Thermal power plant network security early warning management system and method
By monitoring communication traffic in thermal power plant networks and conducting deep learning timing analysis, identifying similarities with known ransomware communication traffic patterns is solved, and a more accurate and timely network security warning is achieved.
Patent Information
- Application Number
- CN202510339071.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-08-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The traditional thermal power plant network security protection system is difficult to effectively identify and warn of new or variant ransomware attacks, resulting in frequent missed detections and affecting network security and normal operations.
By monitoring the communication traffic data of network equipment of thermal power plants, using deep learning technology to perform timing analysis, extract communication traffic pattern characteristics, and perform fine-grained ablation analysis with the communication traffic pattern characteristics of known ransomware, identify abnormal traffic patterns, and generate network security warnings.
It improves the accuracy and timeliness of network security warning in thermal power plants, avoids missed detection of traditional feature library methods, and enhances the ability to identify potential ransomware attacks.
Smart Images

Figure CN120498706A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of thermal power plants, and more specifically, to a network security early warning management system and method for a thermal power plant. Background Art
[0002] With the rapid development of information technology, critical infrastructure such as thermal power plants has become increasingly reliant on computer networks and automation systems for efficient operation and management. However, this high reliance on these systems has also made thermal power plants a target for cyberattacks. Ransomware, a common cyberattack tactic, has caused significant economic losses and operational disruptions worldwide in recent years. Ransomware typically disrupts normal operations by encrypting infected files or locking user interfaces, demanding a ransom for decryption. For thermal power plants, the infection of critical control systems or data by ransomware can not only lead to power outages but also potentially cause safety incidents, resulting in immeasurable impacts on personnel safety and the environment.
[0003] However, with the continuous advancement of network attack technology, especially the increasing frequency and sophistication of ransomware attacks, traditional network security protection systems are facing severe challenges. Traditional ransomware detection methods based on signature libraries mainly build signature libraries based on relatively intuitive and simple static features, such as the hash value of the ransomware file, specific file names, file extensions, and specific modified values of registry keys. Their detection depth is relatively shallow, and they can only identify ransomware that completely matches or is highly similar to existing records in the signature library. For ransomware that has undergone some simple transformations (such as modifying the file name but not the core attack logic) or new variants, as long as their static features are not in the signature library, they are easily missed, making it difficult to deeply analyze whether the ransomware's inherent behavioral logic is consistent with known ransomware.
[0004] Therefore, an optimized network security early warning management system and method for thermal power plants is desired. Summary of the Invention
[0005] The present invention aims to solve at least one of the technical problems existing in the prior art and provides a network security early warning management system and method for a thermal power plant.
[0006] In a first aspect, an embodiment of the present invention provides a method for network security early warning management of a thermal power plant, comprising:
[0007] Monitor the communication flow data of networked devices in a thermal power plant network to obtain a time series data set of the communication flow data;
[0008] Performing time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature;
[0009] Extracting a set of communication traffic time series pattern features of known ransomware from background data;
[0010] performing correlation coding between communication traffic features on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature;
[0011] Performing fine-grained ablation analysis and joint coding on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic;
[0012] Based on the cross-domain ablation coding characteristics of the communication traffic of the networked device, determine whether to generate network security warning prompt information.
[0013] In some possible embodiments, performing time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature includes:
[0014] The time series data set of the communication traffic data is input into a sequence encoder based on a forward LSTM model to obtain a communication traffic time series pattern encoding feature vector as the communication traffic time series pattern encoding feature.
[0015] In some possible embodiments, performing correlation coding between communication traffic features on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature includes:
[0016] The set of communication traffic timing pattern features of the known ransomware is arranged into a ransomware communication traffic timing pattern feature aggregation tensor according to the parameter sample dimension, and then input into a ransomware communication traffic correlation feature encoder based on a void convolutional neural network model to obtain a ransomware communication traffic timing correlation coding feature graph as the ransomware communication traffic timing correlation coding feature.
[0017] In some possible embodiments, fine-grained ablation analysis and joint coding are performed on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic, including:
[0018] Performing a local channel-based feature correlation strength ablation measurement on the communication traffic time series pattern encoding feature vector and the ransomware communication traffic time series correlation encoding feature map to obtain a set of networked device-ransomware communication traffic fine-grained ablation factors;
[0019] Based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, fine-grained ablation modulation is performed on the ransomware communication traffic time series correlation coding feature map to obtain a networked device communication traffic cross-domain ablation coding feature map as the networked device communication traffic cross-domain ablation coding feature.
[0020] In some possible embodiments, the communication traffic time series pattern encoding feature vector and the ransomware communication traffic time series correlation encoding feature map are subjected to a feature correlation strength ablation measurement based on a local channel to obtain a set of network device-ransomware communication traffic fine-grained ablation factors, including:
[0021] Performing fine-grained feature decoupling along the channel dimension on the ransomware communication traffic temporal correlation coding feature graph to obtain a set of ransomware communication traffic temporal correlation coding feature matrices;
[0022] Performing a cross-domain query interaction based on a simulated transformer structure on the communication traffic time series pattern encoding feature vector and each ransomware communication traffic time series correlation encoding feature matrix in the set of the ransomware communication traffic time series correlation encoding feature matrix to obtain a set of networked device-ransomware communication traffic cross-domain query interaction feature vectors;
[0023] Each networking device-ransomware communication traffic cross-domain query interaction feature vector in the set of networking device-ransomware communication traffic cross-domain query interaction feature vectors is input into the ablation metric function to obtain a set of networking device-ransomware communication traffic fine-grained ablation factors.
[0024] In some possible embodiments, based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, fine-grained ablation modulation is performed on the ransomware communication traffic time series correlation coding feature map to obtain a networked device communication traffic cross-domain ablation coding feature map as the networked device communication traffic cross-domain ablation coding feature, including:
[0025] Inputting the set of network device-ransomware communication traffic fine-grained ablation factors into an ablation effect encoding module including a normalization function and a masking function to obtain a set of network device-ransomware communication traffic fine-grained ablation weight factors;
[0026] Based on the set of fine-grained ablation weight factors of the networked device-ransomware communication traffic, the set of time-series correlation coding feature matrices of the ransomware communication traffic is weighted modulated and features are aggregated along the channel dimension to obtain the cross-domain ablation coding feature map of the networked device communication traffic.
[0027] In some possible embodiments, determining whether to generate network security warning prompt information based on the cross-domain ablation coding feature of the networked device communication traffic includes:
[0028] Inputting the cross-domain ablation coding feature map of the networked device communication traffic into a classifier-based security warning module to obtain a security warning analysis result, wherein the security warning analysis result is used to indicate whether abnormal traffic occurs in the networked device;
[0029] In response to the security warning analysis result that abnormal traffic occurs in the networked device, the network security warning prompt information is generated.
[0030] In some possible embodiments, the cross-domain ablation coding feature map of the networked device communication traffic is input into a classifier-based security warning module to obtain a security warning analysis result, where the security warning analysis result is used to indicate whether abnormal traffic occurs in the networked device, including:
[0031] Expanding the cross-domain ablation coding feature map of network device communication traffic into a cross-domain ablation coding feature vector of network device communication traffic;
[0032] Performing full-connection coding on the cross-domain ablation coding feature vector of the networked device communication traffic using the fully-connected layer of the classifier-based security warning module to obtain a fully-connected networked device communication traffic cross-domain ablation coding feature vector;
[0033] Inputting the cross-domain ablation coding feature vector of the communication traffic of fully connected networked devices into the Softmax classification function of the classifier-based security warning module to obtain the probability value of the cross-domain ablation coding feature map of the communication traffic of networked devices belonging to each classification label;
[0034] The classification label corresponding to the largest probability value among the probability values is determined as the security warning analysis result.
[0035] In a second aspect, an embodiment of the present invention provides a network security early warning management system for a thermal power plant, comprising:
[0036] A communication flow data monitoring module is used to monitor the communication flow data of networked devices in the thermal power plant network to obtain a time series data set of the communication flow data;
[0037] A communication traffic data pair time series coding module is used to perform time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature;
[0038] A known ransomware feature extraction module, configured to extract a set of communication traffic time series pattern features of known ransomware from background data;
[0039] a communication traffic feature correlation coding module, configured to perform communication traffic feature correlation coding on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature;
[0040] A fine-grained ablation analysis joint coding module, configured to perform fine-grained ablation analysis and joint coding on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic;
[0041] The early warning prompt information determination module is used to determine whether to generate network security early warning prompt information based on the cross-domain ablation coding characteristics of the communication traffic of the networked device.
[0042] In some possible embodiments, the communication traffic data pair timing encoding module is configured to:
[0043] The time series data set of the communication traffic data is input into a sequence encoder based on a forward LSTM model to obtain a communication traffic time series pattern encoding feature vector as the communication traffic time series pattern encoding feature.
[0044] Compared with the existing technology, the embodiment of the present invention provides a thermal power plant network security early warning management system and method. It monitors the communication traffic data of networked devices in the thermal power plant network and performs time series analysis based on deep learning technology to extract the time series change pattern characteristics of the communication traffic. At the same time, it extracts a set of communication traffic time series pattern characteristics of known ransomware from the background data. By performing fine-grained ablation analysis on the communication traffic time series pattern characteristics of networked devices and the communication traffic time series pattern feature set of known ransomware, it identifies and strengthens the abnormal traffic pattern feature representation in the communication traffic pattern of known ransomware that is similar to the communication traffic of networked devices, thereby realizing intelligent identification and early warning of potential ransomware attack behaviors of networked devices. In this way, the abnormal traffic characteristics of ransomware attack behaviors can be more effectively captured, avoiding missed detections due to the limitations of traditional feature library methods, and improving the accuracy and timeliness of thermal power plant network security early warnings. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0046] Figure 1This is a schematic flow chart of a network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0047] Figure 2 A data flow diagram of a network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0048] Figure 3 This is a schematic flow chart of step S5 in the network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0049] Figure 4 This is a schematic flow chart of step S51 in the network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0050] Figure 5 This is a schematic flow chart of step S52 in the network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0051] Figure 6 This is a schematic flow chart of step S6 in the network security early warning management method for a thermal power plant according to an embodiment of the present application;
[0052] Figure 7 This is a schematic block diagram of a network security early warning management system for a thermal power plant according to an embodiment of the present application. DETAILED DESCRIPTION
[0053] To enable those skilled in the art to better understand the technical solutions of the present invention, the present invention is further described below in conjunction with the accompanying drawings and specific embodiments. It is apparent that the described embodiments are only a portion of the embodiments of the present invention, rather than all of them. Based on the described embodiments of the present invention, all other embodiments obtained by those skilled in the art without requiring creative effort are within the scope of protection of the present invention.
[0054] Unless otherwise specified, the technical terms or scientific terms used in the embodiments of the present invention should be understood by people with ordinary skills in the field to which the present invention belongs. The terms "including" or "comprising" used in the embodiments of the present invention neither limit the shapes, numbers, steps, actions, operations, components, originals and / or their groups mentioned, nor exclude the appearance or addition of one or more other different shapes, numbers, steps, actions, operations, components, originals and / or their groups, or the addition of these. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number and order of the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present invention, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.
[0055] Unless otherwise specifically stated, the relative arrangements of the components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present invention. At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the drawings are not drawn in accordance with actual proportional relationships, and that the techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices shown should be considered part of the authorized specification. In all examples shown and discussed herein, any specific other examples may have different values. It should be noted that similar symbols and letters represent similar items in the following figures, and therefore, once an item is defined in one figure, it does not need to be further discussed in subsequent figures.
[0056] In the description of the embodiments of the present invention, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In the embodiments of the present invention, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in the embodiments of the present invention and the features of different embodiments or examples, unless they are mutually inconsistent.
[0057] Flowcharts are used in this disclosure to illustrate the operations performed by systems according to embodiments of the present invention. It should be understood that the preceding or following operations do not necessarily need to be performed in exact order. Instead, various steps may be processed in reverse order or simultaneously, as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0058] Below, the exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention, and it should be understood that the present invention is not limited to the exemplary embodiments described herein.
[0059] In response to the above technical problems, the technical concept of this application is as follows: by monitoring the communication traffic data of networked devices in the thermal power plant network and performing time series analysis based on deep learning technology to extract the time series change pattern characteristics of the communication traffic, at the same time, extracting a set of communication traffic time series pattern characteristics of known ransomware from the background data, and performing fine-grained ablation analysis on the communication traffic time series pattern characteristics of networked devices and the communication traffic time series pattern feature set of known ransomware, in order to identify and strengthen the abnormal traffic pattern feature representation in the communication traffic pattern of known ransomware that is similar to the communication traffic of networked devices, thereby realizing intelligent identification and early warning of potential ransomware attack behaviors of networked devices. In this way, the abnormal traffic characteristics of ransomware attack behaviors can be more effectively captured, avoiding the missed detection caused by the limitations of traditional feature library methods, and improving the accuracy and timeliness of network security early warnings of thermal power plants.
[0060] Based on this, in the technical solution of this application, if Figure 1 and Figure 2 As shown, the network security early warning management method for a thermal power plant includes: S1, monitoring the communication flow data of networked devices in the thermal power plant network to obtain a time series data set of communication flow data; S2, performing time series coding on the time series data set of communication flow data to obtain communication flow time series pattern coding features; S3, extracting a set of communication flow time series pattern features of known ransomware from background data; S4, performing communication flow feature correlation coding on the set of communication flow time series pattern features of the known ransomware to obtain ransomware communication flow time series correlation coding features; S5, performing fine-grained ablation analysis and joint coding on the communication flow time series pattern coding features and the ransomware communication flow time series correlation coding features to obtain cross-domain ablation coding features of networked device communication flow; S6, determining whether to generate network security early warning prompt information based on the cross-domain ablation coding features of the networked device communication flow.
[0061] For example, in step S1, communication traffic data from networked devices in a thermal power plant network is monitored to obtain a time-series dataset of communication traffic data. It should be understood that communication traffic data is a key source of information reflecting network activity. In a thermal power plant's network system, various networked devices continuously interact with each other, and their communication traffic data contains a wealth of information, including the device's operating status and data transmission status. By continuously monitoring and collecting communication traffic data from networked devices, we can fully understand the changing trends and patterns of traffic data at different time points, helping to detect potential abnormal traffic patterns and signs of ransomware attacks. In specific implementations, network traffic monitoring technology can be used to deploy traffic collection devices, such as network probes or traffic mirror ports, at key network nodes to capture and analyze passing data packets. Key metrics, such as the source IP address, destination IP address, port number, protocol type, and packet size and quantity, are recorded in chronological order. These data are then recorded and stored in a structured database table or a specific binary file format, thereby forming a time-series dataset of communication traffic data.
[0062] Exemplarily, in step S2, the time series data set of the communication traffic data is time-series encoded to obtain the communication traffic time series pattern encoding characteristics. It should be understood that, considering that ransomware attack behaviors are often accompanied by specific communication traffic patterns, and have certain regularity and characteristics in the time dimension. Therefore, in order to effectively identify and warn of attack behaviors, the present application further uses a sequence encoder based on a forward LSTM model to encode the time series data set of the communication traffic data to extract the time series change pattern characteristics of the communication traffic. The LSTM (Long Short-Term Memory) model is a special recurrent neural network (RNN) that can selectively memorize and forget information in the input sequence by introducing structures such as input gates, forget gates, and output gates, thereby being able to maintain memory of key information in long time series. In this solution, the forward LSTM model processes the communication traffic data of each time step in turn based on the time sequence relationship in the time series data set of the communication traffic data, calculates and updates the hidden state of the current moment through a gating mechanism based on the traffic characteristics of the current time step and the hidden state of the previous moment, so as to capture the change trend and correlation of the communication traffic data in the time dimension, generate a communication traffic time series pattern encoding feature vector, and thus realize the effective encoding of the communication traffic time series change pattern.
[0063] In one embodiment, the time series data set of the communication traffic data is time-series encoded to obtain a communication traffic time series pattern encoding feature, including: inputting the time series data set of the communication traffic data into a sequence encoder based on a forward LSTM model to obtain a communication traffic time series pattern encoding feature vector as the communication traffic time series pattern encoding feature.
[0064] Exemplarily, in step S3, a set of communication traffic timing pattern features of known ransomware is extracted from the background data. It should be understood that the communication traffic pattern of known ransomware is an important reference for identifying potential attacks. Therefore, the present application establishes a standard attack pattern library by extracting a set of communication traffic timing pattern features of known ransomware from the background data, so as to compare and analyze the communication traffic of the networked devices actually monitored, and quickly and accurately determine whether there is an attack behavior similar to ransomware. Here, the communication traffic timing pattern features of the known ransomware are the communication traffic timing pattern features extracted from the known ransomware samples by the above-mentioned forward LSTM model-based timing encoding method.
[0065] In one specific embodiment, extracting a set of time-series pattern features of known ransomware traffic from background data involves establishing a database containing known ransomware samples and their corresponding traffic data. This data can be obtained from multiple sources, such as historical attack event records, public security repositories (e.g., malware samples and related network traffic information provided by VirusTotal and MalwareTrafficAnalysis), and data captured by running known ransomware in an internal honeypot or sandbox environment. This ensures that the dataset is both comprehensive and representative, covering a wide range of ransomware types and their variants. Collected data is often unorganized and may contain noise, redundancy, or inconsistent formats. In this application, preprocessing operations can also be performed to ensure the effectiveness of subsequent analysis. Preprocessing steps include denoising and cleaning to remove irrelevant information and retain only the components directly related to ransomware behavior; standardization to convert data from different sources into a unified format for easy comparison and analysis; and normalization to scale numerical features so that the values in each dimension are within a similar order of magnitude, preventing certain features from being over-emphasized or under-emphasized by the model due to differences in magnitude. After preprocessing, the raw data becomes neater and more organized, laying a solid foundation for subsequent feature extraction. Finally, the preprocessed data is passed through the aforementioned forward LSTM model-based temporal encoding method to obtain a set of communication traffic time series pattern features of known ransomware.
[0066] Exemplarily, in step S4, the set of communication traffic timing pattern features of the known ransomware is subjected to correlation coding between communication traffic features to obtain ransomware communication traffic timing correlation coding features. It should be understood that, considering that different ransomware samples have certain differences and diversity in communication traffic timing patterns, directly matching and analyzing the communication traffic timing pattern features of a single ransomware may face high false alarm rates and missed alarm rates. Therefore, the present application further arranges and integrates the set of communication traffic timing pattern features of the known ransomware according to the parameter sample dimension to form a ransomware communication traffic timing pattern feature aggregation tensor, and then utilizes the powerful correlation feature extraction capability of the void convolutional neural network model to perform a sliding convolution operation on the ransomware communication traffic timing pattern feature aggregation tensor to mine the potential correlations and common features between different ransomware communication traffic timing patterns. By introducing dilated convolution kernels, the dilated convolutional neural network model can effectively expand the receptive field of the convolution operation without increasing the computational complexity, thereby capturing a wider range of contextual information and effectively encoding the deep correlation features between the temporal patterns of ransomware communication traffic.
[0067] In one embodiment, the set of communication traffic timing pattern features of the known ransomware is subjected to communication traffic feature correlation coding to obtain a ransomware communication traffic timing correlation coding feature, including: arranging the set of communication traffic timing pattern features of the known ransomware into a ransomware communication traffic timing pattern feature aggregation tensor according to a parameter sample dimension, and then inputting the tensor into a ransomware communication traffic correlation feature encoder based on a dilated convolutional neural network model to obtain a ransomware communication traffic timing correlation coding feature graph as the ransomware communication traffic timing correlation coding feature.
[0068] In one specific embodiment, when constructing an aggregate tensor, the communication traffic time series pattern features of multiple known ransomware samples extracted from background data are arranged according to their parameters (such as timestamp, protocol type, port number, packet size, etc.) and the different ransomware instances each sample represents (i.e., the sample dimension). For example, suppose there are three different ransomware samples, A, B, and C, each containing communication traffic data generated over a period of time. This data can be organized into a three-dimensional tensor, where the first dimension represents the different samples, the second dimension represents each time point in the time series, and the third dimension covers all parameter values recorded at that time point. This ensures that the parameters of each sample at the same time point can be directly compared, and the changes in the same sample at different times can be clearly displayed. This structure not only helps capture the temporal dependencies within individual samples, but also facilitates subsequent analysis of similarities and differences between different samples. Once the aggregate tensor is constructed, the encoder based on the atrous convolutional neural network (ACNN) model is used to process this complex multidimensional dataset. Dilated convolution is a special convolution operation that allows for a larger receptive field while maintaining computational efficiency. This means it can effectively cover a wider range of context, which is crucial for understanding long-term dependencies in traffic. Specifically, when an aggregate tensor is passed as input to the ACNN encoder, each dilated convolution layer adjusts its weights and biases based on the output of the previous layer to learn a feature representation that best distinguishes legitimate from malicious traffic. To better model the interactions between different samples, the encoder may also integrate attention mechanisms or other forms of interaction modules to highlight those components that are critical for ransomware detection. In this process, assume that we are processing an aggregate tensor consisting of N samples, each with T time steps and F feature dimensions. Then, the dilated convolution layer scans the entire tensor layer by layer, each using a convolution kernel with a dilation rate to extract information across multiple time steps. As the number of layers increases, the receptive field gradually expands until it covers the entire time series and even relevant information about other samples. Ultimately, after a series of these operations, the encoder generates a new feature representation: a temporal correlation encoding feature map of ransomware traffic. This feature map condenses the key information of the original communication traffic data and strengthens the feature representation that is crucial for identifying ransomware attacks through deep learning algorithms.
[0069] Exemplarily, in step S5, the communication traffic timing pattern coding feature and the ransomware communication traffic timing correlation coding feature are jointly coded by fine-grained ablation analysis to obtain the cross-domain ablation coding feature of the networked device communication traffic. That is, the communication traffic timing pattern coding feature vector and the ransomware communication traffic timing correlation coding feature graph are further subjected to feature query interaction to achieve intelligent matching and identification of potential ransomware attack behaviors in the networked device communication traffic. In particular, in order to improve the accuracy of feature query interaction analysis, the present application proposes a joint coding method based on fine-grained ablation analysis, which performs fine-grained feature query interaction and ablation operations on the communication traffic timing pattern coding feature vector and the ransomware communication traffic timing correlation coding feature graph to gradually remove irrelevant feature representations, focus on and strengthen feature representations that are highly similar to known ransomware communication traffic patterns, thereby achieving accurate identification of potential ransomware attack behaviors.
[0070] In one embodiment, Figure 3 As shown, the communication traffic timing pattern coding feature and the ransomware communication traffic timing association coding feature are subjected to fine-grained ablation analysis and joint coding to obtain the cross-domain ablation coding feature of the networked device communication traffic, including: S51, performing a feature correlation strength ablation measurement based on a local channel on the communication traffic timing pattern coding feature vector and the ransomware communication traffic timing association coding feature graph to obtain a set of fine-grained ablation factors of the networked device-ransomware communication traffic; S52, based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, performing fine-grained ablation modulation on the ransomware communication traffic timing association coding feature graph to obtain a cross-domain ablation coding feature graph of the networked device communication traffic as the cross-domain ablation coding feature of the networked device communication traffic.
[0071] In one embodiment, Figure 4 As shown, in step S51, the communication traffic time series pattern encoding feature vector and the ransomware communication traffic time series correlation encoding feature map are subjected to feature correlation strength ablation measurement based on a local channel to obtain a set of networked device-ransomware communication traffic fine-grained ablation factors, including: S511, the ransomware communication traffic time series correlation encoding feature map is subjected to feature fine-grained decoupling along the channel dimension to obtain a set of ransomware communication traffic time series correlation encoding feature matrices. Specifically, the process can be expressed as follows:
[0072] Decompose(F2)={M1,M2,...,M n}
[0073] Among them, F2 represents the temporal correlation coding feature map of ransomware communication traffic, Decompose(·) represents the feature fine-grained decoupling operation, M1, M2, M i and M n They respectively represent the first, second, i-th and n-th ransomware communication traffic temporal correlation coding feature matrices in the set of ransomware communication traffic temporal correlation coding feature matrices, and n is the number of channels of the ransomware communication traffic temporal correlation coding feature map.
[0074] S512: Perform a cross-domain query interaction based on a simulated transformer structure on the communication traffic time series pattern encoding feature vector and each ransomware communication traffic time series correlation encoding feature matrix in the set of the ransomware communication traffic time series correlation encoding feature matrix to obtain a set of networked device-ransomware communication traffic cross-domain query interaction feature vectors. Specifically, this process can be expressed as follows:
[0075]
[0076] Wherein, V1 represents the communication traffic time sequence pattern encoding feature vector, W 1q 、W 1v and W 2k denote the query embedding matrix, value embedding matrix and key embedding matrix respectively, b 1q 、b 1v and b 2k Represent different bias terms, Represents matrix multiplication operation, V 1q 、V 1v and Represent the query vector, value vector and the M respectively i The corresponding key matrix, softmax(·) is the normalized exponential function, (·) T represents the transpose of a vector, h i Represents the V1 and the W i Cross-domain query interaction feature vectors between networked device and ransomware communication traffic.
[0077] S513: Input each networked device-ransomware communication traffic cross-domain query interaction feature vector in the set of networked device-ransomware communication traffic cross-domain query interaction feature vectors into an ablation metric function to obtain a set of networked device-ransomware communication traffic fine-grained ablation factors. Specifically, this process can be expressed as follows:
[0078]
[0079] Among them, e(·) represents the ablation metric function, max(·) represents the maximum value function, μ i and σi Respectively represent the h i The feature mean and feature variance of , λ represents the regularization term, e i Indicates the h i The corresponding fine-grained ablation factor of networked device-ransomware communication traffic.
[0080] That is, first, by performing feature decoupling along the channel dimension on the ransomware communication traffic timing correlation coding feature graph, a finer-grained ransomware communication traffic timing correlation coding feature matrix is obtained, providing a more detailed feature basis for subsequent ablation analysis. Then, a query vector and a value vector are constructed based on the communication traffic timing pattern coding feature vector, and a key matrix is constructed based on each ransomware communication traffic timing correlation coding feature matrix after feature decoupling. The correlation between the ransomware communication traffic timing features and the networked device communication traffic timing features is captured through cross-domain query interaction based on the transformer structure. In this process, the transformer structure uses an attention mechanism to strengthen the significant correlation features between the ransomware communication traffic timing features and the networked device communication traffic timing features, while suppressing irrelevant information interference, thereby obtaining the correlation interaction feature representation between each local ransomware communication traffic timing features and the networked device communication traffic timing features. Then, an ablation metric function is further introduced to evaluate and quantify the correlation interaction feature representation between each local ransomware communication traffic timing features and the networked device communication traffic timing features after fine-grained decoupling. Here, the ablation metric function is similar to the ablation analysis in experimental design, which is used to determine the impact of removing a specific relationship on the final interaction effect. It helps to identify the correlation between the timing characteristics of the communication traffic of networked devices and the timing characteristics of different local ransomware communication traffic.
[0081] In one embodiment, Figure 5 As shown, in step S52, based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, the ransomware communication traffic time series correlation coding feature map is fine-grained ablation modulation to obtain a cross-domain ablation coding feature map of the networked device communication traffic as the cross-domain ablation coding feature of the networked device communication traffic, including: S521, inputting the set of fine-grained ablation factors of the networked device-ransomware communication traffic into an ablation effect coding module including a normalization function and a masking function to obtain a set of fine-grained ablation weight factors of the networked device-ransomware communication traffic. Specifically, the process can be expressed as follows:
[0082]
[0083] Among them, M(·) is the ablation effect encoding function, exp(·) represents the exponential function with e as the base, and a i Indicates the ei The corresponding normalized network device-ransomware communication traffic fine-grained ablation factor, mask(·) is the mask function, θ is the gated mask threshold, w i Indicates the M i The corresponding fine-grained ablation weight factor of networked device-ransomware communication traffic.
[0084] S522: Based on the set of fine-grained ablation weight factors for the networked device-ransomware communication traffic, weighted modulation is performed on the set of time-series correlation coding feature matrices of the ransomware communication traffic, and feature aggregation along the channel dimension is performed to obtain a cross-domain ablation coding feature map of the networked device communication traffic. Specifically, this process can be expressed as follows:
[0085] F 1-2 ={M1·w1,M2·w2,...,M n w n}
[0086] Among them, w1, w2, and w n are respectively the M1, the M2, the M i and the M n The corresponding network device-ransomware communication traffic fine-grained ablation weight factor, F 1-2 Represents the cross-domain ablation coding feature map of communication traffic of networked devices.
[0087] That is, based on the evaluation results of the ablation metric function, the weight distribution in the feature query interaction process is dynamically adjusted. Specifically, by normalizing and masking the set of fine-grained ablation factors of networked device-ransomware communication traffic generated by the ablation metric function to standardize the weights and exclude irrelevant items, the abnormal traffic pattern feature representations in the communication traffic patterns of known ransomware that are similar to the networked device communication traffic gain higher attention and weight, while reducing the interference of features that are irrelevant or have low correlation with the timing characteristics of networked device communication traffic, thereby concentrating resources and attention on the timing characteristics of ransomware communication traffic that are most closely related to the timing characteristics of networked device communication traffic. Secondly, based on the set of fine-grained ablation weight factors of networked device-ransomware communication traffic generated, the original set of the ransomware communication traffic timing correlation coding feature matrices is subjected to fine-grained ablation modulation and feature aggregation along the channel dimension, so as to strengthen the ransomware communication traffic timing characteristics that are highly correlated with the timing characteristics of networked device communication traffic, thereby generating an optimized and enhanced cross-domain ablation coding feature representation of networked device communication traffic as the key feature representation output for network security early warning. In this way, irrelevant feature interference is effectively eliminated, the feature's discriminative ability and pertinence are improved, which helps to more accurately reflect potential signs of ransomware attacks and provide a high-quality feature basis for subsequent security warnings.
[0088] In one embodiment, in step S6, Figure 6 As shown, based on the cross-domain ablation coding characteristics of the communication traffic of the networked device, it is determined whether to generate network security warning prompt information, including: S61, inputting the cross-domain ablation coding feature map of the communication traffic of the networked device into a classifier-based security warning module to obtain a security warning analysis result, and the security warning analysis result is used to indicate whether abnormal traffic occurs in the networked device; S62, in response to the security warning analysis result that abnormal traffic occurs in the networked device, generating the network security warning prompt information.
[0089] In one embodiment, in step S61, the cross-domain ablation coding feature map of the networked device communication traffic is input into a classifier-based security warning module to obtain a security warning analysis result, which is used to indicate whether abnormal traffic occurs in the networked device, including: expanding the cross-domain ablation coding feature map of the networked device communication traffic into a cross-domain ablation coding feature vector of the networked device communication traffic; using the fully connected layer of the classifier-based security warning module to fully connect the cross-domain ablation coding feature vector of the networked device communication traffic to obtain a fully connected cross-domain ablation coding feature vector of the networked device communication traffic; inputting the fully connected cross-domain ablation coding feature vector of the networked device communication traffic into the Softmax classification function of the classifier-based security warning module to obtain the probability values of the cross-domain ablation coding feature map of the networked device communication traffic belonging to each classification label; and determining the classification label corresponding to the largest of the probability values as the security warning analysis result. Here, the classification labels include a first classification label indicating that abnormal traffic occurs in the networked device and a second classification label indicating that the networked device does not experience abnormal traffic.
[0090] In summary, according to the embodiment of the present application, a network security early warning management method for a thermal power plant is explained, which monitors the communication traffic data of networked devices in the thermal power plant network and performs time series analysis based on deep learning technology to extract the time series change pattern characteristics of the communication traffic. At the same time, a set of communication traffic time series pattern characteristics of known ransomware is extracted from the background data. By performing fine-grained ablation analysis on the communication traffic time series pattern characteristics of networked devices and the communication traffic time series pattern feature set of known ransomware, the abnormal traffic pattern feature representation that is similar to the communication traffic of networked devices in the communication traffic pattern of known ransomware is identified and strengthened, thereby realizing intelligent identification and early warning of potential ransomware attack behaviors of networked devices. In this way, the abnormal traffic characteristics of ransomware attack behaviors can be more effectively captured, avoiding missed detections due to the limitations of traditional feature library methods, and improving the accuracy and timeliness of network security early warnings for thermal power plants.
[0091] Figure 7 This is a schematic block diagram of the network security early warning management system for a thermal power plant according to an embodiment of the present application. Figure 7As shown, the thermal power plant network security early warning management system 100 includes: a communication flow data monitoring module 110, which is used to monitor the communication flow data of networked devices in the thermal power plant network to obtain a time series data set of the communication flow data; a communication flow data time series encoding module 120, which is used to time series encode the time series data set of the communication flow data to obtain communication flow time series pattern encoding features; a known ransomware feature extraction module 130, which is used to extract a set of communication flow time series pattern features of known ransomware from background data; and a communication flow feature correlation encoding module 140, Used to perform inter-communication traffic feature correlation coding on the set of communication traffic timing pattern features of the known ransomware to obtain the ransomware communication traffic timing correlation coding features; a fine-grained ablation analysis joint coding module 150, used to perform fine-grained ablation analysis and joint coding on the communication traffic timing pattern coding features and the ransomware communication traffic timing correlation coding features to obtain the cross-domain ablation coding features of the networked device communication traffic; an early warning prompt information determination module 160, used to determine whether to generate network security early warning prompt information based on the cross-domain ablation coding features of the networked device communication traffic.
[0092] In one embodiment, the communication traffic data pair timing encoding module is used to: input the time series data set of the communication traffic data into a sequence encoder based on a forward LSTM model to obtain a communication traffic timing pattern encoding feature vector as the communication traffic timing pattern encoding feature.
[0093] Here, those skilled in the art will appreciate that the specific operations of the various modules and units in the above-mentioned thermal power plant network security early warning management system have been described in detail above. Figures 1 to 6 The invention has been introduced in detail in the description of the network security early warning management method of a thermal power plant, and therefore, its repeated description will be omitted.
[0094] An embodiment of the present application further provides a computer program product, which includes computer program code. When the computer program code runs on a computer, the computer implements the methods in the above embodiments of the present application.
[0095] An embodiment of the present application further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a computer, the computer implements the methods in the above embodiments of the present application.
[0096] It will be understood that the above embodiments are merely exemplary embodiments for illustrating the principles of the present invention, and the present invention is not limited thereto. Those skilled in the art will appreciate that various modifications and improvements can be made without departing from the spirit and substance of the present invention, and such modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A network security early warning management method for a thermal power plant, characterized in that: include: Monitor the communication flow data of networked devices in a thermal power plant network to obtain a time series data set of the communication flow data; Performing time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature; Extracting a set of communication traffic time series pattern features of known ransomware from background data; performing correlation coding between communication traffic features on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature; Performing fine-grained ablation analysis and joint coding on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic; Based on the cross-domain ablation coding characteristics of the communication traffic of the networked device, determine whether to generate network security warning prompt information.
2. The network security early warning management method for a thermal power plant according to claim 1 is characterized in that: Performing time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature includes: The time series data set of the communication traffic data is input into a sequence encoder based on a forward LSTM model to obtain a communication traffic time series pattern encoding feature vector as the communication traffic time series pattern encoding feature.
3. The network security early warning management method for a thermal power plant according to claim 2 is characterized in that: Performing correlation coding between communication traffic features on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature, including: The set of communication traffic timing pattern features of the known ransomware is arranged into a ransomware communication traffic timing pattern feature aggregation tensor according to the parameter sample dimension, and then input into a ransomware communication traffic correlation feature encoder based on a void convolutional neural network model to obtain a ransomware communication traffic timing correlation coding feature graph as the ransomware communication traffic timing correlation coding feature.
4. The network security early warning management method for a thermal power plant according to claim 3 is characterized in that: Performing fine-grained ablation analysis and joint coding on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic, including: Performing a local channel-based feature correlation strength ablation measurement on the communication traffic time series pattern encoding feature vector and the ransomware communication traffic time series correlation encoding feature map to obtain a set of networked device-ransomware communication traffic fine-grained ablation factors; Based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, fine-grained ablation modulation is performed on the ransomware communication traffic time series correlation coding feature map to obtain a networked device communication traffic cross-domain ablation coding feature map as the networked device communication traffic cross-domain ablation coding feature.
5. The network security early warning management method for a thermal power plant according to claim 4 is characterized in that: The communication traffic time series pattern encoding feature vector and the ransomware communication traffic time series correlation encoding feature map are subjected to a feature correlation strength ablation measurement based on a local channel to obtain a set of network device-ransomware communication traffic fine-grained ablation factors, including: Performing fine-grained feature decoupling along the channel dimension on the ransomware communication traffic temporal correlation coding feature graph to obtain a set of ransomware communication traffic temporal correlation coding feature matrices; Performing a cross-domain query interaction based on a simulated transformer structure on the communication traffic time series pattern encoding feature vector and each ransomware communication traffic time series correlation encoding feature matrix in the set of the ransomware communication traffic time series correlation encoding feature matrix to obtain a set of networked device-ransomware communication traffic cross-domain query interaction feature vectors; Each networking device-ransomware communication traffic cross-domain query interaction feature vector in the set of networking device-ransomware communication traffic cross-domain query interaction feature vectors is input into the ablation metric function to obtain a set of networking device-ransomware communication traffic fine-grained ablation factors.
6. The network security early warning management method for a thermal power plant according to claim 5 is characterized in that: Based on the set of fine-grained ablation factors of the networked device-ransomware communication traffic, fine-grained ablation modulation is performed on the ransomware communication traffic time series correlation coding feature map to obtain a networked device communication traffic cross-domain ablation coding feature map as the networked device communication traffic cross-domain ablation coding feature, including: Inputting the set of network device-ransomware communication traffic fine-grained ablation factors into an ablation effect encoding module including a normalization function and a masking function to obtain a set of network device-ransomware communication traffic fine-grained ablation weight factors; Based on the set of fine-grained ablation weight factors of the networked device-ransomware communication traffic, the set of time-series correlation coding feature matrices of the ransomware communication traffic is weighted modulated and features are aggregated along the channel dimension to obtain the cross-domain ablation coding feature map of the networked device communication traffic.
7. The network security early warning management method for a thermal power plant according to claim 6 is characterized in that: Determining whether to generate network security warning information based on the cross-domain ablation coding characteristics of the communication traffic of the networked device includes: Inputting the cross-domain ablation coding feature map of the networked device communication traffic into a classifier-based security warning module to obtain a security warning analysis result, wherein the security warning analysis result is used to indicate whether abnormal traffic occurs in the networked device; In response to the security warning analysis result that abnormal traffic occurs in the networked device, the network security warning prompt information is generated.
8. The network security early warning management method for a thermal power plant according to claim 7 is characterized in that: Inputting the cross-domain ablation coding feature map of the networked device communication traffic into a classifier-based security warning module to obtain a security warning analysis result, wherein the security warning analysis result is used to indicate whether abnormal traffic occurs in the networked device, including: Expanding the cross-domain ablation coding feature map of network device communication traffic into a cross-domain ablation coding feature vector of network device communication traffic; Performing full-connection coding on the cross-domain ablation coding feature vector of the networked device communication traffic using the fully-connected layer of the classifier-based security warning module to obtain a fully-connected networked device communication traffic cross-domain ablation coding feature vector; Inputting the cross-domain ablation coding feature vector of the communication traffic of fully connected networked devices into the Softmax classification function of the classifier-based security warning module to obtain the probability value of the cross-domain ablation coding feature map of the communication traffic of networked devices belonging to each classification label; The classification label corresponding to the largest probability value among the probability values is determined as the security warning analysis result.
9. A network security early warning management system for a thermal power plant, characterized in that: include: A communication flow data monitoring module is used to monitor the communication flow data of networked devices in the thermal power plant network to obtain a time series data set of the communication flow data; A communication traffic data pair time series coding module is used to perform time series coding on the time series data set of the communication traffic data to obtain a communication traffic time series pattern coding feature; A known ransomware feature extraction module, configured to extract a set of communication traffic time series pattern features of known ransomware from background data; a communication traffic feature correlation coding module, configured to perform communication traffic feature correlation coding on the set of communication traffic time series pattern features of the known ransomware to obtain a ransomware communication traffic time series correlation coding feature; A fine-grained ablation analysis joint coding module, configured to perform fine-grained ablation analysis and joint coding on the communication traffic time series pattern coding feature and the ransomware communication traffic time series correlation coding feature to obtain a cross-domain ablation coding feature of the networked device communication traffic; The early warning prompt information determination module is used to determine whether to generate network security early warning prompt information based on the cross-domain ablation coding characteristics of the communication traffic of the networked device.
10. The network security early warning management system for thermal power plants according to claim 9, characterized in that: The communication traffic data pair timing encoding module is used to: The time series data set of the communication traffic data is input into a sequence encoder based on a forward LSTM model to obtain a communication traffic time series pattern encoding feature vector as the communication traffic time series pattern encoding feature.
Citation Information
Cited By
New energy station network security threat active defense method and system
CN121396543A