A power terminal bypass safety monitoring analysis method

By constructing a standard for qualified instruction behavior and a multi-dimensional feature deviation quantification, abnormal behavior of power terminals can be detected in real time. This solves the problems of lag and false alarm rate in low-frequency slow bypass attacks in existing technologies, and improves the security and monitoring accuracy of power terminals.

CN120729654BActive Publication Date: 2025-11-07GUIZHOU GUOYU YUANFENG ENERGY CONSERVATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511241225.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2025-11-07
Estimated Expiration
2045-09-02

AI Technical Summary

Technical Problem

Existing technologies lack real-time detection capabilities for bypass attacks on power terminals, making it impossible to effectively identify low-frequency, slow bypass attacks. This can lead to terminal system crashes and data leaks. Furthermore, static thresholds and behavioral standards can result in high false alarm rates, affecting the stability and security of power terminals.

Method used

By constructing qualified behavior standards for power terminal commands, and combining time-series clustering analysis and traffic profiling, command operation data is collected in real time, deviation is quantified, behavior standards are dynamically updated, and low-frequency slow bypass attacks are identified.

Benefits of technology

It enables real-time detection of low-frequency, slow bypass attacks, reduces false alarm rates, improves the security of power terminals and the accuracy of monitoring, and ensures the stable operation of the smart grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729654B_ABST
    Figure CN120729654B_ABST
Patent Text Reader

Abstract

The application discloses a kind of power terminal bypass security monitoring analysis methods, it is related to power terminal security technical field, including the following steps: according to power terminal historical instruction qualified operation log, by time series clustering analysis and flow portrait, the instruction qualified behavior standard of power terminal is constructed, the instruction operation data of power terminal is collected in real time, the instruction time series set of current power terminal is constructed, the operation time stamp and use flow of each type of instruction in the instruction time series set are acquired, the deviation of current power terminal instruction operation data relative to instruction qualified behavior standard is quantified by multidimensional feature comparison analysis, to judge whether power terminal exists low-frequency slow bypass attack phenomenon, if there is, then generate attack warning signal, otherwise, based on the instruction operation data in preset time interval, update power terminal qualified instruction behavior standard, improve the security of power terminal, guarantee the stable operation of smart grid.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of power terminal security, and relates to a power terminal bypass security monitoring and analyzing method. BACKGROUND

[0002] The rapid development of smart grids promotes the large-scale network deployment and application of power terminals. However, the high network and popularity of power terminals also bring new security challenges, such as frequent network attacks, data leaks, unauthorized access, and the like, which seriously threaten the security and reliability of the operation of power terminals, and further endanger the stable operation of the entire smart grid. Among them, bypass attack is the main means of attackers against power terminals, and has the characteristics of strong concealment and difficulty in defense. Therefore, how to effectively monitor the bypass security faced by power terminals is a key link to ensure the security of smart grids.

[0003] In the prior art, there are also some related solutions for monitoring the bypass security of power terminals. For example, the power terminal bypass security analysis method and system disclosed in Chinese Patent No. CN112329025A obtains the assumed energy consumption value matrix by calculating the assumed intermediate value of different data and assumed keys, compares it with the energy consumption curve matrix through a deep learning algorithm to obtain the optimal key, and finally judges the correctness of the optimal key and outputs the risk information, thereby improving the discovery accuracy of the leaked key of the power terminal bypass attack method.

[0004] In addition, the resource-constrained terminal device security monitoring method based on bypass disclosed in Chinese Patent No. CN112306778A analyzes the information existing form outside the system design range of the physical domain function block, establishes a connection relationship using the bypass information, and performs data analysis and feature extraction to establish a machine learning model, thereby realizing terminal device bypass security monitoring.

[0005] Although the above-mentioned solutions propose some solutions for monitoring the bypass security of power terminals, the prior art still has the following limitations. Specifically, (1) the protection mechanism of the prior art only outputs a risk warning when the terminal data is completely stolen or the power terminal reaches the collapse warning condition, lacks real-time detection and active early warning capability for abnormal operation behavior of the terminal during the implementation of the bypass attack, and causes the terminal defense to lag behind the attack process, resulting in sensitive information leakage, system function damage, and further affecting the normal operation of the power terminal.

[0006] (2) Existing technologies use static thresholds and isolated time windows to analyze the characteristics of a single bypass signal, which cannot identify the subthreshold cumulative effect of low-frequency slow bypass attacks. This makes it difficult for existing detection systems to detect low-frequency slow bypass attacks, resulting in serious consequences such as terminal system crashes and long-term data theft, affecting the stability and security of power terminals.

[0007] (3) Existing technologies rely on pre-set static behavior standards and cannot be dynamically updated according to the instructions of the power terminal. As the power terminal continues to operate, it is easy to cause cumulative behavioral feature deviations, which may lead to normal operations being misjudged as attack behavior, affecting the normal operation and execution efficiency of the power terminal. Summary of the Invention

[0008] In view of this, in order to solve the problems mentioned in the background technology, a power terminal bypass safety monitoring and analysis method is proposed.

[0009] The objective of this invention can be achieved through the following technical solution: This invention provides a power terminal bypass safety monitoring and analysis method, comprising: constructing a power terminal instruction qualification behavior standard based on the power terminal's historical instruction qualification operation logs through time-series clustering analysis and traffic profiling, wherein the instruction qualification behavior standard includes time-series high-frequency combinations, time-series probability distribution matrix, traffic fluctuation range, and traffic interaction range.

[0010] Real-time acquisition of instruction operation data from power terminals is used to construct an instruction timing set for power terminals within a preset time interval. The operation timestamps and usage traffic of various instructions within the instruction timing set are obtained. Multi-dimensional feature comparison analysis is used to quantify the deviation of power terminals from the qualified instruction behavior standard within the preset time interval.

[0011] Based on the deviation, it is determined whether the power terminal is subject to a low-frequency slow bypass attack. If so, an attack warning signal is generated; otherwise, the power terminal instruction qualification behavior standard is updated based on the instruction operation data within a preset time interval.

[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention constructs a standard for qualified instruction behavior and combines a multi-dimensional feature deviation real-time quantification mechanism to detect abnormal behavior of power terminals in real time during the implementation of low-frequency slow bypass attacks, generate attack warning signals, break through the lag of the prior art which only passively alarms after the attack, improve the security of power terminals, and ensure the stable operation of the smart grid.

[0013] (2) Based on the instruction operation data without abnormal behavior, the present invention dynamically updates the qualified behavior standard of power terminal instruction, so that the standard can be dynamically adjusted with the changes in power terminal business, solving the problems of high false alarm rate and long-term monitoring failure in the existing technology, and significantly improving the accuracy and reliability of power terminal instruction monitoring.

[0014] (3) The application accurately identifies the hidden asymptotic abnormal behavior of low-frequency slow bypass attacks through comprehensive feature analysis of instruction combination timing deviation, instruction distribution probability anomaly, flow fluctuation out-of-bounds and flow interaction parameter deviation in a preset time interval, ensuring the comprehensiveness and delicacy of power terminal security monitoring. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0016] Figure 1 The method of the application is implemented in the flowchart.

[0017] Figure 2 The logic flowchart for obtaining the high-frequency combination of instruction timing of the application is shown.

[0018] Figure 3 The logic flowchart for obtaining the flow fluctuation interval of the instruction of the application is shown. DETAILED DESCRIPTION

[0019] The technical solutions in the embodiments of the application will be described clearly and completely in the following with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only some embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.

[0020] Referring to Figure 1 The application provides a power terminal bypass security monitoring and analysis method, which comprises: constructing an instruction qualified behavior standard of a power terminal according to a historical instruction qualified operation log of the power terminal through timing clustering analysis and flow portrait depiction, wherein the instruction qualified behavior standard comprises a timing high-frequency combination, a timing probability distribution matrix, a flow fluctuation interval and a flow interaction interval.

[0021] Referring to Figure 2 As a preferred, the obtaining process of the instruction timing high-frequency combination comprises: extracting operation time stamps of various instructions in the historical instruction qualified operation log, and sorting the various instructions according to time sequence to obtain an instruction operation time sequence.

[0022] The instruction operation time sequence is traversed with a fixed step to generate various instruction operation combinations.

[0023] The sequence similarity between each pair of instruction operation combinations is obtained according to the length of the longest common subsequence of the instruction operation combinations.

[0024] The node graph is drawn according to a preset rule by taking each instruction operation combination as a node and taking the sequence similarity between the instruction operation combinations as an edge weight.

[0025] The breadth-first search is performed on the node graph, and a connected component thereof is identified as an independent clustering cluster, so that the instruction operation combinations in the same cluster are classified to obtain each clustering cluster.

[0026] The operation frequencies of the instruction operation combinations in the historical instruction qualified operation log are counted, and the instruction operation combinations in each clustering cluster are arranged in descending order according to the operation frequencies, so that the instruction operation combinations in the first preset number of each clustering cluster are selected as instruction timing high-frequency combinations.

[0027] It should be noted that the length of the longest common subsequence is obtained by comparing the two instruction operation combinations unit by unit, and if the instructions in the same unit are consistent, the unit is recorded as a matching unit, otherwise, the unit is recorded as a non-matching unit. After traversing all units, the number of accumulated matching units is taken as the length of the longest common subsequence of the two instruction sequences.

[0028] It should be noted that the sequence similarity is the ratio of the length of the longest common subsequence of each pair of instruction operation combinations to the length of the instruction operation combination sequence.

[0029] It should be noted that the process of drawing the node graph according to the preset rule includes: comparing the edge weight between each node with a preset connectivity threshold, if it is a greater relationship, a connection edge is established between the two nodes, otherwise, no connection edge is established, and the node graph is drawn by drawing all nodes and connection edges that meet the rule.

[0030] As a preferred embodiment, the process of obtaining the instruction timing probability distribution matrix includes: dividing a time window according to a preset time length, and counting the operation frequencies of each type of instruction in each time window in the historical instruction qualified operation log.

[0031] The operation frequency proportion of each type of instruction in the same time window of each day is calculated and taken as the distribution probability of each type of instruction in the corresponding time window, and the distribution probability of each type of instruction is spliced to generate an instruction probability distribution vector of each time window.

[0032] The unique ordered row encoding of each time window and the unique column encoding of each type of instruction are set, and the instruction probability distribution vector is combined to obtain an instruction timing probability distribution matrix.

[0033] It should be noted that the operation frequency proportion is the ratio of the operation frequency of each type of instruction to the total operation frequency of all instructions in the same time window of each day.

[0034] Referring to Figure 3 As a preferred, the obtaining process of the instruction flow fluctuation interval includes: counting the usage flow of each type of instruction in a certain time window in the historical instruction qualified operation log, and calculating the standard deviation and mean value of the usage flow of each type of instruction respectively.

[0035] According to the standard deviation of the usage flow of each type of instruction, a positive discrete indicator and a negative discrete indicator are independently configured.

[0036] The usage flow mean value, the positive discrete indicator and the negative discrete indicator of each type of instruction are comprehensively determined to determine the upper limit and the lower limit of the flow fluctuation of each type of instruction in the time window, so as to define the flow fluctuation interval of each type of instruction in the time window.

[0037] The above process is repeated to traverse all time windows to form the flow fluctuation interval of each type of instruction in each time window.

[0038] It should be noted that the positive discrete indicator is three times the standard deviation of the usage flow of each type of instruction, and the negative discrete indicator is three times the standard deviation of the usage flow of each type of instruction.

[0039] As a preferred, the obtaining process of the instruction flow interaction interval includes: counting the inbound usage flow and the outbound usage flow of each day in the historical instruction qualified operation log, taking the ratio of the two as a flow interaction parameter, and constructing a flow interaction ascending data set.

[0040] Based on a preset upper limit quantile value and a preset lower limit quantile value, quantile calculation is performed on the flow interaction ascending data set to extract the corresponding quantile value to define the instruction flow interaction interval, wherein the preset upper limit quantile value and the preset lower limit quantile value are statistical parameters for specifying the relative position in the ascending data, and the quantile value is the specific value of the preset percentile in the flow interaction ascending data set.

[0041] It should be noted that the preset upper limit quantile value and the preset lower limit quantile value can be exemplarily set to 75% quantile value and 25% quantile value, respectively, and the basis is that the 25% to 75% quantile interval can cover the normal data distribution range and exclude extreme outliers, so as to ensure that the flow interaction interval can reflect the flow interaction fluctuation under stable business mode.

[0042] The above quantile calculation can be realized by linear interpolation or nearest neighbor method.

[0043] Here, an example of a certain flow interaction ascending data set is According to the 25% quantile value and the 75% quantile value, the quantile values calculated by the linear interpolation method are 0.69 and 0.94, respectively, so as to define the instruction flow interaction interval.

[0044] Real-time acquisition of instruction operation data of the power terminal, construction of an instruction time sequence set of the power terminal within a preset time interval, and acquisition of operation time stamps and usage flow of various instructions in the instruction time sequence set, through multi-dimensional feature comparison and analysis, the deviation of the power terminal from the instruction qualified behavior standard within the preset time interval is quantified.

[0045] As a preferred, the deviation of the power terminal from the instruction qualified behavior standard within the preset time interval is quantified through multi-dimensional feature comparison and analysis, including: traversing the instruction time sequence set within the preset time interval with a fixed step, and generating each current instruction operation combination.

[0046] Extracting the instruction unit in the current instruction operation combination, counting the coverage frequency weight of each instruction time sequence high-frequency combination containing the instruction unit, and positioning the instruction time sequence high-frequency combination with the highest coverage frequency weight as the target instruction high-frequency combination.

[0047] Comparing the time sequence mode of the current instruction operation combination and the target instruction high-frequency combination, if a certain instruction unit in the current instruction operation combination does not conform to the time sequence adjacent relationship feature of the target instruction high-frequency combination, it is marked as a problem instruction unit.

[0048] Removing the problem instruction unit in the current instruction operation combination to generate a corrected instruction operation combination, verifying whether the corrected instruction operation combination matches the time sequence mode of the target instruction high-frequency combination, if it matches, it is determined that the power terminal has instruction parasitic abnormal behavior, otherwise it is determined that the power terminal has instruction recombination abnormal behavior.

[0049] It should be noted that the process of obtaining the coverage frequency weight is: through a fixed detection step, the current instruction operation combination is sampled by a sliding window, the number of times that the instruction subsequence of the current instruction operation combination and each high-frequency combination template in the same sliding window is consistent is counted, and the ratio of the number to the total number of sliding windows is taken as the coverage frequency weight.

[0050] It should be noted that the time sequence adjacent relationship feature is the consistent absolute position of the instruction unit in the combination, and the consistent continuous operation order of the instruction unit and the previous and subsequent instructions.

[0051] It should be noted that the process of verifying whether the corrected instruction operation combination matches the time sequence mode of the target instruction high-frequency combination is: starting from the first sequence, synchronously traversing each unit of the corrected instruction operation combination and the target instruction high-frequency combination, if the instructions of each unit are consistent, the time sequence modes of the two match, otherwise the time sequence modes of the two do not match.

[0052] As a kind of preference, the deviation degree of power terminal relative to qualified instruction behavior standard in preset time interval is quantified by multidimensional feature comparison analysis, comprising: by threshold comparison to each element in the instruction time sequence probability distribution matrix, the high probability instruction and low probability instruction of each time window are determined.

[0053] The operation frequency of high probability instruction and low probability instruction in the same time window of each day in preset time interval is counted, and the high probability instruction daily frequency variation line chart and low probability instruction daily frequency variation line chart of each time window are drawn respectively.

[0054] If the frequency line of high probability instruction of a certain time window presents continuous descending trend and the final value is lower than the minimum value of historical frequency, then it is marked as high probability instruction attenuation abnormal event.

[0055] If the frequency line of low probability instruction of a certain time window presents continuous ascending trend and the final value is higher than the maximum value of historical frequency, then it is marked as low probability instruction sudden increase abnormal event.

[0056] When high probability instruction attenuation abnormal event and low probability instruction sudden increase abnormal event exist simultaneously in preset time interval, it is determined that power terminal exists instruction shunting abnormal behavior.

[0057] It should be noted that the process of determining high probability instruction and low probability instruction of each time window is: comparing each element in the instruction time sequence probability distribution matrix with preset high probability threshold and preset low probability threshold, if an element is greater than preset high probability threshold, then the instruction corresponding to it is high probability instruction, if an element is less than preset low probability threshold, then the instruction corresponding to it is low probability instruction, all elements in the matrix are traversed to determine high probability instruction and low probability instruction of each time window.

[0058] It should be noted that the determination basis of continuous descending trend and ascending trend of frequency line is: least square method operation is carried out on each line point in the daily frequency variation line chart of a certain instruction to obtain the trend line of daily frequency variation line.

[0059] If the slope of the trend line is negative, then it is determined that the frequency line of the instruction presents continuous descending trend.

[0060] If the slope of the trend line is positive, then it is determined that the frequency line of the instruction presents continuous ascending trend.

[0061] As a kind of preference, the deviation degree of power terminal relative to qualified instruction behavior standard in preset time interval is quantified by multidimensional feature comparison analysis, comprising: the use flow of each type of instruction in the same time window of each day in preset time interval is called, and daily average flow sequence of each type of instruction is constructed according to date order.

[0062] The daily inbound and outbound usage traffic of the instruction in a preset time interval is counted to obtain the traffic interaction parameter of each day in the preset time interval, and a traffic interaction parameter sequence is constructed according to the chronological order of the dates.

[0063] When all the following conditions are met, it is determined that the power terminal has data leakage abnormal behavior: a. The daily average traffic sequence of a certain instruction shows a continuous positive trend, and the maximum traffic exceeds the instruction traffic fluctuation interval.

[0064] b. The traffic interaction parameter sequence shows a continuous positive trend, and the maximum traffic interaction parameter exceeds the instruction traffic interaction interval.

[0065] It should be noted that the determination of the continuous positive trend is based on the fitting of the data in the daily average traffic sequence and the traffic interaction parameter sequence by the Matlab fitting toolbox to obtain the corresponding linear change formula.

[0066] When the slope of the linear change formula is positive, the data in the sequence shows a continuous positive trend.

[0067] As a preferred, the deviation degree of the power terminal from the qualified instruction behavior standard in the preset time interval is quantified by multi-dimensional feature comparison analysis, including: setting deviation levels for different abnormal behavior combinations of the power terminal, and assigning corresponding deviation degree values to each deviation level, wherein the deviation levels are in the order of first, second, third and fourth deviation levels from large to small according to the deviation degree assignment.

[0068] Based on the abnormal behavior performance of the power terminal in the preset time interval, the corresponding abnormal behavior combination and the belonging deviation level are matched, and the deviation degree of the belonging deviation level is assigned as the deviation degree of the power terminal from the qualified instruction behavior standard in the preset time interval.

[0069] It should be noted that the matching rule between the abnormal behavior combination of the power terminal and its belonging deviation level is as follows: when the power terminal has no abnormal behavior, the deviation degree is assigned as 0.

[0070] When the power terminal has only one kind of abnormal behavior, it is determined that the power terminal is subjected to a trial attack but has not formed a complete attack chain, which meets the initial characteristics of low-frequency slow bypass attack, and the deviation degree is set as the fourth deviation level.

[0071] When the power terminal has instruction parasitic abnormal behavior and at the same time has instruction shunting abnormal behavior or data leakage abnormal behavior, it is determined that the attacker uses parasitic instructions to maintain a hidden channel and perform data theft, which meets the mid-term collaborative characteristics of low-frequency slow bypass attack, and the deviation degree is set as the third deviation level.

[0072] When the power terminal simultaneously exists instruction shunting abnormal behavior and data leakage abnormal behavior, it is determined that the attacker uses high-frequency operation noise to cover bulk data leakage, which is consistent with the characteristics of low-frequency slow bypass attack to create a legal illusion through instruction shunting, and the deviation degree is set as the third deviation level.

[0073] When the power terminal exists instruction recombination abnormal behavior and simultaneously exists instruction shunting abnormal behavior or data leakage abnormal behavior, it is determined that the core operation chain of the power terminal is destroyed and data stealing is accelerated, which is consistent with the characteristics of the later upgrade of low-frequency slow bypass attack, and the deviation degree is set as the second deviation level.

[0074] When the power terminal exists any three abnormal behaviors, it is determined that the power terminal is continuously stolen sensitive data, which is consistent with the characteristics of multi-module cooperative attack of low-frequency bypass attack, and the deviation degree is set as the first deviation level.

[0075] The embodiment of the application accurately identifies the hidden asymptotic abnormal behavior of low-frequency slow bypass attack by comprehensively analyzing the instruction combination time sequence deviation, instruction distribution probability anomaly, flow fluctuation out-of-bounds and flow interaction parameter deviation in the preset time interval, and ensures the comprehensiveness and delicacy of the power terminal security monitoring.

[0076] According to the deviation degree, it is judged whether the power terminal exists low-frequency slow bypass attack phenomenon, if exists, an attack warning signal is generated, otherwise the power terminal instruction qualified behavior standard is updated based on the instruction operation data in the preset time interval.

[0077] As a preferred, the judgment basis that the power terminal exists low-frequency slow bypass attack phenomenon is that when the deviation degree reaches the deviation degree value corresponding to the third deviation level, it is judged that the power terminal is attacked by low-frequency slow bypass attack.

[0078] It should be noted that when the deviation degree is 0, a qualified instruction operation data signal is generated, and the power terminal instruction qualified behavior standard is updated.

[0079] When the deviation degree reaches the deviation degree value corresponding to the fourth deviation level, an abnormal behavior tracking signal is generated, the power terminal qualified behavior standard updating step is skipped, and the abnormal behavior existing in the power terminal is continuously monitored.

[0080] The embodiment of the application constructs the instruction qualified behavior standard, combines the multi-dimensional feature deviation degree real-time quantization mechanism, detects the abnormal behavior of the power terminal in the implementation process of the low-frequency slow bypass attack, generates an attack warning signal, breaks through the hysteresis of the passive alarm after the attack in the prior art, improves the security of the power terminal, and ensures the stable operation of the smart grid.

[0081] The embodiment of the present application dynamically updates the qualified behavior standard of the power terminal instruction according to the instruction operation data of the non-abnormal behavior, so that the standard can be dynamically adjusted along with the change of the power terminal service, solves the problems of high false positive rate and long-term monitoring failure of the prior art, and significantly improves the accuracy and reliability of the power terminal instruction monitoring.

[0082] The above-described embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented by software, the above-described embodiments can be implemented in whole or in part in the form of a computer program product.

[0083] Those of ordinary skill in the art can realize that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized by electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0084] In addition, each functional module in each embodiment of the present application can be integrated in one processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0085] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0086] Finally, the above is merely preferred embodiments of the present application, and is not used to limit the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be covered in the protection scope of the present application.

Claims

1. A method of power terminal bypass safety monitoring analysis, characterized by, The application comprises: According to the power terminal historical instruction qualified operation log, through time series clustering analysis and traffic portrait description, the instruction qualified behavior standard of the power terminal is constructed, and the instruction qualified behavior standard comprises time series high-frequency combination, time series probability distribution matrix, traffic fluctuation interval and traffic interaction interval; Real-time collection of instruction operation data of the power terminal, construction of instruction time series set of the power terminal in a preset time interval, and acquisition of operation time stamp and usage traffic of each type of instruction in the instruction time series set, and deviation degree of the power terminal relative to the instruction qualified behavior standard in the preset time interval is quantified through multi-dimensional feature comparison and analysis; According to the deviation degree, it is judged whether the power terminal exists low-frequency slow bypass attack phenomenon, if exists, an attack warning signal is generated, otherwise the instruction qualified behavior standard of the power terminal is updated based on the instruction operation data in the preset time interval; The acquisition process of the instruction time series high-frequency combination comprises: extracting the operation time stamp of each type of instruction in the historical instruction qualified operation log, and sorting each type of instruction according to time sequence to obtain the instruction operation time sequence; The instruction operation combination is generated by traversing the instruction operation time sequence with a fixed step length; the sequence similarity between each instruction operation combination is obtained according to the length of the longest common subsequence of each pair of instruction operation combinations; each instruction operation combination is taken as a node, and the sequence similarity between each instruction operation combination is taken as an edge weight, and the node graph is drawn according to a preset rule; the breadth-first search is performed on the node graph, and the connected components are identified as independent clustering clusters, the instruction operation combination of the same cluster node is classified, and each clustering cluster is obtained; the operation frequency of each instruction operation combination in the historical instruction qualified operation log is counted, and the instruction operation combination of each clustering cluster is arranged in descending order, and the first preset number of instruction operation combinations in each clustering cluster are selected as the instruction time series high-frequency combination.

2. The method of claim 1, wherein, The acquisition process of the instruction time series probability distribution matrix comprises: According to the preset time length, the time window is divided, and the operation frequency of each type of instruction in each time window in the historical instruction qualified operation log is counted; The operation frequency proportion of each type of instruction in the historical same time window is calculated, which is taken as the distribution probability of each type of instruction in the corresponding time window, and the distribution probability of each type of instruction is spliced to generate the instruction probability distribution vector of each time window; The unique ordered row encoding of each time window and the unique column encoding of each type of instruction are set, and the instruction probability distribution vector is combined to obtain the instruction time series probability distribution matrix.

3. The method of claim 2, wherein the method further comprises: The acquisition process of the instruction traffic fluctuation interval comprises: The usage traffic of each type of instruction in a certain time window in the historical instruction qualified operation log is counted, and the standard deviation and mean value of the usage traffic of each type of instruction are calculated respectively; According to the standard deviation of the usage traffic of each type of instruction, the positive and negative discrete indicators are independently configured; The usage traffic mean value, positive and negative discrete indicators of each type of instruction are comprehensively determined to determine the upper limit and lower limit of the traffic fluctuation of each type of instruction in the time window, so as to define the traffic fluctuation interval of each type of instruction in the time window; Repeat the above process to traverse all time windows to form the traffic fluctuation interval of each type of instruction in each time window.

4. The method of claim 3, wherein the method further comprises: The obtaining process of the instruction flow interaction interval includes: The inbound and outbound usage flows of each day in the historical instruction qualified operation log are counted, and a ratio of the two is taken as a flow interaction parameter to construct a flow interaction ascending data set; Based on a preset upper limit quantile value and a preset lower limit quantile value, quantile calculation is performed on the flow interaction ascending data set to extract corresponding quantile values to define the instruction flow interaction interval, wherein the preset upper limit quantile value and the preset lower limit quantile value are statistical parameters for specifying the relative position in the ascending data set, and the quantile value is the specific value of the preset percentile in the flow interaction ascending data set.

5. The method of claim 1, wherein the method further comprises: The deviation degree of the power terminal from the relative qualified instruction behavior standard in the preset time interval is quantified by multi-dimensional feature comparison and analysis, including: The instruction time sequence set in the preset time interval is traversed with a fixed step to generate each current instruction operation combination; The instruction unit in the current instruction operation combination is extracted, the coverage frequency weight of each instruction time sequence high-frequency combination containing the instruction unit is counted, and the instruction time sequence high-frequency combination with the highest coverage frequency weight is positioned as a target instruction high-frequency combination; The time sequence mode of the current instruction operation combination and the target instruction high-frequency combination is compared, and if a certain instruction unit in the current instruction operation combination does not conform to the time sequence adjacent relationship feature of the target instruction high-frequency combination, it is marked as a problem instruction unit; The problem instruction unit in the current instruction operation combination is removed to generate a corrected instruction operation combination, and it is verified whether the corrected instruction operation combination matches the time sequence mode of the target instruction high-frequency combination, if it matches, it is determined that the power terminal has an instruction parasitic abnormal behavior, otherwise it is determined that the power terminal has an instruction recombination abnormal behavior.

6. The method of claim 2, wherein the method further comprises: The deviation degree of the power terminal from the relative qualified instruction behavior standard in the preset time interval is quantified by multi-dimensional feature comparison and analysis, including: The high-probability instruction and the low-probability instruction of each time window are determined by threshold comparison of each element in the instruction time sequence probability distribution matrix; The operation frequency of the high-probability instruction and the low-probability instruction in the same time window of each day in the preset time interval is counted, and the daily frequency change line graph of the high-probability instruction and the daily frequency change line graph of the low-probability instruction of each time window are drawn respectively; If the frequency line of the high-probability instruction of a certain time window shows a continuous downward trend and the final value is lower than the minimum historical frequency, it is marked as a high-probability instruction attenuation abnormal event; If the frequency line of the low-probability instruction of a certain time window shows a continuous upward trend and the final value is higher than the maximum historical frequency, it is marked as a low-probability instruction sudden increase abnormal event; When there are both high-probability instruction attenuation abnormal events and low-probability instruction sudden increase abnormal events in the preset time interval, it is determined that the power terminal has an instruction shunt abnormal behavior.

7. The method of claim 4, wherein the method further comprises: The deviation degree of the power terminal from the relative qualified instruction behavior standard in the preset time interval is quantified by multi-dimensional feature comparison and analysis, including: The usage flow of each type of instruction in the same time window of each day in the preset time interval is called, and a daily average flow sequence of each type of instruction is constructed according to the chronological order; The command inbound and outbound traffic of each day in the preset time interval is counted to obtain the traffic interaction parameters of each day in the preset time interval, and a traffic interaction parameter sequence is constructed according to the chronological order of the dates. When all of the following conditions are met, it is determined that the power terminal has data leakage abnormal behavior: a. The daily average traffic sequence of a certain command presents a sustained positive trend, and the maximum traffic exceeds the command traffic fluctuation interval; b. The traffic interaction parameter sequence presents a sustained positive trend, and the maximum traffic interaction parameter exceeds the command traffic interaction interval.

8. The method of claim 1, wherein the method further comprises: The deviation degree of the power terminal from the qualified command behavior standard in the preset time interval is quantified by multi-dimensional feature comparison and analysis, including: For different abnormal behavior combinations of the power terminal, deviation levels are set, and corresponding deviation degree values are assigned to each deviation level, wherein the deviation levels are in the order of first, second, third and fourth deviation levels from large to small according to the deviation degree assignment; Based on the abnormal behavior performance of the power terminal in the preset time interval, the corresponding abnormal behavior combination and the belonging deviation level are matched, and the deviation degree value of the belonging deviation level is taken as the deviation degree of the power terminal from the qualified command behavior standard in the preset time interval.

9. The method of claim 8, wherein the method further comprises: The judgment basis for the power terminal having low-frequency slow bypass attack phenomenon is that when the deviation degree reaches the deviation degree value corresponding to the third deviation level, it is determined that the power terminal is subjected to low-frequency slow bypass attack.

Citation Information

Patent Citations

  • Bypass-based resource-constrained terminal equipment safety monitoring method

    CN112306778A

  • Power terminal bypass safety analysis method and power terminal bypass safety analysis system

    CN112329025A

  • Bypass data monitoring system based on power line carrier

    CN113472394A

  • Power terminal equipment fingerprint generation method and device, electronic equipment and storage medium

    CN116389420A