying network security threats of auxiliary control system of thermal power plant according to the embodiment of the present application. Figure 3 As shown, the step S3 includes the following steps: S31, performing semantic embedding coding on each access record in the time series of the access records to obtain a time series of access record embedding coding feature vectors; S32, inputting the time series of the access record embedding coding feature vectors into the access behavior temporal pattern feature extraction module based on the LSTM model to obtain the access behavior temporal pattern feature coding vector.

[0048] Specifically, the step S31 performs semantic embedding coding on each access record in the time series of the access records to obtain a time series of access record embedding coding feature vectors. Specifically, considering that different access events may have unique semantic meanings, in order to more accurately describe and distinguish different access behaviors, the present application adopts an embedding coding technology based on deep learning, which captures the semantic meaning of the access record, such as the credibility of the access source IP address, the sensitivity of the access target resource, etc., by mapping each access record into a high-dimensional feature space, thereby obtaining an access record embedding coding feature vector that can fully express the semantic behavior information of each access record. In a specific example of the present application, an embedding coding model based on a deep neural network, such as Word2Vec, BERT, etc., is used to perform semantic modeling on each access record, so as to utilize the powerful semantic understanding ability of the deep learning model to convert the key information in the access record into a high-dimensional vector representation, thereby achieving an accurate characterization of the access behavior.

[0049] Specifically, in step S32, the time series of the access record embedded coding feature vector is input into the access behavior temporal pattern feature extraction module based on the LSTM model to obtain the access behavior temporal pattern feature coding vector. It should be understood that since the network access behavior in the auxiliary control system of the thermal power plant usually shows a certain temporal sequence and correlation, that is, some access behaviors may appear in a certain order or pattern. Therefore, in order to accurately capture the changing patterns and laws of the system access behavior over time, the present application adopts the LSTM (long short-term memory neural network) model to perform temporal analysis on the time series of the access record embedded coding feature vector. Those skilled in the art should know that the LSTM model is a special recurrent neural network (RNN), which can effectively handle the time dependency problem in long sequence data by introducing mechanisms such as memory units and forget gates, thereby more accurately extracting the temporal pattern characteristics of the access behavior. After the time series of the access record embedded in the encoding feature vector is input into the LSTM model, the model will gradually analyze each access record according to the order of the time series, and comprehensively consider the state information of the previous time step. Finally, it outputs the access behavior time series pattern feature encoding vector containing the global temporal dependency relationship, thereby characterizing the changing laws and patterns of system access behavior over time, providing strong information support for subsequent security threat classification.

[0050] In the above-mentioned network security threat classification method for the auxiliary control system of a thermal power plant, the step S4 extracts resource usage status characteristics from the time series of the system resource usage information to obtain a system resource usage status characteristic diagram. Figure 4 Flowchart of sub-step S4 of the method for classifying network security threats of auxiliary control system of thermal power plant according to the embodiment of the present application. Figure 4As shown, the step S4 includes the following steps: S41, arranging the time series of the system resource usage information into a system resource usage status matrix according to the parameter sample dimension and the time dimension; S42, inputting the system resource usage status matrix into a system resource usage status feature extraction module based on a void convolution layer to obtain the system resource usage status feature graph.

[0051] Specifically, the step S41 arranges the time series of the system resource usage information into a system resource usage status matrix according to the parameter sample dimension and the time dimension. It should be understood that, considering that the system resource usage information includes resource usage data of multiple dimensions, such as CPU usage, memory occupancy, etc., its time series data not only reflects the changes in the system resource usage status at different time points, but also includes the correlation and mutual influence between multiple resource usage dimensions at the same time. Therefore, in order to comprehensively analyze the correlation and influence between multiple resource usage dimensions and their changing trends over time, the present application further arranges the time series of the system resource usage information according to the parameter sample dimension and the time dimension to form a two-dimensional system resource usage status matrix, so as to better display the distribution and changes of the system resource usage information in different parameters and time dimensions, and provide a more effective data framework for subsequent data analysis.

[0052] Specifically, in step S42, the system resource usage status matrix is input into the system resource usage status feature extraction module based on the dilated convolution layer to obtain the system resource usage status feature graph. It should be understood that dilated convolution is a special convolution operation that increases the receptive field of the convolution kernel by inserting holes in the convolution kernel, thereby being able to capture contextual information in a wider range without increasing the computational complexity. In the present application, by performing a convolution operation on the system resource usage status matrix using a dilated convolution layer, the long-distance dependencies in the system resource usage status matrix can be better captured, and the temporal variation trends of each resource usage parameter and the mutual dependencies between the parameters can be extracted, thereby generating a more representative system resource usage status feature graph.

[0053] In the aforementioned method for classifying network security threats for a thermal power plant auxiliary control system, step S5 performs a cross-domain, fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature encoding vector and the system resource usage status feature graph to obtain a cross-modal, fine-grained aggregation encoding feature vector for access behavior and system resource usage. It should be understood that access behavior and system resource usage are two important aspects of the security status of a thermal power plant auxiliary control system, and there is a complex interaction and correlation between the two. Specifically, when a large number of access behaviors are concentrated in a certain time period, especially accesses to specific services or applications, it directly leads to an increase in system resource utilization. For example, if a large number of clients access and read a data file on a server within a short period of time, the server's CPU needs to process these requests, resulting in a significant increase in CPU utilization. At the same time, normal and regular access behavior generally corresponds to a stable system resource usage state. For example, access behaviors triggered by periodic data collection tasks at fixed times each day will result in a predictable and stable usage pattern of system resources within that time period. However, abnormal access behavior, such as distributed denial of service (DDoS) attacks, a large number of malicious requests will quickly exhaust system resources, CPU usage will soar to 100%, memory will be filled with a large amount of useless request data, network bandwidth will be occupied by malicious traffic, and disk I / O will become abnormally busy due to a large amount of invalid temporary data storage and reading operations. When the system resource usage status fluctuates abnormally, it may also imply the existence of abnormal access behavior. For example, in the absence of normal business operations, the system memory occupancy rate suddenly increases significantly, which may be due to a memory leak attack, which is often accompanied by abnormal access behavior. Based on this, the present application further conducts a joint analysis of access behavior and system resource usage status to deeply explore the potential correlation and interaction mechanism between the two, so as to achieve accurate identification of security threats.

[0054] Figure 5 Flowchart of sub-step S5 of the method for classifying network security threats of auxiliary control system of thermal power plant according to the embodiment of the present application. Figure 5 As shown, the step S5 includes the steps of: S51, performing feature decoupling and feature flattening on the system resource usage status feature graph to obtain a set of local feature vectors of the system resource usage status; S52, calculating the cluster center between the set of local feature vectors of the system resource usage status and the access behavior temporal pattern feature coding vector to obtain the access behavior-system resource usage prior cluster center coding vector; S53, inputting the access behavior-system resource usage prior cluster center coding vector and the set of local feature vectors of the system resource usage status into a cross-domain fine-grained aggregation descriptor based on the cluster center to obtain the access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector.

[0055] Specifically, in step S51, feature decoupling and feature flattening are performed on the system resource usage state feature graph to obtain a set of local feature vectors of the system resource usage state, which is expressed as follows:

[0056] X=decouple(F2)={x1,x2,...,x i ,x j ,...,x n}

[0057] Among them, F2 represents the system resource usage state feature map, decouple (·) feature decoupling processing, X represents the set of local feature vectors of the system resource usage state, x1, x2, x i 、x j and x n They respectively represent the first, second, i-th, j-th and n-th system resource usage status local feature vectors in the set of system resource usage status local feature vectors, and n is the number of the system resource usage status local feature vectors.

[0058] Specifically, in order to achieve cross-domain aggregation interaction between the access behavior temporal pattern feature encoding vector and the system resource usage status feature graph, it is necessary to unify the data dimensions of the two. Since the traditional pooling method will cause indiscriminate information loss when performing feature dimensionality reduction, it may lead to the loss of key feature information, affecting the model's accurate judgment of the system resource usage status. Based on this, in the technical solution of the present application, the system resource usage status feature graph is first subjected to feature decoupling and feature flattening processing to decompose it into a set of finer-grained system resource usage status local feature vectors.

[0059] Specifically, in a specific example of the present application, step S52 includes: first, inputting the set of local feature vectors of the system resource usage status into a modal kernel feature extraction network to obtain a kernel semantic feature encoding vector of the system resource usage status, which is expressed as follows:

[0060]

[0061] Among them, KFDN represents the modal kernel feature extraction network, D i Indicates the x i The semantic difference factor relative to the set of local feature vectors of the system resource usage status, ‖·‖1 represents the norm of the vector, exp represents the exponential function with base e, and v2 represents the kernel semantic feature encoding vector of the system resource usage status.

[0062] Here, by further using the modal kernel feature extraction network to process the set of local feature vectors of the system resource usage status, it is possible to ensure that more core and representative semantic features are extracted while performing feature dimensionality reduction, so as to retain the key information in the system resource usage status feature graph and avoid the loss of important details, thereby generating a system resource usage status kernel semantic feature encoding vector, providing high-quality data input for subsequent feature interaction analysis.

[0063] Then, based on the access behavior temporal pattern feature coding vector and the system resource usage state kernel semantic feature coding vector, the access behavior-system resource usage prior cluster center coding vector is determined, which is expressed as:

[0064] v c =W c [v1; v2]+b c

[0065] Wherein, v1 represents the characteristic coding vector of the access behavior temporal pattern, W c represents the weight matrix, [·;·] represents the cascade, b c represents the bias vector, v c Representing the access behavior - system resource usage prior cluster center encoding vector.

[0066] Specifically, a neural network model performs cross-domain correlation learning on the dimensionally unified access behavior temporal pattern feature encoding vectors and the system resource usage status kernel semantic feature encoding vectors to capture the potential correlation between system resource usage status and access behavior. This allows the model to predict and set a cluster center in the high-dimensional feature space that focuses on the core correlation between system resource usage status and access behavior, generating an access behavior-system resource usage prior cluster center encoding vector. It should be understood that this access behavior-system resource usage prior cluster center encoding vector reflects the key correlation between system resource usage status and access behavior, serving as an important reference point for subsequent feature interaction analysis. It helps guide the model to more accurately focus on the potential connections and interaction patterns between the two, thereby enhancing the ability to identify security threats.

[0067] Specifically, in step S53, the set of the access behavior-system resource usage prior cluster center encoding vector and the system resource usage status local feature vector is input into the cluster center-based cross-domain fine-grained aggregation descriptor to obtain the access behavior-system resource usage cross-modal fine-grained aggregation encoding feature vector, which is expressed as follows:

[0068]

[0069] Among them, r i(x i ,v c ) represents the x i and the v c The Poincare distance between them, arccosh represents the inverse hyperbolic cosine function, τ represents the gate threshold, a(x i ) represents the x i The corresponding gated clustering weight coefficient, x i (j) represents the eigenvalue of the jth position in the local eigenvector of the i-th system resource usage status, v c (j) represents the feature value of the j-th position in the kernel semantic feature encoding vector of the system resource usage status, and V represents the access behavior-system resource usage cross-modal fine-grained aggregate encoding feature vector.

[0070] That is, the access behavior-system resource usage prior cluster center encoding vector is used as a fine-grained interaction anchoring prior bridge, and a fine-grained aggregation analysis is performed on the set of local feature vectors of the system resource usage status to generate an access behavior-system resource usage cross-modal fine-grained aggregation encoding feature vector. It should be understood that the access behavior-system resource usage prior cluster center encoding vector is constructed in a cross-domain feature space based on the feature association between the system resource usage status and the access behavior. Using it as an anchor for fine-grained interaction ensures that data from different modalities maintain their respective characteristics and meanings during the fusion process, while enhancing the understanding of the complex interaction between the two. The final cross-modal fine-grained aggregation encoding feature vector not only retains the key information of the original data, but also reveals the deep connection between access behavior and system resource usage, thereby improving the accuracy and reliability of security threat detection.

[0071] In the above-mentioned network security threat classification method for the auxiliary control system of a thermal power plant, the step S6 determines the type label of the network security threat based on the access behavior-system resource usage cross-modal fine-grained aggregated coding feature vector. In a specific example of the present application, the step S6 includes: inputting the access behavior-system resource usage cross-modal fine-grained aggregated coding feature vector into a classifier-based network security threat identification module to obtain the type label of the network security threat. More specifically, the step S6 includes: using the fully connected layer of the network security threat identification module to fully connect encode the access behavior-system resource usage cross-modal fine-grained aggregated coding feature vector to obtain the access behavior-system resource usage cross-modal fine-grained aggregated fully connected coding feature vector; inputting the access behavior-system resource usage cross-modal fine-grained aggregated fully connected coding feature vector into the Softmax classification function of the network security threat identification module to obtain the probability value of the access behavior-system resource usage cross-modal fine-grained aggregated coding feature vector belonging to each network security threat type label; and determining the network security threat type label corresponding to the largest of the probability values as the type of the network security threat.

[0072] Specifically, the network security threat identification module first uses a fully connected layer to further encode the access behavior-system resource usage cross-modal fine-grained aggregated encoding feature vector to generate a more expressive and compact feature representation. After processing through multiple layers of fully connected layers, the final output is a low-dimensional vector that not only retains the key information of the original data, but also highlights the intrinsic connection between access behavior and system resource usage, while improving computational efficiency. Subsequently, the probability values of the access behavior-system resource usage cross-modal fine-grained aggregated encoding feature vector corresponding to different classification labels are calculated using the Softmax classification function. Each classification label represents a specific type of network security threat, such as normal access, malware attack, DDoS attack, SQL injection attack, etc. For each possible classification label, the Softmax function will give a value between 0 and 1, and all these values add up to 1. Finally, the classification label corresponding to the maximum probability value is selected as the type output of the network security threat.

[0073] After confirming the type label of the network security threat, the emergency response procedure needs to be initiated immediately. This includes assessing the scope and severity of the threat to determine the level of response measures to be taken. For threats that may have a serious impact on system stability (such as attacks that may cause power production interruptions or damage to physical equipment), priority should be given to implementing emergency containment strategies. For example, the threat can be prevented from spreading further by disconnecting the affected network segment, isolating infected equipment, or temporarily shutting down certain critical services. The emergency response team should also develop a detailed recovery plan to clarify how to gradually restore normal operations without affecting the security of the overall system.

[0074] Next, it is necessary to review in detail all log data, access records, and time series of system resource usage information related to the incident, looking for any abnormal patterns or clues to suspicious activities. Using the time series data constructed previously, you can more intuitively observe the changes in system status before and after the incident, helping to locate the root cause of the problem. In addition, you can combine other auxiliary information sources, such as network traffic packet capture files (PCAP), malware samples, etc., to conduct a comprehensive multi-angle analysis. If an external attacker is involved, it is also necessary to cooperate with the network security intelligence sharing platform to obtain the latest threat intelligence to better understand the attacker's background and technical means. Through this comprehensive investigation method, not only can the specific nature of the incident be accurately determined, but it can also provide valuable reference experience for the occurrence of similar incidents in the future.

[0075] After completing the initial investigation, the attacked components need to be repaired. This may include removing malicious code, patching vulnerabilities, updating security configurations, and reinstalling compromised applications. It is particularly important to exercise caution when performing these repair operations to ensure that no new risks are introduced. For example, before applying a patch, its compatibility and effectiveness should be tested in an isolated environment; and when changing security settings, the potential impact on normal business processes should be fully considered. In addition, hardware components that have lost trust due to the attack should be replaced promptly to completely eliminate security risks. The entire repair process needs to be carried out in an orderly manner and strictly adhere to established operating procedures to ensure that each step is effectively verified and recorded.

[0076] In summary, a network security threat classification method for the auxiliary control system of a thermal power plant based on the embodiment of the present application is explained, which first extracts time series data of access records and system resource usage information from the network log data of the auxiliary control system of the thermal power plant, and then further introduces data analysis technology based on deep learning to perform time series analysis on the access records and system resource usage information respectively, so as to respectively mine the time series correlation change patterns of system access behavior and system resource usage status, and through fine-grained cross-modal correlation learning of the two, to reveal the inherent correlation characteristics between network access behavior and system resource usage status, so as to realize intelligent identification and classification of network security threats existing in the auxiliary control system of the thermal power plant on this basis. In this way, the detection capability of complex attack behaviors can be significantly improved, thereby improving the accuracy and real-time performance of network security protection.

[0077] Furthermore, a network security threat classification system for an auxiliary control system of a thermal power plant is also provided.

[0078] Figure 6 FIG is a block diagram of a network security threat classification system for a thermal power plant auxiliary control system according to an embodiment of the present application. Figure 6 As shown, according to the embodiment of the present application, the network security threat classification system 100 of the auxiliary control system of the thermal power plant includes: a network log data collection module 110, which is used to obtain the network log data of the auxiliary control system of the thermal power plant; a time series extraction module 120, which is used to extract the time series of access records and the time series of system resource usage information from the network log data; an access behavior feature encoding module 130, which is used to extract the access behavior temporal pattern features from the time series of the access records to obtain the access behavior temporal pattern feature encoding vector; a resource usage status feature extraction module 140, which is used to extract the resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph; an aggregation analysis module 150, which is used to perform cross-domain fine-grained aggregation analysis on the access behavior temporal pattern feature encoding vector and the system resource usage status feature graph based on clustering centers to obtain an access behavior-system resource usage cross-modal fine-grained aggregation encoding feature vector; a threat identification module 160, which is used to determine the type label of the network security threat based on the access behavior-system resource usage cross-modal fine-grained aggregation encoding feature vector.

[0079] Here, those skilled in the art will appreciate that the specific operations of each module in the above-mentioned network security threat classification system for the auxiliary control system of the thermal power plant have been referenced above. Figures 1 to 5 The network security threat classification method of the auxiliary control system of a thermal power plant has been introduced in detail, and therefore, its repeated description will be omitted.

[0080] The basic principles of the present invention have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in the present invention are merely illustrative and non-limiting, and should not be construed as necessarily possessed by each embodiment of the present invention. Furthermore, the specific details of the above embodiments are provided for illustrative purposes and to facilitate understanding, and are not intended to be limiting. These details do not necessarily limit the present invention to being implemented using these specific details.

[0081] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described or recorded in detail in a particular embodiment, please refer to the relevant descriptions of other embodiments. In the several embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the unit division described is only a logical function division, and other division methods may be used in actual implementation.

[0082] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be encompassed therein. Any reference to a figure in a claim should not be construed as limiting the claim to which it relates.

[0083] Finally, it should be noted that the above description has been provided for purposes of illustration and description. Furthermore, the above embodiments are intended only to illustrate the technical solutions of the present invention and are not intended to be limiting. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art will appreciate that the technical solutions of the present invention may be modified or replaced with equivalents without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for classifying network security threats of auxiliary control systems of thermal power plants, characterized in that: include: Obtain network log data from the auxiliary control system of a thermal power plant; extracting a time series of access records and a time series of system resource usage information from the network log data; Extracting access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature encoding vector; Extracting resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph; Performing cross-domain fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature coding vector and the system resource usage state feature graph to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector; Based on the access behavior-system resource, a cross-modal fine-grained aggregated encoding feature vector is used to determine the type label of the network security threat.

2. The network security threat classification method for the auxiliary control system of a thermal power plant according to claim 1 is characterized in that: The access record includes the access source IP address, access target IP address, access port, access time, access target resource and access operation type, and the system resource usage information includes CPU usage, memory occupancy, network bandwidth occupancy and disk I / O rate.

3. The network security threat classification method for the auxiliary control system of a thermal power plant according to claim 2 is characterized in that: Extracting access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature encoding vector includes: Performing semantic embedding coding on each access record in the time series of the access records to obtain a time series of access record embedding coding feature vectors; The time series of the access record embedded coding feature vector is input into the access behavior temporal pattern feature extraction module based on the LSTM model to obtain the access behavior temporal pattern feature coding vector.

4. The network security threat classification method for the auxiliary control system of a thermal power plant according to claim 3 is characterized in that: Extracting resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph includes: Arranging the time series of the system resource usage information into a system resource usage state matrix according to the parameter sample dimension and the time dimension; The system resource usage state matrix is input into a system resource usage state feature extraction module based on a dilated convolutional layer to obtain the system resource usage state feature graph.

5. The method for classifying network security threats of a thermal power plant auxiliary control system according to claim 4 is characterized in that: Performing a cross-domain fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature coding vector and the system resource usage state feature graph to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector, including: Performing feature decoupling and feature flattening on the system resource usage state feature graph to obtain a set of local feature vectors of the system resource usage state; Calculating the cluster center between the set of local feature vectors of the system resource usage state and the feature coding vector of the access behavior temporal pattern to obtain an access behavior-system resource usage prior cluster center coding vector; The set of the access behavior-system resource usage prior cluster center encoding vector and the system resource usage status local feature vector is input into the cluster center-based cross-domain fine-grained aggregation descriptor to obtain the access behavior-system resource usage cross-modal fine-grained aggregation encoding feature vector.

6. The method for classifying network security threats of a thermal power plant auxiliary control system according to claim 5 is characterized in that: Calculating the cluster center between the set of the system resource usage state local feature vectors and the access behavior temporal pattern feature encoding vector to obtain an access behavior-system resource usage prior cluster center encoding vector, including: Inputting the set of system resource usage status local feature vectors into a modal kernel feature extraction network to obtain a system resource usage status kernel semantic feature encoding vector; The access behavior-system resource usage prior clustering center encoding vector is determined based on the access behavior temporal pattern feature encoding vector and the system resource usage status kernel semantic feature encoding vector.

7. The method for classifying network security threats of a thermal power plant auxiliary control system according to claim 6 is characterized in that: Based on the access behavior-system resource, a cross-modal fine-grained aggregated encoding feature vector is used to determine the type label of the network security threat, including: The access behavior-system resource is encoded using a cross-modal fine-grained aggregated encoding feature vector and input into a classifier-based network security threat identification module to obtain a type label of the network security threat.

8. The method for classifying network security threats of a thermal power plant auxiliary control system according to claim 7 is characterized in that: The access behavior-system resource is encoded using a cross-modal fine-grained aggregated encoding feature vector and input into a classifier-based network security threat identification module to obtain a type label of the network security threat, including: Using the fully connected layer of the network security threat identification module, the access behavior-system resource usage cross-modal fine-grained aggregated encoding feature vector is fully connected to obtain the access behavior-system resource usage cross-modal fine-grained aggregated fully connected encoding feature vector; Inputting the access behavior-system resource usage cross-modal fine-grained aggregated fully connected encoded feature vector into the Softmax classification function of the network security threat identification module to obtain a probability value of the access behavior-system resource usage cross-modal fine-grained aggregated encoded feature vector belonging to each network security threat type label; The network security threat type label corresponding to the largest probability value among the probability values is determined as the type of the network security threat.

9. A network security threat classification system for auxiliary control systems of thermal power plants, characterized by: include: Network log data collection module, used to obtain network log data of the auxiliary control system of the thermal power plant; A time series extraction module, configured to extract the time series of access records and the time series of system resource usage information from the network log data; An access behavior feature encoding module, configured to extract access behavior temporal pattern features from the time series of the access records to obtain an access behavior temporal pattern feature encoding vector; a resource usage status feature extraction module, configured to extract resource usage status features from the time series of the system resource usage information to obtain a system resource usage status feature graph; An aggregation analysis module is used to perform cross-domain fine-grained aggregation analysis based on cluster centers on the access behavior temporal pattern feature coding vector and the system resource usage state feature graph to obtain an access behavior-system resource usage cross-modal fine-grained aggregation coding feature vector; The threat identification module is used to determine the type label of the network security threat based on the access behavior-system resource using a cross-modal fine-grained aggregated encoding feature vector.

Citation Information

Patent Citations

  • Automatic control system and method of storage robot

    CN119668181A

  • Dynamic monitoring system for mine tunneling process

    CN119878304A

  • Test method and system of mobile communication indoor signal monitor and storage medium

    CN120512692A