Network security risk analysis method for electric power information physical fusion system
By analyzing the traffic changes and connection information of device nodes in the power information-physical fusion system and calculating the impact coefficient and abnormal cumulative index, the problem of inaccurate risk assessment caused by not considering the correlation of device nodes in the existing technology is solved, and a more accurate network security risk assessment is achieved.
Patent Information
- Application Number
- CN202511049516.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-10-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies fail to comprehensively and accurately assess network security risks in power cyber-physical fusion systems because they do not consider the correlation between device nodes.
The node anomaly index is determined by analyzing the traffic changes of device nodes, and the impact coefficient and anomaly cumulative index are calculated based on the connection information between device nodes. Finally, the risk index of the device node is quantified, and the replaceability of the device node is considered to accurately assess the network risk.
It improves the accuracy of power system network security risk analysis and provides more comprehensive and reliable risk analysis information.
Smart Images

Figure CN120768645A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a network security risk analysis method for an electric power cyber-physical fusion system. Background Art
[0002] With the continuous development of power system informatization, power cyber-physical systems (CPS) integrate advanced information and automation technologies such as perception, computing, communication, and control, creating complex systems in which physical and cyber elements map to each other, interact in a timely manner, and collaborate efficiently. The characteristics of these systems make them highly vulnerable to attack, necessitating cybersecurity analysis to ensure stable system operation.
[0003] To identify the security risks faced by the system network, existing technologies analyze each device node in the system network separately to identify device nodes with abnormal risks. However, this method does not take into account the correlation between different device nodes, and therefore cannot accurately assess the actual abnormal risks of each device node. This makes the final output of the network risk assessment information not comprehensive and accurate.
[0004] That is to say, the existing technology has low accuracy in analyzing the security risks of power system networks. Summary of the Invention
[0005] In order to solve the technical problem of low accuracy in the existing technology for analyzing security risks of power system networks, the purpose of the present invention is to provide a network security risk analysis method for power cyber-physical fusion systems. The technical solution adopted is as follows: In a first aspect, an embodiment of the present invention provides a method for analyzing network security risks of a power cyber-physical fusion system, the method comprising: Analyzing traffic changes of each device node in a target network, which is a virtual network corresponding to the power cyber-physical fusion system, to obtain a node anomaly index of each device node; Determine multiple influence coefficients of each device node based on connection information between different device nodes, wherein the influence coefficients are used to indicate the degree of influence of the corresponding device node on other device nodes after the abnormality occurs; Determine the cumulative abnormality index of each device node according to multiple influence coefficients of each device node and the node abnormality index of each device node; Obtaining a risk index for each device node based on the anomaly cumulative index of each device node and a replacement index of each device node, wherein the replacement index is used to indicate the number of device nodes that replace the corresponding device node; Analyze the risk index of each device node to obtain risk analysis information of the target network.
[0006] In one embodiment, analyzing the traffic changes of each device node to obtain the node anomaly index of each device node includes: Acquire multiple flow change data for each device node within a current monitoring period, wherein the multiple flow change data correspond one-to-one to multiple consecutive monitoring time periods within the current monitoring period, and the flow change data is used to indicate flow changes of the corresponding device node within the corresponding monitoring time period; Performing anomaly detection on multiple flow change data of each device node within a current monitoring period to determine multiple abnormal flow change data and multiple normal flow change data corresponding to each device node; The data differences between a plurality of abnormal traffic change data and a plurality of normal traffic change data corresponding to each device node are analyzed to obtain a node abnormality index of each device node.
[0007] In one embodiment, analyzing the data differences between the plurality of abnormal traffic change data and the plurality of normal traffic change data corresponding to each device node to obtain the node abnormality index of each device node includes: Calculate the ratio of the number of abnormal traffic change data corresponding to each device node to the number of traffic change data in the current monitoring period, and obtain the abnormal data ratio of each device node; Calculate the average of multiple normal traffic change data corresponding to each device node to obtain reference data corresponding to each device node; Calculate the absolute value of the difference between each abnormal flow change data corresponding to each device node and its corresponding reference data to obtain the abnormal amplitude value of each abnormal flow change data corresponding to each device node; Calculate the sum of multiple abnormal amplitude values of multiple abnormal traffic change data corresponding to each device node to obtain the abnormal amplitude cumulative value of each device node; The product of the accumulated abnormal amplitude value of each device node and the abnormal data ratio is calculated to obtain the node abnormality index of each device node.
[0008] In one embodiment, multiple influence coefficients of each device node are determined based on connection information between different device nodes, including: Obtaining a hub index of a first device node and a communication independence coefficient of a second device node, wherein the first device node and the second device node are any two different device nodes among the plurality of device nodes, the hub index is used to indicate the number of other device nodes associated with the device node in the target network, and the communication independence coefficient is used to indicate the risk resistance of the device node when communicating in the target network; Calculating the product of a control coefficient and a control frequency value of the first device node over the second device node to obtain a control influence coefficient of the first device node over the second device node, wherein the control coefficient is used to indicate the degree to which the first device node is controlled by the first device node when the first device node and the second device node exchange control instructions, and the control frequency value is used to indicate the historical frequency of the exchange of control instructions between the first device node and the second device node; Calculating the product of a communication coefficient and a communication frequency value of the first device node to the second device node to obtain a communication influence coefficient of the first device node to the second device node, wherein the communication coefficient is used to indicate the degree to which the first device node is influenced by the first device node when the first device node and the second device node exchange power information, and the communication frequency value is used to indicate a historical frequency of the exchange of power information between the first device node and the second device node; Calculating the sum of a control influence coefficient and a communication influence coefficient of the first device node on the second device node to obtain a to-be-processed coefficient of the first device node on the second device node; Calculating a ratio of a hub index of the first device node to a communication independence coefficient of the second device node to obtain a correction parameter of the first device node to the second device node; The product of the correction parameter of the first device node on the second device node and the coefficient to be processed is calculated to obtain the influence coefficient of the first device node on the second device node.
[0009] In one embodiment, the step of obtaining the hub index of the first device node includes: Calculating a ratio of the number of neighboring nodes of the first device node to the total number of nodes to obtain a node index of the first device node, wherein the number of neighboring nodes is the number of device nodes adjacent to the first device node, and the total number of nodes is the total number of multiple device nodes included in the target network; identifying a plurality of out-of-band device nodes among the plurality of device nodes according to the first device node, wherein the out-of-band device nodes are not adjacent to the first device node; Searching for the shortest communication path between any two different out-of-band device nodes among the plurality of out-of-band device nodes to obtain a plurality of out-of-band communication paths; Among the multiple out-of-band communication paths, determining the out-of-band communication path including the first device node as a target communication path; Calculating a proportion of the target communication path in the plurality of out-of-band communication paths to obtain a path index of the first device node; The product of the path index and the node index of the first device node is calculated to obtain the hub index of the first device node.
[0010] In one embodiment, the step of acquiring the communication independence coefficient of the second device node includes: Acquire multiple communication paths of the second device node in the target network; Determining an independent communication path corresponding to the second device node among the plurality of communication paths corresponding to the second device node, wherein the independent communication path is a communication path of a device node among the plurality of communication paths that does not overlap with other communication paths except for the second device node; A communication independence coefficient of the second device node is determined according to the number of independent communication paths corresponding to the second device node.
[0011] In one embodiment, determining the cumulative abnormality index of each device node based on multiple influence coefficients of each device node and the node abnormality index of each device node includes: Obtaining multiple target influence coefficients associated with a target device node, wherein the target device node is any one device node among the multiple device nodes, the target influence coefficient is an influence coefficient of a third device node on the target device node, and the third device node is a device node adjacent to the target device node among the multiple device nodes; Calculating the product of each target influence coefficient and the node anomaly index of the corresponding third device node to obtain multiple node anomaly conduction indices associated with the target device node; The node anomaly index of the target device node and the sum of multiple node anomaly conduction indexes associated with the target device node are calculated to obtain the anomaly cumulative index of the target device node.
[0012] In one embodiment, obtaining the risk index of each device node based on the abnormal cumulative index of each device node and the replacement index of each device node includes: Among the one or more hyperedges corresponding to each device node, determining a hyperedge including the least number of device nodes as a target hyperedge for each device node; Calculate the difference between the number of device nodes included in the target hyperedge of each device node and 1 to obtain the replacement index of each device node; The ratio of the abnormal cumulative index of each device node to the replacement index of each device node is calculated to obtain the risk index of each device node.
[0013] In one embodiment, analyzing the risk index of each device node to obtain risk analysis information of the target network includes: Sorting the plurality of device nodes in descending order of risk index to obtain a node sequence; Determine the first Q device nodes in the node sequence as risky device nodes, where Q is an integer greater than 1; Analyze the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network.
[0014] In one embodiment, analyzing the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network includes: Determine at least one risky hyperedge based on the Q risky device nodes, wherein the risky hyperedge is a hyperedge including a number of risky device nodes greater than or equal to a number threshold; The risk analysis information is generated according to the at least one risk hyperedge.
[0015] In a second aspect, another embodiment of the present invention provides a network security risk analysis device for a power cyber-physical fusion system, the device comprising: a traffic analysis module configured to analyze traffic changes of each of the multiple device nodes included in a target network, and obtain a node anomaly index of each device node, wherein the target network is a virtual network corresponding to the power cyber-physical fusion system; A coefficient calculation module determines a plurality of influence coefficients of each device node based on connection information between different device nodes, wherein the influence coefficient is used to indicate the degree of influence of the corresponding device node on other device nodes after the abnormality occurs; An anomaly analysis module, configured to determine an anomaly cumulative index of each device node based on multiple influence coefficients of each device node and a node anomaly index of each device node; a risk calculation module, configured to obtain a risk index for each device node based on the anomaly cumulative index of each device node and a replacement index of each device node, wherein the replacement index indicates the number of device nodes that have replaced the corresponding device node; The risk assessment module is used to analyze the risk index of each device node to obtain risk analysis information of the target network.
[0016] In a third aspect, another embodiment of the present invention further provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the steps of the method described in the first aspect when executed by the processor.
[0017] In a fourth aspect, another embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0018] The present invention has the following beneficial effects: The present invention analyzes the traffic changes of each device node to determine the node anomaly index of each device node, that is, to determine the probability of an anomaly at each device node, and then further analyzes the connection information between different device nodes to determine multiple influence coefficients of each device node, that is, to determine the degree of influence of each device node on other device nodes. Then, combined with the aforementioned node anomaly index and influence coefficient, the anomaly cumulative index of each device node is calculated, that is, the true anomaly probability of each device node considering the anomaly risk transmitted by other device nodes is calculated. Finally, according to the number of replaceable device nodes for each device node and the corresponding true anomaly probability, the risk index of each device is accurately quantified to obtain more comprehensive and accurate risk analysis information through analysis, thereby improving the accuracy of the analysis of safety risks of the power system network. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 A schematic flow chart of a method for analyzing network security risks of a power cyber-physical fusion system provided by one embodiment of the present invention; Figure 2 A schematic structural diagram of a network security risk analysis device for a power cyber-physical fusion system provided by one embodiment of the present invention; Figure 3 The present invention provides a schematic structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0021] To further illustrate the technical means and effectiveness of the present invention in achieving its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effectiveness of a cybersecurity risk analysis method for a power cyber-physical fusion system proposed in accordance with the present invention. In the following description, references to different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.
[0022] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0023] The following describes in detail a specific scheme of a network security risk analysis method for a power cyber-physical fusion system provided by the present invention with reference to the accompanying drawings.
[0024] This paper proposes a network security risk analysis method for power information-physical fusion system. Figure 1 , which shows a schematic flow chart of a method for analyzing network security risks of a power cyber-physical fusion system provided by one embodiment of the present invention, the method comprising the following steps: Step S1: Analyze traffic changes of each device node in a target network to obtain a node anomaly index of each device node.
[0025] Among them, the target network is a virtual network corresponding to the power information-physical fusion system, and each of the device nodes, that is, the corresponding target network, is an electric power device in the power information-physical fusion system, such as renewable energy equipment (such as photovoltaic inverters, wind turbines), traditional energy equipment (such as gas turbines, thermal power generators), smart substation equipment (such as smart circuit breakers, electronic transformers), smart meters, smart distribution terminals, smart sensors, industrial Ethernet switches, edge computing gateways, etc.
[0026] Traffic changes for each device node can be understood as how the data traffic of each device node changes over time within the corresponding monitoring period. The duration of the monitoring period can be set based on experience. For example, if the monitoring period is set to one or three days, the node anomaly index of each device node is calculated every one or three days.
[0027] Furthermore, analyzing the traffic changes of each device node to obtain the node anomaly index of each device node includes: obtain a plurality of traffic change data of each device node in a current monitoring period, wherein the plurality of traffic change data and a plurality of continuous monitoring time periods in the current monitoring period are one-to-one corresponding, and the traffic change data is used to indicate a traffic change of the corresponding device node in the corresponding monitoring time period; perform anomaly detection on the plurality of traffic change data of each device node in the current monitoring period to determine a plurality of abnormal traffic change data and a plurality of normal traffic change data corresponding to each device node; analyze data differences between the plurality of abnormal traffic change data and the plurality of normal traffic change data corresponding to each device node to obtain a node anomaly index of each device node.
[0028] It should be understood that the number of monitoring time periods included in each monitoring period is constant, and the number of continuous monitoring time periods obtained based on the monitoring period can be set based on experience, such as 24.
[0029] The traffic change data can be understood as a Hurst index corresponding to a traffic time sequence (composed of a plurality of traffic values collected at a plurality of time points in the monitoring time period) of the corresponding device node in the corresponding monitoring time period.
[0030] In this process, the plurality of traffic change data of each device node is detected to identify the plurality of abnormal traffic change data and the plurality of normal traffic change data corresponding to each device node, and then the data differences between the plurality of abnormal traffic change data and the plurality of normal traffic change data corresponding to each device node are analyzed to determine the node anomaly index for quantifying the abnormal probability reflected by each device node at the traffic level.
[0031] For example, the operation of the above-mentioned anomaly detection can be completed by using a local outlier factor (LOF) anomaly algorithm.
[0032] Further, the analysis of the data differences between the plurality of abnormal traffic change data and the plurality of normal traffic change data corresponding to each device node to obtain the node anomaly index of each device node comprises: calculate a quantity ratio between the plurality of abnormal traffic change data corresponding to each device node and the plurality of traffic change data of each device node in the current monitoring period to obtain an abnormal data proportion of each device node; calculate a mean value of the plurality of normal traffic change data corresponding to each device node to obtain reference data corresponding to each device node; Calculate the absolute value of the difference between each abnormal flow change data corresponding to each device node and its corresponding reference data to obtain the abnormal amplitude value of each abnormal flow change data corresponding to each device node; Calculate the sum of multiple abnormal amplitude values of multiple abnormal traffic change data corresponding to each device node to obtain the abnormal amplitude cumulative value of each device node; The product of the accumulated abnormal amplitude value of each device node and the abnormal data ratio is calculated to obtain the node abnormality index of each device node.
[0033] For example, the node abnormality index of the vth device node among the multiple device nodes is It can be expressed as: ; in, Indicates the number of abnormal traffic change data corresponding to the vth device node, Indicates the number of multiple flow change data of the vth device node in the current monitoring period. Indicates the i-th abnormal traffic change data among the multiple abnormal traffic change data corresponding to the v-th device node, Represents the mean of multiple normal traffic change data corresponding to the v-th device node (that is, the reference data corresponding to the v-th device node).
[0034] Based on the above settings, by calculating the proportion of abnormal traffic change data in multiple traffic change data of the device node in the current monitoring period, and combining the data difference between each abnormal traffic change data and the corresponding normal traffic change data, the node anomaly index of the corresponding device node can be accurately quantified from two aspects: the frequency of occurrence of abnormal data and the degree of abnormality shown by the abnormal data.
[0035] It should be understood that the higher the proportion of abnormal data of the device node, the higher the frequency of abnormal traffic fluctuations in the device node in the current monitoring period, which means that the device node is more likely to have abnormal risks in the current monitoring period. Therefore, the node anomaly index of the device node is also higher.
[0036] Similarly, the higher the cumulative value of the abnormal amplitude of the device node, the greater the overall deviation of the multiple abnormal traffic change data of the device node in the current monitoring period from the normal traffic change data, which means that the possibility of abnormal risk of the device node in the current monitoring period is greater. Therefore, the node abnormality index of the device node is also higher.
[0037] Step S2: Determine multiple influence coefficients of each device node based on the connection information between different device nodes.
[0038] The impact coefficient is used to indicate the degree of impact of an abnormality in a corresponding device node on other device nodes.
[0039] The connection information between different device nodes is used to indicate whether a connection line exists between different device nodes and the direction of the connection line between different device nodes.
[0040] For example, if there is no connection relationship between the power device X1 and the power device X2, then there is no connection relationship between the two device nodes corresponding to the power device X1 and the power device X2; If there is a connection relationship between power device X1 and power device X2, and power device X1 is a control device and power device X2 is an execution device (the control device sends control instructions to the straight-line device, and the execution device performs related actions based on the control instructions), there will be a unidirectional connection line from the device node corresponding to power device X1 to the device node corresponding to power device X2; If there is a connection relationship between the power device X1 and the power device X2, and the power device X1 and the power device X2 are control devices of the same level (different control devices of the same level can communicate freely without limiting the communication direction), there will be a bidirectional connection line connecting the device node corresponding to the power device X1 in series with the device node corresponding to the power device X2.
[0041] Furthermore, the determining of multiple influence coefficients of each device node based on the connection information between different device nodes includes: Obtaining a hub index of a first device node and a communication independence coefficient of a second device node, wherein the first device node and the second device node are any two different device nodes among the plurality of device nodes, the hub index is used to indicate the number of other device nodes associated with the device node in the target network, and the communication independence coefficient is used to indicate the risk resistance of the device node when communicating in the target network; Calculating the product of a control coefficient and a control frequency value of the first device node over the second device node to obtain a control influence coefficient of the first device node over the second device node, wherein the control coefficient is used to indicate the degree to which the first device node is controlled by the first device node when the first device node and the second device node exchange control instructions, and the control frequency value is used to indicate the historical frequency of the exchange of control instructions between the first device node and the second device node; Calculating the product of a communication coefficient and a communication frequency value of the first device node to the second device node to obtain a communication influence coefficient of the first device node to the second device node, wherein the communication coefficient is used to indicate the degree to which the first device node is influenced by the first device node when the first device node and the second device node exchange power information, and the communication frequency value is used to indicate a historical frequency of the exchange of power information between the first device node and the second device node; Calculating the sum of a control influence coefficient and a communication influence coefficient of the first device node on the second device node to obtain a to-be-processed coefficient of the first device node on the second device node; Calculating a ratio of a hub index of the first device node to a communication independence coefficient of the second device node to obtain a correction parameter of the first device node to the second device node; The product of the correction parameter of the first device node on the second device node and the coefficient to be processed is calculated to obtain the influence coefficient of the first device node on the second device node.
[0042] The other device nodes associated with a device node in the target network can be understood as other device nodes connected to the corresponding device node via connecting lines. A higher hub index indicates a greater number of other device nodes associated with the corresponding device node in the target network. Therefore, a device node anomaly has a greater impact on other device nodes, and the device node's influence coefficient on other device nodes is higher.
[0043] The risk resistance of a device node when communicating in the target network can be approximately understood as the redundancy of the several communication paths corresponding to the device node in the target network. That is, the more communication paths corresponding to the device node in the target network, and the higher the degree of independence between the several communication paths, the stronger the risk resistance of the device node when communicating in the target network (meaning that after one of the communication paths fails or is abnormal, communication can be continued conveniently through other communication paths). Therefore, the corresponding device node is less affected by the abnormalities of other device nodes, and the lower the influence coefficient of other device nodes on the device node is.
[0044] The steps for obtaining the hub index and communication independence coefficient mentioned above can be found in the subsequent instructions and will not be repeated here.
[0045] In the application, the control coefficient and the communication coefficient of the first device node to the second device node can be obtained by analyzing the connection information between different device nodes based on a preset rule. For example, the preset rule can be: In the control dimension, if the first device node corresponds to a control device and the second device node corresponds to an execution device, the control coefficient of the first device node over the second device node is 1; if the first device node and the second device node are peer control devices, the control coefficient of the first device node over the second device node is 0.5; in all other cases except the above two, the control coefficient of the first device node over the second device node is 0; In the communication dimension, if the first device node corresponds to a measurement device (such as a sensor) and the second device node corresponds to a measurement processing device (such as an edge gateway, processor, etc.), then the control coefficient of the first device node over the second device node is 1; if the first device node and the second device node are data sharing devices, then the control coefficient of the first device node over the second device node is 0.5; and in other cases except the above two cases, the control coefficient of the first device node over the second device node is 0.
[0046] It should be pointed out that the above values 0, 0.5, and 1 are all set based on experience, and can be adaptively modified based on actual needs in application.
[0047] Based on the above settings, when evaluating the influence coefficient of the first device node on the second device node, the importance of the first device node, the redundancy of the second device node, and the historical frequency of interactive control instructions and interactive power information (such as grid frequency and voltage phase angle) between the first device node and the second device node are determined respectively, so as to evaluate the influence of the first device node on the second device node from multiple aspects such as the conditions of the two device nodes themselves and the interaction between the two device nodes. This can make the calculated influence coefficient of the first device node on the second device node more accurate and reliable.
[0048] For example, among the multiple device nodes, the influence coefficient of the vth device node on the uth device node is It can be expressed as: ; in, represents the sigmoid normalization function, Indicates the hub index of the vth device node, Indicates the control coefficient of the vth device node to the uth device node; represents the communication coefficient of the vth device node to the uth device node; Indicates the control frequency value of the vth device node to the uth device node; Indicates the communication frequency value of the vth device node to the uth device node; Indicates the communication independence coefficient of the u-th device node.
[0049] Furthermore, the step of obtaining the hub index of the first device node includes: Calculating a ratio of the number of neighboring nodes of the first device node to the total number of nodes to obtain a node index of the first device node, wherein the number of neighboring nodes is the number of device nodes adjacent to the first device node, and the total number of nodes is the total number of multiple device nodes included in the target network; identifying a plurality of out-of-band device nodes among the plurality of device nodes according to the first device node, wherein the out-of-band device nodes are not adjacent to the first device node; Searching for the shortest communication path between any two different out-of-band device nodes among the plurality of out-of-band device nodes to obtain a plurality of out-of-band communication paths; Among the multiple out-of-band communication paths, determining the out-of-band communication path including the first device node as a target communication path; Calculating a proportion of the target communication path in the plurality of out-of-band communication paths to obtain a path index of the first device node; The product of the path index and the node index of the first device node is calculated to obtain the hub index of the first device node.
[0050] The fact that the extra-band device node is not adjacent to the first device node should be understood as: there is no connection line between the extra-band device node and the first device node.
[0051] In the above setting, not only the number of other device nodes adjacent to the first device node is analyzed, but also the frequency of occurrence of the first device node in multiple extra-band communication paths corresponding to its multiple extra-band device nodes is further analyzed to analyze the impact of the first device node on its extra-band device nodes, thereby comprehensively and accurately evaluating the hub index of the first device node, that is, determining the importance of the first device node in the target network.
[0052] It should be understood that the more neighboring nodes the first device node has, the more important the first device node is in the target network, and the greater the impact it may have on other device nodes when it is abnormal; similarly, the higher the proportion of the target communication path in the multiple non-band communication paths, the more important the first device node is in the target network, and the greater the impact it may have on other device nodes when it is abnormal.
[0053] Exemplarily, the shortest communication path between any two different out-of-band device nodes may be searched using the Dijkstra algorithm.
[0054] In one example, the hub index of the first device node It can be expressed as: ; in, Indicates the number of neighboring nodes of the first device node, Indicates the total number of nodes, Indicates the number of target communication paths, Indicates the number of multiple out-of-band communication paths corresponding to the first device node.
[0055] Furthermore, the step of obtaining the communication independence coefficient of the second device node includes: Acquire multiple communication paths of the second device node in the target network; Determining an independent communication path corresponding to the second device node among the plurality of communication paths corresponding to the second device node, wherein the independent communication path is a communication path of a device node among the plurality of communication paths that does not overlap with other communication paths except for the second device node; A communication independence coefficient of the second device node is determined according to the number of independent communication paths corresponding to the second device node.
[0056] In the application, the ratio of the number of independent communication paths corresponding to the second device node to the maximum number of paths can be calculated to determine it as the communication independence coefficient of the second device node, where the maximum number of paths is the number of independent communication paths corresponding to the device node with the largest number of independent communication paths among multiple device nodes.
[0057] The plurality of communication paths of the second device node in the target network correspond one-to-one to a plurality of fourth device nodes, and the plurality of fourth device nodes are a plurality of other device nodes among the plurality of device nodes included in the target network except the second device node.
[0058] The communication path of the second device node in the target network can be understood as: the shortest path between the second device node and the fourth device node (obtained by Dijkstra algorithm).
[0059] For example, if the second device node is set as the u-th device node among the plurality of device nodes, the communication independence coefficient of the second device node is It can be expressed as: ; in, represents the number of independent communication paths corresponding to the second device node, Indicates the number of independent communication paths corresponding to the device node with the largest number of corresponding independent communication paths among multiple device nodes.
[0060] Step S3, determining an abnormality cumulative index of each device node according to the plurality of influence coefficients of each device node and the node abnormality index of each device node.
[0061] Specifically, the determining of the abnormality cumulative index of each device node according to the plurality of influence coefficients of each device node and the node abnormality index of each device node comprises: obtaining a plurality of target influence coefficients associated with a target device node, wherein the target device node is any one of the plurality of device nodes, the target influence coefficient is an influence coefficient of a third device node on the target device node, and the third device node is a device node adjacent to the target device node in the plurality of device nodes; calculating a product of each target influence coefficient and a node abnormality index of a corresponding third device node to obtain a plurality of node abnormality conduction indexes associated with the target device node; calculating a sum of the node abnormality index of the target device node and the plurality of node abnormality conduction indexes associated therewith to obtain the abnormality cumulative index of the target device node.
[0062] In the above process, when evaluating the abnormality risk of the target device node, in addition to calculating the node abnormality index of the target device node itself, the product of the influence coefficient of the third device node on the target device node and the node abnormality index of the corresponding third device node is also calculated, and the product is taken as the abnormality risk of the corresponding third device node conducted to the target device node, so as to comprehensively and accurately evaluate the actual abnormality risk of the target device node.
[0063] Exemplarily, in the plurality of device nodes, the u-th device node (which can be understood as the aforementioned target device node) is based on the node abnormality conduction index introduced by the v-th device node (which can be understood as the aforementioned third device node) which can be expressed as: ; wherein, represents the node abnormality index of the v-th device node, the influence coefficient of the v-th device node on the u-th device node.
[0064] Correspondingly, the abnormality cumulative index of the u-th device node can be expressed as: ; wherein, represents the node abnormality index of the u-th device node, represents the node abnormality conduction index introduced by the j-th device node based on the u-th device node, Indicates the total number of device nodes adjacent to the u-th device node among multiple device nodes.
[0065] Step S4: Obtain a risk index for each device node based on the abnormal cumulative index of each device node and the replacement index of each device node.
[0066] Specifically, the risk index of each device node is obtained based on the abnormal cumulative index of each device node and the replacement index of each device node, including: Among the one or more hyperedges corresponding to each device node, determining a hyperedge including the least number of device nodes as a target hyperedge for each device node; Calculate the difference between the number of device nodes included in the target hyperedge of each device node and 1 to obtain the replacement index of each device node; The ratio of the abnormal cumulative index of each device node to the replacement index of each device node is calculated to obtain the risk index of each device node.
[0067] In the present invention, multiple device nodes located in the same hyperedge satisfy the following relationship: there is a connecting line between any two device nodes among the multiple device nodes.
[0068] The replacement index may be approximately understood as the number of device nodes that replace the corresponding device node.
[0069] Multiple device nodes located in the same hyperedge can be regarded as multiple device nodes that can serve as redundant backups for each other. Among them, the hyperedge with the least number is selected as the target hyperedge of the corresponding device node to represent the set of device nodes that can serve as redundant backups for the corresponding device node under extreme working conditions. After determining the actual abnormality analysis of each device node, the final risk index of each device node is accurately evaluated in combination with the replaceability of each device node (represented by the replacement index).
[0070] It should be understood that the more device nodes the target hyperedge of each device node includes, the more device nodes that can be used as backups, and the smaller the impact of the corresponding device node's abnormality on the entire network. Therefore, the risk index of the corresponding device node is also lower.
[0071] Step S5: Analyze the risk index of each device node to obtain risk analysis information of the target network.
[0072] Specifically, analyzing the risk index of each device node to obtain risk analysis information of the target network includes: Sorting the plurality of device nodes in descending order of risk index to obtain a node sequence; Determine the first Q device nodes in the node sequence as risky device nodes, where Q is an integer greater than 1; Analyze the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network.
[0073] The specific value of Q can be set according to actual needs or experience. For example, when the target network includes 1,000 device nodes and the first 10% of the device nodes in the node sequence are selected as risky device nodes, Q is 100.
[0074] In the above process, several device nodes with the highest risk index are selected from multiple device nodes based on the risk index, and the connection relationship between the nodes is analyzed. By analyzing the connection relationship between different risk device nodes, the aggregation of several risk device nodes is determined, making the final output risk analysis information more accurate and reliable.
[0075] Furthermore, analyzing the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network includes: Determine at least one risky hyperedge based on the Q risky device nodes, wherein the risky hyperedge is a hyperedge including a number of risky device nodes greater than or equal to a number threshold; The risk analysis information is generated according to the at least one risk hyperedge.
[0076] The number threshold may be set based on experience, for example, the number threshold may be set to 3.
[0077] Exemplarily, the process of generating the risk analysis information according to the at least one risk hyperedge may be: Several risky device nodes located within the risk hyperedge may be determined as device nodes to be inspected, and the risk analysis information may be generated based on the node position of each device node to be inspected.
[0078] In the application, after the risk analysis information is generated, the risk analysis information can be output to relevant staff (such as system operation and maintenance personnel) to prompt the relevant staff to perform manual inspection and maintenance work on the equipment nodes to be inspected through the risk analysis information.
[0079] Overall, the present application analyzes the traffic changes of each device node to determine the node anomaly index of each device node, that is, to determine the probability of each device node being abnormal, and then further analyzes the connection information between different device nodes to determine the influence coefficient of each device node, that is, to determine the influence degree of each device node on other device nodes, and then combines the node anomaly index and the influence coefficient to calculate the abnormal cumulative index of each device node, that is, to calculate the real abnormal probability of each device node considering the abnormal risk conducted by other device nodes, and finally accurately quantifies the risk index of each device according to the number of replaceable device nodes of each device node and the corresponding real abnormal probability, to obtain more comprehensive and accurate risk analysis information, and to improve the analysis accuracy of the security risk of the power system network.
[0080] The present application provides a network security risk analysis device for a power information physical fusion system, please refer to Figure 2 which shows a structural schematic diagram of a network security risk analysis device 200 for a power information physical fusion system according to an embodiment of the present application, and the device comprises: a traffic analysis module 201, configured to analyze the traffic changes of each device node in a plurality of device nodes included in a target network to obtain the node anomaly index of each device node, wherein the target network is a virtual network corresponding to the power information physical fusion system; a coefficient calculation module 202, configured to determine a plurality of influence coefficients of each device node according to the connection information between different device nodes, wherein the influence coefficient is used to indicate the influence degree of the corresponding device node on other device nodes after the abnormality of the corresponding device node; an abnormality analysis module 203, configured to determine the abnormal cumulative index of each device node according to the plurality of influence coefficients of each device node and the node anomaly index of each device node; a risk calculation module 204, configured to obtain the risk index of each device node according to the abnormal cumulative index of each device node and the replacement index of each device node, wherein the replacement index is used to indicate the number of device nodes replacing the corresponding device node; a risk evaluation module 205, configured to analyze the risk index of each device node to obtain the risk analysis information of the target network.
[0081] It should be noted that the apparatus provided in the above embodiment is merely exemplified by the division of the above functional modules. In actual applications, the above functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the computer device can be divided into different functional modules to complete all or part of the functions described above. In addition, the network security risk analysis device for a power cyber-physical fusion system provided in the above embodiment and the network security risk analysis method embodiment for a power cyber-physical fusion system are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0082] The embodiment of the present invention also provides an electronic device. Figure 3 , the electronic device may include a processor 301, a memory 302, and a program 3021 stored in the memory 302 and executable on the processor 301.
[0083] When the program 3021 is executed by the processor 301, it can achieve Figure 1 Any steps in the corresponding method embodiments and achieving the same beneficial effects will not be repeated here.
[0084] Those skilled in the art will appreciate that all or part of the steps of implementing the above-described embodiment method may be accomplished through hardware associated with program instructions, and the program may be stored in a readable medium.
[0085] The embodiment of the present invention further provides a readable storage medium, wherein the readable storage medium stores a computer program, and when the computer program is executed by a processor, the above Figure 1 Any steps in the corresponding method embodiments can achieve the same technical effects and will not be described again here to avoid repetition.
[0086] The computer-readable storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or component.
[0087] Computer readable signal media can include a propagated data signal with computer readable program code embodied therein. For example, a propagated signal can be an electromagnetic signal, an optical signal, and / or any suitable combination thereof. Computer readable program code embodied on a computer readable medium can direct a computer to function in a particular manner, such as implementing an application in accordance with the present disclosure.
[0088] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0089] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). These network connections are
[0090] The embodiments of the present application also provide a computer program product, which, when running on a computer, causes the computer to perform the above related steps to realize the network security risk analysis method of the power cyber-physical system provided by the above embodiments.
[0091] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.
[0092] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments.
Claims
1. A network security risk analysis method for a power cyber-physical fusion system, characterized in that: The method comprises: Analyzing traffic changes of each device node in a target network, which is a virtual network corresponding to the power cyber-physical fusion system, to obtain a node anomaly index of each device node; Determine multiple influence coefficients of each device node based on connection information between different device nodes, wherein the influence coefficients are used to indicate the degree of influence of the corresponding device node on other device nodes after the abnormality occurs; Determine the cumulative abnormality index of each device node according to multiple influence coefficients of each device node and the node abnormality index of each device node; Obtaining a risk index for each device node based on the anomaly cumulative index of each device node and a replacement index of each device node, wherein the replacement index is used to indicate the number of device nodes that replace the corresponding device node; Analyze the risk index of each device node to obtain risk analysis information of the target network.
2. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 1, characterized in that: The analysis of traffic changes of each device node to obtain a node anomaly index of each device node includes: Acquire multiple flow change data for each device node within a current monitoring period, wherein the multiple flow change data correspond one-to-one to multiple consecutive monitoring time periods within the current monitoring period, and the flow change data is used to indicate flow changes of the corresponding device node within the corresponding monitoring time period; Performing anomaly detection on multiple flow change data of each device node within a current monitoring period to determine multiple abnormal flow change data and multiple normal flow change data corresponding to each device node; The data differences between a plurality of abnormal traffic change data and a plurality of normal traffic change data corresponding to each device node are analyzed to obtain a node abnormality index of each device node.
3. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 2, characterized in that: The analyzing the data differences between the multiple abnormal traffic change data and the multiple normal traffic change data corresponding to each device node to obtain the node abnormality index of each device node includes: Calculate the ratio of the number of abnormal traffic change data corresponding to each device node to the number of traffic change data in the current monitoring period, and obtain the abnormal data ratio of each device node; Calculate the average of multiple normal traffic change data corresponding to each device node to obtain reference data corresponding to each device node; Calculate the absolute value of the difference between each abnormal flow change data corresponding to each device node and its corresponding reference data to obtain the abnormal amplitude value of each abnormal flow change data corresponding to each device node; Calculate the sum of multiple abnormal amplitude values of multiple abnormal traffic change data corresponding to each device node to obtain the abnormal amplitude cumulative value of each device node; The product of the accumulated abnormal amplitude value of each device node and the abnormal data ratio is calculated to obtain the node abnormality index of each device node.
4. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 1, characterized in that: The determining of multiple influence coefficients of each device node based on the connection information between different device nodes includes: Obtaining a hub index of a first device node and a communication independence coefficient of a second device node, wherein the first device node and the second device node are any two different device nodes among the plurality of device nodes, the hub index is used to indicate the number of other device nodes associated with the device node in the target network, and the communication independence coefficient is used to indicate the risk resistance of the device node when communicating in the target network; Calculating the product of a control coefficient and a control frequency value of the first device node over the second device node to obtain a control influence coefficient of the first device node over the second device node, wherein the control coefficient is used to indicate the degree to which the first device node is controlled by the first device node when the first device node and the second device node exchange control instructions, and the control frequency value is used to indicate the historical frequency of the exchange of control instructions between the first device node and the second device node; Calculating the product of a communication coefficient and a communication frequency value of the first device node to the second device node to obtain a communication influence coefficient of the first device node to the second device node, wherein the communication coefficient is used to indicate the degree to which the first device node is influenced by the first device node when the first device node and the second device node exchange power information, and the communication frequency value is used to indicate a historical frequency of the exchange of power information between the first device node and the second device node; Calculating the sum of a control influence coefficient and a communication influence coefficient of the first device node on the second device node to obtain a to-be-processed coefficient of the first device node on the second device node; Calculating a ratio of a hub index of the first device node to a communication independence coefficient of the second device node to obtain a correction parameter of the first device node to the second device node; The product of the correction parameter of the first device node on the second device node and the coefficient to be processed is calculated to obtain the influence coefficient of the first device node on the second device node.
5. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 4, characterized in that: The step of obtaining the hub index of the first device node includes: Calculating a ratio of the number of neighboring nodes of the first device node to the total number of nodes to obtain a node index of the first device node, wherein the number of neighboring nodes is the number of device nodes adjacent to the first device node, and the total number of nodes is the total number of multiple device nodes included in the target network; identifying a plurality of out-of-band device nodes among the plurality of device nodes according to the first device node, wherein the out-of-band device nodes are not adjacent to the first device node; Searching for the shortest communication path between any two different out-of-band device nodes among the plurality of out-of-band device nodes to obtain a plurality of out-of-band communication paths; Among the multiple out-of-band communication paths, determining the out-of-band communication path including the first device node as a target communication path; Calculating a proportion of the target communication path in the plurality of out-of-band communication paths to obtain a path index of the first device node; The product of the path index and the node index of the first device node is calculated to obtain the hub index of the first device node.
6. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 4, characterized in that: The step of acquiring the communication independence coefficient of the second device node includes: Acquire multiple communication paths of the second device node in the target network; Determining an independent communication path corresponding to the second device node among the plurality of communication paths corresponding to the second device node, wherein the independent communication path is a communication path of a device node among the plurality of communication paths that does not overlap with other communication paths except for the second device node; A communication independence coefficient of the second device node is determined according to the number of independent communication paths corresponding to the second device node.
7. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 1, characterized in that: The step of determining the abnormal cumulative index of each device node according to the multiple influence coefficients of each device node and the node abnormality index of each device node includes: Obtaining multiple target influence coefficients associated with a target device node, wherein the target device node is any one device node among the multiple device nodes, the target influence coefficient is an influence coefficient of a third device node on the target device node, and the third device node is a device node adjacent to the target device node among the multiple device nodes; Calculating the product of each target influence coefficient and the node anomaly index of the corresponding third device node to obtain multiple node anomaly conduction indices associated with the target device node; The node anomaly index of the target device node and the sum of multiple node anomaly conduction indexes associated with the target device node are calculated to obtain the anomaly cumulative index of the target device node.
8. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 1, characterized in that: The risk index of each device node is obtained based on the abnormal cumulative index of each device node and the replacement index of each device node, including: Among the one or more hyperedges corresponding to each device node, determining a hyperedge including the least number of device nodes as a target hyperedge for each device node; Calculate the difference between the number of device nodes included in the target hyperedge of each device node and 1 to obtain the replacement index of each device node; The ratio of the abnormal cumulative index of each device node to the replacement index of each device node is calculated to obtain the risk index of each device node.
9. The method for analyzing network security risks of a power cyber-physical fusion system according to claim 1, characterized in that: Analyzing the risk index of each device node to obtain risk analysis information of the target network includes: Sorting the plurality of device nodes in descending order of risk index to obtain a node sequence; Determine the first Q device nodes in the node sequence as risky device nodes, where Q is an integer greater than 1; Analyze the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network.
10. The method for analyzing network security risks of the power cyber-physical fusion system according to claim 9, characterized in that: The analyzing the connection relationship of the Q risky device nodes to obtain risk analysis information of the target network includes: Determine at least one risky hyperedge based on the Q risky device nodes, wherein the risky hyperedge is a hyperedge including a number of risky device nodes greater than or equal to a number threshold; The risk analysis information is generated according to the at least one risk hyperedge.