Management and control method, device and equipment for network attack of digital power grid, storage medium and program product

By processing multi-source heterogeneous data of the digital power grid and building dynamic knowledge graphs, identifying and defending high-risk attack paths, the problem of low accuracy in network attack control in the existing technology is solved, and efficient network security defense is achieved.

CN120498762APending Publication Date: 2025-08-15ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

Patent Information

Application Number
CN202510626189.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The network attack control methods of digital power grids in the prior art are not very accurate and cannot effectively identify and defend against potential high-risk attack paths.

Method used

By obtaining multi-source heterogeneous data of the digital power grid, data processing is carried out to obtain multimodal fusion characteristics, constructing a dynamic knowledge graph, determining candidate attack paths, and allocating defense information to high-risk attack paths, and sending them to corresponding network security devices to perform defense measures.

Benefits of technology

It improves the accuracy of network attack control, realizes timely identification and defense of high-risk attack paths, and improves data utilization efficiency and knowledge graph construction accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498762A_ABST
    Figure CN120498762A_ABST
Patent Text Reader

Abstract

The invention relates to a management and control method and device for network attacks of a digital power grid, equipment, a storage medium and a program product. The method comprises the steps of obtaining multi-source heterogeneous data of a digital power grid, and performing data processing on the multi-source heterogeneous data to obtain multi-modal fusion features of the digital power grid; constructing a dynamic knowledge graph of the digital power grid according to the multi-modal fusion features, and determining a plurality of candidate attack paths according to the dynamic knowledge graph; according to the first attribute feature information of each knowledge node in the plurality of candidate attack paths and the second attribute feature information of each directed edge, determining at least one high-risk attack path from the plurality of candidate attack paths, and distributing corresponding defense information to each high-risk attack path; and respectively sending the defense information corresponding to each high-risk attack path to the corresponding network security equipment. The control method provided by the embodiment of the invention is higher in accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network security for digital power grids, and in particular to a method, apparatus, device, storage medium, and program product for controlling network attacks on digital power grids. Background Art

[0002] Digital grids, particularly smart grids, are essential components of modern power systems. By integrating network and information technology with the grid, they significantly enhance the reliability, security, and efficiency of power systems. However, this highly information-based and interconnected environment also exposes digital grids to increasingly complex and diverse cyberattack risks. Given that these attacks could impact the secure and stable operation of digital grids, managing and controlling cyberattacks against them is crucial.

[0003] In related technologies, abnormal behavior in network traffic is typically monitored based on pre-set known threat signatures; when abnormal behavior is detected, static alarm information is output. However, this passive control (or defensive) mode in related technologies is not very accurate. Summary of the Invention

[0004] Based on this, it is necessary to provide a method, device, equipment, storage medium and program product for controlling network attacks on digital power grids that can improve the accuracy of control in response to the above technical problems.

[0005] In a first aspect, the present application provides a method for controlling network attacks on a digital power grid, the method comprising: obtaining multi-source heterogeneous data of the digital power grid, and performing data processing on the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid; constructing a dynamic knowledge graph of the digital power grid based on the multimodal fusion features, and determining multiple candidate attack paths based on the dynamic knowledge graph; wherein the dynamic knowledge graph includes first attribute feature information of multiple knowledge nodes and second attribute feature information of multiple directed edges; determining at least one high-risk attack path from the multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the multiple candidate attack paths, and assigning corresponding defense information to each high-risk attack path; sending the defense information corresponding to each high-risk attack path to the corresponding network security device; wherein the defense information is used to instruct the network security device to execute corresponding defense measures based on the defense information.

[0006] In one embodiment, at least one high-risk attack path is determined from multiple candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the multiple candidate attack paths, including: for each candidate attack path, based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the candidate attack path, using a preset nonlinear threat assessment model to determine the attack threat level of the candidate attack path; based on the attack threat level of each candidate attack path, determining at least one high-risk attack path from multiple candidate attack paths.

[0007] In one embodiment, at least one high-risk attack path is determined from multiple candidate attack paths based on the attack threat level of each candidate attack path, including: obtaining a path criticality parameter and a response degree parameter of each candidate attack path; determining a defense priority of each candidate attack path based on the attack threat level, path criticality parameter, and response degree parameter of each candidate attack path; and determining at least one high-risk attack path from multiple candidate attack paths in descending order of the defense priorities of the multiple candidate attack paths.

[0008] In one embodiment, the defense information includes defense resources and defense strategies, and corresponding defense information is assigned to each high-risk attack path, including: according to the attack threat level, response degree parameters and total available defense resources of each high-risk attack path, resource allocation processing is performed using a preset resource allocation model to allocate corresponding defense resources to each high-risk attack path; for each high-risk attack path, according to multiple knowledge nodes and multiple directed edges in the high-risk attack path, a corresponding defense strategy is assigned to the high-risk attack path; wherein the defense strategy includes at least one of the following: firewall rule update strategy, intrusion detection rule optimization strategy, access control list adjustment strategy, device isolation and traffic restriction strategy, log audit and traceability analysis strategy.

[0009] In one embodiment, multiple candidate attack paths are determined based on a dynamic knowledge graph, including: constructing multiple initial attack paths based on the dynamic knowledge graph using a preset breadth-first search algorithm; determining the weight of each initial attack path based on the second attribute feature information of each directed edge in each initial attack path; dynamically adjusting the weight of each initial attack path based on a preset graph neural network model based on multimodal fusion features; and determining multiple candidate attack paths from the multiple initial attack paths based on the adjusted weights of the multiple initial attack paths.

[0010] In one embodiment, multi-source heterogeneous data includes structured device flow data and unstructured attack reference data, and data processing is performed on the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid, including: performing a first parsing process on the device flow data to obtain a device flow feature vector; performing a second parsing process on the attack reference data to obtain an attack reference semantic vector; performing a first feature extraction process on the device flow feature vector based on a preset convolutional neural network to obtain a local pattern feature; performing a second feature extraction process on the attack reference semantic vector based on a preset bidirectional long short-term memory network to obtain a context-dependent feature; and obtaining a multimodal fusion feature based on the local pattern feature and the context-dependent feature.

[0011] In the second aspect, the present application also provides a network attack control device for a digital power grid, which includes: an acquisition module for acquiring multi-source heterogeneous data of the digital power grid; a data processing module for performing data processing on the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid; a construction module for constructing a dynamic knowledge graph of the digital power grid based on the multimodal fusion features; wherein the dynamic knowledge graph includes first attribute feature information of multiple knowledge nodes and second attribute feature information of multiple directed edges; a first determination module for determining multiple candidate attack paths based on the dynamic knowledge graph; a second determination module for determining at least one high-risk attack path from multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the multiple candidate attack paths; an allocation module for assigning corresponding defense information to each high-risk attack path respectively; a sending module for sending the defense information corresponding to each high-risk attack path to the corresponding network security device respectively; wherein the defense information is used to instruct the network security device to execute corresponding defense measures according to the defense information.

[0012] In a third aspect, the present application also provides a digital power grid network attack control device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the methods in the first aspect above when executing the computer program.

[0013] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of any one of the methods in the first aspect when the computer program is executed by a processor.

[0014] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which implements the steps of any one of the methods in the first aspect when executed by a processor.

[0015] The aforementioned digital power grid cyberattack control method, apparatus, device, storage medium, and program product, by processing the acquired multi-source heterogeneous data of the digital power grid to obtain the multimodal fusion characteristics of the digital power grid, can effectively utilize the available information resources of the multi-source heterogeneous data in the digital power grid, which not only helps to improve data utilization efficiency, but also helps to improve the accuracy of the subsequent knowledge graph construction. Furthermore, by constructing a dynamic knowledge graph of the digital power grid based on the multimodal fusion characteristics, because the construction process of the dynamic knowledge graph comprehensively considers the data characteristics of different data sources, the dynamic knowledge graph of the digital power grid in the embodiment of the present application can be more accurate, providing precise data support for the subsequent determination of candidate attack paths. Furthermore, by determining at least one high-risk attack path from a plurality of candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the plurality of candidate attack paths, and assigning corresponding defense information to each high-risk attack path, and sending the defense information corresponding to each high-risk attack path to the corresponding network security device, it is possible to promptly assign corresponding defense information to each pre-detected high-risk attack path, and send the defense information to the corresponding network security device, so that the corresponding network security device can promptly execute the corresponding defense measures based on the defense information, thereby achieving pre-detection of high-risk attack paths and advance defense of network security devices. It can be seen that compared with the passive control mode in the related art, the control method of the embodiment of the present application has higher accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 A schematic diagram of an application scenario of cyber attack management and control for a digital power grid in one embodiment;

[0018] Figure 2 1 is a flow chart of a method for controlling network attacks on a digital power grid according to an embodiment;

[0019] Figure 3 1 is a flow chart of a method for determining a high-risk attack path in one embodiment;

[0020] Figure 4 1 is a flow chart of a method for allocating defense information for high-risk attack paths in one embodiment;

[0021] Figure 51 is a flow chart of a method for determining candidate attack paths in one embodiment;

[0022] Figure 6 1 is a flow chart of a method for acquiring multimodal fusion features in one embodiment;

[0023] Figure 7 A schematic diagram of the structure of a device for controlling network attacks on a digital power grid according to one embodiment;

[0024] Figure 8 A schematic diagram of the structure of a digital power grid network attack control device in one embodiment. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0026] In an exemplary embodiment, Figure 1 FIG. 1 is a schematic diagram of an application scenario of controlling network attacks on a digital power grid in one embodiment. Figure 1 As shown, the application scenarios of the network attack control of the digital power grid according to the embodiment of the present application may include, but are not limited to: a network attack control device 10 and multiple network security devices 11. The network attack control device 10 may implement the control of network attacks on the digital power grid according to the network attack control method for the digital power grid provided in the embodiment of the present application.

[0027] Illustratively, the control device 10 may communicate with any network security device 11 through the network to control the network security device 11 to execute corresponding defense measures.

[0028] Exemplarily, the network security device 11 in the embodiment of the present application may include but is not limited to any of the following: a firewall device, an intrusion detection system / intrusion prevention system (IDS / IPS), a security information and event management (SIEM) device, and an endpoint detection and response (EDR) device.

[0029] In an exemplary embodiment, Figure 2 A flowchart of a method for controlling network attacks on a digital power grid in one embodiment is provided. Figure 1The network attack control device 10 in the example is used for explanation. Figure 2 As shown, the method for controlling network attacks on a digital power grid according to an embodiment of the present application may include the following steps:

[0030] Step S201: Acquire multi-source heterogeneous data of the digital power grid, and perform data processing on the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid.

[0031] In this step, the control device can obtain the multi-source heterogeneous data of the digital grid from multiple core data sources of the digital grid, or obtain the multi-source heterogeneous data of the digital grid from a preset multi-source heterogeneous database. Of course, the control device can also obtain the multi-source heterogeneous data of the digital grid through other methods.

[0032] For example, the multi-source heterogeneous data in the embodiments of the present application may include, but is not limited to, structured device traffic data and unstructured attack reference data. The structured device traffic data and unstructured attack reference data are heterogeneous in form. For example, structured device traffic data is typically structured time series data, while unstructured attack reference data is typically unstructured text descriptions.

[0033] Exemplarily, device traffic data may include but is not limited to device log data and / or network traffic data; attack reference data may include but is not limited to CVE vulnerability library data (which can be used for vulnerability description, impact scope and exploit code, etc.) and / or CERT report data (which can be used to indicate global attack cases and their technical means, etc.) and other historical attack case data.

[0034] For example, device log data is typically generated by Supervisory Control And Data Acquisition (SCADA) systems, communication modules, and / or digital grid sensors. Device log data may include, but is not limited to, at least one of the following: device identifier (ID), device operation, abnormal behavior, timestamp, and event type.

[0035] For example, network traffic data usually records network interaction information in the form of data packets. Network traffic data may include but is not limited to at least one of the following: Internet Protocol (IP) address, port number, protocol type, access status, and interception records.

[0036] In this step, the control device can also process the acquired multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid. The multimodal fusion features can be used to indicate the data fusion characteristics of the multi-source heterogeneous data. For example, the multimodal fusion features involved in the embodiments of the present application can be used to indicate the data fusion characteristics of device traffic data and attack reference data.

[0037] For example, data processing in the embodiments of the present application may include, but is not limited to, at least one of the following: data cleaning, data parsing, feature extraction, and feature fusion. Data cleaning can be used to remove redundant data, noisy data, and / or abnormal data; data parsing can be used to parse feature vectors or semantic vectors corresponding to multi-source heterogeneous data; feature extraction can be used to extract local pattern features or context-dependent features; and feature fusion can be used to fuse different types of features to obtain multimodal fusion features.

[0038] It can be seen that in the embodiment of the present application, by processing multi-source heterogeneous data to obtain the multimodal fusion characteristics of the digital power grid, the available information resources of multi-source heterogeneous data in the digital power grid can be effectively utilized, which is not only beneficial to improving data utilization efficiency, but also beneficial to the subsequent knowledge graph construction accuracy.

[0039] Step S202: construct a dynamic knowledge graph of the digital power grid based on the multimodal fusion features, and determine multiple candidate attack paths based on the dynamic knowledge graph; wherein the dynamic knowledge graph includes first attribute feature information of multiple knowledge nodes and second attribute feature information of multiple directed edges.

[0040] In this step, the control device can construct a dynamic knowledge graph of the digital power grid based on the multimodal fusion features, where the dynamic knowledge graph may include, but is not limited to, first attribute feature information of multiple knowledge nodes and second attribute feature information of multiple directed edges. It should be understood that the dynamic knowledge graph in the embodiments of the present application means that the control device can update the knowledge graph corresponding to the digital power grid in real time or at preset intervals (which can be very small time intervals) based on changes in the multi-source heterogeneous data of the digital power grid.

[0041] Exemplarily, knowledge nodes in a dynamic knowledge graph may include, but are not limited to, asset knowledge nodes, vulnerability knowledge nodes, or attack behavior knowledge nodes. Asset knowledge nodes may represent device assets in a digital grid; vulnerability knowledge nodes may represent vulnerabilities in a digital grid; and attack behavior knowledge nodes may represent attack behaviors in a digital grid.

[0042] Exemplarily, the first attribute characteristic information of any knowledge node can be used to indicate the attribute information of the knowledge node. For example, the first attribute characteristic information of a knowledge node can be used to indicate at least one of the following attribute information of the knowledge node in a specific context: attack stage (such as scanning, penetration, privilege escalation, etc.), knowledge node type (such as SCADA controller, etc.), sensitivity (or importance) of the knowledge node, status information (such as whether it has been exploited, etc.), vulnerability severity, attack success rate, attack method, attack impact range, and attack timeliness.

[0043] For example, a directed edge in a dynamic knowledge graph may refer to a causal relationship or an attack chain between two connected knowledge nodes in the dynamic knowledge graph.

[0044] Exemplarily, the second attribute characteristic information of any directed edge can be used to indicate attribute information of the directed edge. For example, the second attribute characteristic information of a directed edge can be used to indicate at least one of the following attribute information of the directed edge: defense coverage, length, exploit success rate, transmission rate, latency, bandwidth consumption, attack path, data integrity, risk level, security control measures, and impact range.

[0045] It should be understood that the multimodal fusion features in the embodiments of the present application can provide comprehensive multivariate information for each knowledge node and / or each directed edge in the dynamic knowledge graph, so that the management and control equipment can obtain the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the process of constructing the dynamic knowledge graph of the digital power grid based on the multimodal fusion features. The first attribute feature information and / or the second attribute feature information can be the feature expression corresponding to the above multivariate information, which is used to describe the basic attributes of the corresponding knowledge node and / or directed edge.

[0046] It can be seen that in the embodiment of the present application, by constructing a dynamic knowledge graph of the digital power grid based on multimodal fusion features, since the construction process of the dynamic knowledge graph comprehensively considers the data characteristics of different data sources (i.e., the data fusion characteristics of multi-source heterogeneous data), the dynamic knowledge graph of the digital power grid in the embodiment of the present application can be more accurate, providing precise data support for the subsequent determination of candidate attack paths.

[0047] In this step, the control device can also extract multiple candidate attack paths from the dynamic knowledge graph; wherein the candidate attack path can refer to the complete path of potential attack behavior in the digital power grid.

[0048] It should be understood that any candidate attack path may include multiple knowledge nodes and multiple directed edges. The first attribute feature information of any knowledge node in any candidate attack path is the same as the first attribute feature information of the corresponding knowledge node in the dynamic knowledge graph, and the second attribute feature information of any directed edge in any candidate attack path is the same as the second attribute feature information of the corresponding directed edge in the dynamic knowledge graph.

[0049] Step S203: Determine at least one high-risk attack path from the multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the multiple candidate attack paths, and assign corresponding defense information to each high-risk attack path.

[0050] In this step, the management and control device can determine at least one high-risk attack path from multiple candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the multiple candidate attack paths; wherein the high-risk attack path can refer to the complete path of potential high-risk attack behaviors in the digital power grid.

[0051] In one possible implementation, the management and control device can analyze the attack threat level of candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in multiple candidate attack paths, and determine at least one high-risk attack path from the multiple candidate attack paths based on the attack threat level analysis results.

[0052] In another possible implementation, the control device may input the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in multiple candidate attack paths into a preset high-risk attack path identification model to obtain at least one high-risk attack path output by the preset high-risk attack path identification model. The preset high-risk attack path identification model may include, but is not limited to, a machine learning model.

[0053] In this step, the control device may further allocate corresponding defense information to each high-risk attack path; wherein the defense information may include but is not limited to defense resources and / or defense strategies.

[0054] Exemplarily, defense resources may include, but are not limited to, at least one of the following: computing resources, network configuration resources, and human resources.

[0055] Exemplarily, the defense strategy may include but is not limited to at least one of the following: firewall rule update strategy, intrusion detection rule optimization strategy, access control list (ACL) adjustment strategy, device isolation and traffic restriction strategy, log audit and traceability analysis strategy.

[0056] For example, when a high-threat knowledge node (such as a SCADA controller) is detected in a high-risk attack path, the management and control device can automatically adjust the defense measures of the high-threat knowledge node, which may include but is not limited to restricting access rights, increasing IDS sensitivity, or blocking related IP addresses.

[0057] For example, when a vulnerability is detected being exploited, the control device can automatically generate a defense strategy to block the traffic exploiting the vulnerability.

[0058] It can be seen that in the embodiment of the present application, by determining at least one high-risk attack path from multiple candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in multiple candidate attack paths, and assigning corresponding defense information to each high-risk attack path, it is possible to pre-detect each high-risk attack path and promptly assign corresponding defense information to each high-risk attack path.

[0059] Step S204: Send the defense information corresponding to each high-risk attack path to the corresponding network security device respectively; wherein the defense information is used to instruct the network security device to execute corresponding defense measures according to the defense information.

[0060] In this step, the control device may send the defense information corresponding to each high-risk attack path to the corresponding network security device, so that the network security device executes corresponding defense measures according to the received defense information.

[0061] Exemplarily, network security devices may include but are not limited to any of the following: firewall devices, IDS / IPS, SIEM devices, and EDR devices.

[0062] It should be understood that for any high-risk attack path, the management and control device can determine the corresponding network security device based on the defense information assigned to the high-risk attack path, so as to send the defense information corresponding to the high-risk attack path to the corresponding network security device.

[0063] For example, if the defense information assigned to the high-risk attack path includes a firewall rule update policy, the management and control device may determine that the network security device corresponding to the high-risk attack path includes a firewall device.

[0064] For another example, if the defense information assigned to the high-risk attack path includes an intrusion detection rule optimization strategy, the management and control device may determine that the network security device corresponding to the high-risk attack path includes an IDS / IPS.

[0065] In summary, in the embodiments of the present application, by processing the acquired multi-source heterogeneous data of the digital power grid to obtain the multimodal fusion characteristics of the digital power grid, the available information resources of the multi-source heterogeneous data in the digital power grid can be effectively utilized, which is not only conducive to improving data utilization efficiency, but also conducive to the accuracy of subsequent knowledge graph construction. Furthermore, by constructing a dynamic knowledge graph of the digital power grid based on the multimodal fusion characteristics, since the construction process of the dynamic knowledge graph comprehensively considers the data characteristics of different data sources, the dynamic knowledge graph of the digital power grid in the embodiments of the present application can be more accurate, providing precise data support for the subsequent determination of candidate attack paths. Furthermore, by determining at least one high-risk attack path from a plurality of candidate attack paths based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the plurality of candidate attack paths, and assigning corresponding defense information to each high-risk attack path, and sending the defense information corresponding to each high-risk attack path to the corresponding network security device, it is possible to promptly assign corresponding defense information to each pre-detected high-risk attack path, and send the defense information to the corresponding network security device, so that the corresponding network security device can promptly execute the corresponding defense measures based on the defense information, thereby achieving pre-detection of high-risk attack paths and advance defense of network security devices. It can be seen that compared with the passive control mode in the related art, the control method of the embodiment of the present application has higher accuracy.

[0066] In an exemplary embodiment, the embodiment of the present application further introduces and explains the relevant content of "constructing a dynamic knowledge graph of the digital power grid based on multimodal fusion features" in the above step S202.

[0067] For example, the basic data of the dynamic knowledge graph in the embodiment of the present application can be represented by the triple shown in the following formula (1):

[0068] G={(V,E)},V={v1,v2,...,v k ,...,v K},E={e1,e2,...,e q ,...,e Q'}Formula (1)

[0069] Among them, G represents the graph, V represents the knowledge node set, and E represents the directed edge set; each knowledge node v k It can include but is not limited to the corresponding multimodal fusion features; directed edge e q Indicates the relationship between two adjacent knowledge nodes; the value range of k is 1 to K, and the value range of q is 1 to Q', where K and Q' are both integers greater than 1.

[0070] Of course, the basic data of the dynamic knowledge graph in the embodiment of the present application can also be expressed by other modified formulas or equivalent formulas of the above formula (1).

[0071] In one possible implementation, multiple knowledge nodes in a dynamic knowledge graph are constructed based on multimodal fusion features; and multiple directed edges in a dynamic knowledge graph are constructed using a preset relationship extraction model based on the multimodal fusion features and multiple knowledge nodes.

[0072] In this implementation, the control device can construct multiple knowledge nodes in the dynamic knowledge graph based on multimodal fusion features. The knowledge nodes may include but are not limited to: asset knowledge nodes, vulnerability knowledge nodes, or attack behavior knowledge nodes.

[0073] For example, the control device can construct at least one asset knowledge node based on the data features of the device log data in the multimodal fusion feature. The asset knowledge node may include, but is not limited to, the asset (or device) name, as well as attributes such as type and network location. For example, asset knowledge node A: SCADA host, attributes: IP address, service port, and uptime.

[0074] In another exemplary embodiment, the control device may construct at least one attack behavior knowledge node based on the data features of the network traffic data in the multimodal fusion feature or the data features of the attack reference data in the multimodal fusion feature. The attack behavior knowledge node may include, but is not limited to, the attack behavior name and attributes.

[0075] For example, the control device can identify attack behaviors by using the data features of network traffic data in the multimodal fusion feature to obtain attack behavior knowledge node B. Here, attack behavior knowledge node B is: Distributed Denial of Service (DDoS) traffic, with attributes: traffic size and target IP.

[0076] For another example, the control device can perform attack behavior identification (or rule extraction) on the data features of the attack reference data in the multimodal fusion features to obtain attack behavior knowledge nodes.

[0077] In another exemplary embodiment, the control device may construct at least one vulnerability knowledge node based on data features of the attack reference data in the multimodal fusion features.

[0078] For example, the control device can perform vulnerability extraction on the attack reference data in the multimodal fusion feature based on a preset named entity recognition (NER) model to obtain vulnerability knowledge nodes. Vulnerability knowledge nodes may include, but are not limited to, vulnerability names, affected components, and / or exploitation methods. For example, vulnerability knowledge node C: CVE-2024-XXXX has a relationship: exploit the vulnerability to attack the target device.

[0079] Furthermore, the control device can construct multiple directed edges in the dynamic knowledge graph by mining the causal relationships between multimodal fusion features and multiple knowledge nodes based on a preset relationship extraction model. For example, the preset relationship extraction model may include, but is not limited to, a Bidirectional Long Short-Term Memory (BiLSTM) relationship classifier.

[0080] For example, the control device can mine the causal relationship between multimodal fusion features and multiple knowledge nodes based on a preset relationship extraction model to build a relationship between attack behavior knowledge node B and vulnerability knowledge node C, vulnerability knowledge node A → after being exploited → attack behavior knowledge node B; attack chain generation, using vulnerability preconditions and consequences to establish an attack chain, exploiting the vulnerability → privilege escalation → data theft.

[0081] In another possible implementation, the control device can input the multimodal fusion features into a preset dynamic knowledge graph construction model to obtain a dynamic knowledge graph of the digital power grid output by the preset dynamic knowledge graph construction model. The preset dynamic knowledge graph construction model may include but is not limited to a machine learning model.

[0082] Of course, in the embodiment of the present application, the control device can also construct a dynamic knowledge graph of the digital power grid in other ways based on the multimodal fusion characteristics.

[0083] In summary, in the embodiments of the present application, by constructing a dynamic knowledge graph of the digital power grid based on multimodal fusion features, the combination of deep learning technology and knowledge graph construction is realized, and the data characteristics of different data sources can be comprehensively considered. This cross-modal data fusion greatly improves the data utilization efficiency and the accuracy of knowledge graph construction.

[0084] In an exemplary embodiment, to support real-time attack detection and dynamic updating of the knowledge graph, the control device in the embodiment of the present application can also perform time series analysis on multi-source heterogeneous data based on a preset time series analysis model, and update the dynamic knowledge graph based on the time series analysis results. Exemplarily, the preset time series analysis model can include but is not limited to a long short-term memory (LSTM) time series prediction algorithm model.

[0085] Exemplarily, the control device can perform time series analysis on the attack event sequence data in the device traffic data in the multi-source heterogeneous data based on the preset time series analysis model to detect potential abnormal behavior patterns, and update the dynamic knowledge graph according to the time series analysis processing results. The input of the preset time series analysis model may include but is not limited to the attack event sequence data in the device traffic data in the multi-source heterogeneous data (for example, historical attack behaviors, historical attack timestamps and / or historical attack paths, etc.), and the output of the preset time series analysis model may include but is not limited to the predicted behavior state of the next time step (or the so-called predicted behavior pattern).

[0086] For example, when a traffic peak anomaly is detected, the control device can mark the triggered attack behavior and dynamically add a new attack behavior knowledge node to the dynamic knowledge graph.

[0087] For ease of understanding, the first timing prediction formula of the preset timing analysis model is further introduced and explained in the following embodiments of the present application.

[0088] For example, the first time series prediction formula in the embodiment of the present application can be expressed as the following formula (2):

[0089] P(t+1)=σ(W h ·h t +W x ·x t +b1) Formula (2)

[0090] Where P(t+1) is the predicted behavior state at the next time step t+1; h t is the hidden state at the current time step t; x t is the input feature of the current time step t (or called input variable, i.e. event sequence data); W h is the first preset weight matrix of the hidden state; W x is the second preset weight matrix of the input feature; σ is the preset activation function; b1 is the first preset bias term (Bias), which is a learning parameter.

[0091] Of course, the first time series prediction formula in the embodiment of the present application can also be expressed as other equivalent formulas or modified formulas of the above formula (2).

[0092] It can be seen that in the embodiments of the present application, by performing time series analysis processing on multi-source heterogeneous data based on a preset time series analysis model and updating the dynamic knowledge graph according to the time series analysis processing results, the accuracy of the dynamic knowledge graph can be further improved, which is conducive to improving the accuracy of subsequent high-risk attack paths and corresponding defense information.

[0093] In an exemplary embodiment, Figure 3 This is a flow chart of a method for determining a high-risk attack path in one embodiment. This embodiment of the application further introduces and explains the relevant content of the above step S203 "determining at least one high-risk attack path from multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in multiple candidate attack paths". Figure 3 As shown, the method of the embodiment of the present application may include the following steps:

[0094] Step S203A: For each candidate attack path, determine the attack threat level of the candidate attack path using a preset nonlinear threat assessment model based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path.

[0095] In this step, for each candidate attack path, the control device can use a pre-set nonlinear threat assessment model to determine the attack threat level of the candidate attack path based on the first attribute characteristic information of each knowledge node and the second attribute characteristic information of each directed edge in the candidate attack path. It should be noted that the higher the attack threat level of any candidate attack path, the greater the potential threat posed by the candidate attack path to the digital power grid.

[0096] Among them, the preset nonlinear threat assessment model is an assessment model that takes the attribute characteristic information of the knowledge nodes of the candidate attack path (such as vulnerability risk and / or device importance, etc.), the causal weight of the directed edge and the dynamic changes of the candidate attack path as key elements.

[0097] Exemplarily, the preset nonlinear threat assessment model may include but is not limited to a preset Bayesian network nonlinear model.

[0098] For ease of understanding, the following embodiments of the present application further introduce and explain the above-mentioned content of "determining the attack threat level of the candidate attack path by using a preset nonlinear threat assessment model".

[0099] In an exemplary embodiment, the management and control device can determine the threat level of each knowledge node based on the first attribute characteristic information of each knowledge node in the candidate attack path, and determine the weight of each directed edge based on the second attribute characteristic information of each directed edge in the candidate attack path.

[0100] 1) Threat level of knowledge nodes

[0101] For example, if any knowledge node in a candidate attack path is an asset knowledge node or a vulnerability knowledge node, the control device may determine the threat level of the knowledge node based on the first attribute characteristic information of the knowledge node. The first attribute characteristic information may include, but is not limited to, a vulnerability CVSS severity score (or simply a vulnerability CVSS score) and / or a sensitivity score (or an importance score).

[0102] For example, the management and control device can determine the threat level of the knowledge node according to the first attribute characteristic information of the knowledge node through the following formula (3).

[0103] T(v i )=w v CVSS (v i )+w s ·S(v i ) Formula (3)

[0104] Among them, T(v i ) is the knowledge node v in the candidate attack path i Threat level; w v The CVSS severity weight of the preset vulnerability; CVSS (v i ) is the knowledge node v i Vulnerability CVSS severity score; w s is the preset sensitivity weight; S(v i ) is the knowledge node v i sensitivity score.

[0105] It should be understood that if the knowledge node is an asset knowledge node, the control device can determine the threat level of the asset knowledge node according to the sensitivity score and sensitivity weight of the asset knowledge node, that is, w v Set to zero; if the knowledge node is a vulnerability knowledge node, the control device can determine the threat level of the vulnerability knowledge node according to the vulnerability CVSS score of the vulnerability knowledge node, that is, w s Set to zero.

[0106] Of course, the management and control device can also determine the threat level of the knowledge node according to the first attribute characteristic information of the knowledge node through other modified formulas or equivalent formulas of the above formula (3).

[0107] As another example, if any knowledge node in a candidate attack path is an attack behavior knowledge node, the control device can determine the threat level of the knowledge node based on the first attribute characteristic information of the knowledge node. The first attribute characteristic information may include, but is not limited to, at least one of the following: attack method, attack impact range, attack timeliness, attack success rate, and attack path criticality.

[0108] In an embodiment of the present application, the management and control device can query the preset threat level rules based on the first attribute characteristic information of the knowledge node to determine the threat level of the knowledge node. Exemplarily, the preset threat level rules may include but are not limited to at least one of the following: attack method threat level rules (used to indicate different threat levels corresponding to different attack methods), attack impact range threat level (used to indicate different threat levels corresponding to different attack impact ranges), attack success rate threat level rules (used to indicate different threat levels corresponding to different attack success rates), attack timeliness threat level rules (used to indicate different threat levels corresponding to different attack timeliness), and attack path criticality threat level rules (used to indicate different threat levels corresponding to different attack path criticalities).

[0109] For example, the attack method threat level rule can be used to indicate the threat levels corresponding to different attack methods such as SQL injection and cross-site scripting (XSS).

[0110] For example, the attack success rate threat level rule may be used to indicate that the higher the attack success rate, the higher the threat level.

[0111] For example, the attack impact range threat level can be used to indicate that the wider the attack impact range, the higher the threat level. The attack impact range may include but is not limited to the number of devices attacked, system sensitivity areas, etc.

[0112] For example, the attack timeliness threat level rule may be used to indicate that the threat level of recent attack behaviors is greater than the threat level of historical attack behaviors.

[0113] For example, the attack path criticality threat level rule may be used to indicate that the higher the risk position of the attack behavior in the attack chain (located on a high-risk attack path), the higher the threat level.

[0114] Of course, the management and control device may also determine the threat level of the knowledge node in other ways according to the first attribute characteristic information of the knowledge node.

[0115] 2) Weight of directed edges

[0116] In an embodiment of the present application, for any directed edge in a candidate attack path, the control device can obtain the weight of the directed edge based on causal analysis and / or temporal analysis based on the second attribute feature information of the directed edge. The weight of any directed edge can be used to represent the strength of the causal relationship between the two knowledge nodes connected by the directed edge.

[0117] Exemplarily, the second attribute characteristic information of any directed edge may include, but is not limited to: the utilization success probability of the first knowledge node to the last knowledge node corresponding to the directed edge and / or the impact range of the directed edge on the target asset.

[0118] For example, the management and control device may determine the weight of the directed edge using the following formula (4) based on the second attribute characteristic information of the directed edge.

[0119] R(v i ,v i+1 )=ρ·P(v i →v i+1 )+λ·I(v i ,v i+1 ) Formula (4)

[0120] Among them, R(v i ,v i+1 ) is the knowledge node v i To knowledge node v i+1 The edge weight of the directed edge between (or simply the weight of the directed edge); P(v i →v i+1 ) is the knowledge node v i To knowledge node v i+1 The probability of successful utilization of the directed edge between them; ρ is the preset utilization success rate weight; I(v i ,v i+1 ) is the knowledge node v i To knowledge node v i+1 The influence range of the directed edge between them on the target asset; λ is the preset influence range weight.

[0121] Of course, the management and control device may also determine the weight of the directed edge through other modified formulas or equivalent formulas of the above formula (4) according to the second attribute characteristic information of the directed edge.

[0122] Furthermore, to reflect the time sensitivity of attack behavior, the control device can also perform time series analysis on candidate attack paths and calculate their dynamic scores. The dynamic scores of candidate attack paths can be used to measure the degree of temporal correlation between knowledge nodes and directed edges in the candidate attack paths. For example, if the attack behavior in any candidate attack path occurs within a short period of time and the correlation between events is high, the candidate attack path will have a higher dynamic score, indicating that the candidate attack path is more likely to be exploited by attackers.

[0123] In an exemplary embodiment, the control device may determine the dynamic score of the candidate attack path based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path.

[0124] Exemplarily, the first attribute characteristic information of any knowledge node may also include but is not limited to the time interval of the attack behavior event, and the second attribute characteristic information of any directed edge may also include but is not limited to the length of the time window covered by the directed edge and / or the correlation between adjacent events in the directed edge.

[0125] For example, the control device can determine the dynamic score of the candidate attack path by the following formula (5) based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path.

[0126]

[0127] Among them, D(p j ) is the candidate attack path p j The dynamic score of the candidate attack path p j TimeGap(t) is the sum of the lengths of the time windows covered by each directed edge in ; TimeGap(t) is the time interval between attack behavior events; EventCorr(t) is the correlation between adjacent attack behavior events in the directed edges.

[0128] Of course, the control device can also determine the dynamic score of the candidate attack path through other modified formulas or equivalent formulas of the above formula (5) based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path.

[0129] It should be understood that if certain attack behavior events occur within a short time interval and have a strong correlation between the events, the dynamic score of the candidate attack path will be higher, indicating that the candidate attack path is more compact and orderly in a short period of time.

[0130] As can be seen, the embodiments of this application also introduce time series analysis, incorporating the temporal characteristics of attack behavior into the evaluation scope. For example, if the attack steps of a candidate attack path occur within a short period of time, the control device will increase the attack threat level of the candidate attack path based on the time density.

[0131] Furthermore, the control device can obtain the attack threat level of the candidate attack path using a preset nonlinear threat assessment model based on the threat level of each knowledge node, the weight of each directed edge, and the dynamic score of the candidate attack path.

[0132] In an embodiment of the present application, the management and control device can use a preset nonlinear threat assessment model to perform weighted summation on the threat level of each knowledge node, the weight of each directed edge, and the dynamic score of the candidate attack path to obtain the attack threat level of the candidate attack path.

[0133] Exemplarily, the control device can use the preset nonlinear threat assessment model to perform weighted summation on the threat level of each knowledge node, the weight of each directed edge, and the dynamic score of the candidate attack path through the following formula (6) to obtain the attack threat level of the candidate attack path.

[0134]

[0135] Among them, R(p j ) is the candidate attack path p j The attack threat level; n is the candidate attack path p j The number of knowledge nodes in the network; α1 is the first preset threat level weight, which can be used to indicate the degree of attention to the threat level of the knowledge node; β1 is the weight of the first preset edge weight, which can be used to indicate the degree of attention to the strength of the causal relationship; γ1 is the preset dynamic score weight.

[0136] It should be understood that any of the above-mentioned weights involved in the embodiments of the present application (such as the first preset threat level weight, the weight of the preset edge weight and the preset dynamic score weight, etc.) can be preset values, or can be adjusted and set based on statistical learning of historical attack case data.

[0137] Of course, the control device can also use the preset nonlinear threat assessment model to perform weighted summation on the threat level of each knowledge node, the weight of each directed edge, and the dynamic score of the candidate attack path through other modified formulas or equivalent formulas of the above formula (6) to obtain the attack threat level of the candidate attack path.

[0138] It should be noted that, as real-time monitoring of multi-source heterogeneous data is input, the control device can dynamically update the attribute feature information of the knowledge nodes and directed edges of the dynamic knowledge graph, thereby dynamically updating the attack threat level assessment results of the candidate attack paths. It can be seen that the control device in the embodiment of the present application supports dynamic adjustment of the attack threat level to reflect changes in the attack scenario in real time, which is conducive to more accurate identification of high-risk attack paths in the digital power grid.

[0139] For example, if the knowledge node v i If the device traffic data shows that its vulnerability has been exploited, the control device will immediately increase the threat level T (v i ).

[0140] For example, if it is detected that an attacker has successfully completed the knowledge node v using a specific tool i To knowledge node v i+1 For the steps corresponding to the directed edge between the two, the control device will increase the edge weight R(v i ,v i+1 ).

[0141] It can be seen that in the embodiment of the present application, by using a preset nonlinear threat assessment model to determine the attack threat level of the candidate attack path, the threat level of the knowledge node, the weight of the directed edge and the dynamics of the attack path can be combined, which can capture the nonlinear relationship between different steps in the attack path and can comprehensively and accurately reflect the potential threat of the candidate attack path. In addition, in the embodiment of the present application, by introducing the attack path dynamics score, the time dependence of the attack behavior in the attack path can be quantified, so that the real threat of the candidate attack path can be more accurately assessed. In addition, in the embodiment of the present application, the assessment result of the attack threat level of the candidate attack path can also be adjusted according to real-time data, which can ensure the timeliness and accuracy of the assessment result. Therefore, this multi-dimensional dynamic assessment method significantly improves the scientific nature of the path priority calculation and provides strong technical support for the defense response of the digital power grid.

[0142] Step S203B: Determine at least one high-risk attack path from the multiple candidate attack paths according to the attack threat level of each candidate attack path.

[0143] In this step, the control device may determine at least one high-risk attack path from multiple candidate attack paths according to the attack threat level of each candidate attack path, so that corresponding defense information can be allocated to each high-risk attack path in a timely manner.

[0144] In one possible implementation, the control device may select the top N candidate attack paths with higher threat levels among the multiple candidate attack paths as high-risk attack paths, in descending order of their threat levels, where N is an integer greater than zero.

[0145] In another possible implementation, the path criticality parameters and the response degree parameters of each candidate attack path are obtained; the defense priority of each candidate attack path is determined according to the attack threat level, path criticality parameters and response degree parameters of each candidate attack path; and at least one high-risk attack path is determined from the multiple candidate attack paths in descending order of the defense priority of the multiple candidate attack paths.

[0146] The path criticality parameter of any candidate attack path in the embodiment of the present application can be used to represent the importance of key nodes in the candidate attack path. Wherein, the path criticality parameter of any candidate attack path can depend on the high-risk knowledge nodes and corresponding directed edges in the candidate attack path.

[0147] The response degree parameter of any candidate attack path in the embodiment of the present application can be used to indicate the coverage of existing defense measures in the candidate attack path.

[0148] In the embodiment of the present application, the higher the defense priority value of any candidate attack path, the more priority the candidate attack path needs to respond to. Among them, the defense priority of the candidate attack path is the core basis for the defense response and is used to determine the order of distributing defense information.

[0149] In an embodiment of the present application, the management and control device can obtain path criticality parameters and response degree parameters of each candidate attack path.

[0150] For example, for any candidate attack path, the control device can determine the path criticality parameters of the candidate attack path based on the criticality coefficient and sensitivity score of each knowledge node in the candidate attack path. The criticality coefficient of any knowledge node can be dynamically adjusted based on the device type and importance of the knowledge node. For example, the criticality coefficient of a SCADA host or controller is higher than that of an ordinary terminal device.

[0151] Among them, the sensitivity score of any knowledge node can be used to represent the potential impact of the knowledge node on the system after being attacked.

[0152] For example, the control device can determine the path criticality parameter of the candidate attack path by the following formula (7) based on the criticality coefficient and sensitivity score of each knowledge node in the candidate attack path.

[0153]

[0154] Among them, C(p j ) is the candidate attack path p j Path criticality parameters; is the candidate attack path p j Knowledge node v in i The critical coefficient of S(v i ) is the candidate attack path p j Knowledge node v in i sensitivity score.

[0155] Of course, the control device can also determine the path criticality parameters of the candidate attack path through other modified formulas or equivalent formulas of the above formula (7) based on the criticality coefficient and sensitivity score of each knowledge node in the candidate attack path.

[0156] For example, for any candidate attack path, the control device can determine the response degree parameter of the candidate attack path based on the defense coverage of each directed edge in the candidate attack path and the length of the candidate attack path. The defense coverage of a directed edge can be used to indicate whether a corresponding defense measure has been implemented for the directed edge (for example, whether access restrictions have been set or whether firewall rules have been updated).

[0157] For example, the control device can determine the response degree parameter of the candidate attack path by the following formula (8) based on the defense coverage of each directed edge in the candidate attack path and the length of the candidate attack path.

[0158]

[0159] Among them, A(p j ) is the candidate attack path p j The response degree parameter of |p j | is the candidate attack path p j The length of the candidate attack path p j Any directed edge in ; δ(e) is the defense coverage of directed edge e.

[0160] Of course, the control device can also determine the response degree parameter of the candidate attack path through other modified formulas or equivalent formulas of the above formula (8) based on the defense coverage of each directed edge in the candidate attack path and the length of the candidate attack path.

[0161] Furthermore, for any candidate attack path, the management and control device can determine the defense priority of the candidate attack path based on the attack threat level, path criticality parameter, and response degree parameter of the candidate attack path.

[0162] For example, the control device can determine the defense priority of the candidate attack path by the following formula (9) based on the attack threat level, path criticality parameter and response degree parameter of the candidate attack path.

[0163] P(p j )=w R ·R(p j )+w C ·C(p j )-w A ·A(p j )

[0164] Formula (9)

[0165] Among them, P(p j ) is the candidate attack path p j Defense priority of w R is the second preset threat level weight; w C is the preset key parameter weight; w A is the preset response parameter weight. It should be understood that w R 、w C and w A Used to balance the importance of the above factors.

[0166] Of course, the control device can also determine the defense priority of the candidate attack path through other modified formulas or equivalent formulas of the above formula (9) according to the attack threat level, path criticality parameter and response degree parameter of the candidate attack path.

[0167] Furthermore, the management and control device may determine at least one high-risk attack path from the multiple candidate attack paths in descending order of the defense priorities of the multiple candidate attack paths.

[0168] For example, the control device may select the first M candidate attack paths with higher defense priorities among the multiple candidate attack paths as high-risk attack paths in descending order of defense priority, where M is an integer greater than zero.

[0169] It should be understood that the high-risk attack paths determined by the management and control device according to the defense priority of the candidate attack paths are usually attack paths with higher attack threat levels and / or higher path criticality parameters and lower response degree parameters.

[0170] In summary, in an embodiment of the present application, for each candidate attack path, the attack threat level of the candidate attack path is determined by using a preset nonlinear threat assessment model based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path, and at least one high-risk attack path is determined from multiple candidate attack paths based on the attack threat level of each candidate attack path. Since the attack threat level of the candidate attack path in the embodiment of the present application can comprehensively and accurately reflect the potential threat of the candidate attack path, it can be seen that the embodiment of the present application determines the high-risk attack path based on the attack threat level of the candidate attack path, which can improve the accuracy of the determined high-risk attack path, so that limited defense information can be accurately allocated to the high-risk attack path in the future, and it can ensure that the high-risk attack path can be given priority processing, thereby achieving accurate defense against digital power grid attacks.

[0171] In an exemplary embodiment, Figure 4 This is a flowchart of a method for allocating defense information for high-risk attack paths in one embodiment. For example, the defense information involved in this embodiment may include but is not limited to defense resources and defense strategies. This embodiment further introduces and explains the relevant content of "allocating corresponding defense information for each high-risk attack path" in the above step S203. Figure 4 As shown, the method of the embodiment of the present application may include the following steps:

[0172] Step S203C: performing resource allocation processing using a preset resource allocation model based on the attack threat level, response degree parameter, and total available defense resources of each high-risk attack path to allocate corresponding defense resources to each high-risk attack path.

[0173] Exemplarily, the defense resources in the embodiments of the present application may include, but are not limited to, at least one of the following: computing resources, network configuration resources, and human resources.

[0174] In this step, the management and control equipment can use the preset resource allocation model to perform resource allocation processing based on the attack threat level, response degree parameters and total available defense resources of each high-risk attack path, so as to allocate corresponding defense resources to each high-risk attack path, so as to facilitate the implementation of defense measures corresponding to subsequent defense strategies.

[0175] For example, the preset resource allocation model in the embodiment of the present application can be expressed as the following formula (10):

[0176]

[0177] Among them, Minimize is the minimization objective function; m is the number of high-risk attack paths; R(p j' ) is a high-risk attack path pj' Attack threat level; A(p j' ) is a high-risk attack path p j' The response degree parameter R j' is a high-risk attack path p j' Allocated defense resources; R total is the total available defense resources.

[0178] Exemplarily, the control device can solve the above-mentioned preset resource allocation model through a dynamic programming algorithm or a reinforcement learning method to obtain an optimal resource allocation plan, which is conducive to the efficient use of defense resources.

[0179] Of course, the preset resource allocation model in the embodiment of the present application can also be expressed as other modified formulas or equivalent formulas of the above formula (10).

[0180] Step S203D: For each high-risk attack path, assign a corresponding defense strategy to the high-risk attack path according to the multiple knowledge nodes and the multiple directed edges in the high-risk attack path.

[0181] Exemplarily, the defense strategies in the embodiments of the present application may include but are not limited to at least one of the following: firewall rule update strategy, intrusion detection rule optimization strategy, access control list adjustment strategy, device isolation and traffic restriction strategy, log audit and traceability analysis strategy.

[0182] In this step, for each high-risk attack path, the control device can assign a corresponding defense strategy based on the multiple knowledge nodes and directed edges in the high-risk attack path. The defense strategy assigned by the control device to any high-risk attack path can be in the form of a defense instruction; of course, the defense strategy can also be in other forms.

[0183] For example, if the directed edges in a high-risk attack path represent specific access behaviors, the control device can assign a corresponding firewall rule update policy to the high-risk attack path to instruct the firewall device to block related communications, thereby cutting off the attack chain and protecting the security of the target system or device. Specific access behaviors may include, but are not limited to, the following elements: communication source and target: untrusted sources (such as external IP addresses) accessing critical assets (such as SCADA hosts); ports and services: accessing using high-risk ports or abnormal ports; abnormal communication patterns: high-frequency connections, abnormal traffic, port scanning, etc.; targeting specific devices: the communication target is a critical device or system component; protocol abuse: exploiting vulnerabilities or attack attempts using specific protocols.

[0184] For example, the firewall rule update strategy in the embodiment of the present application can be expressed as:

[0185] Rule:Deny IP(υi →υ j ), Protocol: TCP, Port: 80.

[0186] In another example, the control device can assign a corresponding intrusion detection rule optimization strategy to the high-risk attack path according to the threat level of the high-risk knowledge node in the high-risk attack path to indicate the adjustment of the sensitivity of the IDS / IPS. i Is a vulnerability knowledge node, and the threat level is T(υ i ) is high, the management and control equipment can set high-sensitivity detection rules for the vulnerability knowledge node.

[0187] As another example, if the knowledge nodes in the high-risk attack path involve key equipment (such as SCADA controllers, etc.) and the threat level is high, the control device can assign corresponding device isolation and traffic restriction strategies to the high-risk attack path. For example, the device isolation and traffic restriction strategies in the embodiment of the present application can be expressed as:

[0188] Isolate: SCADA Controller ID=1001, Network Segment=192.168.1.0 / 24.

[0189] As another example, if the threat level of a high-risk attack path is high but has not been fully responded to, the management and control device can assign a corresponding log audit and source tracing analysis policy to the high-risk attack path to indicate the start of detailed logging and capture all relevant behaviors to support subsequent attack tracing.

[0190] Of course, the control device can also assign corresponding defense strategies to high-risk attack paths in other ways based on multiple knowledge nodes and multiple directed edges in the high-risk attack paths.

[0191] In summary, in the embodiment of the present application, resource allocation processing is performed using a preset resource allocation model based on the attack threat level, response degree parameter, and total available defense resources of each high-risk attack path, so as to allocate corresponding defense resources to each high-risk attack path. Furthermore, for each high-risk attack path, a corresponding defense strategy is allocated to the high-risk attack path based on the multiple knowledge nodes and multiple directed edges in the high-risk attack path. It can be seen that in the embodiment of the present application, by combining the attack threat level and response degree parameter, defense resources and defense strategies can be dynamically allocated to high-risk attack paths in a timely manner, so as to automatically synchronize to the corresponding network security devices, thereby realizing intelligent and precise defense and rapid response to digital power grid attacks.

[0192] In an exemplary embodiment, considering that attack behavior may change due to the implementation of defense measures, in an embodiment of the present application, the management and control device can also dynamically adjust the defense strategy by real-time monitoring of multi-source heterogeneous data and dynamic knowledge graph updates, which is conducive to improving the accuracy of the defense strategy.

[0193] For example, when a new attack event is detected, the control device will immediately update the defense priority P (p j ) and reallocate defense resources and defense strategies to related high-risk attack paths.

[0194] In another example, if the response degree parameter A(p j ) is improved (such as successfully blocking an attack chain), the control device will lower the defense priority of the candidate attack path and transfer defense resources to other candidate attack paths.

[0195] For example, the control device can dynamically adjust the defense priority of the candidate attack path through the following formula (11):

[0196] ΔP(p j )=w R ·ΔR(p j )+w A ·ΔA(p j ) Formula (11)

[0197] Among them, ΔP(p j ) is the candidate attack path p j The change in defense priority; ΔR(p j ) is the candidate attack path p j The change in the attack threat level (such as caused by the attribute update of knowledge nodes or directed edges); ΔA(p j ) is the candidate attack path p j The change in the response degree parameter.

[0198] Of course, the control device can also dynamically adjust the defense priority of the candidate attack path through other modified formulas or equivalent formulas of the above formula (11).

[0199] It can be seen that in the embodiment of the present application, through the real-time feedback mechanism, the defense strategy can also be adapted to the changes in the attack scenario in a timely manner, thereby further improving the overall defense effectiveness of the digital power grid.

[0200] In an exemplary embodiment, Figure 5 FIG2 is a flow chart of a method for determining a candidate attack path in an embodiment. This embodiment of the application further introduces and explains the relevant content of "determining multiple candidate attack paths according to the dynamic knowledge graph" in the above step S202. Figure 5 As shown, the method of the embodiment of the present application may include the following steps:

[0201] Step S202A: Construct multiple initial attack paths based on the dynamic knowledge graph using a preset breadth-first search algorithm.

[0202] In this step, for each initial attack path, the management and control device can select the initial knowledge node where the attack may start (such as the vulnerability knowledge node of the network boundary device, etc.) based on the dynamic knowledge graph, and use the preset breadth-first search algorithm (Breadth-First Search, BFS) to expand to other knowledge nodes related to the initial knowledge node to find the possible initial attack path.

[0203] For example, the core formula for constructing the initial attack path can be expressed as the following formula (12):

[0204] P={p1,p2,...,p g},p g ={v1→v2→...→v g}

[0205] Formula (12)

[0206] Among them, P is the set of all possible initial attack paths; p g is a line from the initial knowledge node v1 to the end initial node v g The initial attack path.

[0207] Of course, the core formula for constructing the initial attack path can also be expressed as other modified formulas or equivalent formulas of the above formula (12).

[0208] Step S202B: Determine the weight of each initial attack path according to the second attribute feature information of each directed edge in each initial attack path.

[0209] In this step, for each initial attack path, the control device may determine the weight of the initial attack path according to the second attribute feature information of each directed edge in the initial attack path.

[0210] Exemplarily, the control device may determine the weight of each directed edge based on the second attribute characteristic information of each directed edge in the initial attack path. It should be noted that the feasible manner in which the control device determines the weight of each directed edge can refer to the relevant content in the above embodiments of this application and will not be repeated here.

[0211] Furthermore, the control device may determine the weight of the initial attack path according to the weight of each directed edge in the initial attack path.

[0212] For example, the control device may determine the weight of the initial attack path according to the weight of each directed edge in the initial attack path using the following formula (13).

[0213]

[0214] Among them, W(p g ) is the initial attack path p g The weight of w(v g' ,v g'+1 ) is the knowledge node v g' To knowledge node v g'+1 The weight of the directed edge between .

[0215] Furthermore, in order to be more suitable for subsequent algorithm processing, the control device can also normalize the weight of the initial attack path determined by the above formula (13) to obtain the normalized weight of the initial attack path.

[0216] Exemplarily, the weight of the initial attack path assigned by the control device can be normalized using the following formula (14) to obtain the normalized weight of the initial attack path.

[0217]

[0218] Among them, W'(p g ) is the normalized initial attack path p g The weight of ; max(W(P)) is the weight of the maximum initial attack path in the initial attack path set P.

[0219] Of course, the control device may also determine the weight of the initial attack path according to the weights of the directed edges in the initial attack path through other modified formulas or equivalent formulas of the above formula.

[0220] Step S202C: dynamically adjust the weight of each initial attack path using a preset graph neural network model based on the multimodal fusion features.

[0221] In this step, to address the dynamic changes in attacker strategies, the control device can dynamically adjust the weight of each initial attack path using a pre-set Graph Neural Network (GNN) model based on multimodal fusion features. This pre-set GNN model can capture global information in the dynamic knowledge graph through feature propagation of knowledge nodes and directed edges in the dynamic knowledge graph, enabling the determined attack path to reflect changes in attack behavior in real time.

[0222] It should be understood that the control device can dynamically adjust the weight of each initial attack path determined by the above formula (13), or can dynamically adjust the weight of each initial attack path determined by the above formula (14) (i.e., the normalized weight of the initial attack path).

[0223] It should be noted that, for ease of understanding, the following embodiments of the present application are described by taking the example of the control device dynamically adjusting the weight of each initial attack path determined by the above formula (14).

[0224] Exemplarily, the management and control device can dynamically adjust the first attribute feature information of each knowledge node in each initial attack path using a preset graph neural network model based on multimodal fusion features.

[0225] For example, the preset graph neural network model in the embodiment of the present application can update the first attribute feature information of any knowledge node through the following formula (15).

[0226]

[0227] in, represents the feature vector corresponding to the first attribute feature information of knowledge node v at layer t+1; N(v) represents the set of neighboring knowledge nodes of knowledge node v; Represents the feature vector corresponding to the first attribute feature information of the neighbor knowledge node u at layer t; W u is the third preset weight matrix; b2 is the second preset bias term; ReLU is the activation function.

[0228] Of course, the preset graph neural network model in the embodiment of the present application can also update the first attribute feature information of any knowledge node through other modified formulas or equivalent formulas of the above formula (15).

[0229] The preset graph neural network model in the embodiment of the present application can capture the long-range dependency relationship between knowledge nodes through multi-layer propagation. For example, the attack behavior node υ A and asset knowledge node υ B The connection may be activated due to new attack events, resulting in the adjustment of the attack path.

[0230] Furthermore, for any initial attack path, the management and control device may dynamically adjust the weight of the initial attack path according to the dynamically adjusted first attribute feature information of each knowledge node in the initial attack path.

[0231] Exemplarily, the control device can dynamically adjust the weight of the initial attack path according to the dynamically adjusted first attribute feature information of each knowledge node in the initial attack path through the following formula (16).

[0232]

[0233] Among them, W”(p g ) represents the initial attack path p after dynamic adjustment g The weight of h υ is the initial attack path p g The feature vector corresponding to the first attribute feature information of the knowledge node v in ; γ2 is a preset adjustment parameter used to balance the influence of the initial weight and dynamic features.

[0234] Of course, the control device can also dynamically adjust the weight of the initial attack path through other modified formulas or equivalent formulas of the above formula (16) based on the dynamically adjusted first attribute feature information of each knowledge node in the initial attack path.

[0235] It can be seen that the dynamic knowledge graph constructed in the embodiments of the present application can include but is not limited to knowledge node states (such as whether an asset has been attacked, etc.) and temporal relationships (such as the chronological order in which a vulnerability is exploited), and can dynamically adjust the path structure in combination with graph reasoning technology. For example, in the embodiments of the present application, a preset graph neural network model based on an attention mechanism can be used to focus on key nodes when reasoning about attack paths, so that path priorities can be adjusted based on real-time data.

[0236] Step S202D: Determine multiple candidate attack paths from the multiple initial attack paths according to the adjusted weights of the multiple initial attack paths.

[0237] In this step, the control device may determine multiple candidate attack paths that may be adopted by the attacker from the multiple initial attack paths according to the dynamically adjusted weights of the multiple initial attack paths.

[0238] In one possible implementation, the control device may select the first Q initial attack paths with higher weights among the multiple initial attack paths as candidate attack paths in descending order of the adjusted weights of the multiple initial attack paths, where Q is an integer greater than zero.

[0239] In another possible implementation, for each initial attack path, a Markov decision process is constructed based on the adjusted weight of the initial attack path; the path selection strategy parameters are optimized using a preset policy gradient method to optimize the reward value in the Markov decision process; wherein the reward value is the weight of the initial attack path; and multiple candidate attack paths are determined from the multiple initial attack paths in descending order of the weights of the optimized multiple initial attack paths.

[0240] In order to further improve the accuracy of candidate attack path generation, the embodiment of the present application introduces a deep reinforcement learning algorithm based on dynamic adjustment, models the path selection problem as a Markov decision process (MDP), and continuously optimizes the path selection strategy through experiments and feedback.

[0241] In this implementation, for each initial attack path, the control device may construct a Markov decision process (MDP) according to the adjusted weight of the initial attack path.

[0242] For ease of understanding, the following embodiments of the present application provide an exemplary introduction to the relevant contents of the Markov decision process.

[0243] The Markov decision process in the embodiments of the present application may include, but is not limited to, state S, action A, and reward R. State S refers to the current topological structure and knowledge node status of the dynamic knowledge graph, which can be used to indicate the progress of the current initial attack path. Action A refers to adding a new knowledge node to the current initial attack path, which can be used to indicate the direction of attack path expansion. Reward R' refers to the overall weight of the initial attack path, which can be used to indicate the quality of the attack path to guide strategy adjustments.

[0244] For example, the reward value R' can be expressed by the following formula (17):

[0245]

[0246] Among them, g is the initial attack path p g The number of knowledge nodes in v g' is the initial attack path p g The g'th knowledge node in . α2 is the second preset threat level weight. T(v g' ) is the knowledge node v g' The threat level is usually evaluated based on the attributes of the knowledge node (such as vulnerability severity, attack success rate, etc.), and its value range is a positive value. β2 is the weight of the second preset edge weight. R(v g' ,v g'+1 ) is the knowledge node v g' and knowledge node v g'+1 The weight of the directed edge between them indicates the strength of the causal relationship or the difficulty of attack between the two knowledge nodes.

[0247] It can be seen that the reward value R' in the embodiment of the present application is the weighted sum of the threat levels of all knowledge nodes and directed edge weights in the initial attack path, which can be used to measure the overall risk and importance of the initial attack path.

[0248] Of course, the reward value R' can also be expressed by other modified formulas or equivalent formulas of the above formula (17).

[0249] Furthermore, the control device can use a preset policy gradient method to optimize the path selection policy parameters to optimize the reward value in the Markov decision process. The path selection policy parameters can determine the probability distribution of the action selected by the deep reinforcement learning algorithm in the current state.

[0250] In an embodiment of the present application, the control device can optimize the path selection strategy parameters by adopting a preset policy gradient method in a deep reinforcement learning algorithm, with the goal of maximizing the cumulative reward value of the initial attack path.

[0251] For example, the policy gradient update formula in the preset policy gradient method in the embodiment of the present application can be expressed by the following formula (18):

[0252]

[0253] Among them, θ t The path selection policy parameters for the tth update can represent the current policy of the reinforcement learning algorithm. t+1 η is the path selection policy parameter after the t+1th update, obtained by gradient optimization of the expected reward value E[R'] of R'; where E[R'] represents the average reward obtained by the attack path under the current policy. η is the learning rate, which controls the step size of the path selection policy parameter update and is typically in the range of 0 < η ≤ 1 (a larger learning rate can accelerate convergence but may cause oscillation; a smaller learning rate makes the update more stable but slower). The gradient of the reward value R' and the derivative of the path selection strategy parameter θ can indicate how to adjust the path selection strategy parameters to maximize the cumulative reward value (by calculating the sensitivity of E[R'] to the path selection strategy parameters, the update direction and magnitude can be determined).

[0254] Of course, the policy gradient update formula in the preset policy gradient method in the embodiment of the present application can also be expressed through other equivalent formulas or modified formulas of the above formula (18).

[0255] It should be understood that the control device can optimize the weight of the initial attack path by optimizing the reward value in the Markov decision process, so that the most likely attack path can be determined more accurately later.

[0256] Furthermore, the control device may determine multiple candidate attack paths from the multiple initial attack paths according to the weights of the optimized multiple initial attack paths from high to low.

[0257] Exemplarily, the management and control device may select the first Q initial attack paths with higher weights among the multiple initial attack paths as candidate attack paths in descending order of the weights of the optimized multiple initial attack paths.

[0258] It can be seen that in the embodiments of the present application, by introducing a deep reinforcement learning algorithm, high-threat attack paths can be efficiently searched in a large-scale dynamic knowledge graph, and the path selection strategy parameters can be dynamically adjusted according to the actual attack behavior.

[0259] In summary, by capturing the structural changes of the dynamic knowledge graph through feature propagation using a pre-set graph neural network model, dynamic adjustment of attack paths can be achieved, allowing for more intelligent selection of high-threat attack paths. This not only improves adaptability to attack scenarios but also enables real-time prediction of multi-stage complex attacks such as advanced persistent threat (APT) attacks. Furthermore, by introducing a reinforcement learning algorithm in the embodiments of this application, the attack path generation process can optimize search strategies based on environmental changes, thereby further maintaining efficient path prediction capabilities in dynamic attack scenarios.

[0260] In an exemplary embodiment, in order to adapt to the time dependency of attack behaviors, the embodiments of the present application may combine time series analysis technology to incorporate the timing information of attack behaviors into attack path generation.

[0261] For example, the control device can use a long short-term memory network (LSTM) to model the attack event sequence and predict possible future attack steps.

[0262] For example, the second time series prediction formula of the long short-term memory network in the embodiment of the present application can be expressed as the following formula (19):

[0263] h t =σ(W h ·h t-1 +W x ·x t +b1) Formula (19)

[0264] Among them, h t represents the hidden state at the current time step t; h t-1 represents the hidden state at the previous time step t-1.

[0265] In an embodiment of the present application, the control device can also use the predicted attack behavior output by the long short-term memory network (LSTM) as supplementary information for the attack path generation process, so as to further improve the timeliness of the attack path prediction.

[0266] In an exemplary embodiment, Figure 6This is a flow chart of a method for obtaining multimodal fusion features in one embodiment. For example, the multi-source heterogeneous data in the embodiment of the present application may include but is not limited to structured device flow data and unstructured attack reference data. The embodiment of the present application further introduces and explains the relevant content of "processing multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid" in the above step S201. Figure 6 As shown, the method of the embodiment of the present application may include the following steps:

[0267] Step S201A: Perform a first analysis on the device flow data to obtain a device flow feature vector.

[0268] The device traffic data in the embodiments of the present application may include but is not limited to device log data and / or network traffic data.

[0269] In one possible implementation, if the device traffic data includes device log data, the control device may perform a first parsing process on the device log data to obtain a device log feature vector. The first parsing process may include, but is not limited to, formatting and constructing a first feature vector.

[0270] For example, the control device can format the device log data based on regular expressions and predefined formatting rules to extract the key field F n’ , and based on the preset mapping rules, the key field F n’ Perform the first feature vector construction process to obtain the device log feature vector X=[x1,x2,…,x n’ ].

[0271] For example, the preset mapping rule in the embodiment of the present application can be expressed by the following formula (20):

[0272] x n’ =map(F n’ ,D) Formula (20)

[0273] Among them, map is the key field F n’ The mapping relationship with the predefined dictionary D is used to convert field values into semantic information. For example, the key field "active" is mapped to the status value 1, while the key field "offline" is mapped to 0.

[0274] Of course, the preset mapping rules in the embodiment of the present application can also be expressed by other equivalent formulas or modified formulas of the above formula (20).

[0275] In another possible implementation, if the device traffic data includes network traffic data, the control device may perform a first parsing process on the network traffic data to obtain a network traffic feature vector. The first parsing process may include, but is not limited to, packet parsing, traffic pattern recognition, and a second feature vector construction process.

[0276] For example, the control device can use deep packet inspection (DPI) technology to perform packet parsing on network traffic data (usually in the form of data packets) to obtain data packet content, perform traffic pattern recognition on the data packet content based on a flow classification algorithm (such as K-Means) to obtain data packet traffic pattern characteristics, and perform a second feature vector construction process on the traffic pattern characteristics to obtain a network traffic feature vector Y = [y1, y2, ..., y m’ ].

[0277] For example, the control device can construct a second feature vector for the traffic pattern feature using the following formula (21) to obtain the network traffic feature vector Y.

[0278]

[0279] Among them, P m' (t) represents the traffic pattern characteristics (such as packet size and / or flow rate) at time t, and T is the observation time window.

[0280] Of course, the control device can also construct a second feature vector for the traffic pattern characteristics through other equivalent formulas or modified formulas of the above formula (21) to obtain the network traffic feature vector Y.

[0281] Step S201B: perform a second parsing process on the attack reference data to obtain an attack reference semantic vector.

[0282] In this step, the control device can perform a second parsing process on the attack reference data using a preset language model to obtain an attack reference semantic vector. The preset language model may include but is not limited to BERT; the second parsing process may include but is not limited to text embedding.

[0283] For example, the control device may perform text embedding processing on the attack reference data by using a preset language model to convert the attack reference data into a high-dimensional attack reference semantic vector Z = [z1, z2, ..., z k ]. The attack reference semantic vector Z may include but is not limited to semantic vectors corresponding to key entities and relationships (such as the association between vulnerabilities and attack behaviors, etc.) such as attack behaviors, target assets, and vulnerability information.

[0284] For example, the attack behaviors in the embodiments of the present application can be divided into specific stages: for example, the MITRE ATT&CK framework is used to classify the attack behaviors into stages such as "initial access", "persistence", and "privilege escalation".

[0285] For ease of understanding, the following embodiments of this application take the preset language model including BERT as an example to provide an illustrative introduction to the steps of text parsing processing.

[0286] 1) Perform word segmentation on the text and generate a word vector sequence.

[0287] 2) Use the multi-layer attention mechanism of the BERT model to encode the word vector sequence and generate context-related semantic representations.

[0288] 3) Through the fully connected layer and classifier, key entities and relationships such as attack behavior, target assets and vulnerability information are extracted.

[0289] For example, the text parsing process in the embodiment of the present application can be expressed by the following formula (22):

[0290] Z=BERT(T')+FC(W E ·E+b3) Formula (22)

[0291] Where T' is the original text sequence (i.e., attack reference data); BERT converts the original text sequence into a context-related high-dimensional semantic vector; FC extracts semantic features related to specific tasks for accurate extraction of entities and relations; E is the preset word embedding matrix; W E is the fourth preset weight matrix; b3 is the third preset bias item.

[0292] Of course, the text parsing process in the embodiment of the present application can also be expressed by other equivalent formulas or modified formulas of the above formula (22).

[0293] It can be seen that in the embodiment of the present application, by using a preset language model to perform semantic analysis on the attack reference data (text data), key entities (such as attack techniques, target assets, vulnerabilities, etc.) and relationships (such as the association between vulnerabilities and attack tools, etc.) can be accurately extracted, so that these entities and relationships can be subsequently integrated into a unified semantic network through knowledge graph technology, which not only can achieve high-quality construction of knowledge nodes and directed edges in the knowledge graph, but also is conducive to solving the problems of data heterogeneity and isolation.

[0294] Step S201C: performing a first feature extraction process on the device traffic feature vector based on a preset convolutional neural network to obtain a local pattern feature.

[0295] In this step, the control device can perform a first feature extraction process on the device traffic feature vector based on a preset convolutional neural network (CNN) to obtain a local pattern feature. The device traffic feature vector may include but is not limited to a device log feature vector and / or a network traffic feature vector.

[0296] Exemplarily, if the device traffic feature vector includes a device log feature vector, the control device may perform a first feature extraction process on the device log feature vector based on a preset convolutional neural network to obtain a local pattern feature corresponding to the device log feature vector.

[0297] As another example, if the device traffic feature vector includes a network traffic feature vector, the control device can perform a first feature extraction process on the network traffic feature vector based on a preset convolutional neural network to obtain a local pattern feature corresponding to the network traffic feature vector.

[0298] Step S201D: performing a second feature extraction process on the attack reference semantic vector based on a preset bidirectional long short-term memory network to obtain a context-dependent feature.

[0299] In this step, the control device can perform a second feature extraction process on the attack reference semantic vector based on a preset bidirectional long short-term memory network (BiLSTM) to obtain a context-dependent feature corresponding to the attack reference semantic vector.

[0300] Step S201E: Obtain multimodal fusion features based on local pattern features and context-dependent features.

[0301] In this step, the control device can perform feature fusion processing based on the local pattern features and the context-dependent features to obtain a multimodal fusion feature. For example, the control device can obtain a unified multimodal fusion feature by using a fully connected layer dimensionality reduction method.

[0302] It should be understood that in order to facilitate the subsequent construction of a dynamic knowledge graph and / or the determination of high-risk attack paths, the multimodal fusion features in the embodiments of the present application may exist in the form of a multimodal fusion feature vector.

[0303] Exemplarily, when the local pattern features include the local pattern features corresponding to the device log feature vector and the local pattern features corresponding to the network traffic feature vector, the control device can perform feature fusion processing according to the local pattern features and the context-dependent features through the following formula (23) to obtain multimodal fusion features.

[0304] F=ReLU(W c CNN(X)+W 2 c CNN(Y)+W l ·BiLSTM(Z)) Formula (23)

[0305] Among them, F is the multimodal fusion feature; W c is the fifth preset weight matrix of the local pattern feature; CNN(X) is the local pattern feature corresponding to the device log feature vector; CNN(Y) is the local pattern feature corresponding to the network traffic feature vector; W l is the sixth preset weight matrix corresponding to the context-dependent feature; BiLSTM(Z) is the context-dependent feature.

[0306] Of course, the control device can also perform feature fusion processing based on local pattern features and context-dependent features through other equivalent formulas or modified formulas of the above formula (23) to obtain multimodal fusion features.

[0307] In summary, in the embodiments of the present application, by using technologies such as natural language processing and deep learning to comprehensively analyze and extract features from multi-source heterogeneous data, and by fusion analysis of multimodal data features (such as device traffic features and attack reference features, etc.), it is possible to comprehensively consider the characteristics of different data sources. For example, the management and control equipment can associate abnormal behaviors in network traffic features with access records in device log features, so that potential attack behaviors can be captured more accurately. In the embodiments of the present application, this cross-modal data fusion greatly improves the data utilization efficiency and the accuracy of the construction of the dynamic knowledge graph, which not only improves the comprehensiveness of threat perception, but also provides accurate data support for subsequent attack path generation and evaluation.

[0308] In an exemplary embodiment, considering the large amount of data and the uneven quality of digital power grid data, the management and control equipment can clean the acquired multi-source heterogeneous data to improve the accuracy of the subsequently constructed dynamic knowledge graph.

[0309] Exemplarily, the management and control device may use a hybrid cleaning method based on preset rules and statistics to clean multi-source heterogeneous data to remove redundant data, noise data and / or abnormal data.

[0310] For example, when multi-source heterogeneous data includes device log data, the management and control device can clean the duplicate data in the device log data by comparing hash values to remove the duplicate data.

[0311] For another example, when multi-source heterogeneous data includes network traffic data, the control device can use principal component analysis (PCA) to clean abnormal data (such as data surges) in the network traffic data. The method for determining abnormal data can be expressed by the following formula (24):

[0312]

[0313] Among them, x i is the i-th item of data in the network traffic data; μ i is the i-th data x i The corresponding data parameter mean; σ i It should be understood that when the anomaly score is higher than the preset anomaly threshold, the data is marked as abnormal data (or referred to as noise data).

[0314] Of course, the method for judging abnormal data can also be expressed by other equivalent formulas or modified formulas of the above formula (24).

[0315] In an exemplary embodiment, in order to verify the effectiveness of the attack defense method of the embodiment of the present application, the control device can measure the decrease in the overall risk value by the following formula (25):

[0316]

[0317] Among them, Risk RR is the decrease in the overall risk value; R before (p i' ) is the attack path p before the attack defense method in the embodiment of the present application is used i' The risk value of R after (p i' ) is the attack path p after using the attack defense method in the embodiment of the present application i' The risk value of m' is the total number of attack paths.

[0318] In an exemplary embodiment, in order to verify the effectiveness of the attack defense method of the embodiment of the present application, the management and control device can also obtain the risk value reduced per unit resource based on the ratio of the total risk reduction amount to the total resource allocation amount.

[0319] In summary, in the embodiments of the present application, through the dynamic updating and reasoning of the knowledge graph, a deep fusion of multi-source heterogeneous data is achieved, overcoming the problems of data isolation and information loss in traditional methods. Secondly, in the embodiments of the present application, through the combination of the graph neural network model and reinforcement learning, dynamic adjustment and real-time optimization are achieved in attack path generation, significantly improving the adaptability to complex attack scenarios. Then, in the embodiments of the present application, a multi-dimensional dynamic evaluation method is used to comprehensively quantify the attack threat level of the attack path, providing a scientific basis for precise defense.

[0320] In addition, in the embodiment of the present application, through the calculation of path defense priority, the optimal allocation of defense resources and the generation of dynamic defense strategies, a seamless connection from threat assessment to actual defense implementation is achieved. Furthermore, in the embodiment of the present application, the defense strategy can be dynamically adjusted according to real-time changes (when new attack behaviors are detected or the path defense priority changes, the defense measures can be updated in real time to ensure the rational allocation of defense resources and the maximization of defense effects), and automatically synchronized to the network security equipment, which significantly improves the defense efficiency and attack response speed, shows significant advantages in the intelligence and timeliness of attack defense, achieves a significant improvement in defense effectiveness, and provides comprehensive and accurate technical support for the security protection of digital power grids.

[0321] In addition, the knowledge graph-driven high-risk attack path generation and evaluation system in the embodiment of the present application not only improves the overall security protection level of the digital power grid, but also provides a scalable technical paradigm for network protection of critical infrastructure. Its technical effects and social value in practical applications have great potential.

[0322] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0323] Based on the same inventive concept, embodiments of the present application also provide a control device for implementing the aforementioned method for controlling cyber attacks on digital power grids. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the control device for cyber attacks on digital power grids provided below can be found in the aforementioned definition of the method for controlling cyber attacks on digital power grids, and will not be further elaborated here.

[0324] In an exemplary embodiment, Figure 7 FIG. 1 is a schematic diagram of a structure of a device for controlling network attacks on a digital power grid in one embodiment. Figure 7As shown, the digital grid network attack control device of the embodiment of the present application may include: an acquisition module 701, a data processing module 702, a construction module 703, a first determination module 704, a second determination module 705, an allocation module 706 and a sending module 707.

[0325] The acquisition module 701 is used to acquire multi-source heterogeneous data of the digital power grid;

[0326] The data processing module 702 is used to process multi-source heterogeneous data to obtain multi-modal fusion features of the digital power grid;

[0327] A construction module 703 is configured to construct a dynamic knowledge graph of the digital power grid based on the multimodal fusion features; wherein the dynamic knowledge graph includes first attribute feature information of multiple knowledge nodes and second attribute feature information of multiple directed edges;

[0328] A first determination module 704 is configured to determine a plurality of candidate attack paths based on the dynamic knowledge graph;

[0329] A second determining module 705 is configured to determine at least one high-risk attack path from the plurality of candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the plurality of candidate attack paths;

[0330] An allocation module 706 is configured to allocate corresponding defense information to each high-risk attack path;

[0331] The sending module 707 is used to send the defense information corresponding to each high-risk attack path to the corresponding network security device respectively; wherein the defense information is used to instruct the network security device to execute corresponding defense measures according to the defense information.

[0332] In an exemplary embodiment, the second determining module 705 may include:

[0333] a first determining unit configured to determine, for each candidate attack path, an attack threat level of the candidate attack path using a preset nonlinear threat assessment model based on first attribute feature information of each knowledge node and second attribute feature information of each directed edge in the candidate attack path;

[0334] The second determining unit is configured to determine at least one high-risk attack path from a plurality of candidate attack paths according to the attack threat level of each candidate attack path.

[0335] In an exemplary embodiment, the second determining unit may be specifically configured to:

[0336] Obtaining path criticality parameters and response degree parameters of each candidate attack path;

[0337] Determine the defense priority of each candidate attack path based on its attack threat level, path criticality parameter, and response degree parameter;

[0338] At least one high-risk attack path is determined from the multiple candidate attack paths according to the defense priority of the multiple candidate attack paths from high to low.

[0339] In an exemplary embodiment, the defense information includes defense resources and defense strategies. The allocation module 706 may be specifically configured to:

[0340] Based on the attack threat level, response level parameters, and total available defense resources of each high-risk attack path, a preset resource allocation model is used to allocate resources to each high-risk attack path.

[0341] For each high-risk attack path, a corresponding defense strategy is assigned to the high-risk attack path based on the multiple knowledge nodes and multiple directed edges in the high-risk attack path;

[0342] Among them, the defense strategy includes at least one of the following: firewall rule update strategy, intrusion detection rule optimization strategy, access control list adjustment strategy, device isolation and traffic restriction strategy, log audit and traceability analysis strategy.

[0343] In an exemplary embodiment, the first determining module 704 may be specifically configured to:

[0344] Based on the dynamic knowledge graph, a preset breadth-first search algorithm is used to construct multiple initial attack paths;

[0345] Determining the weight of each initial attack path according to the second attribute feature information of each directed edge in each initial attack path;

[0346] Based on the multimodal fusion features, the preset graph neural network model is used to dynamically adjust the weight of each initial attack path;

[0347] A plurality of candidate attack paths are determined from the plurality of initial attack paths according to the adjusted weights of the plurality of initial attack paths.

[0348] In an exemplary embodiment, the multi-source heterogeneous data includes structured device traffic data and unstructured attack reference data. The data processing module 702 may be specifically configured to:

[0349] Performing a first analytical process on the device flow data to obtain a device flow feature vector;

[0350] Performing a second parsing process on the attack reference data to obtain an attack reference semantic vector;

[0351] Performing a first feature extraction process on the device traffic feature vector based on a preset convolutional neural network to obtain a local pattern feature;

[0352] Performing second feature extraction processing on the attack reference semantic vector based on a preset bidirectional long short-term memory network to obtain context-dependent features;

[0353] According to the local pattern features and context-dependent features, multimodal fusion features are obtained.

[0354] The digital power grid network attack control device provided in the embodiment of the present application can be used to execute the technical solution in the embodiment of the digital power grid network attack control method described above in the present application. Its implementation principle and technical effects are similar and will not be repeated here.

[0355] Each module in the aforementioned digital grid cyberattack control device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor within the control device in hardware form, or stored in memory within the control device in software form, allowing the processor to call and execute the corresponding operations of each module.

[0356] In an exemplary embodiment, Figure 8 FIG. 1 is a schematic diagram of a structure of a control device for a network attack on a digital power grid in one embodiment. Figure 8 As shown, a digital grid network attack control device according to an embodiment of the present application may include a processor, a memory, an input / output (I / O) interface, and a communication interface. The processor, memory, and I / O interface are connected via a system bus, and the communication interface is connected to the system bus via the I / O interface. The processor of the digital grid network attack control device is used to provide computing and control capabilities. The memory of the digital grid network attack control device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the digital grid network attack control device is used to store multi-source heterogeneous data, dynamic knowledge graphs, and / or defense information. The I / O interface of the digital grid network attack control device is used to exchange information between the processor and external devices. The communication interface of the digital grid network attack control device is used to communicate with external terminals via a network connection. When executed by the processor, the computer program implements the technical solution of any of the above-mentioned digital grid network attack control method embodiments of the present application.

[0357] Those skilled in the art will understand that Figure 8The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the network attack control device for the digital power grid to which the solution of the present application is applied. The specific network attack control device for the digital power grid may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0358] In an exemplary embodiment, a digital power grid network attack management and control device is also provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0359] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0360] In an exemplary embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0361] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile memory and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a programmable logic unit (PLC), a data processing logic unit based on quantum computing, an artificial intelligence (AI) processor, and the like.

[0362] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0363] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for controlling network attacks on a digital power grid, characterized in that: The method comprises: Acquiring multi-source heterogeneous data of the digital power grid, and performing data processing on the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid; Constructing a dynamic knowledge graph of the digital power grid based on the multimodal fusion features, and determining a plurality of candidate attack paths based on the dynamic knowledge graph; wherein the dynamic knowledge graph includes first attribute feature information of a plurality of knowledge nodes and second attribute feature information of a plurality of directed edges; Determine at least one high-risk attack path from the multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the multiple candidate attack paths, and assign corresponding defense information to each of the high-risk attack paths; The defense information corresponding to each of the high-risk attack paths is sent to the corresponding network security device respectively; wherein the defense information is used to instruct the network security device to execute corresponding defense measures according to the defense information.

2. The method according to claim 1, characterized in that The determining at least one high-risk attack path from the multiple candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the multiple candidate attack paths includes: For each candidate attack path, determining the attack threat level of the candidate attack path using a preset nonlinear threat assessment model based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the candidate attack path; At least one high-risk attack path is determined from a plurality of the candidate attack paths according to the attack threat level of each candidate attack path.

3. The method according to claim 2, characterized in that Determining at least one high-risk attack path from a plurality of candidate attack paths according to the attack threat level of each candidate attack path includes: Obtaining a path criticality parameter and a response degree parameter of each candidate attack path; Determining the defense priority of each candidate attack path according to the attack threat level, the path criticality parameter, and the response degree parameter of each candidate attack path; At least one high-risk attack path is determined from the multiple candidate attack paths in descending order of defense priority of the multiple candidate attack paths.

4. The method according to claim 2 or 3, characterized in that The defense information includes defense resources and defense strategies, and the corresponding defense information is allocated to each high-risk attack path, including: According to the attack threat level, response degree parameter and total available defense resources of each high-risk attack path, a preset resource allocation model is used to perform resource allocation processing to allocate corresponding defense resources to each high-risk attack path; For each of the high-risk attack paths, assigning a corresponding defense strategy to the high-risk attack path according to a plurality of knowledge nodes and a plurality of directed edges in the high-risk attack path; Among them, the defense strategy includes at least one of the following: firewall rule update strategy, intrusion detection rule optimization strategy, access control list adjustment strategy, device isolation and traffic restriction strategy, log audit and traceability analysis strategy.

5. The method according to any one of claims 1 to 3, characterized in that Determining multiple candidate attack paths according to the dynamic knowledge graph includes: Constructing multiple initial attack paths based on the dynamic knowledge graph using a preset breadth-first search algorithm; determining a weight of each of the initial attack paths according to the second attribute feature information of each directed edge in each of the initial attack paths; Dynamically adjust the weight of each of the initial attack paths using a preset graph neural network model based on the multimodal fusion features; The plurality of candidate attack paths are determined from the plurality of initial attack paths according to the adjusted weights of the plurality of initial attack paths.

6. The method according to any one of claims 1 to 3, characterized in that The multi-source heterogeneous data includes structured device flow data and unstructured attack reference data. The data processing of the multi-source heterogeneous data to obtain the multimodal fusion features of the digital power grid includes: Performing a first analytical process on the device flow data to obtain a device flow feature vector; performing a second parsing process on the attack reference data to obtain an attack reference semantic vector; Performing a first feature extraction process on the device traffic feature vector based on a preset convolutional neural network to obtain a local pattern feature; Performing a second feature extraction process on the attack reference semantic vector based on a preset bidirectional long short-term memory network to obtain a context-dependent feature; The multimodal fusion feature is obtained according to the local pattern feature and the context-dependent feature.

7. A digital power grid network attack control device, characterized in that: The device comprises: An acquisition module, configured to acquire multi-source heterogeneous data of the digital power grid; a data processing module, configured to process the multi-source heterogeneous data to obtain multimodal fusion features of the digital power grid; A construction module, configured to construct a dynamic knowledge graph of the digital power grid based on the multimodal fusion features; wherein the dynamic knowledge graph includes first attribute feature information of a plurality of knowledge nodes and second attribute feature information of a plurality of directed edges; A first determination module is configured to determine a plurality of candidate attack paths based on the dynamic knowledge graph; a second determining module, configured to determine at least one high-risk attack path from the plurality of candidate attack paths based on the first attribute feature information of each knowledge node and the second attribute feature information of each directed edge in the plurality of candidate attack paths; An allocation module, configured to allocate corresponding defense information to each of the high-risk attack paths; The sending module is used to send the defense information corresponding to each high-risk attack path to the corresponding network security device respectively; wherein, the defense information is used to instruct the network security device to execute corresponding defense measures according to the defense information.

8. A digital power grid network attack control device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Attack path determination method and device, equipment and storage medium

    CN114915475A

  • Power grid knowledge graph construction method based on self-learning

    CN116028636A

  • Threat intelligence data processing method and computer readable storage medium

    CN117668244A

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A

  • DDoS attack real-time detection and traceability analysis method based on knowledge graph

    CN119728286A

Cited By

  • Heterogeneous atlas-based network attack path prediction method and device, and medium

    CN120785667A

  • Network attack path prediction method and device based on heterogeneous graph, and medium

    CN120785667B

  • Network asset risk identification method and system

    CN120811785A

  • Network asset risk identification method and system

    CN120811785B