Attack-assisted identification method and system for power CPS network
By analyzing the power impact of power nodes and the information exchange impact of information nodes, and combining the link analysis algorithm, the attack identification method of power CPS network is improved, the accuracy of attack identification is increased, and the problem of not considering the impact of power nodes in the existing technology is solved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- YICHUN POWER SUPPLY COMPANY OF STATE GRID HEILONGJIANG ELECTRIC POWER COMPANY
- Filing Date
- 2025-06-13
- Publication Date
- 2026-05-01
AI Technical Summary
In existing power CPS networks, attack identification methods based on the HITs algorithm fail to effectively consider the influence of power nodes, leading to errors in the ranking of information node importance and thus affecting the accuracy of attack identification.
By analyzing the power impact of power nodes and the information exchange impact of information nodes, and combining the link analysis algorithm, a correction factor for each node is determined, and the node importance calculation is improved to identify attacked nodes.
It improves the accuracy of attack identification in power CPS networks, takes into account the coupling nature of power nodes and information nodes, conforms to the actual operation of nodes, and reduces false identification.
Smart Images

Figure CN120547073B_ABST
Abstract
Description
A method and system for attack-assisted identification in power CPS networks Technical Field
[0001] This application relates to the field of power grid network attack identification technology, specifically to an attack-assisted identification method and system for power CPS networks. Background Technology
[0002] A power CPS (Cyber Physical System) network refers to a complex system that deeply integrates the physical system of a power system with an information and communication system. Because power CPS networks are deeply coupled with information networks, attacks on the information network can have a significant impact. If not handled promptly, this can lead to the paralysis of information nodes, causing failures in the coupled power nodes, and ultimately resulting in large-scale power outages.
[0003] Attacks against power CPS primarily use data as a carrier, propagating through the information flow of the information network within the system, disrupting its functionality, transmitting erroneous instructions, and ultimately leading to serious accidents. Existing technologies rely on the Hyperlink-Induced Topic Search (HITs) algorithm to evaluate the importance of nodes in the power information network. This algorithm ranks information nodes based on their hub and authority values. Once a power CPS network is attacked, information exchange and power flow between nodes may be altered, causing changes in node importance. Therefore, node importance can help identify attack events. However, in the traditional HITs algorithm, hub and authority values are obtained iteratively based on the topological relationships of information nodes. In power CPS networks, this does not consider the influence of power nodes within the power grid. Therefore, errors in the ranking of information node importance may occur, leading to misidentification of attacks. Summary of the Invention
[0004] To address the aforementioned technical problems, an attack-assisted identification method and system for power CPS networks are provided to resolve existing issues.
[0005] The solution to the technical problem in this application is to provide an attack-assisted identification method and system for power CPS networks, including the following steps:
[0006] In a first aspect, embodiments of this application provide an attack-assisted identification method for power CPS networks, the method comprising the following steps:
[0007] Each moment and multiple moments within its neighborhood are recorded as local time periods of each moment. The active and reactive power of each power node in the power grid of the power CPS network at each moment are obtained, as well as the amount of data exchange between any two information nodes in the information network of the power CPS network within the local time periods of each moment.
[0008] Based on the connection status of each power node and the power flow direction of the line, a directed graph of the power grid topology is generated; the inflow line and the inflow node and outflow node in the outflow line corresponding to each power node are determined respectively.
[0009] Based on the power difference between the outflow node and the inflow node of any inflow or outflow line within a local time period at each moment, determine the local cumulative power of any inflow or outflow line at each moment; analyze the number of inflow and outflow lines corresponding to each power node, and the degree of difference in the local cumulative power between the inflow and outflow lines, to determine the power influence of each power node at each moment.
[0010] Based on the dispersion and fluctuation range of the active power of each power node in local time periods at each time, the power fluctuation degree of each power node at each time is determined; based on the power influence degree and the power fluctuation degree, the power influence index of each power node at each time is determined.
[0011] Analyze the amount of data exchanged between different information nodes in local time periods at each time and the degree of difference in the amount of data exchanged in local time periods at different times to determine the information exchange impact of each information node at each time.
[0012] Power nodes and information nodes at the same location are denoted as each node; based on the power impact index and the information exchange impact degree, the correction factor for each node at each time is determined; combined with the link analysis algorithm, the importance of each node at each time is determined, and the attacked nodes in the power CPS network are identified.
[0013] Preferably, determining the inflow node and outflow node in the inflow line and outflow line corresponding to each power node includes:
[0014] Based on the directed graph of the power grid topology, the line pointing to each power node is denoted as the inflow line corresponding to each power node, and the line pointing from each power node to the other power nodes is denoted as the outflow line corresponding to each power node. The starting node of any line is taken as the outflow node and the ending node is taken as the inflow node.
[0015] Preferably, determining the local cumulative power of any inflow or outflow line at each time step includes:
[0016] The difference between the active power and reactive power of the outflow node and the inflow node of any inflow line corresponding to each power node at each time is taken as the active power and reactive power of the inflow line corresponding to each power node at each time.
[0017] The sum of the active power and reactive power of any inflow line corresponding to each power node at all times within a local time period is taken as the local cumulative power of any inflow line corresponding to each power node at each time.
[0018] For the active power and reactive power of the outflow node and inflow node of any outflow line corresponding to each power node at each time, the same method as the local cumulative power of the inflow line at each time is used to obtain the local cumulative power of the outflow line corresponding to each power node at each time.
[0019] Preferably, the formula for determining the power impact of each power node at each time point is as follows: ,in, For the first The power node at the ... Power impact at any given moment For the first The corresponding power node is the first The inflow line is in the first Local cumulative power at time t, For the first The corresponding power node is the first The outflow line is in the first Local cumulative power at time t, For the first The number of all inflow lines corresponding to each power node. For the first The number of all outgoing lines corresponding to each power node.
[0020] Preferably, the power fluctuation of each power node at each time moment is the product of the range and dispersion of the active power of each power node at all times within a local time period at each time moment.
[0021] Preferably, the power impact index of each power node at each time point is the normalized result of the ratio of the power impact degree to the power fluctuation degree.
[0022] Preferably, the formula for determining the information exchange impact of each information node at each time point is as follows: ,in, For the first The information node in the first The impact of information exchange at any given moment For the first The number of all other information nodes connected to the first information node. For the first The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. For the first The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. The default value is greater than 0. This is the normalization function.
[0023] Preferably, the correction factor for each node at each time step is the product of the power influence index and the information exchange influence degree.
[0024] Preferably, the importance of each node at each time point includes:
[0025] Based on the topological relationship of information nodes within the information network, and combined with the link analysis algorithm, the hub value and authority value of each node are obtained.
[0026] The sum of the hub value and the authority value is calculated, and the normalized result of the product of the sum and the correction factor is used as the importance of each node at each time step.
[0027] Secondly, embodiments of this application also provide an attack-assisted identification system for a power CPS network, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-described attack-assisted identification methods for a power CPS network.
[0028] This application has at least the following beneficial effects:
[0029] This application determines the local cumulative power of any inflow or outflow line at each time step based on the power difference between the outflow node and the inflow node of any inflow or outflow line within a local time period. It analyzes the number of inflow and outflow lines corresponding to each power node and the degree of difference in the local cumulative power between them to determine the power influence of each power node at each time step. Its beneficial effect is that it considers the balance of inflow and outflow power at each power node, reflecting the importance of the power node in the power transmission process of the power grid. Based on the dispersion and fluctuation range of active power at each power node within a local time step, it determines the power fluctuation of each power node at each time step. Based on the power influence and the power fluctuation, it determines the power influence index of each power node at each time step. Its beneficial effect is that it considers the degree of power fluctuation at each power node, thereby clarifying whether each power node is in a critical position in power transmission and distribution. It also analyzes the data exchange volume between different information nodes within a local time step. The degree of difference in data exchange volume within local time periods at different times determines the information exchange impact of each information node at each time. Its beneficial effect lies in considering the differences in data exchange volume between information nodes within different local time periods, reflecting the fluctuations in information exchange transmission between information nodes, and reflecting the impact of an information node being attacked on other information nodes, indirectly indicating the importance of the information node. Based on the power impact index and the information exchange impact, a correction factor for each node at each time is determined. Combined with the link analysis algorithm, the importance of each node at each time is determined, identifying attacked nodes in the power CPS network. Its beneficial effect lies in considering the coupling nature between power nodes and information nodes in the power CPS network. By combining the impact of power node power changes with the impact of information node data exchange, the HITs algorithm is improved to calculate node importance, making the importance not only dependent on the topological relationship of information nodes but also more consistent with the actual operating conditions of nodes, thus enabling more accurate identification of attacked nodes in the power CPS network. Attached Figure Description
[0030] The following section provides a more detailed description of an attack-assisted identification method for a power CPS network based on this application, with reference to the accompanying drawings.
[0031] Figure 1 is a flowchart of the steps of an attack-assisted identification method for a power CPS network provided in an embodiment of this application;
[0032] Figure 2 is a diagram of the power CPS structure provided in an embodiment of this application;
[0033] Figure 3 is a directed graph of the power grid topology provided in an embodiment of this application;
[0034] Figure 4 is a flowchart of the steps of the method for obtaining the local cumulative power of any inflow line corresponding to each power node at each time according to the embodiment of this application;
[0035] Figure 5 is a schematic diagram of the change in the importance of nodes in the power CPS network provided in the embodiment of this application. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description, in conjunction with the accompanying drawings and implementation examples, provides a method and system for attack-assisted identification of power CPS networks proposed in this application. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0037] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0038] Please refer to Figure 1, which shows a flowchart of the steps of an attack-assisted identification method for a power CPS network according to an embodiment of this application. The method includes the following steps:
[0039] Step 1: Obtain the active and reactive power of each power node in the power grid at each time point, and the data exchange volume between any two information nodes in the information network of the power CPS network during local time periods at each time point.
[0040] The power system has evolved into a cyberphysical system (CPS) with deep coupling between information and physical systems. The continuous interaction between information flow and power flow exposes the power grid to potential cyberattack risks. Power CPS cyberattacks can be categorized into attacks that compromise information availability, integrity, and confidentiality. False data injection (FDIA) attacks are a common form of integrity attack. Attackers can bypass malicious data detection mechanisms, inject false measurement data into compromised instruments or sensors, and arbitrarily manipulate system state estimation, thereby interfering with the normal operation of the power system.
[0041] Therefore, based on the IEEE-30 node system, the power CPS network comprises a power grid consisting of power nodes connected by transmission lines and an information network consisting of information nodes connected by network transmission lines. Power nodes and information nodes are coupled and influence each other. In the power grid, energy transmission follows a power flow distribution, and power nodes provide power support to their corresponding information nodes. Unlike the power grid, the transmission of information packets between information nodes always selects the shortest path, ignoring the effects of other paths on the packet. Information nodes provide data acquisition, information transmission, and control functions to their corresponding power nodes. A power node failure can affect the power supply to information nodes, causing them to fail, while an attack on an information node can cause a power node failure.
[0042] Based on the above analysis, power sensors are installed at each power node in the power grid to collect the active and reactive power of each power node, and the sampling frequency is set to f. All collected data are cleaned and missing values are filled, and then normalized to obtain the active and reactive power of each power node in the power grid at each time.
[0043] Each time point and multiple times points in its neighborhood are recorded as local time periods of each time point;
[0044] Preferably, in this embodiment, all times within each time point and its neighborhood of 1 second are selected and recorded as local time periods of each time point. As for other implementation methods, the implementer can set them according to the actual situation.
[0045] At the same time, network traffic monitoring tools are used to monitor the amount of data exchanged between any two information nodes within the information network during local time periods at various times.
[0046] Preferably, in this embodiment, the sampling frequency is set to 100Hz. As other implementation methods, the implementer can set it according to the actual situation, and this embodiment does not impose any special restrictions on it. Secondly, the Nagios network traffic monitoring tool is used for monitoring. Nagios is a well-known technology and will not be described in detail here. As other implementation methods, the implementer can use other methods of the prior art, such as Wireshark, NetFlow, etc., and this embodiment does not impose any special restrictions on it. The maximum and minimum value normalization method is used for normalization processing, and the linear interpolation algorithm is used for missing value filling. As other implementation methods, the implementer can use other methods of the prior art, such as Z-score normalization method, mean filling, etc., and this embodiment does not impose any special restrictions on it.
[0047] Thus, we obtain the active and reactive power of each power node in the power grid at each time, as well as the data exchange volume between any two information nodes in the information network during local time periods at each time.
[0048] Step 2: Based on the power difference between the outflow node and the inflow node of any inflow or outflow line within a local time period at each moment, determine the local cumulative power of any inflow or outflow line at each moment; analyze the number of inflow and outflow lines corresponding to each power node, and the degree of difference in the local cumulative power between the inflow and outflow lines, to determine the power influence of each power node at each moment.
[0049] Power CPS networks are often abstracted as a system consisting of information nodes, physical nodes, information edges, physical edges, and node relationships. Figure 2 shows the structure of a power CPS network. In Figure 2, B represents the power network topology, A represents the information network topology, 1 represents an information node, 2 represents a power node, 3 represents an information edge, 4 represents a power edge, and 5 represents node relationships. In the power network topology, power nodes include generation nodes, substation nodes, and consumption nodes, connected by transmission lines (power edges). In the information network topology, information nodes include ordinary information nodes and control center information nodes, connected by network transmission lines (information edges). These network transmission lines include both wired connections such as fiber optic cables and wireless network connections.
[0050] In a power grid, power nodes and information nodes in an information network are coupled one-to-one. Power nodes supply power to information nodes, which in turn collect electrical parameters from the power nodes and transmit them to the control center. The information nodes then relay commands from the control center to the power nodes, thus controlling the power grid. Because information networks are open, they are vulnerable to cyberattacks using various methods. One common attack is spoofed data injection, where attackers exploit the data collection capabilities of information nodes to inject false data into the collected data. This misleads the control center into issuing incorrect commands, causing power node malfunctions and potentially propagating throughout the power grid, leading to large-scale power outages.
[0051] In an information network, interconnected nodes can transmit information bidirectionally between each other, so the information network graph is a directed graph. In a power network, the electrical energy generated by the power generation node usually flows to the substation node, and then from the substation node to the power consumption node, so the power network graph is also a directed graph.
[0052] Based on the above analysis, in order to regulate power generation efficiency, the energy flow between power nodes is obtained through an optimal power flow algorithm, specifically:
[0053] The optimal power flow algorithm is used to perform power flow calculations on the active and reactive power of each power node in the power grid at each time point to obtain the line power flow; based on the line power flow, a directed graph of the power grid topology is generated.
[0054] Preferably, in this embodiment, a simplified gradient algorithm is used, with the minimum generation cost as the objective function, to calculate the optimal power flow distribution of the power network and obtain the line power flow. The simplified gradient algorithm is a well-known technique and will not be described in detail here. As other implementation methods, implementers can use other methods of the prior art, such as the Gauss-Seidel algorithm, the Newton-Raphson algorithm, the decoupled optimal power flow algorithm, etc. This embodiment does not impose any special restrictions on this. Secondly, the method for obtaining the directed graph of the power grid topology is a well-known technique and will not be described in detail here.
[0055] It should be noted that the directed graph of the power grid topology is shown in Figure 3. In the figure, black circles represent power nodes, and arrows represent power edges, with the arrows pointing in the direction of power flow. Figure 3 shows that nodes in the power network have varying importance. A power node with more connections to other power nodes is more important, and therefore, the impact of an attack on that node will be greater. If power nodes and information nodes in the same location are denoted as a single node, when any node is attacked by spoofed data injection, it will affect the node's power generation or transmission efficiency, potentially changing the optimal power flow direction and altering the node's importance. Therefore, monitoring the importance of each node can help identify whether the power CPS network is under attack. When the importance of a particular node changes significantly, it indicates that the power CPS network has been attacked.
[0056] Furthermore, since data acquisition from power nodes is continuous, changes in importance can be determined by comparing power variations over different time periods. When assessing node importance, the injected power has a significant impact. Injected power is represented as the power difference between the inflow and outflow from the node, including the power injected by generators into each node and the power consumed by the loads connected to each node. The injected power of each power node reflects the balance of power input and output within the power system, thus reflecting the node's influence on transmitting power from the grid. Therefore, the power influence of each power node is determined as follows:
[0057] Based on the directed graph of the power grid topology, the line pointing to each power node is denoted as the inflow line corresponding to each power node, and the line pointing from each power node to the other nodes is denoted as the outflow line corresponding to each power node. The starting node of any line is taken as the outflow node and the ending node is taken as the inflow node.
[0058] It should be noted that in Figure 3, for power nodes... Power nodes , , All point to power nodes Therefore, power nodes The corresponding inflow line is the line , , Power nodes Point to power node Therefore, power nodes The corresponding outflow line is the line. For the line Power nodes Power flows to power nodes Therefore, the line Middle starting node Outflow node, terminating node This is the inflow node.
[0059] The difference between the active power of the outflow node and the inflow node of any inflow line corresponding to each power node at each time is taken as the active power of any inflow line corresponding to each power node in the power grid at each time.
[0060] The difference between the reactive power of the outflow node and the inflow node of any inflow line corresponding to each power node at each time is taken as the reactive power of any inflow line corresponding to each power node in the power grid at each time.
[0061] The difference between the active power of the outflow node and the inflow node of any outflow line corresponding to each power node at each time is taken as the active outflow power of any outflow line corresponding to each power node in the power grid at each time.
[0062] The difference between the reactive power of the outflow node and the inflow node of any outflow line corresponding to each power node at each time is taken as the reactive power outflow of any outflow line corresponding to each power node in the power grid at each time.
[0063] It should be noted that in Figure 3, the power node Corresponding inflow route The active power flowing into the node at each time point is the power flowing out of the node. With the inflow node The difference in active power between them; power nodes Corresponding inflow route The reactive power flowing into the node at each time point is the power flowing out of the node. With the inflow node The difference in reactive power between them; power nodes Corresponding outflow lines The active power outflow and reactive power outflow at each time point are respectively the outflow nodes. With the inflow node The difference between active power and reactive power.
[0064] The sum of the active power and reactive power of any inflow line corresponding to each power node in the power grid at all times within a local time period is taken as the local cumulative power of any inflow line corresponding to each power node at each time.
[0065] Furthermore, the flowchart of the method for obtaining the local cumulative power of any inflow line corresponding to each power node at each time moment provided in the embodiments of this application is shown in Figure 4.
[0066] The sum of the active power and reactive power of any outgoing line corresponding to each power node in the power grid at all times within a local time period is taken as the local cumulative power of any outgoing line corresponding to each power node at each time.
[0067] The formula for calculating the power impact of each power node in the power grid at each time point is as follows: ,in, For the first in the power grid The power node at the ... Power impact at any given moment For the first in the power grid The corresponding power node is the first The inflow line is in the first Local cumulative power at time t, For the first in the power grid The corresponding power node is the first The outflow line is in the first Local cumulative power at time t, For the first in the power grid The number of all inflow lines corresponding to each power node. For the first in the power grid The number of all outgoing lines corresponding to each power node.
[0068] It should be noted that, Indicated as the inflow of the first Total power of each power node For the first Power flowing out of each power node Indicated as injection of the first The injected power of a power node reflects its power balance within the power grid and its impact on power transmission. A higher injected power indicates a crucial role in power transmission and distribution, potentially influencing the operation of other nodes, thus signifying greater importance. Furthermore, a larger number of connected nodes indicates greater importance and a greater power influence, suggesting that the injected power of a particular node has a significant impact on other nodes in the power network. This implies that a significant change in the injected power of a particular node may indicate an attack, further highlighting its importance.
[0069] Thus, the power impact of each power node in the power grid at each time point is obtained.
[0070] Step 3: Determine the power fluctuation degree of each power node at each time based on the dispersion and fluctuation range of the active power of each power node in the local time period at each time; determine the power influence index of each power node at each time based on the power influence degree and the power fluctuation degree.
[0071] Furthermore, when the injected power of each power node changes, its injected power will fluctuate over a period of time. The greater the fluctuation, the more likely that the power node has been attacked, which will lead to a change in its importance. Therefore, it is necessary to analyze the power fluctuation of each power node and determine the power fluctuation degree, specifically as follows:
[0072] Calculate the range and dispersion of active power of each power node in the power grid at all times within a local time period at each time point;
[0073] The product of the range and the degree of dispersion is used as the power fluctuation of each power node in the power grid at each time.
[0074] Preferably, in this embodiment, the degree of dispersion is calculated by measuring the standard deviation of the active power of each power node in the power grid at all times within a local time period. As for other implementation methods, implementers may use other methods in the prior art, such as variance, coefficient of variation, information entropy, etc. This embodiment does not impose any special restrictions on this.
[0075] It should be noted that the greater the power fluctuation, the greater the fluctuation of the active power of the corresponding power node in a local period, and the greater the impact on the power node. It is more likely that the power node has been attacked. In this case, the importance of the power node should be reduced to avoid affecting other power nodes.
[0076] Furthermore, based on the power impact degree and the power fluctuation degree, a power impact index is determined to reflect the importance of the corresponding node in the power grid, specifically:
[0077] The normalized result of the ratio of the power impact degree to the power fluctuation degree is used as the power impact index of each power node in the power grid at each time.
[0078] It should be noted that a greater power impact indicates a larger injected power or a smaller power fluctuation at the corresponding power node. In this case, the corresponding power node is in a critical position in power transmission and distribution, and its importance is higher. When a power node is attacked, the transmission power may be affected, either decreasing or increasing, while the degree of power fluctuation will increase, thus causing a change in the importance of the power node.
[0079] Thus, the power impact index of each power node in the power grid at each time point is obtained.
[0080] Step 4: Analyze the amount of data exchanged between different information nodes in local time periods at each time and the degree of difference in the amount of data exchanged in local time periods at different times, and determine the information exchange impact of each information node at each time.
[0081] Furthermore, since power nodes in the power grid and information nodes in the information network are coupled one-to-one, if the connection relationship between nodes is not considered, the coupled power node and information node can be regarded as the same node. Attackers inject false data into the information network to launch attacks. When a node is attacked, not only will the power of the power node be affected, but the data exchange and topology between information nodes will also be affected. Therefore, the impact of information exchange is determined based on the changes in the amount of data exchange between information nodes to reflect the degree of impact on information nodes when attacked. Specifically:
[0082] The formula for calculating the impact of information exchange at each information node within the information network at each time point is: ,in, For the first in the information network The information node in the first The impact of information exchange at any given moment For the first in the information network The number of all other information nodes connected to the first information node. For the first in the information network The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. For the first in the information network The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. To ensure that the value is greater than 0 and to avoid a denominator of 0, in this embodiment, The value is 1. As for other implementation methods, the implementer can set it according to the actual situation. As a normalization function, the sigmoid function is used for normalization in this embodiment. As other implementation methods, implementers may use other methods of the prior art, such as the tanh function, etc. This embodiment does not impose any special restrictions on this.
[0083] It should be noted that the first The more information nodes a node can communicate with, the more other information nodes it can communicate with. The larger the value, the more important the corresponding information node. Secondly, the... The greater the amount of data exchanged between an information node and the other information nodes, the more... The larger the value, the more important the corresponding information node. The smaller the difference in data exchange volume between two information nodes in different local time periods, the smaller the fluctuation in data transmission. The greater the importance of the corresponding information node, the greater the impact of the information exchange. If an information node is attacked, it may cut off its connection with other information nodes, causing information exchange to be blocked, which in turn affects the control of the power node. It may also cause the data exchange volume between two information nodes to increase or decrease. If the data exchange volume changes too much, it may be due to an attack, which will cause the importance of the node to change, and the data exchange situation of the information node will be more affected.
[0084] Thus, the impact of information exchange on each information node within the information network at each moment is obtained.
[0085] Step 5: Record power nodes and information nodes at the same location as each node; determine the correction factor for each node at each time based on the power impact index and the information exchange impact degree; combine the link analysis algorithm to determine the importance of each node at each time and identify the attacked nodes in the power CPS network.
[0086] Furthermore, based on the power impact index and the information exchange impact degree, the importance is determined, specifically as follows:
[0087] Power nodes and information nodes in the same location are recorded as each node, and thus each node in the power CPS network.
[0088] Based on the topological relationship of information nodes within the information network, a link analysis algorithm is used for iterative calculation to obtain the hub value and authority value of each node.
[0089] Preferably, in this embodiment, the HITs (Hyperlink-Induced Topic Search) algorithm is used for iterative calculation to obtain the hub value and authority value. The HITs algorithm is a well-known technology and will not be described in detail here.
[0090] The product of the power impact index and the information exchange impact degree is used as a correction factor for each node;
[0091] Calculate the sum of the hub value and the authority value of each node at each time step, and use the normalized result of the product of the sum and the correction factor as the importance of each node in the power CPS network at each time step.
[0092] Preferably, in this embodiment, the sigmoid function is used for normalization. The sigmoid function is a well-known technology and will not be described in detail here. As other implementation methods, implementers may use other methods of the prior art, such as the tanh function, etc. This embodiment does not impose any special restrictions on this.
[0093] It should be noted that the greater the importance, the more critical the position of the power node in power transmission, and the more critical the position of the information node in information exchange. If the importance of a node changes significantly in a short period of time, it indicates that it may be under attack. The greater the magnitude of the change, the greater the possibility of being attacked.
[0094] Furthermore, in a stable power CPS network, the importance of each node does not change drastically because it must maintain the minimum generation cost to ensure optimal power flow. Therefore, by monitoring the changes in node importance in real time, nodes under attack in the power CPS network can be identified, and the corresponding information nodes and power nodes can be checked and repaired in a timely manner. Specifically:
[0095] All nodes are sorted in descending order of importance, and the top-ranked nodes are selected as critical nodes. The critical nodes that have been attacked are then identified.
[0096] It should be noted that, assuming a critical node is attacked, the attacker injects false data into the data collected by the critical node. Due to the misleading nature of the false data, the control center may adjust the control of that critical node, potentially causing a drastic increase or decrease in its importance. For example, Figure 5 illustrates the change in the importance of a critical node in a power CPS network. When each critical node is operating normally, the first critical node, 0.5 seconds prior, will... The importance of each key node fluctuates slightly within a certain range. At 0.5s, the importance of the first node... The importance of the first key node drops rapidly, indicating that the... Several key nodes may be under attack; the corresponding nodes should be checked promptly using network traffic monitoring tools. The IP address of the data request and transmission of the first information node, and for the first... Each power node was inspected and repaired to troubleshoot power node malfunctions.
[0097] Based on the same inventive concept as the above method, this application embodiment also provides an attack-assisted identification system for a power CPS network, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-described attack-assisted identification methods for a power CPS network.
[0098] It should be understood that although the steps in the flowchart of Figure 1 are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in Figure 1 may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0099] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0100] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application. Therefore, any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of this application, without departing from the content of the technical solution of this application, shall fall within the protection scope of the technical solution of this application.
Claims
1. An attack-assisted identification method for power CPS networks, characterized in that, The method includes the following steps: recording each moment and multiple moments within its neighborhood as local time periods; obtaining the active and reactive power of each power node in the power grid of the power CPS network at each moment, and the data exchange volume between any two information nodes in the information network of the power CPS network during the local time periods at each moment; generating a directed graph of the power grid topology based on the connection status of each power node and the power flow direction of the lines; determining the inflow and outflow nodes in the inflow and outflow lines corresponding to each power node; determining the local cumulative power of any inflow or outflow line at each moment based on the power difference between the outflow node and the inflow node of any inflow or outflow line during the local time periods at each moment; analyzing the number of inflow and outflow lines corresponding to each power node, and the local cumulative power between the inflow and outflow lines. The degree of power difference is used to determine the power impact of each power node at each time. Based on the dispersion and fluctuation range of active power of each power node within local time periods at each time, the power fluctuation of each power node at each time is determined. Based on the power impact and power fluctuation, the power impact index of each power node at each time is determined. The data exchange volume between different information nodes within local time periods at each time and the degree of difference in data exchange volume between different time periods are analyzed to determine the information exchange impact of each information node at each time. Power nodes and information nodes at the same location are denoted as each node. Based on the power impact index and the information exchange impact, the correction factor of each node at each time is determined. Combined with a link analysis algorithm, the importance of each node at each time is determined, and nodes under attack in the power CPS network are identified.
2. The attack-assisted identification method for power CPS networks as described in claim 1, characterized in that, The step of determining the inflow and outflow nodes of each power node's corresponding inflow and outflow lines includes: based on the directed graph of the power grid topology, denoteing the lines pointing to each power node as the inflow lines corresponding to each power node, denoteing the lines pointing from each power node to other power nodes as the outflow lines corresponding to each power node, and denoteing the starting node of any line as the outflow node and the ending node as the inflow node.
3. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The determination of the local cumulative power of any inflow or outflow line at each moment includes: taking the difference between the active power and reactive power of the outflow node and the inflow node of any inflow line corresponding to each power node at each moment as the active power inflow power and reactive power inflow power of the inflow line corresponding to each power node at each moment; taking the sum of the active power inflow power and the reactive power inflow power of the inflow line corresponding to each power node at all moments within a local time period as the local cumulative power of the inflow line corresponding to each power node at each moment; and using the same method as the local cumulative power of the inflow line corresponding to each power node at each moment to obtain the local cumulative power of the outflow line corresponding to each power node at each moment for the active power and reactive power of the outflow node and the inflow node of any outflow line corresponding to each power node at each moment.
4. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The formula for determining the power impact of each power node at each time point is as follows: ,in, For the first The power node at the ... Power impact at any given moment For the first The corresponding power node is the first The inflow line is in the first Local cumulative power at time t, For the first The corresponding power node is the first The outflow line is in the first Local cumulative power at time t, For the first The number of all inflow lines corresponding to each power node. For the first The number of all outgoing lines corresponding to each power node.
5. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The power fluctuation of each power node at each time point is the product of the range and dispersion of the active power of each power node at all times within a local time period at each time point.
6. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The power impact index of each power node at each time point is the normalized result of the ratio of the power impact degree to the power fluctuation degree.
7. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The formula for determining the information exchange impact of each information node at each time point is as follows: ,in, For the first The information node in the first The impact of information exchange at any given moment For the first The number of all other information nodes connected to the first information node. For the first The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. For the first The information node and its connection to the first Between the information nodes in the 1st The amount of data exchanged within a local time period of a given moment. The default value is greater than 0. This is the normalization function.
8. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The correction factor for each node at each time point is the product of the power influence index and the information exchange influence degree.
9. The attack-assisted identification method for a power CPS network as described in claim 1, characterized in that, The importance of each node at each time point includes: obtaining the hub value and authority value of each node based on the topological relationship of information nodes within the information network and combined with the link analysis algorithm; calculating the sum of the hub value and the authority value; and using the normalized result of the product of the sum and the correction factor as the importance of each node at each time point.
10. An attack-assisted identification system for a power CPS network, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the attack-assisted identification method for a power CPS network as described in any one of claims 1-9.
Citation Information
Patent Citations
Power grid node importance degree determination method
CN105389670A
Information physical system key node identification method for coping with network attack
CN117729058A