Feature extraction method for power optical transmission network anomaly data and related device

By constructing a time-series feature matrix of abnormal data for monitoring indicators in power optical transmission networks, and combining time factors and multi-dimensional parameters, the problem of insufficient feature extraction in existing technologies is solved, and efficient real-time monitoring and threat identification of power optical transmission networks are realized.

CN120474732BActive Publication Date: 2026-02-10EAST CHINA BRANCH OF STATE GRID CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510376157.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2026-02-10
Estimated Expiration
2045-03-27

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively extract features from abnormal data in power optical transmission networks, leading to complex model construction that may result in overfitting or underfitting, failing to comprehensively cover all potential security threat scenarios, and exhibiting insufficient identification capabilities.

Method used

By acquiring monitoring data from network element devices in the power optical transmission network, an abnormal data time series feature matrix of monitoring indicators is constructed. Combining time factors and multi-dimensional parameters, the temporal evolution pattern and complex correlation of abnormal data are captured, redundant features are reduced, and the specific threats to the power optical transmission network are accurately identified.

Benefits of technology

It improves the real-time monitoring capabilities of power optical transmission networks, prevents faults or malicious attacks, enhances the coverage and identification capabilities of abnormal events, and reduces the false positive rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474732B_ABST
    Figure CN120474732B_ABST
Patent Text Reader

Abstract

The application provides a feature extraction method for abnormal data of a power optical transmission network and related equipment. The method sets monitoring indexes according to the data involved in the actual operation of the network element equipment of the power optical transmission network, so as to monitor the network element equipment according to the monitoring indexes. Then, the features of the abnormal data of each monitoring index are extracted from a large amount of monitoring data of the network element equipment, which is different from general network security features and accurately identifies the exclusive threats of the power optical transmission network. Meanwhile, in the process of extracting the features of the abnormal data, the time factor is introduced to capture the time evolution law and complex correlation of the abnormal data of each monitoring index, reduce redundant features, support dynamic monitoring of the network attack process, and thus provide accurate basis for real-time monitoring of the power optical transmission network and prevent the power optical transmission network from malfunctioning or being maliciously attacked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power optical transmission network, and in particular to a feature extraction method for abnormal data of a power optical transmission network and related equipment. BACKGROUND

[0002] With the development of smart grids, power optical transmission networks play an increasingly important supporting role in the safe production and management of power grids. With the widespread application of power optical transmission networks, network attacks on power optical transmission networks cannot be underestimated. Once a power optical transmission network fails, it will cause great damage to the entire power communication system.

[0003] In related technologies, the features of abnormal data that cause abnormal events in a power optical transmission network are first extracted, and then a neural network model for judging whether the power optical transmission network has been attacked is established according to the features of the abnormal data. However, this method produces a large number of similar feature values when extracting features, and cannot extract features with complex relationships. In the subsequent modeling process, it also causes the construction of the model to be complex, which may cause overfitting or underfitting in the training process of the model, so that it may not be able to comprehensively cover all potential security threat scenarios, resulting in insufficient recognition ability for some abnormal events. SUMMARY

[0004] Therefore, the present application provides a feature extraction method for abnormal data of a power optical transmission network and related equipment, which extracts highly nonlinear and separable features of abnormal data from a large amount of monitoring data of network element devices in a power optical transmission network, provides accurate basis for real-time monitoring of the power optical transmission network, and prevents the power optical transmission network from failing or being maliciously attacked.

[0005] According to an aspect of the present application, a feature extraction method for abnormal data of a power optical transmission network is provided, comprising:

[0006] obtaining monitoring data of a monitoring index of a network element device in a power optical transmission network within a preset monitoring period;

[0007] determining data that does not conform to a preset normal range corresponding to the monitoring index in the monitoring data of the monitoring index as abnormal data of the monitoring index;

[0008] constructing a time sequence feature matrix of the abnormal data of the monitoring index;

[0009] determining features of the abnormal data of the monitoring index according to the time sequence feature matrix of the abnormal data of the monitoring index;

[0010] determining features of abnormal data in the power optical transmission network according to the features of the abnormal data of the monitoring index.

[0011] According to another aspect of the present application, there is provided an apparatus for extracting features of abnormal data of a power optical transmission network, comprising:

[0012] an acquisition module configured to acquire monitoring data of a monitoring index of a network element device in the power optical transmission network within a preset monitoring period;

[0013] a determination module configured to determine, as abnormal data of the monitoring index, data in the monitoring data of the monitoring index that does not conform to a preset normal range corresponding to the monitoring index; and

[0014] construct a time sequence feature matrix of the abnormal data of the monitoring index; and

[0015] determine features of the abnormal data of the monitoring index according to the time sequence feature matrix of the abnormal data of the monitoring index; and

[0016] determine features of the abnormal data of the power optical transmission network according to the features of the abnormal data of the monitoring index.

[0017] According to still another aspect of the present application, there is provided a readable storage medium having stored thereon a program or instructions, which, when executed by a processor, implement the steps of the above-mentioned method for extracting features of abnormal data of a power optical transmission network.

[0018] According to yet another aspect of the present application, there is provided a computer device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the steps of the above-mentioned method for extracting features of abnormal data of a power optical transmission network when executing the program.

[0019] According to the above technical solution, the present application provides a method for extracting features of abnormal data of a power optical transmission network and related devices. The method according to the present application sets monitoring indexes according to data involved in actual operation of network element devices of the power optical transmission network, to monitor the network element devices according to the monitoring indexes. Then, features of abnormal data of each monitoring index are extracted from a large amount of monitoring data of the network element devices, to accurately identify power optical transmission network-specific threats, which are different from general network security features. Meanwhile, in the process of extracting features of abnormal data, time factors are introduced to capture time evolution rules and complex correlations of abnormal data of each monitoring index, to reduce redundant features and support dynamic monitoring of network attack processes, thereby providing accurate basis for real-time monitoring of the power optical transmission network, preventing the power optical transmission network from malfunctioning or being maliciously attacked, and improving abnormal event coverage rate in the monitoring process.

[0020] The above description is only a summary of the technical solutions of the present application. In order to enable one skilled in the art to better understand the technical means of the present application, the present application can be implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the present application to be more apparent and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS

[0021] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application, and the illustrative embodiments of the present application and their description serve to explain the present application, and do not constitute an improper limitation on the present application. In the drawings:

[0022] Figure 1 A flowchart of a feature extraction method for abnormal data of a power optical transmission network provided by an embodiment of the present application is shown;

[0023] Figure 2 A structural block diagram of a feature extraction device for abnormal data of a power optical transmission network provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0024] In the following, the present application will be described in detail with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0025] The embodiments of the present application will be described in detail below, and examples of the embodiments are shown in the accompanying drawings, in which the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be interpreted as a limitation on the present application.

[0026] Those skilled in the art can understand that, unless specifically stated, the singular forms "a", "an" and "the" used herein also include the plural forms. It should be further understood that the phrase "comprising" used in the specification of the present application means that the features, integers, steps, operations, elements and / or components exist, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we say that an element is "connected" or "joined" to another element, it can be directly connected or joined to the other element, or there can be intermediate elements. In addition, "connected" or "joined" used herein can include wireless connection or wireless connection. The phrase "and / or" used herein includes all or any single unit and all combinations of the associated listed items.

[0027] Exemplary embodiments according to this application will now be described in greater detail below with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in various different forms, and should not be construed as being limited only to the embodiments set forth herein. It should be understood that the embodiments are provided so that the present disclosure will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art.

[0028] A feature extraction method for abnormal data of a power optical transmission network is provided in this embodiment, as shown in the figure, the method comprises: Figure 1

[0029] In step 101, the monitoring data of the monitoring indicators of the network element devices in the power optical transmission network within a preset monitoring period is obtained.

[0030] Here, the power optical transmission network is the communication infrastructure of the power system, which is specially used for transmitting key power business data such as power dispatching, real-time monitoring, and relay protection.

[0031] In actual application scenarios, network element devices (such as SDH (Synchronous Digital Hierarchy) devices or OTN (optical transport network) devices, etc.) are usually placed in substations at different levels (such as provincial or county levels), and the network element devices are connected by optical cable lines to form a power optical transmission network. The network element devices are provided with service network ports and management network ports, and the network element devices communicate with each other through the service network ports to transmit data related to power business. The network element devices communicate with the corresponding network management system of the power optical transmission network through the management network ports, so that the network management system can perform network management on the network element devices to realize efficient operation and maintenance of the power optical transmission network.

[0032] At present, the power optical transmission network lacks the situational awareness capability of network attack threats. The alarm function of the network management system is only for device failure, optical cable failure, and other physical failures, and does not effectively monitor events that threaten network security such as abnormal login devices and network management, file access and modification, and unauthorized process start.

[0033] In this embodiment, the network element devices in the power optical transmission network are monitored to perform network security situational awareness on the power optical transmission network according to the monitoring data of the network element devices in the subsequent steps, extract the perception factors (i.e., the features of abnormal data) of abnormal events in the power optical transmission network, provide accurate basis for real-time monitoring of the network element devices, and prevent the network element devices from malfunctioning or being maliciously attacked.

[0034] ​Specifically, a probe is set in the network element device, and the probe is a tool software for reading data. The probe reads power service data sent by the network element device to other network element devices within a preset monitoring period and hardware running state data of the network element device itself, and sends the data to the network management system through a management interface of the network element device, so that a large amount of monitoring data of the network element device within the preset monitoring period is obtained in the network management system.

[0035] It is worth mentioning that in this embodiment, the monitoring indicators of the network element device are set according to the power service data and the hardware running state data (i.e. the data transmitted through the network element device) sent by the network element device, so that the large amount of monitoring data of the network element device within the preset monitoring period is sorted into monitoring data of each monitoring indicator. Then in the subsequent steps, the perception factors of abnormal events corresponding to each monitoring indicator in the power optical transmission network are extracted, which are distinguished from general network security features, and the exclusive threats of the power optical transmission network are accurately identified.

[0036] Here, the monitoring data exists in the form of data packets.

[0037] For example, the monitoring indicators can cover power service, hardware running state of the network element device, security policy access, host login, peripheral access, key file change, network port state, switch mirror traffic, etc. Among them, the power service can include voltage, power value, reactive power compensation value, active power, etc., the hardware running state can include CPU temperature, memory usage, network port throughput, etc. of the network element device, the security policy access can include access beyond the authority, etc., the host login can include abnormal account login, non-working time login without record time, etc., the peripheral access can include illegal external connection, etc., the key file change can include illegal download, content modification beyond the authority, etc., and the network port state can include abnormal work of the blocked network port, etc.

[0038] In step 102, data in the monitoring data of the monitoring indicators that does not conform to the preset normal range corresponding to the monitoring indicators is determined as abnormal data of the monitoring indicators.

[0039] In this embodiment, the normal range corresponding to the monitoring indicators is preset, and when data beyond the preset normal range appears in the monitoring data of the monitoring indicators, the abnormal situation is extracted, providing a data basis for feature extraction in the subsequent steps.

[0040] Exemplarily, monitoring data of all network element devices in the power optical transmission network in the same monitoring index can form a monitoring index data set, data in the monitoring index data set that does not conform to the preset normal range of the monitoring index can be determined as abnormal data of the monitoring index, and the abnormal data of the monitoring index can be converted into an analyzable form. Thus, abnormal events related to the monitoring index occurring in the power optical transmission network in the preset monitoring period can be summarized.

[0041] Here, the preset normal range corresponding to the monitoring index can be determined according to data when the network element device is normally operated in the historical application scenario, or determined based on expert experience, to ensure that key abnormal scenarios are covered.

[0042] Step 103, constructing a time sequence feature matrix of the abnormal data of the monitoring index.

[0043] In this embodiment, a time dimension is introduced to construct a time sequence feature matrix of the abnormal data of the monitoring index in the preset monitoring period, to reflect the time sequence features of dynamic evolution of the abnormal event, for capturing the persistence or mutability of the attack.

[0044] Further, as a refinement and expansion of the specific implementation of the above embodiment, in order to completely describe the specific implementation process of the embodiment, constructing the time sequence feature matrix of the abnormal data of the monitoring index includes: determining an abnormal index of the monitoring index according to the abnormal data of the monitoring index; determining a security coefficient when the network element device sends the abnormal data of the monitoring index according to the abnormal index of the monitoring index; and determining the time sequence feature matrix of the abnormal data of the monitoring index according to the security coefficient when the network element device sends the abnormal data of the monitoring index.

[0045] In this embodiment, information mining is performed on the abnormal data of the monitoring index to obtain an abnormal index of the monitoring index, so as to filter out abnormal events with high confidence from the initial abnormal data corresponding to the monitoring index, and reduce the misjudgment rate when the abnormal alarm occurs.

[0046] Further, considering common security threats (such as network security threats, construction security threats, and data security threats) and attack types (such as Trojan horses, data forgery, and blocking attacks) in the power optical transmission network, the security coefficient quantifies the security degree of the network element device when transmitting data corresponding to the monitoring index in the actual application scenario, to provide a dynamic adjustment basis for subsequent feature extraction.

[0047] It is worth mentioning that the security coefficients of all network element devices in the power optical transmission network for the same monitoring index in the prediction monitoring period are consistent, to reflect the security degree of the power optical transmission network when transmitting data corresponding to the monitoring index in the actual application scenario.

[0048] Thus, according to the security factor when the network element device sends the data corresponding to the monitoring index, the time sequence feature matrix of the abnormal data of the monitoring index is determined, the time evolution law and complex correlation of the abnormal data of the monitoring index are captured, the redundant features are reduced, the network attack process is dynamically monitored, and thus accurate basis is provided for real-time monitoring of the power optical transmission network.

[0049] Further, as a refinement and expansion of the above embodiment, in order to completely describe the specific implementation process of the embodiment, according to the abnormal data of the monitoring index, the abnormal index of the monitoring index is determined, including: determining a first target value according to the target abnormal data of the network element device in the abnormal data of the monitoring index and the correlation coefficient of the network element device, the correlation coefficient being determined according to the distance between the network element devices; determining a second target value according to the first target value and the threat degree of the monitoring index, the second target value being used to indicate the contribution of the network element device to the abnormal index of the monitoring index; and summing the second target value to determine the abnormal index of the monitoring index.

[0050] In this embodiment, the abnormal index of the monitoring index is determined according to the following formula:

[0051]

[0052] Wherein, R i is the abnormal index of the monitoring index i. m is the number of network element devices in the power optical transmission network. ε ij is the target abnormal data of the network element device j in the monitoring index i, i.e., the abnormal data belonging to the network element device j in all abnormal data corresponding to the monitoring index i.

[0053] θ j is the correlation coefficient of the network element device j, which is determined in advance according to the distance between the geographical positions of the network element devices in the power optical transmission network, and represents the relationship degree between the target abnormal data of the network element devices with adjacent geographical positions in the monitoring index i, and the value range is between 0 and 1. For example, if the network element device j is close to other network element devices in the power optical transmission system, θ j can be set to 0.8-1 to reflect the strong correlation between the target abnormal data of the network element devices, and if the network element device j is far away from other network element devices in the power optical transmission system, θ j can be set to 0-0.8 to reduce the correlation between the target abnormal data of the network element devices.

[0054] k it is the threat degree of the monitoring index i, which is set in advance according to the abnormal events related to the monitoring index. Here, the threat degree can be divided into 5 levels in advance, corresponding to the values 5 to 1, so as to give greater weight to high threat events (such as unauthorized login) and suppress low threat noise (such as temporary flow fluctuation).

[0055] A r Let θ be the identity matrix. j ×ε ij The first target value, This is the second target value.

[0056] In this embodiment, a first target value reflects the spatial coordination of equipment anomalies within the power optical transmission network. The threat level of monitoring indicators reflects the threat level of abnormal events of different monitoring indicators to network elements. The summed values ​​are then squared to reduce data dimensionality, resulting in an anomaly index for the monitoring indicators. This anomaly index is used to filter out highly correlated features from the abnormal data of the monitoring indicators, distinguishing between genuine threats (such as persistent attacks) and false alarms (such as brief equipment restarts).

[0057] For example, an isolated network element going offline might be mistakenly identified as an attack, but if the abnormal index value is low, it will be filtered out to prevent misjudgment.

[0058] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully explain the specific implementation process of this embodiment, the security factor when the network element device sends abnormal data of the monitoring indicator is determined according to the abnormality index of the monitoring indicator, including: determining a third target value based on the abnormality index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator; and determining the security factor when the network element device sends abnormal data of the monitoring indicator based on the third target value, the importance level of the monitoring indicator, and the size of the data packet in the abnormal data of the monitoring indicator.

[0059] In this embodiment, taking the abnormal data of the monitoring index transmitted by the network element device as an example, the security factor when the network element device sends the abnormal data of the monitoring index is determined according to the following formula, and the security factor when the network element device sends the abnormal data of the monitoring index is used as the security level of all network element devices in the power optical transmission network transmitting the data corresponding to the monitoring index.

[0060]

[0061] Where, α i This defines the encryption complexity for abnormal data related to monitoring indicator i. In practical applications, network elements encrypt data during the transmission of data corresponding to monitoring indicators to prevent data leakage. Here, different encryption complexities are pre-set for different monitoring indicators to differentiate the varying complexity of different data encryption methods.

[0062] It's worth noting that the higher the encryption level of data transmission, the more secure the data transmission and the higher the security level when network elements send the data. For example, three complexity levels can be set: high, medium, and low, corresponding to values ​​of 3, 2, and 1, respectively. If the data corresponding to the monitoring indicator is encrypted using asymmetric encryption during transmission, its encryption complexity can be set to 3 to reflect its high security and high complexity. If the data corresponding to the monitoring indicator is encrypted using symmetric encryption during transmission, its encryption complexity can be set to 2. If the data corresponding to the monitoring indicator is transmitted in plaintext, its encryption complexity can be set to 1.

[0063] P ix To determine the importance level of monitoring indicator i, critical data requires higher security and more stringent risk assessment. Here, different importance levels for monitoring indicators are pre-set to reflect the criticality of different data to the power optical transmission network. For example, importance levels can be divided into three levels: high, medium, and low, corresponding to values ​​of 3, 2, and 1, respectively. If the data corresponding to the monitoring indicator is core data, such as dispatch instructions, its importance level can be set to 3; if the data corresponding to the monitoring indicator is ordinary data, such as voltage values, its importance level can be set to 2; and if the data corresponding to the monitoring indicator is non-critical data, such as logs, its importance level can be set to 1.

[0064] j iy This refers to the size of the data packets in the abnormal data for monitoring indicator i. It's understood that the data corresponding to a monitoring indicator is composed of data packets. Here, the size of the data packets for different monitoring indicators is pre-set to represent the size of different data packets. Specifically, different size ranges of data packets correspond to different levels, such as data packets larger than 1500 bytes being the large packet level, data packets between 500 and 1500 bytes being the medium packet level, and data packets smaller than 500 bytes being the small packet level, corresponding to values ​​of 3, 2, and 1 respectively. It's worth noting that data packet size affects transmission risk, thus the security factor corresponding to the monitoring indicator is adjusted based on the size of the data packets in the data corresponding to the monitoring indicator.

[0065] S it The security factor when sending abnormal data of monitoring indicator i to network element devices. it Security of data corresponding to comprehensive quantitative monitoring indicators when transmitted through network element devices, S it A higher value indicates greater security for the monitored indicator during transmission, while a lower value indicates higher risk. The security factor provides a quantitative basis for real-time monitoring and helps determine whether defensive measures need to be activated.

[0066] Here, R i ×α i This is the third target value.

[0067] For example, core scheduling instructions (Pix Even with a high encryption level (α value), even with a high encryption level (α), i (The value is relatively large), but because of its high importance, its security factor may also be low, and the overall risk of data transmission is high, requiring key defense.

[0068] In this embodiment, data transmission security is dynamically evaluated through multi-dimensional parameters to reduce the bias of a single indicator. Furthermore, the multi-dimensional parameters are coordinated to balance the safety coefficients of monitoring indicators under different abnormal conditions, suppressing redundant alarms during real-time monitoring of the power optical transmission network and avoiding excessive false alarm interference to critical services.

[0069] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, the time-series feature matrix of the abnormal data of the monitoring indicators is determined based on the security factor when the network element device sends abnormal data of the monitoring indicators. This includes: dividing the abnormal data of the monitoring indicators according to the time when the network element device sends the abnormal data of the monitoring indicators, obtaining the abnormal data components of the monitoring indicators, and determining the dissimilarity between the abnormal data components; determining the average number of data packets of the monitoring indicators based on the number of data packets in the abnormal data of the monitoring indicators and the duration of the preset monitoring period; determining the average daily activity of the monitoring indicators based on the historical data of the monitoring indicators sent by the network element device in the historical monitoring period; and determining the time-series feature matrix of the abnormal data of the monitoring indicators based on the security factor when the network element device sends the abnormal data of the monitoring indicators, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicators, and the average daily activity of the monitoring indicators.

[0070] In this embodiment, the time-series feature matrix of abnormal data for the monitoring indicators is determined according to the following formula:

[0071]

[0072] Among them, A ir d represents the time-series feature matrix of abnormal data for monitoring indicator i. i0This is the dissimilarity matrix between the abnormal data components of monitoring indicator i. Since the abnormal data of the monitoring indicator is all data sent by network elements, the time when the network element sends the abnormal data can be used as the timestamp of the abnormal data. Then, the predictive monitoring period is divided into multiple comparison time periods, and the abnormal data of the monitoring indicator whose timestamp falls within a comparison time period is taken as the abnormal data component corresponding to that comparison time period. Next, the abnormal data components corresponding to two adjacent comparison time periods are taken as adjacent abnormal data components. The differences between adjacent abnormal data components are compared, and the differences between them are taken as adjacent differences. Furthermore, a difference range between abnormal data components is pre-set, with each difference range corresponding to a dissimilarity level. For example, the difference range can be large, medium, and small, corresponding to dissimilarity values ​​of 3, 2, and 1, respectively. Adjacent differences are matched with difference ranges, and the dissimilarity corresponding to the target difference range that matches the adjacent differences is taken as the dissimilarity of the adjacent differences, i.e., the dissimilarity between the abnormal data components corresponding to two adjacent comparison time periods.

[0073] Here, the greater the difference or abrupt change in data between adjacent time periods, the more significant the anomaly.

[0074] It is understandable that the dissimilarity of each adjacent difference can form a diagonal matrix, namely the dissimilarity matrix d. i0 .

[0075] n i0 Let be the average number of data packets for monitoring indicator i. Here, the average number of data packets for the monitoring indicator is calculated based on the number of data packets in the abnormal data of the monitoring indicator within the predicted monitoring period and the length of the predicted monitoring period, in order to reflect the intensity of the anomaly.

[0076] F iv To monitor the daily average activity level of indicator i, it needs to be pre-set. Here, the number of times all network elements in the power optical transmission network send data corresponding to the monitoring indicator within a day is taken as the daily average data frequency of the monitoring indicator. First, different daily average data frequency ranges are pre-defined, and corresponding daily average activity levels are set for each range. For example, daily average activity levels can include high (80-100 times), medium (40-80 times), and low (0-40 times), corresponding to values ​​of 3, 2, and 1, respectively. The higher the daily average activity level, the more times the data corresponding to the monitoring indicator is sent, and the greater the possibility of network attacks. Higher activity levels also enhance the characteristic value.

[0077] For example, if the data corresponding to the monitoring indicator is data that is only sent upon request, then the ratio of the number of times all network elements in the power optical transmission network send historical data of the monitoring indicator within the historical monitoring period to the number of days in the historical monitoring period can be determined as the historical average daily number of times the monitoring indicator is sent. If the network elements send the monitoring indicator data periodically, then the number of times all network elements in the power optical transmission network send historical data of the monitoring indicator on a certain day within the historical monitoring period can be directly determined as the historical average daily number of times the monitoring indicator is sent. Then, the historical average daily number of times the monitoring indicator is matched with the range of daily average times, and the daily average activity of the data corresponding to the target range of daily average times that matches the historical average daily number of times the monitoring indicator is used as the daily average activity of the monitoring indicator.

[0078] In practical applications, when a power line optical transmission network (PLO) is attacked, the network's anomalies change over time, reflecting the persistence of the attack. In this embodiment, a time-series feature matrix of abnormal data from monitoring indicators reflects the dynamic evolution of abnormal events, capturing persistent and sudden attacks. Time-series analysis further distinguishes between normal equipment fluctuations and genuine threats. Simultaneously, multi-dimensional parameters are transformed into time-series features with unified dimensions, facilitating feature comparison during real-time monitoring of the PLO.

[0079] Step 104: Determine the characteristics of the abnormal data of the monitoring indicators based on the time-series feature matrix of the abnormal data of the monitoring indicators.

[0080] Step 105: Determine the characteristics of abnormal data in the power optical transmission network based on the characteristics of abnormal data in the monitoring indicators.

[0081] In this embodiment, by combining time-series features and historical data, the characteristics of abnormal data with time attributes are generated for monitoring indicators. This enables efficient extraction of factors for perceiving abnormal events in the power control optical transmission network, providing accurate basis for real-time alarms and threat decision-making. Therefore, based on the characteristics of abnormal data for each monitoring indicator, the characteristics of abnormal data in the power optical transmission network are determined, providing accurate basis for real-time monitoring of the power optical transmission network, improving the security and defense capabilities of the power optical transmission network, and preventing faults or malicious attacks on the power optical transmission network.

[0082] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process of this embodiment, the characteristics of the abnormal data of the monitoring indicators are determined based on the time-series feature matrix of the abnormal data of the monitoring indicators, including: determining the historical abnormal range of the monitoring indicators and the historical occurrence probability corresponding to the historical abnormal range based on the historical abnormal data of the monitoring indicators sent by the network element devices within the historical monitoring period; matching the abnormal data of the monitoring indicators with the historical abnormal range, and determining the occurrence probability of the abnormal data of the monitoring indicators based on the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicators; and determining the characteristics of the abnormal data of the monitoring indicators based on the time-series feature matrix of the abnormal data of the monitoring indicators and the occurrence probability of the abnormal data of the monitoring indicators.

[0083] In this embodiment, the characteristics of abnormal data for the monitoring indicators are determined according to the following formula:

[0084] C iP =A ir ×μ(a ir )×d ir

[0085] Among them, a ir Abnormal data for monitoring indicator i within a preset monitoring period can be understood as r sets of signals integrated together.

[0086] μ(a ir Let μ(a) be the probability matrix of abnormal data for monitoring indicator i, composed of the probability of occurrence of similar abnormal events within historical monitoring periods. Specifically, based on the historical abnormal data of monitoring indicators sent by all network element devices in the power optical transmission network within historical monitoring periods, the historical abnormal range of the monitoring indicator and the historical occurrence probability corresponding to the historical abnormal range are determined. For example, the historical abnormal range of CPU temperature of network element devices may include 80℃~85℃ (historical occurrence probability of 0.6), 85℃~90℃ (historical occurrence probability of 0.3), 90℃~95℃ (historical occurrence probability of 0.08), and greater than 90℃ (historical occurrence probability of 0.02). Then, the abnormal data of the monitoring indicator is matched with the historical abnormal range, and the occurrence probability of the abnormal data of the monitoring indicator is determined according to the historical occurrence probability corresponding to the target historical abnormal range matched with the abnormal data of the monitoring indicator. It can be understood that the abnormal data of the monitoring indicator includes multiple data, so the occurrence probability of each data in the abnormal data of the monitoring indicator can be used to form the probability matrix of the abnormal data of the monitoring indicator. Thus, μ(a) can be used to determine the probability of occurrence of the abnormal data of the monitoring indicator. ir Suppress occasional false alarms and enhance high-frequency threat detection. For example, low-frequency anomalies (such as occasional device restarts) have a low probability, C iP The C of weakened, high-probability events (such as the periodic activity of Trojans) iPEnhanced, triggering alarms first.

[0087] d ir This is the gain matching coefficient, ranging from 0 to 1, used to balance the difference between historical and current data volumes. For example, if the current data volume is 10 times that of the historical data, then d... ir =0.1 to narrow the gap. To avoid comparison errors caused by different data volumes, coefficient scaling can retain a preset number of significant digits after the decimal point, improving the accuracy of feature comparison and reducing precision loss.

[0088] C iP To describe the characteristics of abnormal data for monitoring indicator i, we define the time-aware element of the abnormal event corresponding to monitoring indicator i in the power optical transmission network. The time-aware element captures the dynamic characteristics of abnormal events over time; for example, attacks may exhibit different patterns at different times, or certain abnormal indicators may have a cumulative effect. Through analysis along the time dimension, persistent attacks or periodic anomalies can be identified more accurately.

[0089] The time-aware elements of abnormal events here refer to the specific characteristics used to identify and describe abnormal events in power optical transmission networks, including system log anomalies, traffic anomalies, protocol anomalies, data anomalies, etc., providing power optical transmission systems with high-precision, low-latency security threat perception capabilities.

[0090] Therefore, in practical application scenarios, the highly nonlinear and separable features of the abnormal data extracted in this application can be used to construct a decision perception model, prevent the decision perception model from overfitting, enhance generalization, and monitor the operation status of the power transmission network in real time through the decision perception model, trigger accurate alarms, and improve the abnormal event coverage of the decision perception model.

[0091] It should be noted that the historical monitoring period should be close to the preset monitoring period, such as the previous month or the previous year, to ensure the reliability of feature extraction.

[0092] In one embodiment, the feature extraction method for abnormal data in a power optical transmission network further includes: dividing the power optical transmission network into multiple monitoring areas; acquiring regional monitoring data of regional equipment in the monitoring areas within a preset monitoring period; determining the characteristics of regional abnormal data of the monitoring indicators based on the regional monitoring data of the monitoring indicators; and determining the characteristics of abnormal data in the power optical transmission network based on the characteristics of the regional abnormal data of the monitoring indicators.

[0093] In this embodiment, the power optical transmission network is divided into multiple sensing intervals (i.e., monitoring areas) according to physical or logical boundaries. Monitoring data of network element devices (i.e., area devices) within each sensing interval is acquired within a preset monitoring period. Similar to step 102, based on the area monitoring data of the monitoring indicators within the sensing intervals, abnormal data for the monitoring indicators within the sensing intervals is determined. Then, similar to steps 103 and 104, the characteristics of the abnormal data for the monitoring indicators within the sensing intervals are calculated, narrowing the calculation scope, improving calculation efficiency and accuracy, and avoiding global data interference. Furthermore, based on the characteristics of the abnormal data for the same monitoring indicator in each sensing interval, the characteristics of the abnormal data for that monitoring indicator in the power optical transmission network are determined, ultimately determining the characteristics of all abnormal data in the power optical transmission network.

[0094] For example, each substation in the power optical transmission network can be used as a sensing interval, or, further, representative network element devices in each substation can be selected as a sensing interval for regional refinement. This can avoid excessive coupling caused by individual device calculations and also avoid the low accuracy caused by treating the entire power optical transmission network as a single interval.

[0095] In one embodiment, the feature extraction method for abnormal data in a power optical transmission network further includes: taking the network management system corresponding to the power optical transmission network as a sensing interval; acquiring the target monitoring data of the target monitoring indicators of the gateway devices in the network management system within a preset monitoring period; determining the abnormal data of the target monitoring indicators based on the target monitoring data of the target monitoring indicators, and extracting the features of the abnormal data of the target monitoring indicators.

[0096] In this embodiment, the network management system at the first level of the power optical transmission network is monitored separately, and the data of the entire network is integrated. Combined with the global perspective of the network management system, the power optical transmission network can be monitored in real time more reliably.

[0097] For example, based on the data involved in the actual operation of the network management system, target monitoring indicators for the network management system are determined, and the network management system is monitored according to these target monitoring indicators. Similarly, probes are set up in the network management system to read data and obtain target monitoring data for the target monitoring indicators. Thus, similar to steps 102 to 104, the characteristics of target abnormal data for each target monitoring indicator are extracted from the large amount of target monitoring data in the network management system.

[0098] Here, the target monitoring indicators can include data transmitted by the network management system, as well as the system operation status data of the network management system itself. For example, the connection status with network elements (timeout failure, device offline), abnormal user logins to the network management system, abnormal operations (exceeding permissions), and abnormal upgrades (upgrades not reported).

[0099] It should be noted that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0100] Furthermore, such as Figure 2 As shown, as a specific implementation of the above-mentioned feature extraction method for abnormal data in power optical transmission networks, this application embodiment provides a feature extraction device 200 for abnormal data in power optical transmission networks. The feature extraction device 200 for abnormal data in power optical transmission networks includes: an acquisition module 201 and a determination module 202.

[0101] Among them, the acquisition module 201 is used to acquire the monitoring data of the monitoring indicators of the network element equipment in the power optical transmission network within a preset monitoring period;

[0102] The determination module 202 is used to determine data in the monitoring data of the monitoring indicators that do not conform to the preset normal range corresponding to the monitoring indicators as abnormal data of the monitoring indicators; and,

[0103] Construct a time-series feature matrix of abnormal data for monitoring indicators; and,

[0104] Based on the time-series feature matrix of abnormal data for monitoring indicators, the characteristics of abnormal data for monitoring indicators are determined; and,

[0105] Based on the characteristics of abnormal data in the monitoring indicators, the characteristics of abnormal data in the power optical transmission network are determined.

[0106] In one embodiment, the determining module 202 is specifically used to determine the abnormal index of the monitoring indicator based on the abnormal data of the monitoring indicator; determine the security factor when the network element device sends the abnormal data of the monitoring indicator based on the abnormal index of the monitoring indicator; and determine the time-series feature matrix of the abnormal data of the monitoring indicator based on the security factor when the network element device sends the abnormal data of the monitoring indicator.

[0107] In one embodiment, the determining module 202 is specifically used to determine a first target value based on the target abnormal data corresponding to the network element device in the abnormal data of the monitoring indicator and the correlation coefficient of the network element device, wherein the correlation coefficient is determined based on the distance between the network element devices; determine a second target value based on the first target value and the threat level of the monitoring indicator, wherein the second target value is used to indicate the contribution of the network element device to the abnormal index of the monitoring indicator; and perform summation processing on the second target value to determine the abnormal index of the monitoring indicator.

[0108] In one embodiment, the determining module 202 is specifically used to determine a third target value based on the anomaly index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator; and to determine the security factor when the network element device sends the abnormal data of the monitoring indicator based on the third target value, the importance level of the monitoring indicator and the size of the data packets in the abnormal data of the monitoring indicator.

[0109] In one embodiment, the determining module 202 is specifically used to: divide the abnormal data of the monitoring indicators according to the time when the network element device sends the abnormal data of the monitoring indicators, obtain the abnormal data components of the monitoring indicators, and determine the dissimilarity between the abnormal data components; determine the average number of data packets of the monitoring indicators based on the number of data packets in the abnormal data of the monitoring indicators and the duration of the preset monitoring period; determine the average daily activity of the monitoring indicators based on the historical data of the monitoring indicators sent by the network element device in the historical monitoring period; and determine the time-series feature matrix of the abnormal data of the monitoring indicators based on the security factor when the network element device sends the abnormal data of the monitoring indicators, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicators, and the average daily activity of the monitoring indicators.

[0110] In one embodiment, the determining module 202 is specifically used to determine the historical abnormal range of the monitoring indicators and the historical occurrence probability corresponding to the historical abnormal range based on the historical abnormal data of the monitoring indicators sent by the network element device within the historical monitoring period; match the abnormal data of the monitoring indicators with the historical abnormal range, and determine the occurrence probability of the abnormal data of the monitoring indicators based on the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicators; and determine the characteristics of the abnormal data of the monitoring indicators based on the time-series feature matrix of the abnormal data of the monitoring indicators and the occurrence probability of the abnormal data of the monitoring indicators.

[0111] In one embodiment, the feature extraction device 200 for abnormal data in a power optical transmission network further includes:

[0112] The segmentation module is used to divide the power optical transmission network into multiple monitoring areas; acquire regional monitoring data of regional equipment in the monitoring areas within a preset monitoring period; determine the characteristics of regional abnormal data of the monitoring indicators based on the regional monitoring data of the monitoring indicators; and determine the characteristics of abnormal data in the power optical transmission network based on the characteristics of regional abnormal data of the monitoring indicators.

[0113] Specific limitations regarding the feature extraction device for abnormal data in power optical transmission networks can be found in the limitations of the feature extraction method for abnormal data in power optical transmission networks described above, and will not be repeated here. Each module in the aforementioned feature extraction device for abnormal data in power optical transmission networks can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0114] Based on the above, Figure 1 Accordingly, embodiments of this application also provide a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. Figure 1 The method for feature extraction of abnormal data in power optical transmission networks is shown.

[0115] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.

[0116] Based on the above, Figure 1 The method shown, and Figure 2 To achieve the above objectives, the present application also provides a computer device, specifically a personal computer, server, network device, etc., as shown in the virtual device embodiment. This computer device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to achieve the above-described objectives. Figure 1 The method for feature extraction of abnormal data in power optical transmission networks is shown.

[0117] Optionally, the computer device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Bluetooth interfaces, Wi-Fi interfaces), etc.

[0118] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the computer device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0119] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages and stores the hardware and software resources of a computer device, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software within the physical device.

[0120] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platform, or the embodiments of this application can be implemented by hardware.

[0121] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or they can be located in one or more apparatuses different from this embodiment, with corresponding changes. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.

[0122] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A method for feature extraction of abnormal data in a power optical transmission network, characterized in that, The method includes: Acquire monitoring data of network element equipment in the power optical transmission network within a preset monitoring period; Data that does not conform to the preset normal range corresponding to the monitoring indicator in the monitoring data is identified as abnormal data of the monitoring indicator. Construct a time-series feature matrix of the abnormal data for the monitoring indicators; Based on the time-series feature matrix of the abnormal data of the monitoring indicators, the characteristics of the abnormal data of the monitoring indicators are determined. Based on the characteristics of the abnormal data of the monitoring indicators, the characteristics of the abnormal data in the power optical transmission network are determined; The construction of the time-series feature matrix of the abnormal data of the monitoring indicators includes: Based on the abnormal data of the monitoring indicators, determine the abnormal index of the monitoring indicators; Based on the anomaly index of the monitoring indicator, determine the security factor when the network element device sends abnormal data of the monitoring indicator; Based on the security factor when the network element sends abnormal data of the monitoring indicator, determine the time-series feature matrix of the abnormal data of the monitoring indicator; The step of determining the abnormal index of the monitoring indicator based on the abnormal data of the monitoring indicator includes: Based on the abnormal data of the network element device in the abnormal data of the monitoring indicators, and the correlation coefficient of the network element device, a first target value is determined, wherein the correlation coefficient is determined based on the distance between the network element devices; Based on the first target value and the threat level of the monitoring indicator, a second target value is determined, which is used to indicate the contribution of the network element device to the anomaly index of the monitoring indicator. The second target value is summed to determine the anomaly index of the monitoring indicator; The step of determining the time-series feature matrix of the abnormal data of the monitoring indicator based on the security factor when the network element sends the abnormal data of the monitoring indicator includes: Based on the time when the network element sends the abnormal data of the monitoring indicator, the abnormal data of the monitoring indicator is divided into abnormal data components to obtain the abnormal data components of the monitoring indicator, and the dissimilarity between the abnormal data components is determined. The average number of data packets for the monitoring indicator is determined based on the number of abnormal data packets in the monitoring indicator and the duration of the preset monitoring period. The average daily activity level of the monitoring indicators is determined based on the historical data of the monitoring indicators sent by the network element devices during the historical monitoring period. Based on the security factor when the network element sends abnormal data of the monitoring indicator, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicator and the average daily activity of the monitoring indicator, the time series feature matrix of the abnormal data of the monitoring indicator is determined. The step of determining the characteristics of the abnormal data of the monitoring indicators based on the time-series feature matrix of the abnormal data of the monitoring indicators includes: Based on the historical abnormal data of the monitoring indicators sent by the network element device within the historical monitoring period, the historical abnormal range of the monitoring indicators and the historical occurrence probability corresponding to the historical abnormal range are determined. The abnormal data of the monitoring indicator is matched with the historical abnormal range, and the occurrence probability of the abnormal data of the monitoring indicator is determined according to the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicator. Based on the time-series feature matrix of the abnormal data of the monitoring indicators and the occurrence probability of the abnormal data of the monitoring indicators, the characteristics of the abnormal data of the monitoring indicators are determined. The abnormality index of the monitoring indicator is expressed as: ; in, For monitoring indicators i Abnormal index, The number of network elements in a power optical transmission network. For network element equipment j In monitoring indicators i The target abnormal data, For network element equipment j The correlation coefficient, It is the identity matrix. For monitoring indicators i The level of threat; The time-series feature matrix of the abnormal data of the monitoring indicators is represented as follows: ; in, For monitoring indicators i The time-series feature matrix of the abnormal data, Send monitoring indicators to network element devices i Safety factor when dealing with abnormal data. For monitoring indicators i The dissimilarity matrix between the outlier data components. For monitoring indicators i The average number of data packets, For monitoring indicators i The daily average activity data.

2. The feature extraction method for abnormal data in power optical transmission networks according to claim 1, characterized in that, The step of determining the security factor when the network element sends abnormal data of the monitoring indicator based on the abnormality index of the monitoring indicator includes: The third target value is determined based on the anomaly index of the monitoring indicator and the encryption complexity of the abnormal data of the monitoring indicator. Based on the third target value, the importance level of the monitoring indicator, and the size of the data packets in the abnormal data of the monitoring indicator, the security factor when the network element sends the abnormal data of the monitoring indicator is determined.

3. The feature extraction method for abnormal data in power optical transmission networks according to claim 1, characterized in that, The method further includes: The power optical transmission network is divided into multiple monitoring areas; Acquire regional monitoring data of the monitoring indicators of the regional equipment in the monitoring area within the preset monitoring period; Based on the regional monitoring data of the monitoring indicators, determine the characteristics of the regional abnormal data of the monitoring indicators; Based on the characteristics of the regional abnormal data of the monitoring indicators, the characteristics of abnormal data in the power optical transmission network are determined.

4. A feature extraction device for abnormal data in a power optical transmission network, characterized in that, The device includes: The acquisition module is used to acquire monitoring data of network element equipment in the power optical transmission network within a preset monitoring period; The determination module is used to determine data in the monitoring data of the monitoring indicator that does not conform to the preset normal range corresponding to the monitoring indicator as abnormal data of the monitoring indicator; and, Construct a time-series feature matrix of the abnormal data for the monitoring indicators; and, Based on the time-series feature matrix of the abnormal data of the monitoring indicators, the characteristics of the abnormal data of the monitoring indicators are determined; and, Based on the characteristics of the abnormal data of the monitoring indicators, the characteristics of the abnormal data in the power optical transmission network are determined; The construction of the time-series feature matrix of the abnormal data of the monitoring indicators includes: Based on the abnormal data of the monitoring indicators, determine the abnormal index of the monitoring indicators; Based on the anomaly index of the monitoring indicator, determine the security factor when the network element device sends abnormal data of the monitoring indicator; Based on the security factor when the network element sends abnormal data of the monitoring indicator, determine the time-series feature matrix of the abnormal data of the monitoring indicator; The step of determining the abnormal index of the monitoring indicator based on the abnormal data of the monitoring indicator includes: Based on the abnormal data of the network element device in the abnormal data of the monitoring indicators, and the correlation coefficient of the network element device, a first target value is determined, wherein the correlation coefficient is determined based on the distance between the network element devices; Based on the first target value and the threat level of the monitoring indicator, a second target value is determined, which is used to indicate the contribution of the network element device to the anomaly index of the monitoring indicator. The second target value is summed to determine the anomaly index of the monitoring indicator; The step of determining the time-series feature matrix of the abnormal data of the monitoring indicator based on the security factor when the network element sends the abnormal data of the monitoring indicator includes: Based on the time when the network element sends the abnormal data of the monitoring indicator, the abnormal data of the monitoring indicator is divided into abnormal data components to obtain the abnormal data components of the monitoring indicator, and the dissimilarity between the abnormal data components is determined. The average number of data packets for the monitoring indicator is determined based on the number of abnormal data packets in the monitoring indicator and the duration of the preset monitoring period. The average daily activity level of the monitoring indicators is determined based on the historical data of the monitoring indicators sent by the network element devices during the historical monitoring period. Based on the security factor when the network element sends abnormal data of the monitoring indicator, the dissimilarity between the abnormal data components, the average number of data packets of the monitoring indicator and the average daily activity of the monitoring indicator, the time series feature matrix of the abnormal data of the monitoring indicator is determined. The step of determining the characteristics of the abnormal data of the monitoring indicators based on the time-series feature matrix of the abnormal data of the monitoring indicators includes: Based on the historical abnormal data of the monitoring indicators sent by the network element device within the historical monitoring period, the historical abnormal range of the monitoring indicators and the historical occurrence probability corresponding to the historical abnormal range are determined. The abnormal data of the monitoring indicator is matched with the historical abnormal range, and the occurrence probability of the abnormal data of the monitoring indicator is determined according to the historical occurrence probability corresponding to the target historical abnormal range that matches the abnormal data of the monitoring indicator. Based on the time-series feature matrix of the abnormal data of the monitoring indicators and the occurrence probability of the abnormal data of the monitoring indicators, the characteristics of the abnormal data of the monitoring indicators are determined. The abnormality index of the monitoring indicator is expressed as: ; in, For monitoring indicators i Abnormal index, The number of network elements in a power optical transmission network. For network element equipment j In monitoring indicators i The target abnormal data, For network element equipment j The correlation coefficient, It is the identity matrix. For monitoring indicators i The level of threat; The time-series feature matrix of the abnormal data of the monitoring indicators is represented as follows: ; in, For monitoring indicators i The time-series feature matrix of the abnormal data, Send monitoring indicators to network element devices i Safety factor when dealing with abnormal data. For monitoring indicators i The dissimilarity matrix between the outlier data components. For monitoring indicators i The average number of data packets, For monitoring indicators i The daily average activity data.

5. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps of the feature extraction method for abnormal data in power optical transmission networks as described in any one of claims 1 to 3.

6. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the program, it implements the feature extraction method for abnormal data in power optical transmission networks as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Industrial control system safety protection method and device

    CN112637220A

  • Network event security monitoring method and system

    CN118200019A