Power data communication network security situation prediction method
By obtaining physical node coordinates and real-time network traffic in the power data communication network, using geographic information mapping and timing event chain construction technology to generate a global security situation view, the problem of insufficient spatial positioning and timing analysis in the existing technology is solved, and dynamic analysis and prediction of hot spot situations of the power data communication network is realized.
Patent Information
- Application Number
- CN202510754819.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-05
AI Technical Summary
The existing power data communication network security situation prediction methods have shortcomings in spatial positioning, timing analysis and incremental change monitoring, and it is difficult to achieve multi-dimensional refined portrayal and real-time analysis, resulting in poor prediction accuracy and practicality.
By obtaining physical node coordinates, real-time network traffic and business priority data, using geographic information mapping and timing event chain construction technology, a hot spot multi-dimensional orientation description vector is generated, combined with time window sliding calculation and multi-dimensional data integration, a global security situation view is generated, and dynamic analysis of hot spot situations is realized through dynamic weight adjustment and time series prediction.
It realizes comprehensive and dynamic analysis of hotspot situations in power data communication networks, provides strong support for network security management and decision-making, and improves the accuracy and real-time performance of predictions.
Smart Images

Figure CN120602152A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power systems, and in particular to a method for predicting the security situation of a power data communication network. Background Art
[0002] Power data communication network security situation prediction is a key research area to ensure the stable operation of power systems. Its importance lies in the timely detection of potential threats and the implementation of protective measures through dynamic monitoring and analysis of network security situation, thus providing support for the reliability and security of power data communication networks. With the acceleration of the digital transformation of power systems, network attack methods are becoming increasingly complex. Real-time perception and prediction of security situation have become a core requirement for maintaining power infrastructure. However, existing methods have significant limitations when dealing with complex network environments. The main manifestation is the lack of multi-dimensional and refined characterization of security hotspots, making it difficult to achieve comprehensive analysis from local to global and from static to dynamic. As a result, existing systems often suffer from insufficient analysis accuracy or poor real-time performance when dealing with spatial positioning, temporal correlation, and incremental changes.
[0003] In the field of power data communication network security situation prediction, the core challenges lie in the following technical factors: First, the precise location and dynamic tracking of security hotspots in the spatial dimension are difficult, making it difficult to accurately construct a comprehensive location model at the physical, network, and business levels. Second, the temporal dimension of security events is insufficient, making it difficult to effectively integrate the causal paths between events with the quantitative assessment of the hotspot lifecycle. Finally, the lack of a real-time, global situational view leads to weak dynamic monitoring capabilities for incremental changes. These technical difficulties prevent existing methods from fully capturing the evolution of security situations, thus affecting the accuracy and practicality of predictions.
[0004] Therefore, how to construct a power data communication network security situation prediction method and system that can accurately characterize the spatial characteristics, temporal evolution laws and incremental changes of security hotspots through data fusion and cross-dimensional correlation has become a key issue in this study. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method for predicting the security situation of power data communication network in response to the above-mentioned deficiencies in the existing technology, which can comprehensively and dynamically analyze the hotspot situation in the power data communication network and provide strong support for network security management and decision-making.
[0006] To solve the above technical problems, the present invention adopts a technical solution: a method for predicting the security situation of a power data communication network, comprising:
[0007] Obtain physical node coordinates, real-time network traffic, service priority data, and topological connection relationships from the physical nodes and service flows of the power data communication network to obtain a spatial positioning feature set;
[0008] Extract physical node coordinates, real-time network traffic, service priority data, and node load status from the spatial positioning feature set to generate a multi-dimensional hotspot location description vector.
[0009] Based on the hotspot multi-dimensional orientation description vector, network security event logs are obtained, and the time series event chain construction technology is used to obtain the event chain sequence;
[0010] The event trigger frequency, service interruption duration, and hotspot impact range are extracted from the event chain sequence, and a time window sliding calculation is used to obtain the quantitative indicators of the life cycle.
[0011] Obtain topological connection relationships, event triggering frequencies, and real-time network traffic from spatial positioning feature sets, event chain sequences, and lifecycle quantitative indicators to generate global security situation view data;
[0012] Extract the hotspot impact range and abnormal traffic fluctuations from the global security situation view data to obtain the incremental change feature set;
[0013] Based on the incremental change feature set, real-time network traffic and event logs are obtained to generate real-time hotspot situation descriptions;
[0014] Extract event trigger frequency, abnormal traffic fluctuations, and node load status from real-time hotspot situation descriptions, and use time series prediction technology to obtain the predicted evolution path;
[0015] Based on the predicted evolution path, historical situation data is obtained to generate dynamic security situation analysis results.
[0016] The above-mentioned method for predicting the security situation of a power data communication network, wherein the physical node coordinates, real-time network traffic, service priority data, and topological connection relationships are obtained from the physical nodes and service flows of the power data communication network to obtain a spatial positioning feature set, adopts geographic information mapping technology, and determines the azimuth coordinates of hotspots at the physical layer and service layer by converting the longitude and latitude position data with the coordinates of the topological connection matrix; includes:
[0017] Obtain the longitude and latitude coordinates of physical nodes, real-time network traffic, service priorities, and topological connection matrices. Through data preprocessing, clean outliers and missing values to obtain a standardized data set.
[0018] Using geographic information mapping technology, through the coordinate conversion of longitude and latitude coordinates and topological connection matrix, the distance between nodes and connection weight are calculated to determine the physical layer hotspot azimuth coordinates;
[0019] If the node traffic of the physical layer hotspot coordinate exceeds the preset threshold, the business layer hotspot distribution is determined by weighted traffic analysis combined with business priority to obtain the business hotspot coordinates;
[0020] Based on the coordinates of the physical layer hotspots and the business layer hotspots, a spatial positioning feature set is constructed. The hotspot areas are classified using the K-means clustering algorithm to obtain the hotspot area division results.
[0021] Based on the hotspot area division results, the node connection relationship and traffic distribution characteristics are analyzed, and the shortest path algorithm is used to optimize the topology connection matrix to obtain the optimized network topology structure;
[0022] If there are high-load nodes in the optimized network topology, the load balancing algorithm is used to adjust the traffic distribution to obtain balanced traffic distribution data;
[0023] According to the balanced traffic distribution data, the spatial positioning feature set is updated, and the geographic information map of hotspot distribution and topological structure is generated through visualization technology to obtain the final positioning feature set.
[0024] The above-mentioned method for predicting the security situation of power data communication networks, wherein the physical node coordinates, real-time network traffic, service priority data, and node load status are extracted from the spatial positioning feature set to generate a multi-dimensional hotspot orientation description vector, uses weighted vector calculation to redistribute the weights of event correlation strength and service priority data, and integrates the node load status; includes:
[0025] Obtain node coordinates, flow data, priority data, and load status from the spatial positioning feature set, generate an initial feature set through a feature extraction algorithm, and obtain a node feature matrix;
[0026] Using the weighted calculation method, the initial weighted vector is calculated based on the traffic data and priority data in the node feature matrix, combined with the event correlation strength, to obtain the weighted feature vector;
[0027] Through the weight adjustment algorithm, if the event correlation strength is higher than the preset threshold, the weight is redistributed according to the priority data to obtain the adjusted weighted feature vector;
[0028] Obtain the adjusted weighted feature vector, fuse the load status data, generate a multi-dimensional hotspot orientation description vector through the data fusion algorithm, and obtain the hotspot description vector;
[0029] According to the hotspot description vector, the nodes are grouped by clustering algorithm, the hotspot area to which the node belongs is determined, and the hotspot area division result is obtained;
[0030] Based on the hotspot area division results, if the node load status exceeds the preset threshold, the event correlation strength is adjusted through traffic data analysis to obtain the optimized event correlation strength;
[0031] The optimized event association strength is adopted to recalculate the weighted feature vector and fuse the load status to generate the final multi-dimensional hotspot orientation description vector and obtain the final hotspot description vector.
[0032] The above-mentioned power data communication network security situation prediction method, which obtains network security event logs based on the hotspot multi-dimensional orientation description vector and obtains the event chain sequence, adopts the time series event chain construction technology to determine the hotspot-related event trigger frequency and service interruption duration by matching the event trigger frequency and event correlation strength; includes:
[0033] Obtain network security event logs, use preprocessing technology, and obtain standardized event data sets through log parsing and data cleaning;
[0034] Extract temporal event features from the standardized event dataset and use temporal analysis techniques to construct the initial event chain sequence;
[0035] For the initial event chain sequence, we construct a multi-dimensional description vector of the hotspot and use vector matching technology to determine the event triggering frequency related to the hotspot;
[0036] If the event triggering frequency exceeds the preset threshold, the event correlation strength value is obtained by using the weighted graph model through correlation strength calculation;
[0037] Based on the event correlation strength value, the service interruption duration data is obtained, and an optimized event chain sequence is generated through dynamic adjustment of the time series event chain.
[0038] Extract key event nodes from the optimized event chain sequence and use anomaly detection algorithms to identify potential network security threats;
[0039] Based on the judgment results of potential threats, the feature library of event logs is updated to generate real-time network security event monitoring data.
[0040] The above-mentioned power data communication network security situation prediction method extracts event trigger frequency, service interruption duration, and hotspot impact range from the event chain sequence to obtain lifecycle quantitative indicators, adopts time window sliding calculation, and determines the hotspot lifecycle stage by quantifying node load status and abnormal traffic fluctuations; including:
[0041] Using a sliding time window, we extract event triggering frequency, service interruption duration, and hotspot impact range from the event chain sequence and calculate time series features.
[0042] The K-means algorithm is used to cluster the time series features and determine the initial stage of hot events;
[0043] If the hot event trigger frequency exceeds the preset threshold, the abnormal traffic fluctuation is calculated based on the node load status to obtain the fluctuation quantification value;
[0044] Based on the fluctuation quantification value and service interruption duration, a decision tree algorithm is used to determine the hotspot life cycle stage and obtain the stage classification result;
[0045] Based on the impact scope and stage classification results of hotspots, the quantitative indicators of the life cycle are calculated to determine the impact weight of hotspot events;
[0046] If the impact weight exceeds the preset threshold, the data flow analysis results are predicted in time series to obtain the life cycle trend characteristics;
[0047] According to the life cycle trend characteristics, the parameters of the sliding time window are updated to obtain new time series characteristics.
[0048] The above-mentioned power data communication network security situation prediction method, which obtains topological connection relationships, event triggering frequencies, and real-time network traffic from spatial positioning feature sets, event chain sequences, and lifecycle quantitative indicators to generate global security situation view data, adopts multidimensional data integration technology, and uses weighted mapping based on geographical environment constraints and weight redistribution; includes:
[0049] The topological connection relationship, event triggering frequency and real-time network traffic are obtained from spatial positioning features, event chain sequences and life cycle indicators, and multi-dimensional data fusion technology is used to process them to obtain the initial fused data set;
[0050] If the topological connection relationship in the initial fused dataset does not match the preset geographical environment constraints, the connection strength is adjusted by redistributing the weights to obtain an optimized topological structure;
[0051] Based on the optimized topology structure and event triggering frequency, the weighted mapping technology is used to calculate the security status value of each node and generate the node status distribution;
[0052] Extract abnormal fluctuation characteristics of real-time network traffic from node status distribution, use random forest algorithm to determine whether there is potential security threat, and obtain threat classification results;
[0053] If the threat classification results indicate the existence of a high-risk threat, the trigger source is traced back according to the event chain sequence to generate the threat propagation path;
[0054] Based on the threat propagation path and the global security situation, visualization technology is used to generate dynamic view data to obtain a global security situation view;
[0055] Key nodes and traffic change trends are extracted from the global security situation view, and time series analysis is used to predict future situation evolution to obtain predicted situation data.
[0056] The above-mentioned power data communication network security situation prediction method, wherein the hotspot impact range and abnormal traffic fluctuation are extracted from the global security situation view data to obtain the incremental change feature set, uses the incremental change monitoring technology. If the hotspot impact range or abnormal traffic fluctuation exceeds a preset threshold, the node load state is adjusted and redistributed according to the weight; includes:
[0057] The hotspot impact range and abnormal traffic fluctuations are obtained from the global security situation data. The incremental change monitoring technology is used to calculate the change rate R_h of the hotspot impact range and the change rate R_f of the abnormal traffic fluctuation. R_h represents the incremental change ratio of the hotspot impact range, and R_f represents the incremental change ratio of the abnormal traffic fluctuation. The change rate set of the hotspot impact range and abnormal traffic fluctuation is obtained.
[0058] If the rate of change R_h or R_f exceeds the preset threshold T_h or T_f, the node load status data is extracted from the global security situation data, and the load value L_i of each node is calculated, where L_i represents the current load of the i-th node, and the node load status set is obtained;
[0059] According to the node load status set, the K-means clustering algorithm is used to divide the nodes into a high-load node group H and a low-load node group L, where H contains nodes with load values Li higher than the average load, and L contains nodes with load values Li lower than the average load, thus obtaining the node load grouping result;
[0060] Based on the node load grouping results, for the high-load node group H, reduce its weight W_i, where W_i represents the assigned weight of the i-th node, and is calculated using the formula W_i = W_i(1-αL_i / L_max), where α is the weight adjustment coefficient and L_max is the maximum load value, to obtain the adjusted weight set;
[0061] According to the adjusted weight set, traffic is redistributed to the low-load node group L. The weighted polling algorithm is used to distribute traffic to nodes according to the weight W_i to obtain the traffic redistribution result;
[0062] Extract the incremental change features from the traffic redistribution results, calculate the traffic change rate C_i of each node, where C_i represents the traffic increment ratio of the i-th node, and obtain the incremental change feature set;
[0063] The global security situation data is updated through the incremental change feature set, and the time series analysis algorithm is used to detect the long-term trend of the incremental change features, to determine whether the incremental change features are stable, and to obtain a stable incremental change feature set.
[0064] The above-mentioned method for predicting the network security situation of power data communication network, wherein the method acquires real-time network traffic and event logs for incremental change feature sets, generates real-time hotspot situation descriptions, adopts dynamic weight adjustment technology, redistributes weights of event correlation strength and business priority data, and combines data smoothing to update global security situation view data; includes:
[0065] Obtain real-time network traffic and event logs from network devices and security devices, use time series analysis technology to extract incremental change features, and obtain feature data sets;
[0066] For feature data sets, dynamic weight adjustment technology is used. If the event correlation strength is higher than the preset threshold, the weight is redistributed according to the business priority to obtain a weighted feature set;
[0067] The weighted feature set is denoised by data smoothing technology, and a moving average algorithm is used to obtain a smooth feature set.
[0068] Based on the smoothed feature set, the global security situation view is updated, and the features are grouped using a clustering algorithm to obtain situation grouping data;
[0069] Extract high-priority events from the situation grouping data. If the event correlation strength matches the business priority, generate a real-time hotspot situation description and obtain hotspot description data.
[0070] Based on the hotspot description data, visualization technology is used to generate a security situation view and obtain real-time situation view data;
[0071] Through real-time situation view data, the network traffic analysis model is updated and the anomaly detection algorithm is used to obtain the abnormal behavior data set.
[0072] The above-mentioned power data communication network security situation prediction method extracts event trigger frequency, abnormal flow fluctuation and node load status from the real-time hotspot situation description to obtain the predicted evolution path. Time series prediction technology is used to determine the trend direction of the hotspot life cycle stage through historical pattern analysis and time window span calculation, combined with data smoothing and prediction error range assessment. The method includes:
[0073] Obtain real-time hotspot situation data, extract event trigger frequency, abnormal traffic fluctuations, and node load status, and store them as time series data sets;
[0074] The sliding window method is used to calculate the time window span, extract historical patterns from the time series data set, and generate a feature data set;
[0075] Perform data smoothing on the feature data set using an exponential smoothing algorithm to obtain a smoothed feature data set;
[0076] If the event trigger frequency of the smoothed feature data set exceeds the preset threshold, the ARIMA model is used to predict the time series and obtain the preliminary trend direction;
[0077] If the threshold is not exceeded, the trend direction is generated based on historical pattern analysis;
[0078] For the preliminary trend direction, calculate the forecast error range, evaluate the forecast accuracy by the mean square error, and obtain the optimized trend direction;
[0079] Based on the optimization trend direction and the hotspot lifecycle stage classification rules, the current hotspot lifecycle stage is determined and a stage label is generated;
[0080] Through stage labels and optimization trend directions, the Markov chain model is used to predict the future evolution path and obtain the predicted evolution path.
[0081] The above-mentioned power data communication network security situation prediction method, which acquires historical situation data and generates dynamic security situation analysis results based on the predicted evolution path, adopts cross-dimensional data fusion technology to extract association rules based on geographical environment constraints, node load status, and topological connection relationships, and combines weight redistribution and trend direction judgment to update the hotspot multi-dimensional orientation description vector; includes:
[0082] Obtain historical situation data, extract time series features, spatial distribution features, and network topology features from multi-source data, and obtain a standardized feature set through data cleaning and formatting;
[0083] Adopting cross-dimensional fusion technology, the principal component analysis algorithm is used to reduce the dimension of the standardized feature set, and the fused feature vector is obtained by combining the geographical environment constraints and node load status;
[0084] By using the association rule extraction method, the association patterns of geographical environment constraints, node load status and topological connection relationships are extracted from the fused feature vector to obtain a feature association rule set.
[0085] If the rule strength in the feature association rule set is greater than the preset threshold, the weight redistribution method is used to adjust the weights of the features in the association rule set through the entropy method to obtain a weighted feature vector;
[0086] According to the weighted eigenvector, the time series analysis method is used to determine the trend direction and obtain the trend of situation change;
[0087] By analyzing the trend of situation changes, we update the multi-dimensional position description vector and use clustering algorithm to group the vectors to obtain the dynamic security situation distribution.
[0088] Extract key situation indicators from dynamic security situation distribution and generate analysis results through visualization technology.
[0089] Compared with the existing technology, the present invention has the following advantages: The present invention provides a method for analyzing the hotspot situation of an electric power data communication network. By obtaining data such as physical node coordinates and real-time network traffic, geographic information mapping technology is used to determine the spatial positioning characteristics of the hotspot, and a multi-dimensional orientation description vector of the hotspot is generated in combination with the event correlation strength. A time series event chain is further constructed to determine the hotspot life cycle stage and generate global security situation view data. The present invention also updates the hotspot situation description in real time through incremental change monitoring and dynamic weight adjustment, and uses time series prediction technology to predict the hotspot evolution path. Finally, historical situation data is integrated to generate dynamic security situation analysis results. This method can comprehensively and dynamically analyze the hotspot situation in the electric power data communication network, providing strong support for network security management and decision-making.
[0090] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION
[0092] like Figure 1 As shown, the power data communication network security situation prediction method of the present invention may specifically include:
[0093] Step S101, obtain physical node coordinates, real-time network traffic, business priority data and topological connection relationships from the physical nodes and business flows of the power data communication network, use geographic information mapping technology, and determine the azimuth coordinates of the hotspot at the physical layer and business layer through coordinate conversion of longitude and latitude position data and the topological connection matrix to obtain a spatial positioning feature set.
[0094] Obtain the longitude and latitude coordinates of physical nodes, real-time network traffic, service priorities, and topological connection matrix. Through data preprocessing, clean outliers and missing values to obtain a standardized data set. The following calculation formula is used:
[0095]
[0096] C(x, y) represents the coordinates of the hotspot center, w_i represents the weight of the i-th node, (x_i, y_i) represents the coordinates of the i-th node, and m represents the number of nodes participating in the calculation.
[0097]
[0098] H_k represents the weight value of the kth hotspot, A_ij represents the topological connection matrix element, P_ij represents the connection probability between nodes, and n represents the total number of nodes.
[0099]
[0100] W_ij represents the connection weight between nodes, d_ij represents the actual distance between nodes, and σ represents the bandwidth parameter of the Gaussian kernel function.
[0101]
[0102] D_ij represents the distance between two points, x_i and y_i represent the longitude and latitude coordinates of the i-th node, and x_j and y_j represent the longitude and latitude coordinates of the j-th node. Using geographic information mapping technology, the longitude and latitude coordinates are converted into coordinates of the topological connection matrix to calculate the distance between nodes and the connection weight, and determine the physical layer hotspot coordinates. If the node traffic at the physical layer hotspot coordinates exceeds the preset threshold, weighted traffic analysis is used in conjunction with service priorities to determine the business layer hotspot distribution and obtain the business hotspot coordinates. Based on the physical layer hotspot and business layer hotspot coordinates, a spatial positioning feature set is constructed. The hotspot areas are classified using the K-means clustering algorithm to obtain the hotspot area division results. Based on the hotspot area division results, the node connection relationships and traffic distribution characteristics are analyzed. The shortest path algorithm is used to optimize the topological connection matrix to obtain the optimized network topology. If there are high-load nodes in the optimized network topology, the load balancing algorithm is used to adjust the traffic distribution to obtain balanced traffic distribution data. According to the balanced traffic distribution data, the spatial positioning feature set is updated, and the geographic information map of hotspot distribution and topological structure is generated through visualization technology to obtain the final positioning feature set.
[0103] Exemplarily, physical node coordinates, real-time network traffic, service priority data and topological connection relationships are obtained from the power data communication network. First, the latitude and longitude position data of the physical nodes are converted into coordinates of the topological connection matrix through geographic information mapping technology.
[0104] For example, assume there are three physical nodes in a power data communication network, with longitudes and latitudes of Node A (30.6586°N, 104.0648°E), Node B (31.2304°N, 121.4737°E), and Node C (39.9042°N, 116.4074°E). Using a coordinate conversion algorithm, these longitudes and latitudes are mapped into two-dimensional coordinates, forming a topological connection matrix. Next, real-time network traffic data is acquired through a traffic monitoring system. Assume that the traffic from Node A to Node B is 500 Mbps, the traffic from Node B to Node C is 300 Mbps, and the traffic from Node A to Node C is 200 Mbps. Service priority data is then categorized based on service type: for example, the service from Node A to Node B has high priority, the service from Node B to Node C has medium priority, and the service from Node A to Node C has low priority. By analyzing this data, a hotspot location algorithm, such as the density-based spatial clustering algorithm (DBSCAN), is used to determine the location coordinates of the hotspot at both the physical and service layers.
[0105] For example, using the DBSCAN algorithm, with a neighborhood radius of 100 kilometers and a minimum sample size of 2, we can identify nodes B and C as hotspots. Their business-layer hotspot coordinates are (31.2304°N, 121.4737°E) and (39.9042°N, 116.4074°E). Ultimately, this data is integrated into a spatial positioning feature set, providing a basis for subsequent network optimization and troubleshooting.
[0106] Step S102 extracts physical node coordinates, real-time network traffic, service priority data, and node load status from the spatial positioning feature set, uses weighted vector calculation, redistributes the weights of event correlation strength and service priority data, integrates node load status, and generates a hotspot multi-dimensional orientation description vector.
[0107] Node coordinates, traffic data, priority data, and load status are obtained from the spatial positioning feature set. The initial feature set is generated through a feature extraction algorithm to obtain the node feature matrix. A weighted calculation method is used to calculate the initial weight vector based on the traffic data and priority data in the node feature matrix, combined with the event association strength, to obtain the weighted feature vector. The formula used is as follows:
[0108]
[0109] E_ij represents the association strength between nodes i and j, γ represents the association coefficient, p represents the number of features, T_i represents the feature vector of node i, and C_j represents the feature vector of node j.
[0110]
[0111] S_k represents the weighted score of the kth feature, β represents the weight adjustment factor, m represents the feature dimension, V_i represents the i-th feature value, and Q_i represents the weight coefficient of the i-th feature.
[0112]
[0113] W_i represents the weighted feature vector of the i-th node, α represents the normalization coefficient, n represents the total number of nodes, F_j represents the traffic data of the j-th node, P_j represents the priority data of the j-th node, and R_ij represents the strength of the association between nodes i and j. Through the weight adjustment algorithm, if the event association strength exceeds the preset threshold, the weight is redistributed based on the priority data to obtain the adjusted weighted feature vector.
[0114]
[0115] F_i represents the adjusted eigenvector, β represents the global adjustment factor, Wij represents the weight matrix element, Pj represents the corresponding priority score, and m represents the number of related events.
[0116]
[0117] P_i represents the priority score, v_k represents the weight value of the k-th feature, p_k represents the priority value of the k-th feature, and n represents the total number of features.
[0118]
[0119] W_ij represents the association weight between events, r_ij represents the event association strength, μ represents the preset threshold, σ represents the standard deviation parameter, and α represents the weight adjustment coefficient. The adjusted weighted feature vector is obtained, fused with the load status data, and a multidimensional hotspot location description vector is generated using a data fusion algorithm to obtain the hotspot description vector. Based on the hotspot description vector, the nodes are grouped using a clustering algorithm to determine the hotspot area to which the nodes belong, resulting in the hotspot area division results. For the hotspot area division results, if the node load status exceeds the preset threshold, the event association strength is adjusted through traffic data analysis to obtain an optimized event association strength. Using the optimized event association strength, the weighted feature vector is recalculated and fused with the load status to generate the final multidimensional hotspot location description vector, resulting in the final hotspot description vector.
[0120] Exemplarily, when extracting the physical node coordinates from the spatial positioning feature set, the latitude and longitude information of the node can be obtained through the GPS module, for example, the coordinates of node A are (39.9042, 116.4074). Real-time network traffic data can be collected through a network monitoring tool, assuming that the current traffic of node A is 120Mbps. Service priority data can be divided according to the service type, for example, the priority of video streaming service is 3 and that of voice service is 5. The node load status can be measured by CPU utilization, assuming that the CPU utilization of node A is 75%. When using weighted vector calculation, first define the weight vector W = (0.4, 0.3, 0.2, 0.1), corresponding to the physical node coordinates, real-time network traffic, service priority and node load status respectively. Through event correlation strength analysis, assuming that the correlation strength between node A and node B is 0.8, the redistributed weight vector is W' = (0.32, 0.24, 0.16, 0.08). When integrating the node load status, the CPU usage is normalized to 0.75 and multiplied by the weight vector to obtain the adjusted vector W'' = (0.24, 0.18, 0.12, 0.06). The final generated hotspot multi-dimensional orientation description vector is V = (39.9042, 116.4074, 120, 3, 0.75), and the comprehensive score is obtained through weighted calculation.
[0121] S = 39.9042 × 0.24 + 116.4074 × 0.18 + 120 × 0.12 + 3 × 0.16 + 0.75 × 0.06 = 9.577 + 20.953 + 14.4 + 0.48 + 0.045 = 45.455. This vector and score can be used for subsequent hotspot identification and resource scheduling decisions.
[0122] Step S103, for the hotspot multi-dimensional orientation description vector, obtain the network security event log, adopt the time series event chain construction technology, determine the hotspot related event triggering frequency and service interruption duration by matching the event triggering frequency and event correlation strength, and obtain the event chain sequence.
[0123] Obtain network security event logs and employ preprocessing techniques to obtain a standardized event dataset through log parsing and data cleansing. Extract time-series event features from the standardized event dataset and employ time-series analysis techniques to construct an initial event chain sequence. For the initial event chain sequence, construct a multi-dimensional hotspot orientation description vector and employ vector matching techniques to determine the hotspot-related event triggering frequency. If the event triggering frequency exceeds a preset threshold, calculate the correlation strength using a weighted graph model to obtain the event correlation strength value. Based on the event correlation strength value, obtain service interruption duration data and dynamically adjust the time-series event chain to generate an optimized event chain sequence. Extract key event nodes from the optimized event chain sequence and employ anomaly detection algorithms to identify potential network security threats. Based on the potential threat identification results, update the event log feature library to generate real-time network security event monitoring data.
[0124] For example, in network security event analysis, hotspots are first modeled using multidimensional azimuth description vectors. For example, a principal component analysis (PCA) algorithm is used to reduce the dimensionality of network traffic data and extract key feature vectors, such as source IP, destination IP, and port number, to form a hotspot description vector. Next, relevant data is obtained from network security event logs, and time series analysis methods are used to calculate the frequency of event triggering. For example, the frequency of abnormal login behavior detected from a certain IP address is 5 times per minute within a certain time period, which is significantly higher than the normal threshold. Then, an event correlation strength algorithm, such as a correlation analysis based on cosine similarity, is used to calculate the correlation strength between different events. For example, the correlation strength between abnormal login behavior and DDoS attack events is found to be 0.85, indicating that the two may be related. Furthermore, based on the event triggering frequency and service interruption duration, a time series event chain construction technique is used to arrange related events in chronological order to form an event chain sequence. For example, in a certain event chain, after the abnormal login behavior is triggered, a DDoS attack occurs, resulting in a service interruption of 30 minutes. Finally, by analyzing the event chain sequence, the triggering frequency of hotspot-related events and the duration of business interruption are determined, providing data support for early warning and response to network security incidents.
[0125] In step S104, the event triggering frequency, service interruption duration, and hotspot impact range are extracted from the event chain sequence, and a time window sliding calculation is used to determine the hotspot life cycle stage by quantifying the node load status and abnormal traffic fluctuations to obtain a life cycle quantitative indicator.
[0126] The event triggering frequency, service interruption duration, and hotspot impact range are extracted from the event chain sequence through a sliding time window to calculate the time series features. The K-means algorithm is used to cluster the time series features and determine the initial stage of the hotspot event. If the hotspot event triggering frequency exceeds the preset threshold, the abnormal traffic fluctuation is calculated based on the node load status to obtain the fluctuation quantification value. Based on the fluctuation quantification value and the service interruption duration, the decision tree algorithm is used to determine the hotspot life cycle stage and obtain the stage classification result. Based on the hotspot impact range and stage classification results, the life cycle quantification index is calculated to determine the impact weight of the hotspot event. If the impact weight exceeds the preset threshold, the data flow analysis results are used for time series prediction to obtain the life cycle trend characteristics. Based on the life cycle trend characteristics, the parameters of the sliding time window are updated to obtain new time series characteristics.
[0127] For example, when extracting the event triggering frequency from the event chain sequence, a sliding time window with a fixed interval of 5 minutes can be used. By counting the number of events in the window and dividing it by the window length, the event triggering frequency value per minute is obtained. For example, if 15 events occur in a window, the frequency is 3 times / minute. The service interruption duration calculation needs to be combined with the event start and end timestamps, and the event overlap detection algorithm is used to eliminate duplicate statistics. For example, three overlapping events last for 10, 15, and 20 minutes respectively. After merging, the actual interruption duration is 20 minutes. The hotspot impact range is divided by geographical grids, and the number of affected nodes is counted in units of 500 meters × 500 meters. The weighted impact value is calculated in combination with the node weight (such as the base station traffic ratio). For example, a hotspot covers 6 grids with a total of 120 nodes, and the weighted impact value is 85. The time window sliding calculation uses an exponentially weighted moving average algorithm, and the weight coefficient is set to 0.3. For the frequency sequence of 10 consecutive windows,
[0128] The trend curve is smoothed using the values [2.1, 3.4, 2.8, 4.1, 5.0, 4.7, 3.9, 3.2, 2.5, 1.8]. Node load status is quantified using metrics such as CPU utilization and memory usage. An 80% threshold is set as the critical overload point. Load anomalies are identified when the threshold is exceeded for three consecutive sampling periods. Traffic fluctuations are detected using the 3σ principle. With a baseline mean of 100 Mbps and a standard deviation of 15 Mbps, an anomaly is identified when the rate exceeds 145 Mbps. Hotspot lifecycle stages are categorized using K-means clustering, selecting frequency, duration, and range. The cluster center of [4.2 times / minute, 18 minutes, 72] corresponds to the mature stage. The final lifecycle quantification metrics are constructed using the Analytic Hierarchy Process (AHP) to construct an evaluation matrix. Eigenvectors are calculated to yield dimensional indicators such as a stability coefficient of 0.68 and a diffusion coefficient of 0.42.
[0129] Step S105, obtain the topological connection relationship, event triggering frequency and real-time network traffic from the spatial positioning feature set, event chain sequence and life cycle quantitative indicators, adopt multi-dimensional data integration technology, and generate global security situation view data through weighted mapping of geographical environment constraints and weight redistribution.
[0130] Topological connectivity, event triggering frequency, and real-time network traffic are extracted from spatial positioning features, event chain sequences, and lifecycle indicators. Multidimensional data fusion techniques are used to process these data to generate an initial fused dataset. If the topological connectivity in the initial fused dataset does not match the pre-set geographic constraints, the connection strength is adjusted by redistributing weights to obtain an optimized topological structure. Based on the optimized topological structure and event triggering frequency, a weighted mapping technique is used to calculate the security status value of each node, generating a node status distribution. Abnormal fluctuations in real-time network traffic are extracted from the node status distribution, and a random forest algorithm is used to determine whether potential security threats exist, generating a threat classification result. If the threat classification result indicates a high-risk threat, the triggering source is traced based on the event chain sequence to generate a threat propagation path. Based on the threat propagation path and the global security status, dynamic visualization data is generated using visualization techniques to obtain a global security status view. Key nodes and traffic trends are extracted from the global security status view, and time series analysis is used to predict future security evolution, generating predicted status data.
[0131] For example, when extracting topological connectivity from a set of spatial location features, a graph-theory-based minimum spanning tree algorithm, such as the Prim algorithm, can be used to generate a network topology by calculating the Euclidean distance between nodes, with a threshold of 100 meters. Within the event chain sequence, time series analysis methods, such as sliding window technology, are used with a 10-minute window size to calculate event triggering frequency. For example, if an area triggers 15 alarm events within an hour, it indicates a high security risk. Lifecycle quantitative indicators are calculated by calculating the device's online time and peak traffic volume. For example, if a device is online for 8 hours and has a peak traffic volume of 500 Mbps, a weighted mapping method is used to reassign the security score of each node, taking into account geographical constraints such as building height and terrain slope. Weight coefficients are set to 0.3 and 0.7, respectively, to reassign the security score of each node. Finally, multidimensional data integration techniques are used to fuse topological connectivity, event triggering frequency, and real-time network traffic data to generate a global security situation view. For example, a comprehensive security score of 85 for an area indicates a medium security level, requiring further monitoring and early warning.
[0132] Step S106: Extract the hotspot impact range and abnormal traffic fluctuations from the global security situation view data, and use incremental change monitoring technology. If the hotspot impact range or abnormal traffic fluctuation exceeds the preset threshold, the weight is redistributed by adjusting the node load status to obtain an incremental change feature set.
[0133] The hotspot impact range and abnormal traffic fluctuations are obtained from global security situation data. Incremental change monitoring technology is used to calculate the rate of change R_h of the hotspot impact range and the rate of change R_f of the abnormal traffic fluctuations, where R_h represents the incremental change ratio of the hotspot impact range and R_f represents the incremental change ratio of the abnormal traffic fluctuations. This yields a set of rates of change for the hotspot impact range and abnormal traffic fluctuations. If the rate of change R_h or R_f exceeds the preset threshold T_h or T_f, node load status data is extracted from the global security situation data, and the load value L_i of each node is calculated, where L_i represents the current load of the i-th node. This yields a node load status set. Based on the node load status set, the K-means clustering algorithm is used to group the nodes into a high-load node group H and a low-load node group L. H contains nodes with load values L_i above the average load, and L contains nodes with load values L_i below the average load, resulting in the node load grouping results. Based on the node load grouping results, the weight W_i of the high-load node group H is reduced, where W_i represents the allocation weight of the i-th node. This is calculated using the formula W_i = W_i(1-αL_i / L_max), where α is the weight adjustment coefficient and L_max is the maximum load value. This yields the adjusted weight set. Based on the adjusted weight set, traffic is redistributed to the low-load node group L. A weighted round-robin algorithm is used to distribute traffic to nodes according to the weight W_i, yielding the traffic redistribution results. Incremental change features are extracted from the traffic redistribution results, and the traffic change rate C_i of each node is calculated, where C_i represents the traffic increment ratio of the i-th node. This yields the incremental change feature set. Using the incremental change feature set, global security situation data is updated, and a time series analysis algorithm is used to detect the long-term trend of the incremental change features and determine whether the incremental change features are stable, yielding a stable incremental change feature set.
[0134] For example, when extracting the hotspot impact range and abnormal traffic fluctuations from the global security situation view data, the network traffic data is first acquired in real time through the data acquisition module, for example, 1,000 data packets are collected per second, and the data is pre-processed using a sliding window algorithm with a window size of 10 seconds and a step size of 1 second. Then, the density-based spatial clustering algorithm (DBSCAN) is used to identify the hotspot area, setting the neighborhood radius ε to 50 meters and the minimum number of samples MinPts to 5, thereby extracting the hotspot impact range. For abnormal traffic fluctuations, the Z-score standardization method is used to process the traffic data, and the Z-score value at each time point is calculated. If the absolute value of the Z-score exceeds 3, it is determined to be an abnormal fluctuation. When the hotspot impact range exceeds a preset threshold (for example, 500 meters) or the abnormal traffic fluctuation exceeds a preset threshold (for example, the Z-score is 5), the system automatically triggers the node load state adjustment mechanism. Node weights are redistributed through a weighted round-robin algorithm, for example, reducing the weight of high-load nodes from 0.8 to 0.5 while increasing the weight of low-load nodes from 0.2 to 0.5 to achieve balanced traffic distribution. Ultimately, the system generates incremental change feature sets, including the change in the hotspot's impact range (for example, from 300 meters to 600 meters) and the change in abnormal traffic fluctuations (for example, the Z-score increases from 3 to 6), and stores these feature sets in a database for subsequent analysis.
[0135] Step S107, for the incremental change feature set, obtain real-time network traffic and event logs, adopt dynamic weight adjustment technology, redistribute the weights of event correlation strength and business priority data, combine data smoothing processing, update the global security situation view data, and generate a real-time hotspot situation description.
[0136] Real-time network traffic and event logs are acquired from network and security devices. Time series analysis techniques are used to extract incremental change features to generate a feature dataset. Dynamic weight adjustment techniques are used for the feature dataset. If the event correlation strength exceeds a preset threshold, weights are reallocated based on business priorities to generate a weighted feature set. Data smoothing techniques are used to denoise the weighted feature set, and a moving average algorithm is used to generate a smoothed feature set. Based on the smoothed feature set, a global security situation view is updated, and clustering algorithms are used to group features to generate situation group data. High-priority events are extracted from the situation group data. If the event correlation strength matches the business priority, a real-time hotspot situation description is generated to generate hotspot description data. Visualization techniques are used to generate a security situation view for the hotspot description data, generating real-time situation view data. The network traffic analysis model is updated using the real-time situation view data, and an anomaly detection algorithm is used to generate an abnormal behavior dataset.
[0137] For example, when acquiring real-time network traffic and event logs, the system captures traffic at a rate of 1,000 packets per second using traffic collectors deployed at network boundaries and key nodes. This system also uses log collection tools to extract event logs from devices such as firewalls and intrusion detection systems to form an initial dataset. For the incremental change feature set, a sliding window technique is used, with a 5-minute window, to dynamically extract incremental features from traffic and logs, such as newly added IP addresses and abnormal port access frequencies. In the dynamic weight adjustment technique, the system quantifies the correlation between events using a cosine similarity algorithm based on an event correlation strength calculation model. For example, when the similarity between two events reaches 0.85, the correlation strength is considered high. Furthermore, based on business priority data, the weight of critical business events (such as core database access) is set to 0.9, and the weight of non-critical events (such as ordinary user logins) is set to 0.3. The weights are then redistributed using a weighted average method. During the data smoothing phase, an exponential smoothing algorithm is used, with a smoothing coefficient α set to 0.7, to smooth the weighted data, eliminating the impact of short-term fluctuations on the overall security situation. Finally, based on the updated global security situation view data, the system uses clustering analysis algorithms (such as K-means clustering) to group similar events and generate real-time hotspot situation descriptions. For example, it can identify DDoS attacks against a specific server within a certain time period and mark it as a high-risk hotspot. Through this process, the system can accurately reflect changes in the network security situation in real time, providing support for security decision-making.
[0138] Step S108, extract the event trigger frequency, abnormal traffic fluctuations and node load status from the real-time hotspot situation description, use time series prediction technology, through historical pattern analysis and time window span calculation, combined with data smoothing processing and prediction error range evaluation, to determine the trend direction of the hotspot life cycle stage and obtain the predicted evolution path.
[0139] Real-time hotspot situation data is acquired, and event triggering frequency, abnormal traffic fluctuations, and node load status are extracted and stored as a time series dataset. A sliding window method is used to calculate the time window span, and historical patterns are extracted from the time series dataset to generate a feature dataset. The feature dataset is smoothed using an exponential smoothing algorithm to obtain a smoothed feature dataset. If the event triggering frequency of the smoothed feature dataset exceeds a preset threshold, an ARIMA model is used for time series forecasting to obtain a preliminary trend direction. If it does not exceed the threshold, a trend direction is generated based on historical pattern analysis. For the preliminary trend direction, the prediction error range is calculated, and the prediction accuracy is evaluated using the mean squared error to obtain the optimized trend direction. Based on the optimized trend direction and in combination with the hotspot life cycle stage classification rules, the current hotspot life cycle stage is determined and a stage label is generated. Using the stage label and the optimized trend direction, a Markov chain model is used to predict the future evolution path, resulting in a predicted evolution path.
[0140] For example, when extracting event trigger frequencies from real-time hotspot situation descriptions, a sliding window statistical method can be used. For example, a 5-minute time window is used to count the number of event triggers within the window. If the number of event triggers within a window exceeds a threshold of 50, it is marked as a high-frequency event. An exponential smoothing algorithm (smoothing coefficient α = 0.3) is also used to smooth the raw data to eliminate random fluctuations. For traffic anomaly fluctuation detection, a Z-score algorithm is used to calculate the deviation of current traffic from the historical mean (e.g., the average of 1000 QPS over the past hour). An anomaly is identified when the absolute value of the Z-score exceeds 3. The ARIMA model (with parameters p = 2, d = 1, and q = 1) is then used to predict traffic trends for the next three time points. Node load status analysis collects metrics such as CPU utilization (e.g., node A's current load is 85%) and memory usage. A K-means clustering algorithm (k = 3) is used to classify nodes into three categories: high, medium, and low load. A load state transition matrix is then established (e.g., a high-load node has a 60% probability of maintaining its current state). During the time series forecasting phase, an LSTM neural network (64 hidden units) was used to train a model containing 7 days of historical data. Prediction accuracy was assessed using the mean squared error (MSE = 0.15). A trend change was identified when the predicted value exceeded the confidence interval [μ±2σ] for three consecutive periods. Finally, a weighted fusion (weighting event frequency 0.4, traffic fluctuation 0.3, and load status 0.3) was used to calculate the hotspot lifecycle score. A score above 0.7 for two consecutive hours was considered an upward trend, while a score below 0.3 was considered a downward trend, forming a complete evolutionary path forecast.
[0141] Step S109, for the predicted evolution path, obtain historical situation data, adopt cross-dimensional data fusion technology, extract association rules based on geographical environment constraints, node load status and topological connection relationships, combine weight redistribution and trend direction judgment, update the hotspot multi-dimensional orientation description vector, and generate dynamic security situation analysis results.
[0142] Historical situation data is obtained, and time series features, spatial distribution features, and network topology features are extracted from multiple sources. Data cleaning and formatting are performed to obtain a standardized feature set. Cross-dimensional fusion technology is used to reduce the dimensionality of the standardized feature set using principal component analysis. This fusion feature vector is then combined with geographic constraints and node load status to generate a fused feature vector. Association rule extraction is used to extract association patterns between geographic constraints, node load status, and topological connectivity from the fused feature vector to generate a feature association rule set. If the rule strength in the feature association rule set exceeds a preset threshold, a weight redistribution method is used to adjust the weights of the features in the association rule set using an entropy method to generate a weighted feature vector. Based on the weighted feature vector, time series analysis is used to determine the trend direction and determine the situation change trend. Based on the situation change trend, a multidimensional orientation description vector is updated. Clustering algorithms are used to group the vectors to generate a dynamic security situation distribution. Key situation indicators are extracted from the dynamic security situation distribution, and visualization techniques are used to generate analytical results.
[0143] For example, when predicting the evolution path, historical situation data is first collected through the time series database, such as the hourly network traffic data of a certain area in the past 30 days, with a numerical range of 1000-5000Mbps. The ARIMA model is used for trend fitting with parameters p=2, d=1, and q=1. In the cross-dimensional data fusion stage, the base station coordinates in the geographic information system (such as longitude 116.404, latitude 39.915) are spatially associated with the real-time load data (CPU utilization 70%-90%), and the fusion confidence is calculated using DS evidence theory. When the topological connection weight exceeds the threshold of 0.7, the association rule engine is triggered. The weight distribution adopts the entropy weight method to dynamically adjust the bandwidth occupancy rate (weight 0.4), delay (weight 0.3), and packet loss rate (weight 0.3). The trend judgment uses the LSTM network to analyze the change direction in the next 3 hours, and the hidden layer dimension is set to 64. Finally, the hotspot description vector is updated through the vector space model, for example, the security threat dimension value is adjusted from [0.2, 0.5, 0.3] to
[0144] [0.3, 0.4, 0.3], the output dynamic situation score is 82.5 points (out of 100). The entire process is realized in real time through the Spark distributed framework, and the window interval is set to 5 minutes.
[0145] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any way. Any simple modification, change and equivalent structural change made to the above embodiment based on the technical essence of the present invention shall still fall within the scope of protection of the technical solution of the present invention.
Claims
1. A method for predicting the security situation of power data communication network, characterized in that: The method comprises: Obtain physical node coordinates, real-time network traffic, service priority data, and topological connection relationships from the physical nodes and service flows of the power data communication network to obtain a spatial positioning feature set; Extract physical node coordinates, real-time network traffic, service priority data, and node load status from the spatial positioning feature set to generate a multi-dimensional hotspot location description vector. Based on the hotspot multi-dimensional orientation description vector, network security event logs are obtained, and the time series event chain construction technology is used to obtain the event chain sequence; The event trigger frequency, service interruption duration, and hotspot impact range are extracted from the event chain sequence, and a time window sliding calculation is used to obtain lifecycle quantitative indicators. Obtain topological connection relationships, event triggering frequencies, and real-time network traffic from spatial positioning feature sets, event chain sequences, and lifecycle quantitative indicators to generate global security situation view data; Extract the hotspot impact range and abnormal traffic fluctuations from the global security situation view data to obtain the incremental change feature set; Based on the incremental change feature set, real-time network traffic and event logs are obtained to generate real-time hotspot situation descriptions; Extract event trigger frequency, abnormal traffic fluctuations, and node load status from real-time hotspot situation descriptions, and use time series prediction technology to obtain the predicted evolution path; Based on the predicted evolution path, historical situation data is obtained to generate dynamic security situation analysis results.
2. A method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method of obtaining physical node coordinates, real-time network traffic, service priority data, and topological connection relationships from the physical nodes and service flows of the power data communication network to obtain a spatial positioning feature set adopts geographic information mapping technology to determine the location coordinates of hotspots at the physical layer and service layer by converting the longitude and latitude position data with the coordinates of the topological connection matrix; including: Obtain the longitude and latitude coordinates of physical nodes, real-time network traffic, service priorities, and topological connection matrices. Through data preprocessing, clean outliers and missing values to obtain a standardized data set. Using geographic information mapping technology, through the coordinate conversion of longitude and latitude coordinates and topological connection matrix, the distance between nodes and connection weight are calculated to determine the physical layer hotspot azimuth coordinates; If the node traffic of the physical layer hotspot coordinate exceeds the preset threshold, the business layer hotspot distribution is determined by weighted traffic analysis combined with business priority to obtain the business hotspot coordinates; Based on the coordinates of the physical layer hotspots and the business layer hotspots, a spatial positioning feature set is constructed. The hotspot areas are classified using the K-means clustering algorithm to obtain the hotspot area division results. Based on the hotspot area division results, the node connection relationship and traffic distribution characteristics are analyzed, and the shortest path algorithm is used to optimize the topology connection matrix to obtain the optimized network topology structure; If there are high-load nodes in the optimized network topology, the load balancing algorithm is used to adjust the traffic distribution to obtain balanced traffic distribution data; According to the balanced traffic distribution data, the spatial positioning feature set is updated, and the geographic information map of hotspot distribution and topological structure is generated through visualization technology to obtain the final positioning feature set.
3. A method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method extracts physical node coordinates, real-time network traffic, service priority data, and node load status from the spatial positioning feature set to generate a hotspot multi-dimensional orientation description vector, adopts weighted vector calculation, and integrates the node load status by redistributing the weights of event correlation strength and service priority data; including: Obtain node coordinates, flow data, priority data, and load status from the spatial positioning feature set, generate an initial feature set through a feature extraction algorithm, and obtain a node feature matrix; Using the weighted calculation method, the initial weighted vector is calculated based on the traffic data and priority data in the node feature matrix, combined with the event correlation strength, to obtain the weighted feature vector; Through the weight adjustment algorithm, if the event correlation strength is higher than the preset threshold, the weight is redistributed according to the priority data to obtain the adjusted weighted feature vector; Obtain the adjusted weighted feature vector, fuse the load status data, generate a multi-dimensional hotspot orientation description vector through the data fusion algorithm, and obtain the hotspot description vector; According to the hotspot description vector, the nodes are grouped by clustering algorithm, the hotspot area to which the node belongs is determined, and the hotspot area division result is obtained; Based on the hotspot area division results, if the node load status exceeds the preset threshold, the event correlation strength is adjusted through traffic data analysis to obtain the optimized event correlation strength; The optimized event association strength is adopted to recalculate the weighted feature vector and fuse the load status to generate the final multi-dimensional hotspot orientation description vector and obtain the final hotspot description vector.
4. A method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method of obtaining network security event logs and event chain sequences based on the hotspot multi-dimensional orientation description vector is used to determine the hotspot-related event triggering frequency and service interruption duration by matching the event triggering frequency and event correlation strength. The method includes: Obtain network security event logs, use preprocessing technology, and obtain standardized event data sets through log parsing and data cleaning; Extract temporal event features from the standardized event dataset and use temporal analysis techniques to construct the initial event chain sequence; For the initial event chain sequence, we construct a multi-dimensional description vector of the hotspot and use vector matching technology to determine the event triggering frequency related to the hotspot; If the event triggering frequency exceeds the preset threshold, the event correlation strength value is obtained by using the weighted graph model through correlation strength calculation; Based on the event correlation strength value, the service interruption duration data is obtained, and an optimized event chain sequence is generated through dynamic adjustment of the time series event chain. Extract key event nodes from the optimized event chain sequence and use anomaly detection algorithms to identify potential network security threats; Based on the judgment results of potential threats, the feature library of event logs is updated to generate real-time network security event monitoring data.
5. The method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method extracts the event trigger frequency, service interruption duration, and hotspot impact range from the event chain sequence to obtain the lifecycle quantitative indicators. The method uses a time window sliding calculation to determine the hotspot lifecycle stage by quantifying the node load status and abnormal traffic fluctuations. The method includes: Using a sliding time window, we extract event triggering frequency, service interruption duration, and hotspot impact range from the event chain sequence and calculate time series features. The K-means algorithm is used to cluster the time series features and determine the initial stage of hot events; If the hot event trigger frequency exceeds the preset threshold, the abnormal traffic fluctuation is calculated based on the node load status to obtain the fluctuation quantification value; Based on the fluctuation quantification value and service interruption duration, a decision tree algorithm is used to determine the hotspot life cycle stage and obtain the stage classification result; Based on the impact scope and stage classification results of hotspots, the quantitative indicators of the life cycle are calculated to determine the impact weight of hotspot events; If the impact weight exceeds the preset threshold, the data flow analysis results are predicted in time series to obtain the life cycle trend characteristics; According to the life cycle trend characteristics, the parameters of the sliding time window are updated to obtain new time series characteristics.
6. A method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method of obtaining topological connection relationships, event triggering frequencies, and real-time network traffic from spatial positioning feature sets, event chain sequences, and lifecycle quantitative indicators to generate global security situation view data adopts multi-dimensional data integration technology and weighted mapping through geographical environment constraints and weight redistribution; including: The topological connection relationship, event triggering frequency and real-time network traffic are obtained from spatial positioning features, event chain sequences and life cycle indicators, and multi-dimensional data fusion technology is used to process them to obtain the initial fused data set; If the topological connection relationship in the initial fused dataset does not match the preset geographical environment constraints, the connection strength is adjusted by redistributing the weights to obtain an optimized topological structure; Based on the optimized topology structure and event triggering frequency, the weighted mapping technology is used to calculate the security status value of each node and generate the node status distribution; Extract abnormal fluctuation characteristics of real-time network traffic from node status distribution, use random forest algorithm to determine whether there is potential security threat, and obtain threat classification results; If the threat classification results indicate the existence of a high-risk threat, the trigger source is traced back according to the event chain sequence to generate the threat propagation path; Based on the threat propagation path and the global security situation, visualization technology is used to generate dynamic view data to obtain a global security situation view; Key nodes and traffic change trends are extracted from the global security situation view, and time series analysis is used to predict future situation evolution to obtain predicted situation data.
7. The method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method extracts the hotspot impact range and abnormal traffic fluctuations from the global security situation view data to obtain an incremental change feature set, and adopts incremental change monitoring technology. If the hotspot impact range or abnormal traffic fluctuation exceeds a preset threshold, the node load status is adjusted and redistributed; including: The hotspot impact range and abnormal traffic fluctuations are obtained from the global security situation data. The incremental change monitoring technology is used to calculate the change rate R_h of the hotspot impact range and the change rate R_f of the abnormal traffic fluctuation. R_h represents the incremental change ratio of the hotspot impact range, and R_f represents the incremental change ratio of the abnormal traffic fluctuation. The change rate set of the hotspot impact range and abnormal traffic fluctuation is obtained. If the rate of change R_h or R_f exceeds the preset threshold T_h or T_f, the node load status data is extracted from the global security situation data, and the load value L_i of each node is calculated, where L_i represents the current load of the i-th node, and the node load status set is obtained; According to the node load status set, the K-means clustering algorithm is used to divide the nodes into a high-load node group H and a low-load node group L, where H contains nodes with load values Li higher than the average load, and L contains nodes with load values Li lower than the average load, thus obtaining the node load grouping result; Based on the node load grouping results, for the high-load node group H, reduce its weight W_i, where W_i represents the assigned weight of the i-th node, and is calculated using the formula W_i = W_i(1-αL_i / L_max), where α is the weight adjustment coefficient and L_max is the maximum load value, to obtain the adjusted weight set; According to the adjusted weight set, traffic is redistributed to the low-load node group L. The weighted polling algorithm is used to distribute traffic to nodes according to the weight W_i to obtain the traffic redistribution result; Extract the incremental change features from the traffic redistribution results, calculate the traffic change rate C_i of each node, where C_i represents the traffic increment ratio of the i-th node, and obtain the incremental change feature set; The global security situation data is updated through the incremental change feature set, and the time series analysis algorithm is used to detect the long-term trend of the incremental change features, to determine whether the incremental change features are stable, and to obtain a stable incremental change feature set.
8. The method for predicting the security situation of a power data communication network according to claim 1, characterized in that: The method uses dynamic weight adjustment technology to update the global security situation view data by redistributing the weights of event correlation strength and business priority data and combining data smoothing processing based on the incremental change feature set to obtain real-time network traffic and event logs and generate real-time hotspot situation descriptions; including: Obtain real-time network traffic and event logs from network devices and security devices, use time series analysis technology to extract incremental change features, and obtain feature data sets; For feature data sets, dynamic weight adjustment technology is used. If the event correlation strength is higher than the preset threshold, the weight is redistributed according to the business priority to obtain a weighted feature set; The weighted feature set is denoised by data smoothing technology, and a moving average algorithm is used to obtain a smooth feature set. Based on the smoothed feature set, the global security situation view is updated, and the features are grouped using a clustering algorithm to obtain situation grouping data; Extract high-priority events from the situation grouping data. If the event correlation strength matches the business priority, generate a real-time hotspot situation description and obtain hotspot description data. Based on the hotspot description data, visualization technology is used to generate a security situation view and obtain real-time situation view data; Through real-time situation view data, the network traffic analysis model is updated and the anomaly detection algorithm is used to obtain the abnormal behavior data set.
9. The method for predicting the security situation of a power data communication network according to claim 1, characterized in that: When extracting event trigger frequency, abnormal traffic fluctuations, and node load status from the real-time hotspot situation description to obtain the predicted evolution path, time series prediction technology is used to determine the trend direction of the hotspot life cycle stage through historical pattern analysis and time window span calculation, combined with data smoothing and prediction error range assessment; including: Obtain real-time hotspot situation data, extract event trigger frequency, abnormal traffic fluctuations, and node load status, and store them as time series data sets; The sliding window method is used to calculate the time window span, extract historical patterns from the time series data set, and generate a feature data set; Perform data smoothing on the feature data set using an exponential smoothing algorithm to obtain a smoothed feature data set; If the event trigger frequency of the smoothed feature data set exceeds the preset threshold, the ARIMA model is used to predict the time series and obtain the preliminary trend direction; If the threshold is not exceeded, the trend direction is generated based on historical pattern analysis; For the preliminary trend direction, calculate the forecast error range, evaluate the forecast accuracy by the mean square error, and obtain the optimized trend direction; Based on the optimization trend direction and the hotspot lifecycle stage classification rules, the current hotspot lifecycle stage is determined and a stage label is generated; Through stage labels and optimization trend directions, the Markov chain model is used to predict the future evolution path and obtain the predicted evolution path.
10. The method for predicting the security situation of a power data communication network according to claim 1, characterized in that: When predicting the evolution path, acquiring historical situation data, and generating dynamic security situation analysis results, cross-dimensional data fusion technology is used to extract association rules based on geographical environment constraints, node load status, and topological connection relationships, combined with weight redistribution and trend direction judgment, to update the hotspot multi-dimensional orientation description vector; including: Obtain historical situation data, extract time series features, spatial distribution features, and network topology features from multi-source data, and obtain a standardized feature set through data cleaning and formatting; Adopting cross-dimensional fusion technology, the principal component analysis algorithm is used to reduce the dimension of the standardized feature set, and the fused feature vector is obtained by combining the geographical environment constraints and node load status; By using the association rule extraction method, the association patterns of geographical environment constraints, node load status and topological connection relationships are extracted from the fused feature vector to obtain a feature association rule set. If the rule strength in the feature association rule set is greater than the preset threshold, the weight redistribution method is used to adjust the weights of the features in the association rule set through the entropy method to obtain a weighted feature vector; According to the weighted eigenvector, the time series analysis method is used to determine the trend direction and obtain the trend of situation change; By analyzing the trend of situation changes, we update the multi-dimensional position description vector and use clustering algorithm to group the vectors to obtain the dynamic security situation distribution. Extract key situation indicators from dynamic security situation distribution and generate analysis results through visualization technology.
Citation Information
Cited By
High-position remote landslide disaster early warning method and system based on multi-source data fusion
CN121438503A
High-position remote landslide disaster early warning method and system based on multi-source data fusion
CN121438503B
Self-adaptive dynamic power consumption adjusting method and system for Internet of Things equipment
CN122172592A