Communication link diagnosis system based on dynamic trigger model

Through the communication link diagnosis system based on the dynamic trigger model, multi-source verification data packets are used for cross-validation and link evaluation, which solves the problems of insufficient dynamic adaptability and anomaly detection accuracy in the existing technology and realizes efficient and reliable communication link diagnosis.

CN120658564APending Publication Date: 2025-09-16STATE GRID INFO TELECOM GREAT POWER SCI & TECH +2

Patent Information

Application Number
CN202510976415.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing communication link diagnosis technology is insufficient in dynamic adaptability, multi-source verification capability, and link anomaly detection accuracy, resulting in low diagnostic efficiency and high false alarm rate. It is unable to flexibly respond to complex communication environments and diverse abnormal scenarios, and lacks the ability to monitor and diagnose dynamic changes in communication links in real time.

Method used

A communication link diagnosis system based on a dynamic trigger model is adopted, including a dynamic model configuration module, a data bug generation module and a detection and comparison module. By building a dynamic configuration model to generate detection tasks, cross-validating using multi-source verification data packets, and combining reliability algorithms and link evaluation models, real-time diagnosis and anomaly analysis of the link are achieved.

Benefits of technology

It improves the reliability and security of communication link diagnosis, reduces resource usage, improves response efficiency, can detect anomalies in a timely manner and conduct multi-dimensional link reliability tests, and avoids detection task data deviation caused by a single problem.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658564A_ABST
    Figure CN120658564A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication link diagnosis, in particular to a communication link diagnosis system based on a dynamic trigger model, which comprises a dynamic configuration module, a data generation module and a comparison verification module. The dynamic configuration module constructs a dynamic task model to generate a detection task; the data generation module generates a detection object according to the task, generates a multi-source verification packet through a multi-source packaging strategy, and transmits the multi-source verification packet to a target node; and the comparison verification module calculates a reliability value by using a multi-source analysis strategy, restores the detection data and generates a link state evaluation result. According to the invention, efficient and accurate communication link diagnosis can be realized, rapid positioning of the fault point of the communication link is realized, and the intelligent level of link anomaly detection and evaluation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power grid data communication diagnosis and analysis, and more particularly to a communication link diagnosis system based on a dynamic trigger model. Background Art

[0002] In recent years, a wide range of applications, including remote fee control, remote time synchronization, power outage monitoring, low voltage monitoring, full-event data collection, leakage protection data collection, and multi-meter centralized data collection, have been deployed. This has led to a continuous increase in data collection requirements, and the numerous concurrent data collection tasks have put increasing strain on communication resources. Some services require stringent communication success rates and timeliness. For example, remote fee control and remote time synchronization involve security authentication interactions, and responses from terminals and meters are subject to varying degrees of timeliness. Timeouts can result in task failure. Data collection systems involve numerous communication links, involving the coordination of multiple parties, including master station manufacturers, mobile operators, terminal manufacturers, carrier manufacturers, and meter manufacturers. Failures in any of these links can lead to communication failures. Identifying the faulty link in the event of a communication failure is a challenging task. With the development of new power systems and the deepening of reforms to the marketization of renewable energy power, demands for communication network stability and reliability are becoming increasingly stringent. Existing communication link diagnostic technologies are increasingly lacking in dynamic adaptability, multi-source verification capabilities, and link anomaly detection accuracy. Most existing technologies rely on a single path or fixed strategy for link detection, making them difficult to cope with complex communication environments and diverse abnormal scenarios. This leads to problems such as low diagnostic efficiency, high false alarm rates, and unreasonable resource utilization. Furthermore, communication systems also face packet sticking, software issues, bad packets, and protocol retransmission mechanism issues. A method and system for processing massive data communications in a distribution network system, published under publication number CN105245579B, is disclosed. This patent uses a node management service to read configuration information from a configuration repository, initiate protocol link services, protocol processing services, data processing services, and data distribution services, and match services according to preset matching rules, thereby achieving efficient uplink and downlink data transmission. However, this technical solution primarily focuses on optimizing the data transmission process and lacks the ability to monitor and diagnose dynamic changes in communication links in real time. Furthermore, its reliance on fixed protocol links and service matching rules makes it inflexible in responding to link anomalies or sudden interference, potentially leading to inaccurate or delayed diagnostic results. A method for synchronous measurement and communication link configuration in a distribution network for distributed state estimation, published under publication number CN110138620B, is disclosed. This patent optimizes the configuration of synchronized phasor measurement devices, phasor data concentrators, and communication links by constructing an adjacency matrix and inter-node communication path vectors, combined with the needs of distributed state estimation, thereby reducing the communication burden and improving real-time analysis and control capabilities. However, this technical solution mainly focuses on the static configuration optimization of the communication link and lacks a dynamic trigger mechanism to deal with abnormal conditions in the operation of the link. At the same time, it does not involve the design of multi-source verification data packets and cross-validation strategies, which may result in the inability to effectively restore the test data in the event of link abnormalities, affecting the reliability and accuracy of the diagnosis. Summary of the Invention

[0003] In view of this, an object of the present invention is to provide a communication link diagnosis system based on a dynamic trigger model.

[0004] In order to solve the above technical problems, the technical solution of the present invention is: a communication link diagnosis system based on a dynamic trigger model, comprising a dynamic model configuration module, a data worm generation module and a detection and comparison module;

[0005] The dynamic model configuration module is used to construct a dynamic configuration model, and the dynamic configuration model is used to generate a detection task according to monitoring information, and the detection task includes baseline detection information, a dynamic response strategy and a contention factor;

[0006] The data worm generation module is used to generate a corresponding detection data worm according to the detection task. The detection data worm is configured with a detection path, an update condition, a multi-source verification packet sub-strategy and an execution task group. The multi-source packet sub-strategy is encapsulated to generate a multi-source verification data packet according to the inspection data, and transmit the multi-source verification data packet according to the detection path until it reaches the target acquisition end. The multi-source verification data packet includes an attack verification sub-packet, a transmission verification sub-packet, a storage verification sub-packet and an interaction verification sub-packet. Each verification sub-packet includes complete inspection data. When the multi-source verification data packet triggers the update condition during the transmission process, the corresponding detection path is updated. The execution task group includes a number of execution sub-tasks. When the detection data worm reaches the target node, the corresponding execution sub-task is executed to obtain the inspection data;

[0007] The detection and comparison module is configured with a multi-source evaluation strategy, including a reliability evaluation algorithm, a data restoration strategy, and a link evaluation model. This strategy is used to calculate the reliability value of each verification sub-packet. The data restoration strategy restores the test data based on the reliability value of the verification sub-packet; the link evaluation model is used to generate a link evaluation result based on the test data. In this way, the detection data is generated through a dynamic configuration model. Cross-validation can then be performed using multi-source verification data that reaches the target terminal using different transmission methods. This prevents data deviation or loss due to interference during transmission of a single test data. The test data is then restored through cross-validation, completing the diagnosis of the link.

[0008] Furthermore, the data worm generation module includes a contention generation unit. The contention generation unit selects eligible target generation nodes based on benchmark detection information, obtains occupancy data for the target generation nodes, and calculates the occupancy value of each target generation node using a preset contention evaluation algorithm based on the occupancy data. When the occupancy value falls within a preset occupancy value range, the detection data worm is generated. The occupancy value range is determined based on a contention factor. In this way, the number of detection data worms generated is determined based on the contention factor to avoid conflicts with normal node transmission operations.

[0009] Furthermore, the dynamic model configuration module includes a monitoring generation unit configured with an information feature library, which is configured with a number of extracted features. The monitoring generation unit matches clue data that meets the extracted features from the real-time monitoring information and link evaluation results, and generates the benchmark detection information based on the clue data. This ensures that the generation of detection data bugs is based on the monitoring information and link evaluation results. For example, when the link is idle, more data bugs are generated; when the link is abnormal, more data bugs are generated; conversely, fewer data bugs are generated.

[0010] Furthermore: the dynamic model configuration module includes a model training unit, which is used to train the dynamic configuration model based on historical abnormal samples. The model training unit generates abnormal representations through historical abnormal data, and retrieves abnormal detection features from a preset knowledge base based on the abnormal representations, and determines corresponding detection information based on the abnormal detection features. The historical abnormal samples are generated based on the abnormal representations and the detection information. The model training unit inputs the abnormal representations as monitoring information into the dynamic configuration model and corrects the dynamic configuration model through the matching deviation between the detection information and the detection task. This setting, through machine learning training, makes the dynamic configuration model more clear about the relationship between detection tasks and detection information, that is, determines under what circumstances the abnormal representations should detect which data.

[0011] Furthermore, the data worm generation module is configured with a condition generation unit, and the condition generation unit is used to generate the update condition according to the dynamic response strategy. In this way, the target terminal can be reached through different transmission modes and paths.

[0012] Furthermore, the detection data worm is configured as a parasite. When configured as a parasite, the detection data worm uses the local data to be transmitted from the current node to the next node in the detection path as verification data to generate a multi-source verification data packet, and then occupies the transmission task of the local data for transmission. This configuration allows the data to be transmitted in conjunction with the local data, reducing the use of local data transmission resources.

[0013] Furthermore: the multi-source packet sub-strategy includes an attack data encapsulation method, a transmission data encapsulation method, a storage data encapsulation method, and an interaction data encapsulation method. The attack data encapsulation method includes obtaining security data features from an internal database, generating security induction data based on the security data features, and obtaining a corresponding data transmission format, adding the verification data to a blank field of the data transmission format, and adding the security induction data to a content field of the data transmission format; the transmission data encapsulation method includes generating a transmission disturbance factor and adding the transmission disturbance factor to a transmission field of the corresponding data transmission format, adding the verification data to the content field, and The transmission disturbance factor changes according to log information during the transmission process until the transmission is complete. The storage data encapsulation method includes configuring an identification code group and adding the identification code group to any field of the corresponding data transmission format. The identification code group is configured with a number of identification codes according to the transmission path. When a detection data worm passes through a node, the corresponding identification code is stored in the corresponding node storage area. The interaction data encapsulation method includes screening detection data worms with associated relationships, and generating interaction data for the current data worm using a preset mapping function based on the interaction data of the corresponding detection data worm, and adding the interaction data to any field of the data transmission format. This arrangement ensures that link anomalies do not have different impacts on multiple sub-packets by sending different verification sub-packets in different ways. The supply data is encapsulated with inductive information to increase its usability. The transmission data is encapsulated with a disturbance factor to be more sensitive to transmission risks. The storage encapsulation verifies consistency through the use of legacy identification codes. The interaction data is generated using the inherent mapping relationship of different data worms. This allows the interaction data of different data worms to be analyzed and compared after the transmission is completed to determine the interference during the transmission process.

[0014] Furthermore, the reliability algorithm is configured with several verification items, including comparison verification, data feature verification, and transmission verification. The comparison verification item is used to reflect the degree of data deviation between verification sub-packets, the data feature verification item is used to reflect the degree of abnormality of the data features of the verification sub-packets, and the transmission verification item is used to reflect the degree of transmission deviation of the verification sub-packets. In this way, reliability can be assessed through verification using different verification items.

[0015] Furthermore, the data restoration strategy includes determining a verification sub-package as baseline data based on a reliable value sequence, obtaining reliable fields from other verification sub-packages using a preset evaluation and recognition algorithm, and comparing the obtained reliable fields to update the verification sub-package serving as the baseline data. By obtaining reliable fields, different verification sub-packages are combined to generate the final verification data corresponding to the verification sub-package.

[0016] Furthermore, the link evaluation model includes the master station pre-evaluation sub-model, the remote channel evaluation sub-model, the acquisition terminal evaluation sub-model, the local channel evaluation sub-model, the smart energy meter evaluation sub-model, and the associated evaluation sub-model. This setup allows evaluations to be conducted by the five independent evaluation sub-models, which are then fed to the associated evaluation sub-model for further evaluation. This allows for multi-dimensional data analysis to be performed by combining five different knowledge graphs, improving reliability and security.

[0017] The technical effects of the present invention are mainly reflected in the following aspects: through such settings, the detection data worm is generated by the dynamic model, so that the entire communication system can complete the detection task with the minimum load. At the same time, when an abnormality or abnormal risk occurs, the corresponding detection data worm will also update the task to detect the abnormality in time. The multi-source verification data packet can perform link reliability testing from different dimensions, thereby avoiding a single problem causing the detection task data to be affected and deviated. At the same time, the abnormal analysis results obtained by the link evaluation sub-model are provided to the system to generate the detection data worm for use, thereby improving reliability, security and response efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a system structure diagram of the present invention.

[0019] Figure 2-1 This is the RTT (TCP message round-trip time) time diagram measured by a terminal on the master side.

[0020] Figure 2-2 This is the system status feedback diagram when the message is normal;

[0021] Figure 2-3 This is the system status feedback diagram when the message is abnormal;

[0022] Figure 3 This is a typical sticky packet data structure diagram;

[0023] Figure 4-1 Comparison of online data and communication traffic Figure 1 ;

[0024] Figure 4-2 Figure 2 shows the comparison of online numbers and communication traffic. DETAILED DESCRIPTION

[0025] The specific embodiments of the present invention are further described below in conjunction with the accompanying drawings to make the technical solutions of the present invention easier to understand and grasp.

[0026] A communication link diagnosis system based on a dynamic trigger model includes a dynamic model configuration module, a data bug generation module, and a detection and comparison module; a communication link diagnosis system based on a dynamic trigger model is provided, and its structure is as follows Figure 1As shown in the figure, the system includes a dynamic configuration module, a data generation module, and a comparison and verification module. The dynamic configuration module generates detection tasks through its internal monitoring generation unit and model training unit and passes these detection tasks to the data generation module. The data bug generation module generates detection objects based on the detection tasks and generates multi-source verification packages using a multi-source encapsulation strategy, transmitting them to the target node. The comparison and verification module receives the verification packages from the target node and uses a multi-source analysis strategy to perform reliability calculations, data restoration, and link status assessment, ultimately outputting the link status assessment results.

[0027] The dynamic model configuration module is used to build a dynamic configuration model, and the dynamic configuration model is used to generate detection tasks based on monitoring information. The detection tasks include baseline detection information, dynamic response strategies, and contention factors. The dynamic model configuration module includes a monitoring generation unit, and the monitoring generation unit is configured with an information feature library. The information feature library is configured with a number of extracted features. The monitoring generation unit matches clue data that meets the extracted features from the real-time monitoring information and link evaluation results, and generates the benchmark detection information based on the clue data. The dynamic model configuration module realizes the generation of detection tasks based on monitoring information by building a dynamic configuration model. The core of the model is the collaborative work of the monitoring generation unit and the model training unit: the monitoring generation unit is configured with an information feature library containing a number of extracted features, and is collected from real-time monitoring information. Such as the online rate, packet loss rate, RTT response time of the remote channel, the meter reading rate, one-time success rate, signal-to-noise ratio of the local channel, and the message parsing rate and server load of the master station front; in the link evaluation results, the clue data that meets the extracted features is matched, and the monitoring information is referenced. Figure 2-1 、 2-2 , 2-3, Figure 2-1 This is a time chart of the RTT (TCP packet round trip time) measured by a terminal on the master side. The chart shows that the RTT value of this terminal is relatively small most of the time, about 0.5 seconds, but in some periods the RTT value increases significantly, even reaching more than several minutes. Looking at the specific packets, we can also see that when the RTT value is small, the communication between the master and the terminal is relatively smooth, and the interaction between the sender and the receiver is clear, such as Figure 2-2 When the RTT value increases significantly, the communication between the master station and the terminal becomes "stuck", and packet loss and retransmission occur, such as Figure 2-3As shown in the figure, key parameters are extracted to generate benchmark detection information. This benchmark detection information includes basic configurations such as detection targets, detection cycles, and detection parameters. For example, high-frequency link transmission quality detection tasks are generated for packet loss anomalies. Monitoring information is acquired by relying on bypass mirroring packet capture technology to replicate the full communication traffic on the terminal access layer switch or router, losslessly capturing the original TCP / IP messages. Combined with multi-source information such as status data reported by the terminal and task execution logs, real-time operation data covering all links including the master station front-end, remote channels, collection terminals, local channels, and smart electricity meters is generated. Dynamic response strategies are based on preset rules based on historical failure modes and real-time detection requirements. For example, when update conditions such as transmission delay exceeding a threshold or a sudden drop in signal strength are triggered during the transmission of detection data, the detection path, transmission mode, or verification strategy are dynamically adjusted. Dynamic response strategies are obtained from a preset dynamic strategy database to adapt to different link anomaly scenarios. The contention factor is a key parameter for controlling the number of detection data worms generated. It is dynamically set by the dynamic model configuration module based on factors such as the current link load status and historical detection results. It usually ranges from 0.3 to 0.7 and is used to determine the occupancy value range: the contention generation unit screens the target generation node based on the benchmark detection information, obtains the node's load rate, transmission queue length and other occupancy data, and calculates the occupancy value of each node through the preset contention evaluation algorithm. When the occupancy value falls into the occupancy value range generated by the contention factor, the generation of detection data worms is triggered, thereby avoiding conflicts between the detection task and the normal transmission action of the node. For example, when the link is idle, the contention factor is automatically lowered to increase the number of data worms generated. When the link is abnormal, the contention factor is increased to accurately generate targeted detection tasks. The model training unit uses historical anomaly samples, including anomaly representations and detection information; it trains the dynamic configuration model and retrieves anomaly detection features from the preset knowledge base through anomaly representations. For example, the corresponding detection information is determined based on anomaly representations such as a sudden increase in RTT response time and frequent IP switching. The anomaly representation is then input into the dynamic configuration model as monitoring information. The model is continuously corrected through the matching deviation between detection information and detection tasks, making the dynamic configuration model more accurate in the correlation between detection tasks and detection information, ensuring the generation of optimized detection tasks, benchmark detection information, dynamic response strategies and contention factor parameters under different monitoring information.

[0028] The dynamic model configuration module includes a model training unit, which is used to train the dynamic configuration model based on historical abnormal samples. The model training unit generates abnormal representations through historical abnormal data, and retrieves abnormal detection features from a preset knowledge base based on the abnormal representations, and determines the corresponding detection information based on the abnormal detection features. The historical abnormal samples are generated based on the abnormal representations and detection information. The model training unit inputs the abnormal representations as monitoring information into the dynamic configuration model and corrects the dynamic configuration model through the matching deviation between the detection information and the detection task. The benchmark detection parameters are generated by collecting monitoring information in real time and extracting key data in combination with the feature extraction library. The monitoring generation unit extracts abnormal performance features from the link status and adjusts the generation frequency and priority of the benchmark detection parameters based on the distribution rules of the link idle state and abnormal state. For example, the number of detection tasks is increased when the link is idle, and the priority of the detection task is increased when the link is abnormal. The model training unit trains the dynamic task model using historical anomaly samples. The specific process is as follows: first, it extracts anomaly characteristics from historical anomaly data and determines detection parameters based on anomaly detection features in the knowledge base. Then, using the anomaly characteristics as input and the deviation between the detection parameters and the detection task as feedback, it optimizes the parameters of the dynamic task model through a machine learning algorithm, enabling it to more accurately map the relationship between anomaly characteristics and the detection task. The monitoring generation unit and the model training unit work together to ensure that the dynamic task model can generate detection tasks that meet actual requirements based on real-time monitoring information and historical data. The model training unit achieves iterative optimization of the dynamic task model by establishing a mapping mechanism from "anomaly representation to detection parameters to task generation." Its core is to convert historical anomaly data into computable feature vectors and use machine learning algorithms to correct the deviation between the detection task and actual requirements. The specific process is as follows: First, time domain features (such as the time intervals between sudden changes in RTT response durations), frequency domain features (such as the frequency distribution of carrier signal distortion), and statistical features (such as the mean and variance of the number of disconnections) are extracted from historical anomaly samples to form an anomaly performance feature vector (such as the RTT99 value sequence and the IP handoff count matrix when the remote channel is abnormal). Then, combined with the pre-set anomaly detection features in the knowledge base, a feature fusion algorithm is used to determine detection parameters, such as the detection period, path priority, and verification sub-packet type. During the training phase, the anomaly performance features are used as input layer data, and the deviation between the detection parameters and the actual generated detection task (such as the difference between the preset contention factor of 0.6 and the actual optimal value of 0.7) is used as the backpropagation signal. The gradient descent method is used to optimize the parameter matrix of the dynamic task model, enabling the model to directly output a detection task containing baseline detection information, dynamic response strategy, and contention factor based on the input feature vector.

[0029] Taking the remote channel disconnection anomaly as an example, the model training unit extracts a feature combination from historical data when the mobile terminal disconnects: RTT99 value > 2 seconds, IP switching number > 2 times / hour, and online rate < 99.5%. Combined with the detection features of insufficient authentication device capacity in the knowledge base and response delay > 0.5 seconds, it generates a detection task with a high-frequency detection period of 2 minutes, multi-base station path verification, 3 different transmission paths, and a contention factor of 0.6. During the training process, if actual detection finds that the task interferes with normal business by > 5%, the deviation value, the difference between the contention factor 0.6 and the optimal value of 0.5, is fed back to the model, and the influence factor of the IP switching number in the feature weight matrix is ​​adjusted from 0.3 to 0.4, so that the contention factor of subsequently generated tasks is automatically reduced to 0.55. Another example is a local channel interference scenario. The model extracts features from historical samples when high-power equipment starts up, including a sudden drop in signal-to-noise ratio (SNR) greater than 10dB and a decrease in meter reading success rate greater than 10%. Combined with the detection features of carrier signal distortion in the knowledge base, including a signal distortion rate greater than 15%, it generates a detection task that includes dual-channel transmission: carrier + wireless, real-time path switching conditions, switching when the SNR is less than 25dB, and a contention factor of 0.4. If training finds that this task has a real-time impact of greater than 10% on the flexible control service, the weight of the meter reading success rate in the feature fusion algorithm is adjusted through feedback, reduced from 0.5 to 0.3, and the weight of the SNR is increased to 0.6, so that subsequent tasks prioritize channel stability detection and reduce resource usage. In this way, the model training unit realizes the precise mapping of benchmark detection information in the detection task, such as the specific values ​​of the detection cycle, number of paths, dynamic response strategy update condition threshold and contention factor in the range of 0.3-0.7, with the abnormal performance characteristics. For example, when the input feature is "remote channel packet loss rate > 0.03% and local channel signal-to-noise ratio < 20dB", the detection task output by the model will automatically include a contention factor of 0.5, a dual-channel verification strategy and a 1-minute detection cycle. This process uses the processing effects of similar anomalies in historical data as training labels to ensure that the deviation rate between the generated detection task parameters and actual requirements is less than 8%.

[0030] The data worm generation module is used to generate a corresponding detection data worm according to the detection task. The detection data worm is configured with a detection path, an update condition, a multi-source verification packet sub-strategy and an execution task group. The multi-source packet sub-strategy is encapsulated to generate a multi-source verification data packet according to the inspection data, and transmit the multi-source verification data packet according to the detection path until it reaches the target acquisition end. The multi-source verification data packet includes an attack verification sub-packet, a transmission verification sub-packet, a storage verification sub-packet and an interaction verification sub-packet. Each verification sub-packet includes complete inspection data. When the multi-source verification data packet triggers the update condition during the transmission process, the corresponding detection path is updated. The execution task group includes a number of execution sub-tasks. When the detection data worm reaches the target node, the corresponding execution sub-task is executed to obtain the inspection data;

[0031] The data worm generation module includes a contention generation unit, which screens eligible target generation nodes based on benchmark detection information, obtains occupancy data for the target generation nodes, and calculates the occupancy value of each target generation node using a preset contention evaluation algorithm based on the occupancy data. When the occupancy value falls within a preset occupancy value range, the detection data worm is generated. The occupancy value range is generated based on the contention factor. The contention generation unit also determines the number and timing of generated detection objects by analyzing the current load and historical load distribution of the target node, combined with the requirements of the detection task, to avoid conflicts with the normal transmission actions of the target node. In addition, the condition generation unit in the data generation module generates update rules based on the response strategy and dynamically adjusts the content of the update rules by analyzing the dynamic change characteristics of the link and combining the actual conditions of the transmission path. For example, when the link load is high, an alternative path is selected, and when the link interference is strong, the transmission mode is adjusted to ensure that the detection object can reach the target node via the optimal path. For detection targets in specific scenarios, they can be configured in parasitic mode. This mode uses the local data to be transmitted from the current node to the next node as detection data to generate a multi-source verification packet, and then occupies the transmission task of this local data for transmission. This reuses local data transmission resources and reduces additional link bandwidth usage. The data worm generation module achieves adaptive generation of detection data worms and transmission path optimization through the coordinated operation of the contention generation unit, the conditional generation unit, and the parasitic mode configuration. The contention generation unit collects real-time current load data such as CPU utilization, memory usage, and transmission queue length from the target node, and constructs a load prediction model based on historical load distribution. For example, it uses the ARIMA algorithm to predict node load trends for the next 15 minutes. Combining the detection task priority and resource requirements, the optimal number of detection data worms to be generated is calculated using a queuing theory model. If the target node's current load exceeds 70% and the load is predicted to continue to rise over the next 5 minutes, the number of generated detection data worms is automatically reduced by 30%, and the generation is delayed until the load is low. This prevents detection tasks from conflicting with the node's normal transmission queue, such as mobile operator terminals that experience disconnections due to excessive load.

[0032] The data bug generation module is configured with a conditional generation unit, which is configured to generate the update condition based on the dynamic response strategy. For example, a mobile operator's remote channel in a regional collection system experiences persistent packet loss. Real-time monitoring shows a packet loss rate of 0.08%, which is ≤0.01% of the normal threshold, and the average RTT response time exceeds 0.15 seconds, with a baseline value of 0.1 seconds. Simultaneously, the target node load rate reaches 75%, exceeding the 70% threshold. Based on the "packet loss rate > 0.05% and duration > 3 minutes" rule in the dynamic response strategy, the conditional generation unit extracts historical throughput data for the current transmission path in real time, compares it with the backup fiber private network path, and generates an update rule to "switch to the fiber private network path and reduce the transmission disturbance factor threshold." This rule lowers the allowed RTT fluctuation range for transmission verification packets from 20% to 15%. Simultaneously, the contention generation unit obtains load data such as the target node's CPU utilization and transmission queue length, and uses the ARIMA algorithm to predict a continued load increase over the next 10 minutes. Using a queuing theory model, the unit reduces the number of detection data bugs generated by 30% and delays their generation until the load is low. The condition generation unit is based on a rule base preset by the dynamic response strategy, which contains more than 200 rules for link abnormality scenarios. It generates update conditions in combination with the real-time collected dynamic change data of the link: when the remote channel packet loss rate exceeds 0.05% and lasts for more than 2 minutes, it automatically generates an update rule for switching to the backup fiber-optic private network path, and dynamically adjusts the priority of the backup path according to the historical throughput data of the transmission path; in scenarios with strong link interference, such as when the local channel signal-to-noise ratio is lower than 20dB, by analyzing the frequency domain characteristics of the interference signal, it generates an update rule for adjusting the transmission mode to spread spectrum communication, and switches the modulation mode of the transmission sub-packet from BPSK to QPSK to improve anti-interference capability. The threshold parameters of the update rule will be dynamically modified through the reinforcement learning algorithm based on the historical optimization effect.

[0033] The detection data worm is configured with a parasitic ecology. When the detection data worm is configured as a parasitic ecology, the local data to be transmitted from the current node to the next node in the detection path is used as the inspection data to generate a multi-source verification data packet, and the transmission task of the local data is occupied for transmission. For detection scenarios that need to reduce bandwidth occupancy, the data worm can be configured as a parasitic mode: when the detection data worm arrives at a certain node, the local data transmitted by the node to the subsequent node, such as meter reading data and soft control instructions, is extracted as inspection data, and the inspection data is embedded in the blank field of the transmission format of the local data using a multi-source packet sub-strategy to generate a multi-source verification data packet containing an attack verification sub-packet, a transmission verification sub-packet, etc. This data packet reuses the transmission task of the local data for transmission. It has been measured that 40% of the additional bandwidth occupancy can be reduced. For example, in the local channel interference processing, the detection data worm and the meter reading data are transmitted synchronously in the parasitic mode, without causing delays to normal business. In addition, in the parasitic mode, a sticky packet splitting mechanism is also configured. Refer to Figure 3As shown, a typical sticky package is Figure 3 As shown in the figure, the underlined portion indicates the start of packet 376. Currently, the acquisition system master station can only process the first 376 packets of stuck data; all remaining data is discarded. Some acquisition terminals process byte-by-byte and can handle stuck packets, but others cannot. Excessive stuck packets can reduce acquisition communication efficiency and, in severe cases, affect acquisition success rates. Essentially, stuck packets occur when the TCP protocol handler (typically operating at the driver layer) fails to promptly send data written by the application to the send buffer, or when the application fails to promptly read data from the receive buffer. In the acquisition system, the former scenario is often the case. Failure of the TCP handler to send data promptly could be due to a network issue or a TCP handler issue. TCP handler delays can be resolved by setting the PSH flag and enabling TCP_NODELAY. However, network issues are more complex. Typically, when network latency increases, the TCP handler automatically initiates a retransmission mechanism if it doesn't receive an ACK within a certain period of time after sending data. This mechanism resends data that hasn't yet been ACKed. If the network is slow and the application continues to write data to the TCP buffer, the TCP handler will repackage and resend the unsent data, creating a "stuck packet" pattern. This process reduces resource usage by identifying and reprocessing stuck packets. Meanwhile, the parasitic detection data worm records the local data transmission trajectory and tracks data integrity by storing and verifying the identification code groups of sub-packets. If the identification code stored by a node doesn't match the preset sequence, the trigger condition generation unit dynamically adjusts the subsequent transmission path to ensure the coordinated reliability of the detection data worm and local data transmission. For example, during peak hours in a certain substation, the local channel node load reached 85%, the meter reading success rate dropped from 98% to 85%, and the local channel signal-to-noise ratio was monitored to be below 20dB. The contention generation unit reduces the number of detection data worms generated by 40% based on the current load data such as the target node's memory occupancy rate and transmission queue length, combined with the historical load distribution, through the queuing theory model calculation, and adjusts the contention factor from 0.5 to 0.3 to reduce resource usage; at the same time, the detection data worm is configured as a parasitic mode, extracting the local meter reading data transmitted by the node to the subsequent node as the test data, and using the multi-source packet sub-strategy to embed the test data into the blank field of the local data transmission format, generating a multi-source verification data packet containing an attack verification sub-packet and a transmission verification sub-packet, and multiplexing the transmission task of the local data for delivery. It can also be used, for example, Figure 4-1 and Figure 4-2 The comparison results of the online number and communication traffic are analyzed, and the corresponding parasitic positions and parasitic time periods are predicted based on the online number and communication traffic configuration.

[0034] The multi-source packet sub-strategy includes an attack data encapsulation method, a transmission data encapsulation method, a storage data encapsulation method, and an interaction data encapsulation method. The attack data encapsulation method includes obtaining security data features from an internal database, generating security inducement data based on the security data features, obtaining a corresponding data transmission format, adding verification data to a blank field of the data transmission format, and adding the security inducement data to a content field of the data transmission format; extracting security data features from an internal database, generating security inducement data, matching the corresponding data transmission format, adding verification data to a blank format field, and filling the content field with security inducement data. For example, when testing the remote channel's anti-attack capabilities, the security data features select traffic features of common DDoS attacks, generate security inducement data containing false requests, and embed electricity meter reading data as verification data into the blank CRC checksum field of the transmission format. If the link responds abnormally to the security inducement data during transmission, such as frequent disconnections, the link is determined to have a security vulnerability, such as a disconnection problem caused by an attack on the mobile operator's authentication device. The transmission data encapsulation method includes generating a transmission disturbance factor and adding the transmission disturbance factor to the transmission field of the corresponding data transmission format, adding verification data to the content field, and the transmission disturbance factor changes according to the log information in the transmission process until the transmission action is completed; generating a disturbance factor based on the transmission log, adding it to the transmission field, and storing the verification data in the content field. Taking the bandwidth bottleneck case of the Fujian company's export router as an example, when the packet loss rate in the transmission log exceeds 0.05%, the disturbance factor is automatically adjusted to 1.5 times the current packet loss rate and added to the window size parameter of the TCP transmission field. At the same time, the remote channel RTT response time is filled in the content field as verification data. If the deviation between the disturbance factor after transmission and the actual packet loss rate exceeds 20%, it is determined that the link transmission stability is insufficient. The storage data encapsulation method includes configuring an identification code group, adding the identification code group to any field of the corresponding data transmission format, wherein the identification code group is configured with a plurality of identification codes according to the transmission path. When a detection data worm passes through a node, the corresponding identification code is stored in the corresponding node storage area. Preferably, the carrier communication time and the identification code of the storage verification sub-packet can be associated: the carrier communication time is the carrier communication time for the second data item of the task of the meter, which is the difference between the meter reading times of two consecutive successful data items under the same terminal, the same meter, and the same task number; configuring an identification code group dynamically allocated according to the transmission path, adding it to any field of the data transmission format, and storing the code in the storage area when the detection data worm passes through the node. For example, when there is interference from high-power equipment in the local channel, the identification code group is set to "10101" and transmitted to each node along with the detection data worm. When the code stored at a node changes to "10111", it is determined that the node storage area has been interfered with, resulting in data tampering. Combined with the sudden drop in signal-to-noise ratio, the interference source is located as nearby industrial equipment.The interactive data encapsulation method includes screening associated detection data worms, generating interactive data for the current data worm using a preset mapping function based on the interactive data of the corresponding detection data worms, and adding the interactive data to any field in the data transmission format. The data restoration strategy includes determining a verification sub-package as baseline data based on a reliable value sequence, obtaining reliable fields from other verification sub-packages using a preset evaluation and recognition algorithm, and comparing the obtained reliable fields to update the verification sub-package as the baseline data. The associated detection data worms are screened, and local interactive data is generated using a mapping function such as a hash function and added to the transmission format field. For example, in the photovoltaic flexible control service, interactive data encapsulation requires linking detection data worms for steps such as calling the ESAM and establishing an application connection. The response timestamps of each step are generated into 64-bit interactive data using the SHA-256 hash function and embedded into the function code field of the Modbus protocol. If the interactive data of a step does not match the preset hash value, the communication logic of that step is determined to be abnormal, such as when an electric meter error code is returned during application connection establishment.

[0035] The detection and comparison module is configured with a multi-source evaluation strategy, including a reliability evaluation algorithm, a data restoration strategy, and a link evaluation model. It calculates the reliability value of each verification sub-packet. The link evaluation model generates a link evaluation result based on the verification data. The link evaluation model includes the master station pre-evaluation sub-model, the remote channel evaluation sub-model, the acquisition terminal evaluation sub-model, the local channel evaluation sub-model, the smart energy meter evaluation sub-model, and the association evaluation sub-model. The following describes the functions and roles of each sub-model: 1. Master station pre-evaluation sub-model: This inputs real-time data such as the master station pre-evaluation rate, server load, and number of concurrent connections, as well as historical operational data such as the average message parsing rate and peak server load during different periods of the past week. Using an ARIMA model based on time series analysis and an association rule mining algorithm, it outputs a master station pre-evaluation operational status score (0-10, with higher scores indicating better status), a potential fault risk level, and anomaly types such as message parsing errors and insufficient server resources. Its function is to monitor the performance of the master station frontend in real time and provide early warning of faults that could impact data collection and transmission. For example, if the packet parsing rate falls below 8,000 packets per second for 30 consecutive minutes, the model predicts a high risk of a large data backlog within the next hour and indicates the anomaly type as "inefficient parsing algorithm." 2. Remote Channel Evaluation Sub-Model: This model uses remote channel online rate, packet loss rate, RTT response time, and signal strength as input, combined with historical channel quality data, such as daily packet loss rate curves over the past month. It uses a neural network model, such as an LSTM, to learn and predict this data, outputting a channel quality rating, channel stability assessment, and potential fault location. This sub-model continuously tracks remote channel conditions and promptly identifies trends in channel quality degradation. For example, if the packet loss rate of a remote channel in a certain area gradually increases from 0.01% to 0.05% and signal strength continues to decline, the model will determine that the channel stability is "fluctuating" and the potential fault location is "at the edge of a base station's signal coverage." 3. Collection terminal evaluation sub-model: This model takes as input data such as the battery undervoltage status, communication module temperature, and task execution success rate of the collection terminal, while also referencing the terminal's historical maintenance records, such as the number of faults and fault types in the past year. Using decision trees and Bayesian classification algorithms, it outputs a terminal health status assessment, a remaining service life estimate, and an analysis of possible fault causes. Its function is to fully understand the operating status of the collection terminal and arrange maintenance plans in advance. For example, when the terminal battery charge is less than 20% and the task execution success rate is less than 95% for three consecutive days, the model determines that the terminal health status is "sub-healthy" and the possible cause of the fault is "battery aging affecting communication stability." 4. Local channel evaluation sub-model: This model takes as input real-time data such as the local channel's meter reading rate, first-time success rate, signal-to-noise ratio, and carrier signal strength, as well as the local power network topology and historical power load change data.Utilizing a graph neural network combined with a power line communication channel model, it outputs a local channel communication quality score, interference source location, and optimization recommendations. This sub-model focuses on local channel performance analysis to address channel interference. If the local channel meter reading rate in a particular area drops sharply and the signal-to-noise ratio falls below 20dB, the model identifies the interference source as newly added industrial equipment nearby and provides an optimization recommendation to adjust the carrier frequency outside the interference band. 5. Smart Meter Evaluation Sub-Model: This model takes smart meter measurement accuracy, data reporting integrity, reporting timeliness, and clock error as input, along with historical meter calibration data and software version information. Using a regression-based measurement error prediction model and a data integrity verification algorithm, it outputs meter status, data transmission reliability assessment, and clock synchronization recommendations. This sub-model ensures the reliability of smart meter measurement and data transmission. For example, if a meter's measurement error exceeds ±0.5% and the data upload integrity falls below 98%, the model determines the meter's measurement status as "excessive error" and its data transmission reliability as "unreliable," recommending meter calibration and software upgrades.

[0036] The association evaluation submodel, as the core integration unit of the link evaluation model, uses a Bayesian network algorithm to perform probabilistic reasoning and weighted fusion on the output data of the five submodels: the master station frontend, remote channel, data collection terminal, local channel, and smart energy meter. Its inputs include performance scores from the master station frontend evaluation submodel, such as the status level corresponding to a message parsing rate of 12,000 packets / second and a data storage latency of 30ms; channel quality indicators generated by the remote channel evaluation submodel, such as stability assessments of 99.96% online rate and 0.005% packet loss rate; health status data from the data collection terminal evaluation submodel, such as device health of 99.8% task execution rate and 65% load factor; interference analysis results from the local channel evaluation submodel, such as channel quality scores of 28dB signal-to-noise ratio and 97.5% first-pass meter reading success rate; and metering reliability data from the smart energy meter evaluation submodel, such as a metering status of 99.7% meter reading success rate and 1-second clock error. This input data is received as standardized feature vectors. Each feature vector contains the original metric output by the sub-model, the deviation rate from the historical baseline, and the confidence level of the anomaly. For example, when the remote channel packet loss rate exceeds the baseline by 20%, the confidence level is 0.85. The output of the correlation evaluation sub-model comprises a three-tiered structure: a comprehensive score for the entire link, fault causal chain analysis, and optimization strategy recommendations. For example, at a certain power supply company, when the master station pre-evaluation sub-model outputs a packet parsing rate of 8,000 packets per second, 20% below the baseline, and the remote channel evaluation sub-model indicates a packet loss rate of 0.03%, exceeding the threshold by three times, the correlation evaluation sub-model, using a Bayesian network, calculates a failure probability of 0.91 for an "egress router bandwidth bottleneck." It also generates optimization recommendations: replacing the router, expected to increase the parsing rate to 12,000 packets per second, and upgrading the bandwidth from 100 Mbps to 1,000 Mbps. During this process, the weights of the input data for each sub-model are dynamically adjusted based on historical fault sample training. The weight of the remote channel packet loss rate is automatically increased to 0.4 in network anomaly scenarios, ensuring a high degree of accuracy in matching the output results with the actual fault scenario. Master station front-end link collaborative diagnosis: By building a traceable communication data warehouse, it aggregates terminal connection status, task trajectories, and service logs in real time. It incorporates indicators such as message parsing rate (e.g., processing 6,000,000 frames per second) and data storage timeliness into the input parameters of the dynamic configuration model. When the server load exceeds 80%, it automatically lowers the contention factor of the detection task (e.g., from 0.6 to 0.3) to avoid overloading the master station resources. Active detection of sub-healthy stations: It uses a Top-N algorithm to rank the terminal communication comprehensive scores, selecting the top 5% stations with the lowest scores as key detection targets.For example, based on the scoring results of "remote communication KPI = 0.2, local communication KPI = 0.6" for a certain substation, a targeted detection task is generated: local data transmission resources are reused through the parasitic ecology of data worms, focusing on verifying the cause of packet loss in the remote channel (such as the bandwidth bottleneck of the egress router), and locating the interference source (such as high-power equipment in the substation) in combination with GIS spatial information.

[0037] The reliability algorithm is configured with several verification items, including comparison verification items, data feature verification items, and transmission verification items. The comparison verification item is used to reflect the degree of data deviation between verification sub-packets, the data feature verification item is used to reflect the degree of abnormality of the data features of the verification sub-packets, and the transmission verification item reflects the degree of transmission deviation of the verification sub-packets. A multi-dimensional evaluation system is constructed by these three types of verification items. The specific formulas and parameter definitions are as follows:

[0038] Comparison verification item calculation formula:

[0039]

[0040] Where D is the average relative deviation rate between verification sub-packages, which is used to measure data consistency, and the threshold is set to 5%; n is the number of verification sub-packages; x i : The test data of the ith verification sub-package; x ref : Benchmark data value, taken from the median of multiple source sub-packets or the mean of historical normal data. Application scenario: When the RTT values ​​of 5 groups of transmission verification sub-packets of a certain area collection terminal are 0.102 seconds, 0.137 seconds, 0.137 seconds, 0.078 seconds, and 0.074 seconds respectively, x ref Taking the median as 0.102 seconds, we calculate D = 22.5%, which exceeds the 5% threshold and is determined to be a transmission link abnormality.

[0041] 2. Data feature verification formula:

[0042]

[0043] Where Z is the standard score (Z-score) of the data feature, which measures the degree to which the current data deviates from the historical normal distribution. An anomaly is identified when |Z| > 3; x is the current detection data; μ is the historical data mean; and σ is the historical data standard deviation. Application scenario: A smart electricity meter has a daily curve acquisition success rate of 95%, while the historical mean μ is 99.1% and the standard deviation σ is 0.4%. The calculated Z is -10.25, and |Z| is much greater than 3, indicating a data anomaly.

[0044] 3. Transmission verification item formula:

[0045]

[0046] Where F is the fluctuation range of the transmission index, which is used to evaluate the deviation between the real-time transmission status and the benchmark value, and the threshold is set to 20%; current : Current transmission index measured value; t base : Transmission indicator benchmark value. Application scenario: The current RTT99 value of a remote channel is 2.37 seconds, and the benchmark value t base = 0.5 seconds, and the calculated F = 374%, which far exceeds the 20% threshold, and is determined to be abnormal transmission delay.

[0047] The calculation formula of comprehensive reliability value is as follows:

[0048] R=[w1·(1-D / 5%)+w2·e -|Z| / 3 +w3·(1-F / 20%)]Q

[0049] Where R is the comprehensive reliability value, with an accuracy of 0.01. A higher value indicates greater data reliability. w1, w2, and w3 are weight coefficients, which are dynamically adjusted based on the business scenario. For example, in remote channel diagnosis, w1 = 0.4, w2 = 0.3, and w3 = 0.3. Q is the task execution rate.

[0050] Application scenario: When D=4%, Z=1.5, F=15% of a certain detection task, and weights w1=0.4, w2=0.3, w3=0.3, the calculated value is R=[0.4×(1-0.8)+0.3e -0.5 +0.3×(1-0.75)]0.8=0.248, indicating a low reliability value. The data restoration strategy is initiated. The "task execution rate" metric is introduced. Using real-time terminal task monitoring data (such as the number of executions and failure reasons for daily frozen data collection tasks), the task execution rate is calculated as: actual execution times / planned execution times × 100%. This serves as a supplementary parameter for verifying sub-package reliability. This improves anomaly detection sensitivity, particularly for issues such as task data collection suspension caused by terminal program bugs (e.g., a terminal terminating an entire task after a single meter data collection failure).

[0051] The data restoration strategy restores the inspection data based on the reliability value of the verification sub-packet. Based on the reliability value sequence of multi-source verification sub-packets, the sub-packet with the highest reliability value is selected as the benchmark data. For example, during remote channel detection, five verification sub-packets are generated with reliability values ​​of 0.85, 0.62, 0.91, 0.78, and 0.59, respectively. The transmission verification sub-packet with a reliability value of 0.91 is selected as the benchmark, and the RTT response duration it carries, 0.078 seconds, is used as the benchmark value for the current link transmission delay, such as normal data with an RTTavg of 0.078 seconds for a mobile 5G channel. An evaluation and recognition algorithm is used to extract reliable fields from other sub-packets and compare them with the benchmark data. For example, when a smart electricity meter fails to acquire curve data, the attack verification sub-packet has a reliability value of 0.72, while the meter error code field in the security-induced data it carries has a reliability value of 0.95. By comparing the verification items, the calculated deviation rate is less than 3%, while the packet loss rate field of the transmission verification sub-packet has a reliability value of 0.88. These two fields are extracted and compared with the corresponding fields in the benchmark sub-packet. If the extracted reliable field deviates from the baseline data by more than a threshold, the baseline data is updated. For example, if the meter reading success rate for the baseline sub-packet is 99.6%, but the reliable fields extracted from other sub-packets indicate a meter reading success rate of only 95.8% for a particular area, the baseline data is updated to 95.8%, triggering local channel diagnosis and an iterative optimization mechanism. If the baseline data updates by more than 20% over three consecutive detections, the model training unit is activated to recalibrate the reliability value algorithm weights. For example, if a terminal experiences frequent baseline data updates, the model training unit adjusts the comparison verification item weight from 0.4 to 0.6 based on historical anomaly samples, enhancing sensitivity to data deviations and avoiding misjudgments.

[0052] Of course, the above are only typical examples of the present invention. In addition, the present invention may also have many other specific implementation methods. Any technical solutions formed by equivalent replacement or equivalent transformation fall within the scope of protection required by the present invention.

Claims

1. A communication link diagnostic system based on a dynamic trigger model, characterized by: Including dynamic model configuration module, data bug generation module and detection and comparison module; The dynamic model configuration module is used to construct a dynamic configuration model, and the dynamic configuration model is used to generate a detection task according to monitoring information, and the detection task includes baseline detection information, a dynamic response strategy and a contention factor; The data worm generation module is used to generate a corresponding detection data worm according to the detection task. The detection data worm is configured with a detection path, an update condition, a multi-source verification packet sub-strategy and an execution task group. The multi-source packet sub-strategy is encapsulated to generate a multi-source verification data packet according to the inspection data, and transmit the multi-source verification data packet according to the detection path until it reaches the target acquisition end. The multi-source verification data packet includes an attack verification sub-packet, a transmission verification sub-packet, a storage verification sub-packet and an interaction verification sub-packet. Each verification sub-packet includes complete inspection data. When the multi-source verification data packet triggers the update condition during the transmission process, the corresponding detection path is updated. The execution task group includes a number of execution sub-tasks. When the detection data worm reaches the target node, the corresponding execution sub-task is executed to obtain the inspection data; The detection and comparison module is configured with a multi-source evaluation strategy configured with a reliable evaluation algorithm, a data restoration strategy and a link evaluation model, which is used to calculate the reliability value of each verification sub-package. The data restoration strategy restores the inspection data according to the reliability value of the verification sub-package; the link evaluation model is used to generate a link evaluation result based on the inspection data.

2. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The data worm generation module includes a contention generation unit, which screens qualified target generation nodes according to benchmark detection information, obtains occupancy data of the target generation nodes, calculates the occupancy value of each target generation node according to the occupancy data through a preset contention evaluation algorithm, and generates the detection data worm when the occupancy value falls within a preset occupancy value range, and the occupancy value range is generated according to the contention factor.

3. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The dynamic model configuration module includes a monitoring generation unit, which is configured with an information feature library, and the information feature library is configured with a number of extracted features. The monitoring generation unit matches clue data that meets the extracted features from the real-time collected monitoring information and link evaluation results, and generates the benchmark detection information based on the clue data.

4. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The dynamic model configuration module includes a model training unit, which is used to train the dynamic configuration model based on historical abnormal samples. The model training unit generates anomaly representations through historical abnormal data, and retrieves anomaly detection features from a preset knowledge base based on the anomaly representations, and determines corresponding detection information based on the anomaly detection features. The historical abnormal samples are generated based on the anomaly representations and the detection information. The model training unit inputs the anomaly representations into the dynamic configuration model as monitoring information and corrects the dynamic configuration model based on the matching deviation between the detection information and the detection task.

5. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The data worm generation module is configured with a condition generation unit, and the condition generation unit is used to generate the update condition according to the dynamic response strategy.

6. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The detection data worm is configured with a parasitic ecology. When the detection data worm is configured as a parasitic ecology, the local data to be transmitted from the current node to the next node in the detection path is used as the inspection data to generate a multi-source verification data packet, and the transmission task of the local data is occupied for transmission.

7. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The multi-source encapsulation sub-strategy includes an attack data encapsulation method, a transmission data encapsulation method, a storage data encapsulation method, and an interaction data encapsulation method. The attack data encapsulation method includes obtaining security data features from an internal database, generating security inducement data based on the security data features, and obtaining a corresponding data transmission format. The verification data is added to a blank field of the data transmission format, and the security inducement data is added to a content field of the data transmission format. The transmission data encapsulation method includes generating a transmission disturbance factor and adding the transmission disturbance factor to the transmission field of the corresponding data transmission format, and adding the inspection data to the content field. The transmission disturbance factor changes according to the log information in the transmission process until the transmission action is completed; the storage data encapsulation method includes configuring an identification code group and adding the identification code group to any field of the corresponding data transmission format. The identification code group is configured with a number of identification codes according to the transmission path. When the detection data worm passes through a node, the corresponding identification code will be retained in the corresponding node storage area; the interaction data encapsulation method includes screening detection data worms with an associated relationship, and generating the interaction data of the current data worm according to the interaction data of the corresponding detection data worm using a preset mapping function, and adding the interaction data to any field of the data transmission format.

8. The communication link diagnostic system based on a dynamic trigger model according to claim 7, wherein: The reliability algorithm is configured with several verification items, including comparison verification items, data feature verification items, and transmission verification items. The comparison verification items are used to reflect the degree of data deviation between verification sub-packages, the data feature verification items are used to reflect the degree of abnormality of the data features of the verification sub-packages, and the transmission verification items reflect the degree of transmission deviation of the verification sub-packages.

9. The communication link diagnostic system based on a dynamic trigger model according to claim 1, wherein: The data restoration strategy includes determining the verification sub-package as the benchmark data based on the reliable value sequence, obtaining the reliable fields of other verification sub-packages through a preset evaluation and recognition algorithm, and comparing the obtained reliable fields to update the verification sub-package as the benchmark data.

10. The communication link diagnostic system based on a dynamic trigger model according to claim 1, characterized in that: The link evaluation model includes the master station pre-evaluation sub-model, the remote channel evaluation sub-model, the acquisition terminal evaluation sub-model, the local channel evaluation sub-model, the smart electric energy meter evaluation sub-model and the associated evaluation sub-model.

Citation Information

Patent Citations

  • A method and system for processing massive data communication in distribution network system

    CN105245579B

  • Distribution Network Synchronization Measurement and Communication Link Configuration Method for Distributed State Estimation

    CN110138620B

Cited By

  • Protection method and device of energy storage device, energy storage system and electric equipment

    CN120855613A