Power system network attack identification method and device based on endogenous security
By setting a whitelist in the power system and monitoring SCADA and PMU data, combining state estimation and topological analysis to identify power system network attacks, the problem of indistinguishable network attacks is solved, and high-precision attack identification and effective protection measures are achieved.
Patent Information
- Application Number
- CN202510587758.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-08-12
AI Technical Summary
It is difficult to distinguish between network attacks and system failures in power system networks, and it is difficult for the existing technology to effectively identify and deal with endogenous security threats.
By setting the whitelist of application and network communications, monitoring SCADA and PMU data, analyzing abnormal data using state estimation and residual detection, combining topological design and fault recording data, identifying the type of network attacks and implementing corresponding protection schemes.
It improves the accuracy and adaptability of network attack identification, reduces operation and maintenance costs, and reduces the economic losses of false alarms and large-scale power outages.
Smart Images

Figure CN120474762A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system network security, particularly to security measurement of power business operations, and is a method and device for identifying power system network attacks based on intrinsic security. Background Art
[0002] With the development of the power industry, the pace of informatization is accelerating. Information technology has been widely applied in all aspects of power industry production. Grid dispatching, power production management, power marketing, and the operation and management of power enterprises have all been fully informatized. As a private, dedicated information network within power enterprises, the power information network is an indispensable infrastructure supporting the application of informatization in the power industry. Power information services cover every aspect of power generation, transmission, transformation, distribution, consumption, and dispatch. They are characterized by complex and widely distributed business entities, high business continuity requirements, wide-ranging implications, and significant impact. Power production and operations are completely dependent on the normal operation of the power information network. Therefore, the importance of power information network security is self-evident.
[0003] At the same time, power system cybersecurity faces multiple threats. These include whether software is fully autonomous and controllable; and whether third-party software, databases, and middleware contain vulnerabilities. Furthermore, new technologies like the Internet of Things and artificial intelligence are driving more complex and complex malicious software behaviors and methods, making them more concealed, distributed, persistent, and targeted.
[0004] Therefore, how to effectively identify whether a power system network failure is related to the power system network security, identify uncertain threats based on endogenous security issues, and what causes the failure is an important issue for technical personnel in this field to study. Summary of the Invention
[0005] The technical problem to be solved by the present invention is: to address the inherent security issues existing in the power system network, network attacks may be confused with power system faults themselves, and are difficult to detect effectively, and to provide a power system network attack protection method that integrates multiple physical feature information.
[0006] In order to solve the above technical problems, the present invention proposes a method and device for identifying power system network attacks based on intrinsic security. By analyzing the abnormal data and signals generated by sensors and fault protection devices in the power system, it is possible to analyze whether a power system network fault has occurred and distinguish it from a power system fault.
[0007] The technical solution of the present invention is: a method for identifying power system cyber attacks based on intrinsic security, which uses abnormal data and signals generated by sensors and fault protection devices in the power system to analyze whether a power system cyber attack has occurred, distinguish it from a power system fault, determine the type of cyber attack, and implement a corresponding security protection plan, including the following steps:
[0008] Step A: Set up an application whitelist and a network communication whitelist for the power system network, allowing only whitelisted objects to operate or communicate in the power system. Under this condition, monitor the data of the data acquisition and supervision system (SCADA) and the phasor measurement unit (PMU). If there is any abnormal sensor data, proceed to step B.
[0009] Step B: Monitor and analyze sensor data with abnormalities. If only the SCADA data is abnormal and does not conform to physical laws, it is determined to be a cyber attack. The power system data is analyzed using state estimation methods, and the type of cyber attack is determined based on whether the abnormality does not conform to physical laws. If both the PMU data and the SCADA data are abnormal, it is determined to be a cyber attack, and the cyber attack type is false data injection (FIDA). If there are SCADA data abnormalities exceeding the set value in the monitored local area, proceed to step C.
[0010] Step C: Make two judgments on the data anomalies in the designated local area:
[0011] 1) For sensors with abnormal SCADA data, a topology design is conducted to detect the communication capabilities between nodes. The single-point failure risk is identified for the topological root node. If there is a root node failure and the sensor can return to normal after troubleshooting, it is judged as a power system communication failure. If there is no root node failure and the sensors are functioning normally, it is judged that the local power system network is under network attack. The type of network attack is determined based on the difference between the sensor data of the power system network control center and the actual sensor data. If the sensor data of the control center is different from the actual sensor data, it is judged as false data injection (FIDA). If the actual sensor data is normal but the sensor data of the control center is abnormal or the instruction is wrong, it is judged as a denial of service attack (DoS).
[0012] 2) If the data anomaly triggers the activation of the power system fault protection device, proceed to step D;
[0013] Step D: After the power system fault protection device is activated, the fault recording data and operation log are retrieved and analyzed. If the transient characteristics in the fault recording data do not meet the development characteristics at the time of the fault, or if there are abnormal operations in the operation log, it is judged to be a network attack and the type of network attack is determined;
[0014] Step E: After determining that it is a power system network attack and determining the attack type, initiate the corresponding protection plan.
[0015] Furthermore, the application whitelist in step A only allows authorized programs to run in the power system infrastructure equipment, blocks all unauthorized executable files, and combines digital signature verification to ensure the reliability and integrity of authorized programs.
[0016] Furthermore, the network communication whitelist in step A only allows communication using authorized IP addresses, ports, and protocols, blocks the flow of abnormal traffic, and uses DPI technology to filter data that does not comply with the power protocol.
[0017] Furthermore, in step B, the SCADA data anomaly is judged to determine whether it is inconsistent with physical laws, including violations of Kirchhoff's laws in voltage and current data, violations of the law of conservation of energy in terms of power and energy, and abnormal voltage-power relationship in power flow calculations.
[0018] Furthermore, the state estimation method mathematically combines the power, voltage, and current measurement data with the topology of the power grid model to solve the system state and analyze whether the solved system state violates the physical constraints of the power system, including:
[0019] Step 1: Establish a measurement model;
[0020] z=h(x)+e Formula (1)
[0021] In formula (1), z is the measurement vector, x is the state vector, h(·) is the nonlinear measurement function, and e is the measurement error vector;
[0022] Step 2: Minimize the weighted residual sum of squares to solve;
[0023]
[0024] In formula (2), m is the total number of measurement vectors, σ l 2 is the error variance of the lth measurement, R is the measurement error variance covariance matrix;
[0025] Step 3: Set the initial state x based on historical data in the power grid system (0) ;
[0026] Step 4: Use the Newton-Raphson method to linearize the measurement equation and solve it iteratively to obtain the system state x;
[0027]
[0028] Δx (k) =(HT R -1 H) -1 H T R -1 [zh(x (k) )] Formula (4)
[0029] When Δx<ε Equation (5)
[0030] x (k+1) =x (k) +Δx (k) Formula (6)
[0031] In formula (3), H is the Jacobian matrix of the measurement vector, m is the dimension of the measurement vector, and n is the dimension of the state variable vector.
[0032] In formula (4), k is the number of iterations, Δx (k) is the difference between the kth iteration and the k-1th iteration;
[0033] In formula (5), ε is the convergence criterion, which is set to 10 -4 ;
[0034] In formula (6), x (k) is the system state quantity of the kth iteration.
[0035] Furthermore, the state estimation method is used to analyze the power system data, and the type of network attack is determined based on whether the current abnormal data is inconsistent with physical laws. The residual detection method is used to determine the type of network attack based on the power system state estimated by the state estimation method, including:
[0036] Perform physical law detection on the state estimation results;
[0037] 1) Power conservation law detection:
[0038] like
[0039]
[0040] This indicates that the power grid system is under cyber attack, and the type of cyber attack is false data injection attack FDIA; in formula (7), P ij is the active power flow of line ij, P i,inj is the active power injected into node i, ε P is the error threshold based on the measurement noise level; Q in formula (8) ij is the reactive power flow of line ij, Q i,inj is the reactive power injected into node i, ε Q is the error threshold based on the measurement noise level;
[0041] 2) Equipment operation limit detection:
[0042] like
[0043]
[0044] or
[0045] |S ij |>S ij,max Formula (10)
[0046] This indicates that the power grid system is under network attack, and the network attack type is denial of service attack DoS; in formula (9), V a is the voltage of line ai, V a,min is the minimum voltage of line a, V a,max is the maximum voltage of line a; S in formula (10) ij is the line capacity of line ij, S ij,max is the maximum line capacity of line ij;
[0047] The residual detection method is used to perform data detection on the system state estimated by the state estimation method;
[0048] like
[0049]
[0050] It means that the norm of the residual vector exceeds the normal threshold, indicating that the power grid system is attacked by the network, and the network attack type is false data injection attack FDIA; in formula (11), z is the measurement vector, χ α 2 is the chi-square distribution threshold at the confidence level α, is the estimated system state variable;
[0051] If the residual distribution deviates from the Gaussian characteristic, it indicates that the power grid system has been attacked by a cyber attack, and the type of cyber attack is an advanced persistent threat (APT).
[0052] Furthermore, for the designated local area monitored in step B, the judgment value of SCADA data anomaly is set according to the power grid level of the local area. For the medium-voltage distribution network, if there are five or more SCADA data anomalies, step C is entered. For the power grid system with a level smaller than the medium-voltage distribution network, the setting of the judgment value is lowered.
[0053] Furthermore, the single point failure risk identification of the topology root node in step C includes key node identification, failure probability identification, impact range analysis, and risk quantification, as follows:
[0054] Step 1: Identification of key nodes;
[0055]
[0056] In formula (12), C B is the betweenness centrality parameter of the power system topology, node s and node u are all nodes except the target node v, σ su is the total number of shortest paths from node s to node u, σ su (v) is the number of shortest paths from node s to node u passing through node v; C B It is used to measure the intermediary role of the node in the shortest path and is used to identify the key hubs in the power grid system. Therefore, the betweenness centrality C is taken B The largest node is the root node;
[0057] Step 2: Use the exponential distribution model to evaluate the root node failure probability;
[0058] P(t)=1-e -λt Formula (13)
[0059] In formula (13), λ is the average number of failures per unit time of the selected root node, t is the time period, and P(t) is the probability of failure occurring in time period t;
[0060] Step 3: Fault impact analysis;
[0061] 1) Remove the root node from the power grid topology. Let node v be the root node. After the root node v is removed, the admittance matrix Y changes.
[0062]
[0063] In formula (14), nodes s and u are nodes other than the root node v, and Y su,new is the mutual admittance between node s and node u in the modified admittance matrix, Y su is the direct mutual admittance between node s and node u in the original admittance matrix, Y sv and Y vu are the mutual admittance between node s and node v and the mutual admittance between node v and node u, Y vv is the self-admittance of node v;
[0064] 2) Rapidly evaluate the active power flow distribution, ignoring line resistance and ground admittance, and only retaining reactance X su , the active power flow equation is:
[0065]
[0066] In formula (15), P s is the net active injected power of node s, θ u is the voltage phase angle of node u, B su is the imaginary part of the node admittance matrix. When s≠u, X su is the reactance of the line between node s and node u. When s=u, That is, the sum of the inverse reactances of all lines connected to node s; its matrix form is:
[0067] P=Bθ Formula (16)
[0068] In formula (16), P is the node injected active power vector, B is the imaginary part of the node admittance matrix, and θ is the node voltage phase angle vector;
[0069] 3) The imaginary part of the admittance matrix B formed by the modified admittance matrix obtained in 1) new Substitute into equation (16) and solve for the phase angle vector θ;
[0070] P=B new θ Equation (17)
[0071] 4) Calculate and determine the active power flow of the line:
[0072]
[0073] like
[0074] |P su |>P su,max Formula (19)
[0075] This means that the failure of the root node v will cause the line flow between node s and node u to be overloaded;
[0076] Step 4: Calculate key indicators based on the root node according to the fault impact analysis and perform quantitative risk modeling.
[0077]
[0078] In formula (20), ΔL P is the total load loss caused by the failure of the root node v, ΔL max is the maximum possible load loss of the power system network, P(v) is the failure probability obtained in step 2, CI is the key indicator parameter, that is, the risk quantification result.
[0079] Furthermore, the transient characteristics in the fault recording data in step D do not meet the development characteristics when the fault occurs, including the sudden change of voltage and current instantaneous values without inertia, abnormal distribution of harmonic components, mismatch between dynamic response and physical model, and abnormal statistical feature discovery.
[0080] Furthermore, there are abnormal operations in the operation log in step D, including unauthorized configuration modification, abnormal source of operation instructions, destruction of log completeness, and abnormal user behavior.
[0081] Furthermore, the corresponding protection scheme in step E includes:
[0082] To prevent false data from being injected into the FDIA, the SCADA and PMU systems under attack are isolated. A pre-existing FDIA attack pattern library is used for comparison. The data is continuously verified for credibility, marked, counted, and analyzed. For long-term false data injection into the FDIA, a backup system is activated, switching to an offline backup database to restore key node status estimation data.
[0083] For DoS attacks, a DoS attack defense plan should be prepared during the normal operation of the power system. When the power system network is attacked by a DoS attack, the attacked data acquisition and monitoring system (SCADA) and phasor measurement unit (PMU) should be isolated to prevent the attack from spreading. Traffic cleaning equipment should then be activated to filter abnormal traffic, ensure core business bandwidth, and verify key parameters such as protection device set values and frequency control parameters.
[0084] For advanced persistent threats (APTs), defense deployments include quantum encryption communication technology upgrades, honeypot detection, layered protection systems, and testing system anti-attack capabilities through red-blue confrontation exercises.
[0085] The present invention also provides a power system network attack identification device based on intrinsic security, comprising
[0086] The permission configuration unit is used to set an application whitelist and a network communication whitelist for the power system network, authorize the application to run or communicate in the network, and monitor and filter unauthorized applications and network communications;
[0087] Data monitoring unit, used to monitor data from the data acquisition and monitoring system SCADA and the phasor measurement unit PMU;
[0088] The attack identification unit is used to perform the above-mentioned power system network attack identification method based on intrinsic security on the abnormal SCADA and PMU data monitored by the data monitoring unit.
[0089] Beneficial effects: The method and device for identifying power system network attacks based on intrinsic security proposed by the present invention have the following advantages:
[0090] 1. Improve detection accuracy. The causes of power system network failures are complex. Traditional methods find it difficult to distinguish network attack types and form a complete identification process. The method described in the present invention uses multi-dimensional physical feature data for cross-verification, which improves detection accuracy. Some attacks are difficult to detect through only a single level, but the method described in the present invention improves the effectiveness of identification through multi-level judgment of physical features.
[0091] 2. Enhanced adaptability to complex attacks. After identifying the type of network attack on the power system, the method of the present invention provides a corresponding protection scheme, making short-term protection measures for some attack types and long-term defense deployment for some attack types.
[0092] 3. Reduced operation and maintenance costs. The method of the present invention can perform network security measurement when abnormal data exists in the power system, reduce the time spent on manual investigations due to false alarms and device malfunctions, and avoid economic losses caused by large-scale power outages. BRIEF DESCRIPTION OF THE DRAWINGS
[0093] Figure 1 This is a flow chart of the method for identifying power system network attacks based on intrinsic security of the present invention.
[0094] Figure 2 Schematic diagram of the structure of the power system network attack identification device based on intrinsic security of the present invention. Specific implementation methods
[0095] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0096] Figure 1 This is a flow chart of the method for identifying power system network attacks based on intrinsic security of the present invention. Figure 1 As shown, the steps are as follows.
[0097] Step A: Set up an application whitelist and a network communication whitelist for the power system network, allowing only whitelisted objects to operate or communicate in the power system. Under this condition, monitor the data of the data acquisition and monitoring system SCADA and the phasor measurement unit PMU. If there is any abnormal sensor data, proceed to step B.
[0098] Step B: Monitor and analyze sensor data with data anomalies: If the SCADA data in the sensor is abnormal and clearly inconsistent with physical laws, it is judged as a network attack and the type of network attack is determined; if both the PMU data and SCADA data in the sensor are abnormal, it is judged as a network attack, and the type of network attack is false data injection (FIDA); for the designated local area being monitored, if there are SCADA data anomalies of a set value or above, proceed to step C.
[0099] It is generally believed that when a power system fails, SCADA data will also produce anomalies, but these anomalies are in accordance with physical laws and can be compared through the flow of the previous and next nodes. Therefore, in step B, if the SCADA data is abnormal but does not exceed the constraints of physical laws, it should be classified as a power system failure. Since the method of the present invention first performs the SCADA data anomaly judgment, it can be considered that only the SCADA anomaly is abnormal and the anomaly does not exceed the constraints of physical laws. In this case, it is classified as a power system failure.
[0100] Step C: Two-pronged Judgment on Data Anomalies
[0101] (1) For sensors with abnormal SCADA data, a topology design is conducted to detect the communication capabilities between nodes. The single point failure risk is identified for the topological root node. If there is a root node failure and the sensor can return to normal after troubleshooting, it is judged as a power system communication failure. If there is no root node failure and the sensors function normally, it is judged as a local area under network attack, and the type of network attack is determined. If there is no root node failure and the sensors function normally, only network attacks can cause SCADA data abnormalities. At this time, the data of the power system network control center is analyzed. If the control center sensor data is different from the actual sensor data, it is judged as a FIDA false data injection attack. If the actual sensor data is normal but the control center data is abnormal or the command is wrong, it is judged as a DoS denial of service attack.
[0102] (2) If the data anomaly triggers the operation of the power system fault protection device, proceed to step D.
[0103] Step D: After the power system fault protection device is activated, its fault recording data and operation log are retrieved and analyzed. If the transient characteristics such as the instantaneous values of voltage and current and their harmonic components in the recorded data of the protection device do not meet the development characteristics when the fault occurred or there are abnormal operations in the operation log of the protection device, it is judged as a network attack and the type of network attack is determined.
[0104] Step E: After determining that it is a power system network attack and determining the attack type, initiate the corresponding protection plan.
[0105] In this embodiment, the application whitelist in step A only allows authorized programs to run in the power system infrastructure equipment, blocks all unauthorized executable files, and combines digital signature verification to ensure the reliability and integrity of authorized programs.
[0106] In this embodiment, the network communication whitelist in step A only allows communication using authorized IP addresses, ports, protocols and other network communication standards, blocks the flow of abnormal traffic, and uses DPI technology to filter data that does not comply with the power protocol.
[0107] In this embodiment, in step B, the SCADA data is abnormal and obviously inconsistent with physical laws, and the state estimation method is used to analyze the power system, including obvious violations of Kirchhoff's laws in data such as voltage and current, obvious violations of the law of conservation of energy in terms of power and energy, and abnormal voltage-power relationship in power flow calculation.
[0108] The state estimation method mathematically combines power, voltage, current, and other measurement data with the topology of the power grid model to determine the system state. The solved system state is analyzed to determine whether there are any violations of the physical constraints of the power system. The residual detection method is then used to determine the fault type. The specific steps are as follows:
[0109] Step 1: Establish a measurement model;
[0110] z=h(x)+e Formula (1)
[0111] In formula (1), z is the measurement vector, x is the state vector, h(·) is the nonlinear measurement function, and e is the measurement error vector;
[0112] Step 2: Minimize the weighted residual sum of squares to solve;
[0113]
[0114] In formula (2), m is the total number of measurement vectors, σ l 2 is the error variance of the lth measurement, R is the measurement error variance covariance matrix;
[0115] Step 3: Set the initial state x based on historical data in the power grid system (0) ;
[0116] Step 4: Use the Newton-Raphson method to linearize the measurement equation and solve it iteratively to obtain the system state x;
[0117]
[0118] Δx (k) =(H T R -1 H) -1 H T R -1 [zh(x (k) )] Formula (4)
[0119] When Δx(k) <ε Formula (5)
[0120] x (k+1) =x (k) +Δx (k) Formula (6)
[0121] In formula (3), H is the Jacobian matrix of the measurement vector, m is the dimension of the measurement vector, and n is the dimension of the state variable vector.
[0122] In formula (4), k is the number of iterations, Δx (k) is the difference between the kth iteration and the k-1th iteration;
[0123] In formula (5), ε is the convergence criterion, which is generally set to 10 -4 ;
[0124] In formula (6), x (k) is the system state quantity of the kth iteration.
[0125] After analyzing the power system data using the state estimation method, the network attack type is determined based on whether the current abnormal data is inconsistent with physical laws. The residual detection method is then used to determine the network attack type based on the power system state estimated by the state estimation method, including:
[0126] Perform physical law detection on the state estimation results;
[0127] 1) Power conservation law detection:
[0128] like
[0129]
[0130] This indicates that the power grid system is under cyber attack, and the type of cyber attack is false data injection attack FDIA; in formula (7), P ij is the active power flow of line ij, P i,inj is the active power injected into node i, ε P is the error threshold based on the measurement noise level; Q in formula (8) ij is the reactive power flow of line ij, Q i,inj is the reactive power injected into node i, ε Q is the error threshold based on the measurement noise level;
[0131] 2) Equipment operation limit detection:
[0132] like
[0133]
[0134] or
[0135] |Sij |>S ij,max Formula (10)
[0136] This indicates that the power grid system is under network attack, and the network attack type is denial of service attack DoS; in formula (9), V a is the voltage of line ai, V a,min is the minimum voltage of line a, V a,max is the maximum voltage of line a; S in formula (10) ij is the line capacity of line ij, S ij,max is the maximum line capacity of line ij;
[0137] The residual detection method is used to perform data detection on the system state estimated by the state estimation method;
[0138] like
[0139]
[0140] It means that the norm of the residual vector exceeds the normal threshold, indicating that the power grid system is attacked by the network, and the network attack type is false data injection attack FDIA; in formula (11), z is the measurement vector, χ α 2 is the chi-square distribution threshold at the confidence level α, is the estimated system state variable, that is, the system state solved by the state estimation method.
[0141] If the residual distribution deviates from the Gaussian characteristic, it indicates that the power grid system has been attacked by a cyber attack, and the type of cyber attack is an advanced persistent threat (APT).
[0142] In this embodiment, the designated local area monitored in step B is generally a medium-voltage distribution network, such as an urban built-up area or industrial park. Five or more SCADA data anomalies are considered a threshold, and if five or more SCADA data anomalies are present, the process proceeds to step C. If monitoring is performed in a smaller power grid system, such as a rural township, the "five or more" threshold can be modified to reduce the threshold.
[0143] In this embodiment, the topology root node single point failure risk identification in step C includes key node identification, failure probability identification, impact range analysis, and risk quantification. For the power grid system topology diagram, the specific steps are as follows:
[0144] Step 1: Identification of key nodes;
[0145]
[0146] In formula (12), C Bis the betweenness centrality parameter of the power system topology, node s and node u are all nodes except the target node v, σ su is the total number of shortest paths from node s to node u, σ su (v) is the number of shortest paths from node s to node u passing through node v; C B It is used to measure the intermediary role of the node in the shortest path and is used to identify the key hubs in the power grid system. Therefore, the betweenness centrality C is taken B The largest node is the root node;
[0147] Step 2: Use the exponential distribution model to evaluate the root node failure probability;
[0148] P(t)=1-e -λt Formula (13)
[0149] In formula (13), λ is the average number of failures per unit time of the selected root node, t is the time period, which is generally one month, and P(t) is the probability of failure occurring in time period t;
[0150] Step 3: Fault impact analysis;
[0151] 1) Remove the root node from the power grid topology. Let node v be the root node. After the root node v is removed, the admittance matrix Y changes.
[0152]
[0153] In formula (14), nodes s and u are nodes other than the root node v, and Y su,new is the mutual admittance between node s and node u in the modified admittance matrix, Y su is the direct mutual admittance between node s and node u in the original admittance matrix, Y sv and Y vu are the mutual admittance between node s and node v and the mutual admittance between node v and node u, Y vv is the self-admittance of node v;
[0154] 2) To quickly evaluate the active power flow distribution, the line resistance and ground admittance are ignored, and only the reactance X is retained. su , and the phase angle difference θ st =θ s -θ t The active power flow equation is:
[0155]
[0156] In formula (15), P s is the net active injected power of node s, θ u is the voltage phase angle of node u, B suis the imaginary part of the node admittance matrix. When s≠u, X su is the reactance of the line between node s and node u. When s=u, That is, the sum of the inverse reactances of all lines connected to node s; its matrix form is:
[0157] P=Bθ Formula (16)
[0158] In formula (16), P is the node injected active power vector, B is the imaginary part of the node admittance matrix, and θ is the node voltage phase angle vector;
[0159] 3) The imaginary part of the admittance matrix B formed by the modified admittance matrix obtained in 1) new Substitute into equation (16) and solve for the phase angle vector θ;
[0160] P=B new θ Equation (17)
[0161] 4) Calculate and determine the active power flow of the line:
[0162]
[0163] like
[0164] |P su |>P su,max Formula (19)
[0165] This means that the failure of the root node v will cause the line flow between node s and node u to be overloaded;
[0166] Step 4: Calculate key indicators based on the root node according to the fault impact analysis and perform quantitative risk modeling.
[0167]
[0168] In formula (20), ΔL P is the total load loss caused by the failure of the root node v, ΔL max is the maximum possible load loss of the power system network, P(v) is the failure probability obtained in step 2, CI is the key indicator parameter, that is, the risk quantification result, which is used to evaluate whether the root node has a fault.
[0169] In this embodiment, the transient characteristics such as the instantaneous values of voltage and current and their harmonic components in the recorded data of the protection device in step D do not meet the development characteristics when the fault occurs, including the sudden change of the instantaneous values of voltage and current without inertia, abnormal distribution of harmonic components, mismatch between dynamic response and physical model, and abnormality found in statistical characteristics.
[0170] In this embodiment, in step D, there are abnormal operations in the protection device operation log, including unauthorized configuration modification, abnormal source of operation instructions, log completeness destruction, abnormal user behavior, etc.
[0171] In this embodiment, the corresponding protection scheme in step E is as follows: for false data injection into FDIA, the attacked data acquisition and monitoring system SCADA and phasor measurement unit PMU should be isolated, and a pre-stored FDIA attack pattern library should be called for comparison. The credibility of the data therein should be continuously verified, and marked statistics and analysis should be made. For long-term false data injection into FDIA, the backup system should be selected to be activated, and the offline backup database should be switched to restore the key node status estimation data. For denial of service attacks (DoS), a DoS attack defense plan should be prepared during the normal operation of the power system. After the power system network suffers a denial of service attack, the attacked data acquisition and monitoring system SCADA and phasor measurement unit PMU should be isolated first to prevent the attack from spreading. Then, traffic cleaning equipment should be activated to filter abnormal traffic, ensure core business bandwidth, and verify key parameters such as protection device set values and frequency control parameters. For advanced persistent threats (APT), defense against this type of attack generally relies on long-term defense deployment. Existing defense deployments include quantum encryption communication technology upgrades, honeypot detection, protection system layering (physical layer, network layer, and application layer), and testing the system's anti-attack capabilities through red-blue confrontation drills.
[0172] The present invention also provides a power system network attack identification device based on intrinsic security, such as Figure 2 Shown, including
[0173] The permission configuration unit is used to set an application whitelist and a network communication whitelist for the power system network, authorize the application to run or communicate in the network, and monitor and filter unauthorized applications and network communications;
[0174] Data monitoring unit, used to monitor data from the data acquisition and monitoring system SCADA and the phasor measurement unit PMU;
[0175] The attack identification unit is used to perform the above-mentioned power system network attack identification method based on intrinsic security on the abnormal SCADA and PMU data monitored by the data monitoring unit.
[0176] The power system network attack identification device based on intrinsic security provided by the embodiment of the present disclosure can execute the power system network attack identification method based on intrinsic security provided by any embodiment of the present disclosure, and has the corresponding functions and beneficial effects of the execution method.
Claims
1. A method for identifying power system network attacks based on intrinsic security, characterized by: The abnormal data and signals generated by sensors and fault protection devices in the power system are used to analyze whether a power system cyber attack has occurred, distinguish it from a power system fault, determine the type of cyber attack, and implement a corresponding security protection plan. The steps include the following: Step A: Set up an application whitelist and a network communication whitelist for the power system network, allowing only whitelisted objects to operate or communicate in the power system. Under this condition, monitor the data of the data acquisition and supervision system (SCADA) and the phasor measurement unit (PMU). If there is any abnormal sensor data, proceed to step B. Step B: Monitor and analyze sensor data with abnormalities. If only the SCADA data is abnormal and does not conform to physical laws, it is determined to be a cyber attack. The power system data is analyzed using state estimation methods, and the type of cyber attack is determined based on whether the abnormality does not conform to physical laws. If both the PMU data and the SCADA data are abnormal, it is determined to be a cyber attack, and the cyber attack type is false data injection (FIDA). If there are SCADA data abnormalities exceeding the set value in the monitored local area, proceed to step C. Step C: Make two judgments on the data anomalies in the designated local area: 1) For sensors with abnormal SCADA data, a topology design is conducted to detect the communication capabilities between nodes. The single-point failure risk is identified for the topological root node. If there is a root node failure and the sensor can return to normal after troubleshooting, it is judged as a power system communication failure. If there is no root node failure and the sensors are functioning normally, it is judged that the local power system network is under network attack. The type of network attack is determined based on the difference between the sensor data of the power system network control center and the actual sensor data. If the sensor data of the control center is different from the actual sensor data, it is judged as false data injection (FIDA). If the actual sensor data is normal but the sensor data of the control center is abnormal or the instruction is wrong, it is judged as a denial of service attack (DoS). 2) If the data anomaly triggers the activation of the power system fault protection device, proceed to step D; Step D: After the power system fault protection device is activated, the fault recording data and operation log are retrieved and analyzed. If the transient characteristics in the fault recording data do not meet the development characteristics at the time of the fault, or if there are abnormal operations in the operation log, it is judged to be a network attack and the type of network attack is determined; Step E: After determining that it is a power system network attack and determining the attack type, initiate the corresponding protection plan.
2. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The application whitelist in step A only allows authorized programs to run in the power system infrastructure equipment, blocks all unauthorized executable files, and combines digital signature verification to ensure the reliability and integrity of authorized programs.
3. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The network communication whitelist in step A only allows communication using authorized IP addresses, ports, and protocols, blocks the flow of abnormal traffic, and uses DPI technology to filter data that does not comply with the power protocol.
4. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: In step B, the SCADA data anomaly is judged to see whether it is inconsistent with physical laws, including violations of Kirchhoff's laws in voltage and current data, violations of the law of conservation of energy in terms of power and energy, and abnormal voltage-power relationship in power flow calculations.
5. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The state estimation method uses mathematical methods to combine power, voltage, and current measurement data with the topology of the power grid model to solve the system state and analyze whether it conforms to physical laws. It includes: Step 1: Establish a measurement model; z=h(x)+e Formula (1) In formula (1), z is the measurement vector, x is the state vector, h(·) is the nonlinear measurement function, and e is the measurement error vector; Step 2: Minimize the weighted residual sum of squares to solve; In formula (2), m is the total number of measurement vectors, σ l 2 is the error variance of the lth measurement, R is the measurement error variance covariance matrix; Step 3: Set the initial state x based on historical data in the power grid system (0) ; Step 4: Use the Newton-Raphson method to linearize the measurement equation and solve it iteratively to obtain the system state x; Δx (k) =(H T R -1 H) -1 H T R -1 [z - h(x (k) )] Equation (4) When Δx<ε Equation (5) x (k+1) = x (k) + Δx (k) Equation (6) In formula (3), H is the Jacobian matrix of the measurement vector, m is the dimension of the measurement vector, and n is the dimension of the state variable vector. In formula (4), k is the number of iterations, Δx (k) is the difference between the kth iteration and the k-1th iteration; In formula (5), ε is the convergence criterion, which is set to 10 -4 ; In formula (6), x (k) is the system state quantity of the kth iteration.
6. The method for identifying power system network attacks based on intrinsic security according to claim 1 or 5, characterized in that: The system state is solved using the state estimation method. The solved system state is analyzed to see if there are any violations of the physical constraints of the power system. The type of network attack is determined based on whether the current abnormal data does not conform to the physical laws. The residual detection method is used to determine the type of network attack based on the power system state estimated by the state estimation method, including: Perform physical law detection on the state estimation results; 1) Power conservation law detection: like This indicates that the power grid system is under cyber attack, and the type of cyber attack is false data injection attack FDIA; in formula (7), P ij is the active power flow of line ij, P i,inj is the active power injected into node i, ε P is the error threshold based on the measurement noise level; Q in formula (8) ij is the reactive power flow of line ij, Q i,inj is the reactive power injected into node i, ε Q is the error threshold based on the measurement noise level; 2) Equipment operation limit detection: like or |S ij |>S ij,max Formula (10) This indicates that the power grid system is under network attack, and the network attack type is denial of service attack DoS; in formula (9), V a is the voltage of line ai, V a,min is the minimum voltage of line a, V a,max is the maximum voltage of line a; S in formula (10) ij is the line capacity of line ij, S ij,max is the maximum line capacity of line ij; The residual detection method is used to perform data detection on the system state estimated by the state estimation method; like It means that the norm of the residual vector exceeds the normal threshold, indicating that the power grid system is attacked by the network, and the network attack type is false data injection attack FDIA; in formula (11), z is the measurement vector, χ α 2 is the chi-square distribution threshold at the confidence level α, is the estimated system state variable; If the residual distribution deviates from the Gaussian characteristic, it indicates that the power grid system has been attacked by a cyber attack, and the type of cyber attack is an advanced persistent threat (APT).
7. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: For the designated local area monitored in step B, the judgment value of SCADA data anomaly is set according to the power grid level of the local area. For the medium-voltage distribution network, if there are five or more SCADA data anomalies, step C is entered. For the power grid system with a level smaller than the medium-voltage distribution network, the setting of the judgment value is lowered.
8. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The single point failure risk identification of the topology root node in step C includes key node identification, failure probability identification, impact range analysis, and risk quantification, as follows: Step 1: Identification of key nodes; In formula (12), C B is the betweenness centrality parameter of the power system topology, node s and node u are all nodes except the target node v, σ su is the total number of shortest paths from node s to node u, σ su (v) is the number of shortest paths from node s to node u passing through node v; C B It is used to measure the intermediary role of the node in the shortest path and is used to identify the key hubs in the power grid system. Therefore, the betweenness centrality C is taken B The largest node is the root node; Step 2: Use the exponential distribution model to evaluate the root node failure probability; P(t)=1-e -λt Formula (13) In formula (13), λ is the average number of failures per unit time of the selected root node, t is the time period, and P(t) is the probability of failure occurring in time period t; Step 3: Fault impact analysis; 1) Remove the root node from the power grid topology. Let node v be the root node. After the root node v is removed, the admittance matrix Y changes. In formula (14), nodes s and u are nodes other than the root node v, and Y su,new is the mutual admittance between node s and node u in the modified admittance matrix, Y su is the direct mutual admittance between node s and node u in the original admittance matrix, Y sv and Y vu are the mutual admittance between node s and node v and the mutual admittance between node v and node u, Y vv is the self-admittance of node v; 2) Rapidly evaluate the active power flow distribution, ignoring line resistance and ground admittance, and only retaining reactance X su , the active power flow equation is: In formula (15), P s is the net active injected power of node s, θ u is the voltage phase angle of node u, B su is the imaginary part of the node admittance matrix. When s≠u, X su is the reactance of the line between node s and node u. When s=u, That is, the sum of the reciprocals of the reactance of all lines connected to node s; Its matrix form is: P=Bθ Formula (16) In formula (16), P is the node injected active power vector, B is the imaginary part of the node admittance matrix, and θ is the node voltage phase angle vector; 3) The imaginary part of the admittance matrix B formed by the modified admittance matrix obtained in 1) new Substitute into equation (16) and solve for the phase angle vector θ; P=B new θ Equation (17) 4) Calculate and determine the active power flow of the line: like |P su |>P su,max Formula (19) This means that the failure of the root node v will cause the line flow between node s and node u to be overloaded; Step 4: Calculate key indicators based on the root node according to the fault impact analysis and perform quantitative risk modeling. In formula (20), ΔL P is the total load loss caused by the failure of the root node v, ΔL max is the maximum possible load loss of the power system network, P(v) is the failure probability obtained in step 2, CI is the key indicator parameter, that is, the risk quantification result.
9. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The transient characteristics in the fault recording data in step D do not meet the development characteristics when the fault occurs, including the sudden change of voltage and current instantaneous values without inertia, abnormal distribution of harmonic components, mismatch between dynamic response and physical model, and abnormal statistical feature discovery.
10. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: There are abnormal operations in the operation log in step D, including unauthorized configuration modification, abnormal source of operation instructions, destruction of log completeness, and abnormal user behavior.
11. The method for identifying power system network attacks based on intrinsic security according to claim 1 is characterized in that: The corresponding protection scheme in step E includes: To prevent false data from being injected into the FDIA, the SCADA and PMU systems under attack are isolated. A pre-existing FDIA attack pattern library is used for comparison. The data is continuously verified for credibility, marked, counted, and analyzed. For long-term false data injection into the FDIA, a backup system is activated, switching to an offline backup database to restore key node status estimation data. For DoS attacks, a DoS attack defense plan should be prepared during the normal operation of the power system. When the power system network is attacked by a DoS attack, the attacked data acquisition and monitoring system (SCADA) and phasor measurement unit (PMU) should be isolated to prevent the attack from spreading. Traffic cleaning equipment should then be activated to filter abnormal traffic, ensure core business bandwidth, and verify key parameters such as protection device set values and frequency control parameters. For advanced persistent threats (APTs), defense deployments include quantum encryption communication technology upgrades, honeypot detection, layered protection systems, and testing system anti-attack capabilities through red-blue confrontation exercises.
12. The power system network attack identification device based on intrinsic security is characterized by: include The permission configuration unit is used to set an application whitelist and a network communication whitelist for the power system network, authorize the application to run or communicate in the network, and monitor and filter unauthorized applications and network communications; Data monitoring unit, used to monitor data from the data acquisition and monitoring system SCADA and the phasor measurement unit PMU; The attack identification unit is used to perform the power system network attack identification method based on intrinsic security according to any one of claims 1 to 11 on the abnormal SCADA and PMU data monitored by the data monitoring unit.