Feature extraction method for abnormal data of power optical transmission network and related equipment
By constructing a timing feature matrix of abnormal data in the power optical transmission network, capturing the time evolution law of monitoring indicators, the problem of insufficient identification capabilities in the existing technology is solved, and efficient real-time monitoring and threat identification of the power optical transmission network is achieved.
Patent Information
- Application Number
- CN202510376157.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-03-27
AI Technical Summary
The prior art is difficult to effectively identify abnormal data features in power optical transmission networks, resulting in insufficient recognition of network attacks and complex model construction, which may lead to overfitting or insufficient fitting, and the inability to fully cover potential security threats.
By obtaining monitoring data of network element equipment in the power optical transmission network, setting monitoring indicators, building a timing feature matrix of abnormal data, capturing the time evolution law of abnormal data and complex correlation, reducing redundant features, and accurately identifying the exclusive threat of the power optical transmission network.
It improves the real-time monitoring capabilities of the power optical transmission network, reduces the rate of misjudgment, enhances the ability to identify network attacks, and prevents network failures or malicious attacks.
Smart Images

Figure CN120474732A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power optical transmission networks, and in particular to a method for extracting features of abnormal data in power optical transmission networks and related equipment. Background Art
[0002] With the development of smart grids, power optical transmission networks are playing an increasingly important role in supporting safe production and operational management of power grids. However, with their widespread application, cyberattacks on power optical transmission networks should not be underestimated. A failure in the power optical transmission network can cause significant damage to the entire power communication system.
[0003] In related technologies, features of abnormal data that cause abnormal events in power optical transmission networks are first extracted. Based on these features, a neural network model is then built to determine whether the power optical transmission network has been attacked. However, this method generates a large number of similar feature values when extracting features and is unable to extract features with complex relationships. This also complicates model construction during subsequent modeling, potentially leading to overfitting or underfitting during model training. Consequently, the model may not fully cover all potential security threat scenarios, resulting in insufficient recognition of some abnormal events. Summary of the Invention
[0004] In view of this, the present application provides a feature extraction method and related equipment for abnormal data of an electric power optical transmission network, which extracts the features of highly nonlinear and separable abnormal data from a large amount of monitoring data of network element devices in the electric power optical transmission network, providing an accurate basis for real-time monitoring of the electric power optical transmission network, and preventing the electric power optical transmission network from failures or malicious attacks.
[0005] According to one aspect of the present application, a method for extracting features from abnormal data in a power optical transmission network is provided, comprising:
[0006] Obtain monitoring data of monitoring indicators of network element equipment in the power optical transmission network within a preset monitoring period;
[0007] Determining data of the monitoring indicator that does not fall within a preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator;
[0008] Constructing a time series feature matrix of abnormal data of the monitoring indicators;
[0009] Determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator;
[0010] According to the characteristics of the abnormal data of the monitoring indicator, the characteristics of the abnormal data in the power optical transmission network are determined.
[0011] According to another aspect of the present application, a device for extracting features of abnormal data in a power optical transmission network is provided, comprising:
[0012] An acquisition module is used to obtain monitoring data of monitoring indicators of network element devices in the power optical transmission network within a preset monitoring period;
[0013] a determination module, configured to determine data in the monitoring data of the monitoring indicator that does not conform to a preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator; and
[0014] Constructing a time series feature matrix of abnormal data of the monitoring indicators; and
[0015] Determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator; and
[0016] According to the characteristics of the abnormal data of the monitoring indicator, the characteristics of the abnormal data in the power optical transmission network are determined.
[0017] According to another aspect of the present application, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the feature extraction method of abnormal data of the power optical transmission network are implemented.
[0018] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the program, the steps of the feature extraction method for abnormal data of the power optical transmission network are implemented.
[0019] By means of the above technical solution, the present application provides a method for extracting features of abnormal data of an electric power optical transmission network and related equipment. The method described in the present application sets monitoring indicators based on the data involved in the actual operation of the network element equipment of the electric power optical transmission network, so as to monitor the network element equipment according to the monitoring indicators. Then, the features of the abnormal data of each monitoring indicator are extracted from a large amount of monitoring data of the network element equipment, which is different from the general network security features, and the exclusive threats of the electric power optical transmission network are accurately identified. At the same time, in the process of extracting the features of the abnormal data, the time factor is introduced to capture the time evolution law and complex association of the abnormal data of each monitoring indicator, reduce redundant features, and support dynamic monitoring of the network attack process, thereby providing an accurate basis for the real-time monitoring of the electric power optical transmission network, preventing the electric power optical transmission network from malfunctioning or being attacked maliciously, and improving the coverage rate of abnormal events during the monitoring process.
[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0022] Figure 1 A schematic diagram showing a flow chart of a method for extracting features of abnormal data in a power optical transmission network provided by an embodiment of the present application is shown;
[0023] Figure 2 The structural block diagram of the feature extraction device for abnormal data of the power optical transmission network provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0024] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.
[0025] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and are not to be construed as limiting the present application.
[0026] It will be understood by those skilled in the art that, unless expressly stated otherwise, the singular forms "a", "an", "said" and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of this application refers to the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "connected" to another element, it may be directly connected or connected to the other element, or there may be intermediate elements. In addition, "connected" or "connected" as used herein may include wireless connection or wireless fusion. The term "and / or" used herein includes all or any unit and all combinations of one or more associated listed items.
[0027] Now, exemplary embodiments according to the present application will be described in more detail with reference to the accompanying drawings. However, these exemplary embodiments may be implemented in a variety of different forms and should not be construed as being limited to the embodiments set forth herein. It should be understood that these embodiments are provided to make the disclosure of this application thorough and complete and to fully convey the concepts of these exemplary embodiments to those of ordinary skill in the art.
[0028] In this embodiment, a method for extracting features of abnormal data in a power optical transmission network is provided. Figure 1 As shown, the method includes:
[0029] Step 101: Acquire monitoring data of monitoring indicators of network element devices in a power optical transmission network within a preset monitoring period.
[0030] Here, the power optical transmission network is the communication infrastructure of the power system, specifically used to transmit key power business data such as power dispatching, real-time monitoring, and relay protection.
[0031] In actual application scenarios, network element devices (such as SDH (Synchronous Digital Hierarchy) devices or OTN (Optical Transport Network) devices) are usually placed in substations at different levels (such as provincial or county levels). The network element devices are connected by optical cable lines to form a power optical transmission network. The network element devices are equipped with service network ports and management network ports. The network element devices communicate with each other through the service network ports to transmit data related to power services. The network element devices communicate with the network management system corresponding to the power optical transmission network through their management network ports, so that the network management system can perform network management on the network element devices and realize efficient operation and maintenance of the power optical transmission network.
[0032] Currently, power optical transmission networks lack situational awareness of cyberattack threats. The network management system's alert function only addresses physical failures, such as equipment and fiber optic cable failures. It fails to effectively monitor incidents that threaten network security, such as abnormal logins to devices and network management, file access and modification, and unauthorized process startups.
[0033] In this embodiment, the network element devices in the power optical transmission network are monitored so that in subsequent steps, network security situation awareness of the power optical transmission network is performed based on the monitoring data of the network element devices, and perception factors of abnormal events in the power optical transmission network (i.e., characteristics of abnormal data) are extracted to provide an accurate basis for real-time monitoring of the network element devices, thereby preventing the network element devices from malfunctioning or being attacked maliciously.
[0034] Specifically, a probe is installed in the network element device. The probe is a tool software for reading data. The probe reads the power service data sent by the network element device to other network elements during the preset monitoring cycle, as well as the network element device's own hardware operating status data. This data is then sent to the network management system through the network element device's management interface. The network management system then obtains a large amount of monitoring data from the network element device during the preset monitoring cycle.
[0035] It's worth noting that in this embodiment, monitoring indicators for network element devices are set based on the power service data and hardware operating status data (i.e., data transmitted by the network element devices). This allows the large amount of monitoring data from the network element devices within a preset monitoring period to be organized into monitoring data for each monitoring indicator. In subsequent steps, the perception factors of abnormal events corresponding to each monitoring indicator in the power optical transmission network are specifically extracted, distinguished from general network security features, and accurately identified threats specific to the power optical transmission network.
[0036] Here, the monitoring data exists in the form of data packets.
[0037] Exemplarily, monitoring indicators may cover aspects such as power services, network element equipment hardware operating status, security policy access, host login, peripheral access, key file changes, network port status, and switch mirror traffic. Among them, power services may include voltage, power value, reactive power compensation value, active power, etc.; hardware operating status may include CPU temperature, memory usage, network port throughput, etc. of the network element equipment; security policy access may include access exceeding authorization limits; host login may include abnormal account logins, non-working hours logins without a filing time, etc.; peripheral access may include illegal external connections; key file changes may include illegal downloads, content modifications exceeding authorization limits, etc.; network port status may include abnormal operation of a blocked network port, etc.
[0038] Step 102 : Determine the data of the monitoring indicator that does not conform to the preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator.
[0039] In this embodiment, the judgment is made according to the normal range corresponding to the preset monitoring indicator. When data exceeding the preset normal range appears in the monitoring data of the monitoring indicator, the abnormal situation is extracted to provide a data basis for feature extraction in subsequent steps.
[0040] For example, the monitoring data for the same monitoring indicator for all network element devices in the power optical transmission network can be combined into a monitoring indicator data set. Data in the monitoring indicator data set that does not fall within a preset normal range corresponding to the monitoring indicator is identified as abnormal data for the monitoring indicator, and the abnormal data for the monitoring indicator is converted into an analyzable form. This allows for the aggregation of abnormal events related to the monitoring indicator that occur within a preset monitoring period for all network element devices in the power optical transmission network.
[0041] Here, the preset normal range corresponding to the monitoring indicator can be determined based on data from the normal operation of the network element equipment in historical application scenarios, or based on expert experience, to ensure that key abnormal scenarios are covered.
[0042] Step 103: construct a time series feature matrix of abnormal data of monitoring indicators.
[0043] In this embodiment, the time dimension is introduced to construct a time series feature matrix of abnormal data of monitoring indicators within a preset monitoring period to reflect the time series characteristics of the dynamic evolution of abnormal events and to capture the persistence or mutation of attacks.
[0044] Furthermore, as a refinement and expansion of the specific implementation methods of the above-mentioned embodiments, in order to fully illustrate the specific implementation process of this embodiment, a time series characteristic matrix of the abnormal data of the monitoring indicators is constructed, including: determining the abnormal index of the monitoring indicators based on the abnormal data of the monitoring indicators; determining the safety factor when the network element device sends the abnormal data of the monitoring indicators based on the abnormal index of the monitoring indicators; determining the time series characteristic matrix of the abnormal data of the monitoring indicators based on the safety factor when the network element device sends the abnormal data of the monitoring indicators.
[0045] In this embodiment, information mining is performed on the abnormal data of the monitoring indicators to obtain the abnormal index of the monitoring indicators, so as to filter out high-confidence abnormal events from the initial abnormal data corresponding to the monitoring indicators and reduce the misjudgment rate during abnormal alarms.
[0046] Furthermore, by comprehensively considering the common security threats (such as network security threats, construction security threats, data security threats, etc.) and attack types (such as Trojans, data forgery, blocking attacks, etc.) in the power optical transmission network field, the security factor is used to quantify the security level of network element equipment in actual application scenarios when transmitting data corresponding to monitoring indicators, providing a dynamic adjustment basis for subsequent feature extraction.
[0047] It is worth mentioning that during the prediction monitoring period, the safety factors of all network element devices in the power optical transmission network for the same monitoring indicator are consistent, reflecting the security level of the data corresponding to the monitoring indicator transmitted by the power optical transmission network in actual application scenarios.
[0048] Therefore, according to the safety factor of the data corresponding to the monitoring indicators sent by the network element equipment, the time series feature matrix of the abnormal data of the monitoring indicators is determined, the time evolution law and complex correlation of the abnormal data of the monitoring indicators are captured, the redundant features are reduced, and the dynamic monitoring of the network attack process is supported, thereby providing an accurate basis for the real-time monitoring of the power optical transmission network.
[0049] Furthermore, as a refinement and expansion of the specific implementation methods of the above-mentioned embodiments, in order to fully illustrate the specific implementation process of this embodiment, the abnormal index of the monitoring indicator is determined based on the abnormal data of the monitoring indicator, including: determining a first target value based on the target abnormal data corresponding to the network element device in the abnormal data of the monitoring indicator, and the correlation coefficient of the network element device, and the correlation coefficient is determined according to the distance between the network element devices; determining a second target value based on the threat level of the first target value and the monitoring indicator, and the second target value is used to indicate the contribution of the network element device to the abnormal index of the monitoring indicator; summing the second target value to determine the abnormal index of the monitoring indicator.
[0050] In this embodiment, the abnormality index of the monitoring indicator is determined according to the following formula:
[0051]
[0052] Among them, R i is the abnormal index of monitoring indicator i. m is the number of network element devices in the power optical transmission network. ε ij is the target abnormal data of network element device j in monitoring indicator i, that is, the abnormal data belonging to network element device j in all abnormal data corresponding to monitoring indicator i.
[0053] θ j is the correlation coefficient of network element device j, which is predetermined based on the geographical distance between network element devices in the power optical transmission network. It represents the degree of relationship between the target abnormal data of monitoring indicator i between network element devices with adjacent geographical locations, and its value range is between 0 and 1. For example, if network element device j is close to other network element devices in the power optical transmission system, then θ j It can be set to 0.8-1 to reflect the strong correlation between the target abnormal data of the network element devices. If the network element device j is far away from other network element devices in the power optical transmission system, θ j It can be set to 0-0.8 to reduce the correlation between target abnormal data of network element devices.
[0054] k it The threat level of monitoring indicator i is pre-set based on abnormal events related to the monitoring indicator. Here, the threat level can be pre-classified into 5 levels, corresponding to values 5 to 1, to give higher weight to high-threat events (such as unauthorized logins) and suppress low-threat noise (such as short-term traffic fluctuations).
[0055] A r is the identity matrix. Here, θ j ×ε ij is the first target value, is the second target value.
[0056] In this embodiment, the first target value reflects the spatial coordination of device anomalies within the power optical transmission network, and the threat level of the monitoring indicator is used to reflect the threat level of abnormal events of different monitoring indicators to network element devices. The summed values are squared to reduce the data dimension and obtain the anomaly index of the monitoring indicator. The anomaly index can thus filter out highly correlated features in the abnormal data of the monitoring indicators and distinguish true threats (such as persistent attacks) from false alarms (such as temporary device restarts).
[0057] For example, the disconnection of an isolated network element device may be mistakenly identified as an attack, but if the anomaly index value is low, it will be filtered out to prevent misjudgment.
[0058] Furthermore, as a refinement and expansion of the specific implementation methods of the above-mentioned embodiments, in order to fully illustrate the specific implementation process of this embodiment, the safety factor of the network element device when sending the abnormal data of the monitoring indicator is determined according to the abnormal index of the monitoring indicator, including: determining the third target value according to the abnormal index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator; determining the safety factor when the network element device sends the abnormal data of the monitoring indicator according to the third target value, the importance level of the monitoring indicator and the size of the data packet in the abnormal data of the monitoring indicator.
[0059] In this embodiment, taking the abnormal data of the monitoring indicator transmitted by the network element device as an example, the safety factor when the network element device sends the abnormal data of the monitoring indicator is determined according to the following formula, and the safety factor when the network element device sends the abnormal data of the monitoring indicator is used as the safety level of all network element devices in the power optical transmission network transmitting the data corresponding to the monitoring indicator.
[0060]
[0061] Among them, α i The encryption complexity of the abnormal data for monitoring indicator i. In actual application scenarios, network element devices encrypt data corresponding to monitoring indicators when sending them to prevent data leakage. Here, the encryption complexity corresponding to different monitoring indicators is pre-set to distinguish the complexity of different data encryption methods.
[0062] It's worth noting that the higher the degree of data encryption, the more secure the data transmission, and the higher the security factor when the network element device sends the data. For example, you can set three complexity levels: high, medium, and low, corresponding to the values 3, 2, and 1, respectively. If the data corresponding to the monitoring indicator is encrypted using asymmetric encryption during transmission, the encryption complexity can be set to 3 to reflect its high security and high complexity. If the data corresponding to the monitoring indicator is encrypted using symmetric encryption during transmission, the encryption complexity can be set to 2. If the data corresponding to the monitoring indicator is transmitted in plain text, the encryption complexity can be set to 1.
[0063] P ix The importance level of monitoring indicator i is denoted by the importance of the data. Important data requires higher security assurance and more rigorous risk assessment. Here, the importance levels of different monitoring indicators are pre-set to reflect the criticality of different data to the power optical transmission network. For example, the importance level can be divided into three levels: high, medium, and low, corresponding to the values 3, 2, and 1, respectively. If the data corresponding to the monitoring indicator is core data, such as a dispatch instruction, its importance level can be set to 3. If the data corresponding to the monitoring indicator is ordinary data, such as voltage values, its importance level can be set to 2. If the data corresponding to the monitoring indicator is non-critical data, such as a log, its importance level can be set to 1.
[0064] j iy is the size of the data packet in the abnormal data of the monitoring indicator i. It can be understood that the data corresponding to the monitoring indicator is composed of data packets. Here, the size of the data packet of different monitoring indicators is pre-set to represent the size of different data packets. Specifically, different size intervals of data packets correspond to different levels, such as data packets larger than 1500 bytes are large packet levels, data packets of 500 bytes-1500 bytes are medium packet levels, and data packets smaller than 500 bytes are small packet levels, corresponding to values of 3, 2, and 1 respectively. It is worth mentioning that the size of the data packet will affect the transmission risk, and thus the safety factor corresponding to the monitoring indicator is adjusted according to the size of the data packet in the data corresponding to the monitoring indicator.
[0065] S it The safety factor when the network element sends abnormal data of monitoring indicator i. it The security of the data corresponding to the comprehensive quantitative monitoring indicators when transmitted through network element equipment, S it A higher value indicates a more secure transmission of the monitoring indicator, while a lower value indicates a higher risk. The safety factor provides a quantitative basis for real-time monitoring and assists in determining whether defensive measures should be initiated.
[0066] Here, R i ×α i is the third target value.
[0067] For example, the core scheduling instruction (Pix higher values), even if the encryption is stronger (α i The value is relatively large), but due to its high importance, its security factor may also be low, and the overall risk of data transmission is high, requiring special defense.
[0068] In this embodiment, data transmission security is dynamically assessed using multiple parameters, reducing the bias of a single indicator. Furthermore, these parameters coordinate with each other to balance the safety factor of the monitoring indicators under different abnormal conditions, suppressing redundant alarms during real-time monitoring of the power optical transmission network and avoiding excessive false alarms that disrupt critical services.
[0069] Further, as a refinement and expansion of the specific implementation methods of the above-mentioned embodiments, in order to fully illustrate the specific implementation process of this embodiment, the time series characteristic matrix of the abnormal data of the monitoring indicators is determined according to the safety factor when the network element device sends the abnormal data of the monitoring indicators, including: dividing the abnormal data of the monitoring indicators according to the time when the network element device sends the abnormal data of the monitoring indicators, obtaining the abnormal data components of the monitoring indicators, and determining the dissimilarity between the abnormal data components; determining the average number of data packets of the monitoring indicators according to the number of data packets in the abnormal data of the monitoring indicators and the length of the preset monitoring period; determining the average daily data activity of the monitoring indicators according to the historical data of the monitoring indicators sent by the network element device within the historical monitoring period; determining the time series characteristic matrix of the abnormal data of the monitoring indicators according to the safety factor when the network element device sends the abnormal data of the monitoring indicators, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicators and the average daily data activity of the monitoring indicators.
[0070] In this embodiment, the time series feature matrix of abnormal data of the monitoring indicator is determined according to the following formula:
[0071]
[0072] Among them, A ir is the time series feature matrix of abnormal data of monitoring indicator i. i0is the dissimilarity matrix between abnormal data components of monitoring indicator i. Here, since the abnormal data of the monitoring indicators are all data sent by the network element devices, the time when the network element devices sent the abnormal data of the monitoring indicators can be used as the timestamp of the abnormal data of the monitoring indicators. Then, the predicted monitoring period is divided into multiple comparison time periods, and the abnormal data of the monitoring indicators with timestamps within the comparison time period are used as the abnormal data components corresponding to the comparison time period. Next, the abnormal data components corresponding to two temporally adjacent comparison time periods are used as adjacent abnormal data components. Adjacent abnormal data components are compared, and the differences between adjacent abnormal data components are used as adjacent differences. Furthermore, difference intervals are pre-set between the abnormal data components, with each difference interval corresponding to a dissimilarity. For example, the difference intervals can be large, medium, or small, corresponding to dissimilarity values of 3, 2, and 1, respectively. The adjacent differences are matched with the difference intervals, and the dissimilarity corresponding to the target difference interval that matches the adjacent difference is used as the adjacent difference dissimilarity, that is, the dissimilarity between the abnormal data components corresponding to the two temporally adjacent comparison time periods.
[0073] Here, the greater the difference and mutation of data in adjacent time periods, the more significant the anomaly.
[0074] It can be understood that the dissimilarity of each adjacent difference can form a diagonal matrix, namely the dissimilarity matrix d i0 .
[0075] n i0 is the mean number of packets of monitoring indicator i. Here, the mean number of packets of the monitoring indicator is calculated based on the number of packets in the abnormal data of the monitoring indicator in the predicted monitoring period and the time period length of the predicted monitoring period to reflect the duration of the abnormality.
[0076] F iv The average daily data activity of monitoring indicator i needs to be pre-set. Here, the number of times that all network element devices in the power optical transmission network send data corresponding to the monitoring indicator in one day is taken as the average daily data activity of the monitoring indicator. First, different average daily data activity intervals are pre-divided, and the average daily data activity values corresponding to the average daily data activity intervals are set. For example, the average daily data activity can include high (80 times-100 times), medium (40 times-80 times), and low (0-40 times), corresponding to values 3, 2, and 1, respectively. The higher the average daily data activity, the more times the data corresponding to the monitoring indicator is sent, and the greater the possibility of being attacked by the network. The higher the activity, the stronger the characteristic value.
[0077] For example, if the data corresponding to the monitoring indicator is data that will only be sent after a query instruction, then the ratio of the number of times all network element devices in the power optical transmission network send historical data of the monitoring indicator during the historical monitoring period to the number of days in the historical monitoring period can be determined as the average daily number of historical data of the monitoring indicator. If the network element device sends the data of the monitoring indicator regularly, then the number of times all network element devices in the power optical transmission network send historical data of the monitoring indicator on a certain day in the historical monitoring period can be directly determined as the average daily number of historical data of the monitoring indicator. Then, the average daily number of historical data of the monitoring indicator is matched with the average daily number of data interval, and the average daily activity of the data corresponding to the target average daily number of data interval that matches the average daily number of historical data of the monitoring indicator is used as the average daily activity of the data of the monitoring indicator.
[0078] In practical applications, when a power optical transmission network is attacked, its anomalies will change over time, reflecting the persistence of the attack. In this embodiment, a time-series feature matrix of abnormal data from monitoring indicators is used to reflect the dynamic evolution of abnormal events, capturing persistent attacks and sudden attacks. Time series analysis is also used to distinguish between normal equipment fluctuations and real threats. Furthermore, multi-dimensional parameters are converted into time-series features of a unified dimension, facilitating feature comparison during real-time monitoring of the power optical transmission network.
[0079] Step 104 : determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator.
[0080] Step 105 : determining the characteristics of abnormal data in the power optical transmission network according to the characteristics of abnormal data of the monitoring indicators.
[0081] In this embodiment, time series features are combined with historical data to generate features of abnormal data with time attributes for monitoring indicators. This enables efficient extraction of factors that perceive abnormal events in the power control optical transmission network, providing an accurate basis for real-time alarms and threat decision-making. Based on the features of abnormal data for each monitoring indicator, the features of abnormal data in the power optical transmission network are determined, providing an accurate basis for real-time monitoring of the power optical transmission network, improving its security and defense capabilities, and preventing failures or malicious attacks on the power optical transmission network.
[0082] Furthermore, as a refinement and expansion of the specific implementation methods of the above-mentioned embodiments, in order to fully illustrate the specific implementation process of this embodiment, the characteristics of the abnormal data of the monitoring indicators are determined based on the time series characteristic matrix of the abnormal data of the monitoring indicators, including: determining the historical abnormal range of the monitoring indicators and the historical occurrence probability corresponding to the historical abnormal range based on the historical abnormal data of the monitoring indicators sent by the network element equipment within the historical monitoring period; matching the abnormal data of the monitoring indicators with the historical abnormal range, and determining the occurrence probability of the abnormal data of the monitoring indicators based on the historical occurrence probability corresponding to the target historical abnormal range matched with the abnormal data of the monitoring indicators; determining the characteristics of the abnormal data of the monitoring indicators based on the time series characteristic matrix of the abnormal data of the monitoring indicators and the occurrence probability of the abnormal data of the monitoring indicators.
[0083] In this embodiment, the characteristics of abnormal data of the monitoring indicator are determined according to the following formula:
[0084] C iP =A ir ×μ(a ir )×d ir
[0085] Among them, a ir It is the abnormal data of monitoring indicator i within the preset monitoring period, which can be understood as r groups of integrated signals.
[0086] μ(a ir ) is the probability matrix of occurrence of abnormal data of monitoring indicator i, which is composed of the probability of occurrence of similar abnormal events within the historical monitoring period. Specifically, based on the historical abnormal data of the monitoring indicators sent by all network element devices in the power optical transmission network within the historical monitoring period, the historical abnormal range of the monitoring indicator and the historical occurrence probability corresponding to the historical abnormal range are determined. For example, the historical abnormal range of the CPU temperature of the network element device may include 80℃~85℃ (historical occurrence probability is 0.6), 85℃~90℃ (historical occurrence probability is 0.3), 90℃~95℃ (historical occurrence probability is 0.08), and greater than 90℃ (historical occurrence probability is 0.02). Then, the abnormal data of the monitoring indicator is matched with the historical abnormal range, and the probability of occurrence of the abnormal data of the monitoring indicator is determined based on the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicator. It can be understood that the abnormal data of the monitoring indicator includes multiple data, so the occurrence probability of each data in the abnormal data of the monitoring indicator can be used to form the probability matrix of the abnormal data of the monitoring indicator. Thus, μ(a ir ) suppress occasional false alarms and enhance high-frequency threats. For example, low-frequency anomalies (such as occasional device restarts) have a low probability, C iP Weakened, high probability events (such as Trojan horse periodic activities) C iPEnhanced, triggering alarms first.
[0087] d ir is the gain matching coefficient, ranging from 0 to 1, which is used to balance the difference in the magnitude of historical and current data. For example, if the current data volume is 10 times that of the historical data, then d ir =0.1 to narrow the gap. To avoid comparison errors caused by different data magnitudes, coefficient scaling can retain the pre-placed significant digits after the decimal point, improve feature comparison accuracy, and reduce precision loss.
[0088] C iP The characteristic of abnormal data for monitoring indicator i represents the time-sensitive element of abnormal events corresponding to monitoring indicator i in the power optical transmission network. Time-sensitive elements can capture the dynamic characteristics of abnormal events over time. For example, attacks may exhibit different patterns in different time periods, or some abnormal indicators may have cumulative effects. By analyzing the time dimension, persistent attacks or periodic anomalies can be more accurately identified.
[0089] The time perception elements of abnormal events here refer to the specific features used to identify and describe abnormal events in the power optical transmission network, including system log anomalies, traffic anomalies, protocol anomalies, data anomalies, etc., providing the power optical transmission system with high-precision, low-latency security threat perception capabilities.
[0090] Therefore, in actual application scenarios, the highly nonlinear and separable features of the abnormal data extracted by this application can be used to construct a decision-making perception model, prevent the decision-making perception model from overfitting, enhance generalization, and use the decision-making perception model to monitor the operating status of the power transmission network in real time, trigger accurate alarms, and improve the abnormal event coverage of the decision-making perception model.
[0091] It should be noted that the historical monitoring period must be close to the preset monitoring period, such as the previous month or the previous year, to ensure the reliability of feature extraction.
[0092] In one embodiment, the feature extraction method of abnormal data of the power optical transmission network also includes: dividing the power optical transmission network into multiple monitoring areas; obtaining regional monitoring data of monitoring indicators of regional equipment in the monitoring area within a preset monitoring period; determining the characteristics of the regional abnormal data of the monitoring indicators based on the regional monitoring data of the monitoring indicators; determining the characteristics of the abnormal data in the power optical transmission network based on the characteristics of the regional abnormal data of the monitoring indicators.
[0093] In this embodiment, the electric power optical transmission network is divided into multiple sensing intervals (i.e., monitoring areas) according to physical or logical boundaries, and regional monitoring data of monitoring indicators of network element devices (i.e., regional devices) in the sensing intervals within a preset monitoring period are obtained. Similar to step 102, regional abnormal data of monitoring indicators in the sensing intervals are determined based on the regional monitoring data of the monitoring indicators in the sensing intervals, and thus, similar to steps 103 and 104, the characteristics of regional abnormal data of monitoring indicators in the sensing intervals are calculated, the calculation range is narrowed, the calculation efficiency and accuracy are improved, and global data interference is avoided. Furthermore, based on the characteristics of the regional abnormal data of the same monitoring indicator in each sensing interval, the characteristics of the abnormal data of the monitoring indicator in the electric power optical transmission network are determined, and finally the characteristics of all abnormal data in the electric power optical transmission network are determined.
[0094] For example, each substation in the power optical transmission network can be regarded as a sensing interval, or further, representative network element devices can be selected in each substation as a sensing interval for regional refinement processing, which can not only avoid excessive coupling caused by a single device calculating alone, but also avoid low accuracy caused by treating the entire power optical transmission network as one interval.
[0095] In one embodiment, the feature extraction method of abnormal data of the power optical transmission network also includes: taking the network management system corresponding to the power optical transmission network as a perception interval; obtaining the target monitoring data of the target monitoring indicators of the gateway device in the network management system within a preset monitoring period; determining the abnormal data of the target monitoring indicators based on the target monitoring data of the target monitoring indicators, and extracting the features of the abnormal data of the target monitoring indicators.
[0096] In this embodiment, the network management system at the first level of the power optical transmission network is monitored separately, and the data of the entire network is integrated. Combined with the global perspective of the network management system, the power optical transmission network is monitored more reliably in real time.
[0097] For example, target monitoring indicators for the network management system are determined based on data related to the actual operation of the network management system, and the network management system is then monitored based on the target monitoring indicators. Similarly, probes for reading data are provided in the network management system to obtain target monitoring data for the target monitoring indicators. Thus, similarly to steps 102 to 104, features of target abnormal data for each target monitoring indicator are extracted from the large amount of target monitoring data in the network management system.
[0098] Target monitoring indicators here can include data transmitted by the NMS and the NMS's own system operating status data. For example, connection status with network element devices (timeout, device disconnection), abnormal user logins to the NMS, abnormal operations (exceeding permissions), and abnormal upgrades (failure to report upgrades).
[0099] It should be noted that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0100] Further, if Figure 2 As shown, as a specific implementation of the above-mentioned feature extraction method for abnormal data of the power optical transmission network, an embodiment of the present application provides a feature extraction device 200 for abnormal data of the power optical transmission network, and the feature extraction device 200 for abnormal data of the power optical transmission network includes: an acquisition module 201 and a determination module 202.
[0101] The acquisition module 201 is used to obtain monitoring data of monitoring indicators of network element devices in the power optical transmission network within a preset monitoring period;
[0102] A determination module 202 is configured to determine data of the monitoring indicator that does not conform to a preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator; and
[0103] Constructing a time series feature matrix of abnormal data of monitoring indicators; and,
[0104] Determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator; and
[0105] According to the characteristics of abnormal data of monitoring indicators, the characteristics of abnormal data in the power optical transmission network are determined.
[0106] In one embodiment, the determination module 202 is specifically used to determine the abnormal index of the monitoring indicator based on the abnormal data of the monitoring indicator; determine the safety factor when the network element device sends the abnormal data of the monitoring indicator based on the abnormal index of the monitoring indicator; and determine the time series characteristic matrix of the abnormal data of the monitoring indicator based on the safety factor when the network element device sends the abnormal data of the monitoring indicator.
[0107] In one embodiment, the determination module 202 is specifically used to determine a first target value based on the target abnormal data corresponding to the network element device in the abnormal data of the monitoring indicator and the correlation coefficient of the network element device, where the correlation coefficient is determined according to the distance between the network element devices; determine a second target value based on the threat level of the first target value and the monitoring indicator, and the second target value is used to indicate the contribution of the network element device to the abnormal index of the monitoring indicator; and sum the second target values to determine the abnormal index of the monitoring indicator.
[0108] In one embodiment, the determination module 202 is specifically used to determine a third target value based on the abnormality index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator; and determine the safety factor when the network element device sends the abnormal data of the monitoring indicator based on the third target value, the importance level of the monitoring indicator and the size of the data packet in the abnormal data of the monitoring indicator.
[0109] In one embodiment, the determination module 202 is specifically used to divide the abnormal data of the monitoring indicator according to the time when the network element device sends the abnormal data of the monitoring indicator, obtain the abnormal data components of the monitoring indicator, and determine the dissimilarity between the abnormal data components; determine the average number of data packets of the monitoring indicator according to the number of data packets in the abnormal data of the monitoring indicator and the duration of the preset monitoring period; determine the average daily data activity of the monitoring indicator according to the historical data of the monitoring indicator sent by the network element device within the historical monitoring period; determine the time series feature matrix of the abnormal data of the monitoring indicator according to the safety factor when the network element device sends the abnormal data of the monitoring indicator, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicator and the average daily data activity of the monitoring indicator.
[0110] In one embodiment, the determination module 202 is specifically used to determine the historical abnormal range of the monitoring indicator and the historical occurrence probability corresponding to the historical abnormal range based on the historical abnormal data of the monitoring indicator sent by the network element device within the historical monitoring period; match the abnormal data of the monitoring indicator with the historical abnormal range, and determine the occurrence probability of the abnormal data of the monitoring indicator based on the historical occurrence probability corresponding to the target historical abnormal range matched with the abnormal data of the monitoring indicator; determine the characteristics of the abnormal data of the monitoring indicator based on the time series feature matrix of the abnormal data of the monitoring indicator and the occurrence probability of the abnormal data of the monitoring indicator.
[0111] In one embodiment, the feature extraction device 200 for abnormal data of the power optical transmission network further includes:
[0112] A division module is used to divide the power optical transmission network into multiple monitoring areas; obtain regional monitoring data of monitoring indicators of regional equipment in the monitoring area within a preset monitoring period; determine the characteristics of regional abnormal data of the monitoring indicators based on the regional monitoring data of the monitoring indicators; and determine the characteristics of abnormal data in the power optical transmission network based on the characteristics of the regional abnormal data of the monitoring indicators.
[0113] Regarding the specific definition of the feature extraction device for abnormal data of the electric power optical transmission network, please refer to the definition of the feature extraction method for abnormal data of the electric power optical transmission network above, and no further details will be given here. Each module in the above-mentioned feature extraction device for abnormal data of the electric power optical transmission network can be implemented in whole or in part by software, hardware, and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0114] Based on the above Figure 1 The method shown in FIG. 1 is a method for performing the above-mentioned operation. Accordingly, the embodiment of the present application further provides a readable storage medium having a computer program stored thereon. When the computer program is executed by the processor, the computer program is executed as shown in FIG. Figure 1 The feature extraction method for abnormal data of power optical transmission network shown in FIG.
[0115] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each implementation scenario of the present application.
[0116] Based on the above Figure 1 The method shown, and Figure 2 In order to achieve the above-mentioned purpose, the embodiment of the present application further provides a computer device, which can be a personal computer, a server, a network device, etc. The computer device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figure 1 The feature extraction method for abnormal data of power optical transmission network shown in FIG.
[0117] Optionally, the computer device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a Wi-Fi module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a Bluetooth interface, a Wi-Fi interface), etc.
[0118] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the computer device, and may include more or fewer components, or a combination of certain components, or different component arrangements.
[0119] The storage medium may also include an operating system and a network communication module. An operating system is a program that manages and stores the hardware and software resources of a computer device, supporting the execution of information processing programs and other software and / or programs. The network communication module facilitates communication between components within the storage medium, as well as with other hardware and software within the physical device.
[0120] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented with the help of software plus the necessary general hardware platform, and can also implement the embodiments of the present application through hardware.
[0121] Those skilled in the art will understand that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily required to implement the present application. Those skilled in the art will understand that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the implementation scenario description, or can be changed accordingly and located in one or more devices different from the implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple sub-modules.
[0122] The serial numbers of the above application are for descriptive purposes only and do not represent the advantages or disadvantages of the implementation scenarios. The above disclosure only discloses several specific implementation scenarios of the present application, but the present application is not limited thereto. Any changes that can be conceived by those skilled in the art should fall within the scope of protection of the present application.
Claims
1. A method for extracting features from abnormal data in a power optical transmission network, characterized in that: The method comprises: Obtain monitoring data of monitoring indicators of network element equipment in the power optical transmission network within a preset monitoring period; Determining data of the monitoring indicator that does not fall within a preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator; Constructing a time series feature matrix of abnormal data of the monitoring indicator; Determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator; According to the characteristics of the abnormal data of the monitoring indicator, the characteristics of the abnormal data in the power optical transmission network are determined.
2. The feature extraction method for abnormal data of power optical transmission network according to claim 1 is characterized in that: The step of constructing a time series feature matrix of abnormal data of the monitoring indicator includes: Determining an abnormality index of the monitoring indicator according to the abnormal data of the monitoring indicator; Determining, according to the abnormality index of the monitoring indicator, a safety factor when the network element device sends abnormal data of the monitoring indicator; A time series feature matrix of the abnormal data of the monitoring indicator is determined according to a safety factor when the network element device sends the abnormal data of the monitoring indicator.
3. The feature extraction method for abnormal data of power optical transmission network according to claim 2 is characterized in that: Determining the abnormality index of the monitoring indicator according to the abnormal data of the monitoring indicator includes: determining a first target value according to target abnormal data corresponding to the network element devices in the abnormal data of the monitoring indicator and a correlation coefficient of the network element devices, wherein the correlation coefficient is determined according to a distance between the network element devices; Determining a second target value based on the first target value and the threat level of the monitoring indicator, where the second target value is used to indicate a contribution of the network element device to an abnormality index of the monitoring indicator; The second target value is summed to determine the abnormality index of the monitoring indicator.
4. The feature extraction method for abnormal data of power optical transmission network according to claim 2 is characterized in that: The determining, according to the abnormality index of the monitoring indicator, a safety factor when the network element device sends abnormal data of the monitoring indicator includes: determining a third target value according to the abnormality index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator; A safety factor when the network element device sends the abnormal data of the monitoring indicator is determined according to the third target value, the importance level of the monitoring indicator and the size of the data packet in the abnormal data of the monitoring indicator.
5. The feature extraction method for abnormal data of power optical transmission network according to claim 2 is characterized in that: The determining, according to the safety factor when the network element device sends the abnormal data of the monitoring indicator, a time series feature matrix of the abnormal data of the monitoring indicator includes: Dividing the abnormal data of the monitoring indicator according to the time when the network element device sends the abnormal data of the monitoring indicator to obtain abnormal data components of the monitoring indicator, and determining the degree of difference between the abnormal data components; Determining a mean value of the number of data packets of the monitoring indicator according to the number of data packets in the abnormal data of the monitoring indicator and the duration of the preset monitoring period; Determining the average daily activity of the monitoring indicator data according to the historical data of the monitoring indicator sent by the network element device within the historical monitoring period; The time series feature matrix of the abnormal data of the monitoring indicator is determined based on the safety factor when the network element device sends the abnormal data of the monitoring indicator, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicator and the average daily activity of the data of the monitoring indicator.
6. The feature extraction method for abnormal data of power optical transmission network according to claim 1 is characterized in that: The determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator includes: Determining, based on historical abnormal data of the monitoring indicator sent by the network element device within a historical monitoring period, a historical abnormal range of the monitoring indicator and a historical occurrence probability corresponding to the historical abnormal range; Matching the abnormal data of the monitoring indicator with the historical abnormal range, and determining the occurrence probability of the abnormal data of the monitoring indicator based on the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicator; The characteristics of the abnormal data of the monitoring indicator are determined according to the time series characteristic matrix of the abnormal data of the monitoring indicator and the occurrence probability of the abnormal data of the monitoring indicator.
7. The feature extraction method for abnormal data of power optical transmission network according to claim 1 is characterized in that: The method further comprises: dividing the power optical transmission network into a plurality of monitoring areas; Acquire regional monitoring data of the monitoring indicators of the regional equipment in the monitoring area within the preset monitoring period; Determining characteristics of regional abnormal data of the monitoring indicator based on the regional monitoring data of the monitoring indicator; According to the characteristics of the regional abnormal data of the monitoring indicator, the characteristics of the abnormal data in the power optical transmission network are determined.
8. A feature extraction device for abnormal data of power optical transmission network, characterized in that: The device comprises: An acquisition module is used to obtain monitoring data of monitoring indicators of network element devices in the power optical transmission network within a preset monitoring period; a determination module, configured to determine data of the monitoring indicator that does not conform to a preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator; and Constructing a time series feature matrix of abnormal data of the monitoring indicators; and Determining the characteristics of the abnormal data of the monitoring indicator according to the time series characteristic matrix of the abnormal data of the monitoring indicator; and According to the characteristics of the abnormal data of the monitoring indicator, the characteristics of the abnormal data in the power optical transmission network are determined.
9. A readable storage medium having a program or instruction stored thereon, characterized in that: When the program or instruction is executed by a processor, the steps of the method for extracting features of abnormal data of a power optical transmission network according to any one of claims 1 to 7 are implemented.
10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, wherein: When the processor executes the program, the method for extracting features of abnormal data of a power optical transmission network according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Industrial control system safety protection method and device
CN112637220A
Network event security monitoring method and system
CN118200019A
Industrial control network threat trend detection method and system based on time sequence characteristics
CN119210897A
Network traffic abnormity monitoring method and device based on BiLSTM-Att network
CN119232490A
Service abnormality prediction method and device, storage medium, and electronic device
WO2023045829A1