Power grid continuous information attack defense method, system and device based on node coupling degree and medium

By constructing the power cyber-physical system architecture and continuous information attack model, characterizing the node coupling degree, and formulating targeted defense strategies, the problems of abnormal propagation and insufficient defense strategies in power grid information attacks are solved, and the resilience and stability of the power grid are improved.

CN120811751APending Publication Date: 2025-10-17GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511211351.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

When facing information attacks, the existing power grid cyber-physical system lacks sufficient consideration of the coupling relationship between information nodes and physical nodes, resulting in easy propagation of anomalies and lack of targeted defense strategies, making it difficult to assess the cumulative damage of continuous attacks.

Method used

Build the power information-physical system architecture, establish a continuous information attack model, characterize the node coupling degree, and formulate a defense strategy based on the coupling degree. Through the configuration of electronic security perimeter equipment and defense resources, simulate the attack process and intensity and optimize defense measures.

Benefits of technology

It improves the resilience and stability of the power grid under information attacks, can accurately assess fault damage, rationally allocate defense resources, reduce economic losses due to communication interruptions, and ensure the reliability of power supply.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811751A_ABST
    Figure CN120811751A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent power distribution networks, and discloses a node coupling degree-based power grid continuous information attack defense method, system and device and a medium, and the method comprises the steps: through the representation and analysis of the coupling degree, the damage degree of various fault conditions to a power distribution network can be evaluated more accurately. In the aspect of attack defense, a continuous information attack model is constructed, the model not only considers division of a security area and configuration of electronic security perimeter equipment, but also combines related factors such as defense equipment types and the number of operation and maintenance personnel, and comprehensively depicts the process and strength of information attack. Therefore, formulation of a defense strategy is more targeted and effective, and proper defense measures can be taken according to different attack scenes and node coupling conditions. Meanwhile, by testing the defense strategy, the defense scheme can be continuously optimized and perfected, and the toughness of the power grid CPS to malicious information attacks is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intelligent power distribution network, and particularly relates to a power grid continuous information attack defense method and system based on node coupling degree, equipment and medium. BACKGROUND

[0002] With the maturity of the power grid information network system, the power grid has become a typical cyber-physical system (CPS), in which the information network and the physical network are tightly coupled and integrated. The smart grid integrates power, communication, sensing, computing and control technologies. This complexity and heterogeneity make the operation and control extremely complex. While the information system provides rich information resources, it also exposes the power system to greater attack threats. Information attacks, with the help of computers, remotely invade the power system, which is an invasion of the information nodes corresponding to the physical nodes of the power system, resulting in the failure or error of these nodes. In recent years, there have been attacks on the power system, such as malicious software attacks and power grid information attacks. Attacks on the power system refer to attacks on the power system through network connections with the purpose of disrupting the stable operation of the power system or reducing the economic efficiency of the power system. With the expansion of the power system and the complexity of the network structure, the security and stability problem has become increasingly prominent. Due to the coupling characteristics of the power CPS, when the information nodes are abnormal, the abnormality will quickly spread to the physical network, causing losses.

[0003] Therefore, it is necessary to propose a power grid continuous information attack defense method based on node coupling degree, which considers the coupling of physical nodes and information nodes, improves the resilience of the power CPS to malicious information attacks and reduces the possible losses. SUMMARY

[0004] In view of the above existing problems, the present application is proposed.

[0005] Therefore, the present application provides a power grid continuous information attack defense method and system based on node coupling degree, which can solve the problem of prominent security and stability problems caused by information attacks in the power information physical system, and the problem of easy transmission of abnormality and loss.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] In a first aspect, the present application provides a power grid continuous information attack defense method based on node coupling degree, comprising:

[0008] obtaining the power grid structure of the target power system, and establishing a power information physical system architecture based on the power grid structure;

[0009] The power information physical system architecture comprises a physical system model, an information system model and an information physical interaction layer model;

[0010] A continuous information attack model based on the power information physical system architecture is established;

[0011] The continuous information attack model comprises a plurality of preset security zones, and each security zone is configured with an electronic security perimeter device; an information attack model is matched for each electronic security perimeter device, and information attack models of all electronic security perimeter devices are integrated as the continuous information attack model;

[0012] Coupling degrees of a plurality of nodes in the power information physical system architecture are characterized, and a defense strategy based on the coupling degrees is established;

[0013] The defense strategy is tested based on the continuous information attack model.

[0014] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degrees, the establishment of the continuous information attack model based on the power information physical system architecture comprises:

[0015] The continuous information attack model further comprises a defense device type category, an operation and maintenance personnel quantity and related factors of each electronic security perimeter device, which represent the ability of the node to resist information attacks;

[0016] An attack resource is used to represent the attack strength of the information attack model;

[0017] The continuous information attack model is represented by the defense capability and the attack strength.

[0018] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degrees, the establishment of the continuous information attack model based on the power information physical system architecture further comprises:

[0019] When an information node fails, it is determined that the target power system can no longer independently cope with information attacks, and the continuous attack ends;

[0020] When the continuous information attack model attacks successfully and causes a physical node to fail, it is determined that the information physical coordination fails, and the communication loss cannot be recovered.

[0021] The preferred scheme can clearly attack different key states in the process, effectively evaluate the influence degree of the attack on the power system. For the judgment of the failure of the information node, it is helpful to understand the change of the defense ability of the target power system in time, avoid invalid defense operation when the system has been unable to cope with the attack independently, and reasonably allocate defense resources to concentrate resources in the scene with more defense value. For the judgment of the success of the continuous information attack model leading to the failure of the physical node, the serious situation of information-physical collaborative failure can be clearly defined, the plan for the communication loss that cannot be recovered is prepared in advance, and the confusion and loss caused by communication interruption to the operation of the power system is reduced. This helps to build a more scientific and efficient power grid continuous information attack defense system, improve the overall security and stability of the power system in the face of information attack, ensure the reliability of power supply, and reduce the potential risks and economic losses caused by information attack.

[0022] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degree of the application, wherein: the coupling degree of the plurality of nodes in the power information physical system architecture comprises:

[0023] The coupling degree of the plurality of nodes comprises the coupling degree between a plurality of physical nodes and information nodes corresponding to the physical nodes;

[0024] The coupling degree is used to represent the damage degree of physical node failure, information node failure and joint failure of physical node and information node to the distribution network;

[0025] If joint failure occurs, and the damage caused by joint failure to the target power system is greater than the sum of the damage caused by the failure of the two independent nodes of the physical node and the information node, then it is determined as a collaborative failure;

[0026] Otherwise, the joint failure is determined as the basic failure of the two independent nodes of the physical node and the information node.

[0027] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degree of the application, wherein: the establishment of the defense strategy based on the coupling degree comprises:

[0028] If the physical node fails and the information node is normal, it is determined that the continuous information attack model has not successfully attacked the physical node and the information node;

[0029] If the physical node is normal and the information node is failed, it is determined that the continuous information attack model successfully attacks and causes the information node to fail;

[0030] If the physical node fails and the information node fails, it is determined that the continuous information attack model successfully attacks and causes the information node to fail, and causes the physical node to fail.

[0031] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degree provided by the application, wherein: the power information physical system architecture comprises:

[0032] Each physical node in the power grid structure of the target power system is grouped into a physical system model;

[0033] All information devices of each physical node in the power grid structure of the target power system are assembled into an information node, and the information node and the corresponding physical node form an information physical coupling, and all information nodes are grouped into an information system model.

[0034] As a preferred scheme of the power grid continuous information attack defense method based on node coupling degree provided by the application, wherein: the power information physical system architecture further comprises recording the result of all information physical couplings as an information physical interaction layer model.

[0035] In a second aspect, the application provides a power grid continuous information attack defense system based on node coupling degree, comprising:

[0036] The architecture establishment module is configured to obtain the power grid structure of the target power system, and establish a power information physical system architecture based on the power grid structure;

[0037] The power information physical system architecture comprises a physical system model, an information system model, and an information physical interaction layer model;

[0038] The attack model establishment module is configured to establish a continuous information attack model based on the power information physical system architecture;

[0039] The continuous information attack model comprises a plurality of preset security zones, and each security zone is configured with an electronic security perimeter device, an information attack model is matched for each electronic security perimeter device, and the information attack models of all electronic security perimeter devices are integrated as the continuous information attack model;

[0040] The defense strategy formulation module is configured to represent the coupling degree of a plurality of nodes in the power information physical system architecture, and establish a defense strategy based on the coupling degree;

[0041] The test module is configured to test the defense strategy based on the continuous information attack model.

[0042] In a third aspect, the application provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method as described above when executing the computer program.

[0043] In a fourth aspect, the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of the method described above.

[0044] Compared with the prior art, the present application has the beneficial effects that: the present application proposes a power grid continuous information attack defense method based on node coupling degree, in the power grid information physical system, the physical nodes and the information nodes are related to and influence each other, the present application can more accurately evaluate the damage degree caused by various fault conditions to the distribution network through the characterization and analysis of their coupling degree. In terms of attack defense, the present application constructs a continuous information attack model, which not only considers the division of the security area and the configuration of the electronic security perimeter device, but also combines related factors such as the type category of the defense device, the number of operation and maintenance personnel, and comprehensively describes the process and strength of the information attack. This makes the formulation of the defense strategy more targeted and effective, and can take appropriate defense measures according to different attack scenes and node coupling conditions. At the same time, through the test of the defense strategy, the defense scheme can be continuously optimized and improved, and the resilience of the power grid CPS to malicious information attacks can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0046] Figure 1 A method flow chart of a power grid continuous information attack defense method based on node coupling degree provided by an embodiment of the present application.

[0047] Figure 2 A power CPS architecture schematic diagram of a power grid continuous information attack defense method based on node coupling degree provided by an embodiment of the present application.

[0048] Figure 3 An attack and defense flow chart of a power grid continuous information attack defense method based on node coupling degree provided by an embodiment of the present application.

[0049] Figure 4 An internal structure diagram of an electronic device of a power grid continuous information attack defense method based on node coupling degree provided by an embodiment of the present application. DETAILED DESCRIPTION

[0050] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the present application.

[0051] Embodiment 1, refer to Figures 1-3 For the first embodiment of the present application, the embodiment provides a power grid continuous information attack defense method based on node coupling degree, comprising:

[0052] In the prior art, there are some problems, some methods only focus on the security protection of information nodes or physical nodes at a single level, and do not fully consider the coupling relationship between the two, resulting in that when an information attack occurs, the rapid propagation of abnormalities between the information network and the physical network cannot be effectively dealt with. Moreover, the existing attack model and defense strategy often lack comprehensive consideration of the continuous information attack scene, making it difficult to accurately assess the cumulative damage caused by continuous attacks to the power grid. In addition, when formulating the defense strategy, the distinction of fault types under different node coupling degrees is not detailed enough, so that the defense measures lack pertinence and cannot be accurately defended according to the actual fault situation.

[0053] The present application provides a method that can effectively solve the above-mentioned problems. Next, how to realize the power grid continuous information attack defense method based on node coupling degree will be described in detail in combination with multiple embodiments.

[0054] Figure 1 A method flowchart of a power grid continuous information attack defense method based on node coupling degree is shown, comprising:

[0055] S101, the power grid structure of the target power system is acquired, and a power information physical system architecture is established based on the power grid structure, wherein:

[0056] It should be noted that in order to effectively defend against power grid continuous information attacks, a reasonable and accurate power information physical system architecture must first be constructed. This requires a comprehensive analysis of the device composition and connection relationship of the target power system. Specifically, the construction of the system architecture needs to cover two core elements: the physical device layer (including power infrastructure such as generator sets, transmission lines, transformers and distribution devices) and the information device layer (containing state sensors, data communication devices, control terminals and other intelligent components), by accurately collecting the topological connection relationship and technical parameters of various devices, a holographic data model reflecting the real running state of the power grid is established, providing accurate data support for the construction of the subsequent attack defense system.

[0057] In some specific embodiments, the acquisition of power grid structure data can be achieved by combining various technical means. Typical data collection methods include, but are not limited to: integrating spatial data through a geographic information system (GIS) platform to establish a geographic distribution model of power grid equipment; using a SCADA system to collect real-time equipment operation parameters and build a dynamic monitoring network; deploying an intelligent sensor array to achieve accurate sensing of key node states; and combining with a UAV inspection system to obtain high-precision equipment image data. These technical means can be flexibly selected or combined according to the actual application scenario to provide multi-dimensional data support for the construction of the power information physical system architecture.

[0058] In some specific embodiments, the power grid structure can include a power generation side structure, a transmission line structure, a power transformation link structure, and a power distribution side structure. The power generation side structure covers various types of power plants, such as thermal power plants, hydroelectric power plants, wind power plants, and solar power plants. Different types of power plants have different power generation tasks in the power grid, and their equipment characteristics and operation modes also differ. Thermal power plants mainly generate electricity by burning fossil fuels such as coal and natural gas, and the equipment includes boilers, steam turbines, and generators. Hydroelectric power plants use the energy of water flow to drive water turbines, which in turn drive generators to generate electricity, involving equipment such as dams, water turbines, and generators. Wind power plants rely on wind to drive wind turbine generators to generate electricity, with the main equipment being wind turbines. Solar power plants convert solar energy into electricity through solar panels.

[0059] The transmission line structure is an important link between power plants and substations, as well as between substations, and it is responsible for transmitting the electricity generated by power plants to various regions. Transmission lines are divided into overhead lines and cable lines. Overhead lines have the advantages of low construction cost and convenient maintenance, but are susceptible to natural environmental influences. Cable lines are suitable for densely populated areas or places with high environmental requirements, and have the advantages of small footprint and high reliability.

[0060] The power transformation link structure is mainly composed of substations. The role of substations is to change voltage levels to achieve efficient transmission and distribution of electric energy. Substations contain devices such as transformers, circuit breakers, disconnectors, and busbars. Through the coordinated work of these devices, high-voltage electric energy from transmission lines can be converted into low-voltage electric energy suitable for user consumption.

[0061] The power distribution side structure directly faces users and is responsible for distributing the electric energy output by substations to various user terminals. The power distribution system includes devices such as distribution transformers, distribution boxes, and distribution lines, and it must ensure that electric energy can be safely and reliably supplied to users to meet their diverse electricity needs. At the same time, with the large-scale access of distributed power sources, the power distribution side structure has become more complex, and the coordinated operation of distributed power sources and the power grid needs to be considered.

[0062] However, the above power grid structure cannot fully adapt to the defense needs of modern power grids in the face of continuous information attacks. Modern power grids are facing increasingly complex and diversified information attacks, and the above power grid structure only sorts out physical devices and information devices and their connection relationships, lacking consideration of system dynamic changes under information attack environment.

[0063] On the one hand, this structure does not fully consider the chain reaction of device failure caused by information attacks. When an information node is attacked and fails, it may quickly affect the physical nodes coupled with it, thereby triggering abnormal operation of the entire power grid. The existing power grid structure does not establish an effective mechanism to timely capture and respond to such chain failures.

[0064] On the other hand, in the face of continuous information attacks, the above power grid structure lacks the ability to dynamically assess attack intensity and duration. Continuous attacks can cause cumulative damage to the power grid, and the existing structure is difficult to accurately assess the impact of such cumulative damage on the overall performance and reliability of the power grid. Moreover, the power grid structure is not flexible in defense strategy formulation. It does not provide diversified and targeted defense measures according to different node coupling degrees and attack scenarios. For different types of information attacks, such as distributed denial of service attacks and malware attacks, the defense strategy cannot be adjusted in time to effectively respond.

[0065] In addition, the above power grid structure also has deficiencies in data sharing and collaborative defense. In modern power grids, effective data sharing and collaborative defense are needed between different regions and different levels of power grids to respond to cross-regional and cross-level information attacks. However, the existing structure does not establish a perfect data sharing mechanism and collaborative defense system, making it difficult for the power grid to form a unified defense force in the face of complex attacks.

[0066] Therefore, it is necessary to further optimize and improve the existing power grid structure to improve the defense capability and reliability of the power grid under continuous information attacks.

[0067] In an embodiment of the present application, the power information physical system architecture includes a physical system model, an information system model, and an information physical interaction layer model.

[0068] In an embodiment of the present application, the power information physical system architecture includes:

[0069] Each physical node in the power grid structure of the target power system is grouped into a physical system model.

[0070] All information devices of each physical node in the power grid structure of the target power system are assembled into an information node, which forms an information physical coupling with its corresponding physical node, and all information nodes are assembled into an information system model.

[0071] In an embodiment of the present application, the power cyber-physical system architecture further comprises recording the result of the overall cyber-physical coupling as a cyber-physical interaction layer model.

[0072] Specifically, as shown in FIG. 1, based on the obtained power grid structure data, the power cyber-physical system architecture is established. Each physical node in the power grid structure of the target power system is grouped to form a physical system model, which is an abstract representation of the actual physical devices in the power grid and their mutual connection relationship. It reflects the physical topology structure and power transmission characteristics of the power system, and is the basis for the operation of the power system. Figure 2

[0073] At the same time, all information devices of each physical node in the power grid structure of the target power system are assembled into an information node, and the information node and its corresponding physical node form a cyber-physical coupling. The information device is responsible for collecting the operating state information of the physical device and transmitting these information to the control system to realize remote monitoring and control of the physical device. All information nodes are grouped to form an information system model, which embodies the flow and processing process of information in the power grid and is the key to realizing intelligent operation of the power grid.

[0074] Finally, the result of the overall cyber-physical coupling is recorded as a cyber-physical interaction layer model. The cyber-physical interaction layer model describes the interaction and influence between the physical system and the information system, which reflects how the operating state of the physical device is fed back to the information system through the information device, and how the control instructions of the information system act on the physical device. By establishing the three models, a complete power cyber-physical system architecture is formed, which provides a solid foundation for subsequent establishment of continuous information attack models and development of defense strategies.

[0075] It should be noted that obtaining the power grid structure of the target power system and establishing the power cyber-physical system architecture based on the power grid structure can clearly and accurately grasp the correlation and interaction relationship between the physical devices and the information devices in the power system. When establishing the continuous information attack model subsequently, the possible link and path of the attack can be accurately located according to this architecture.

[0076] S102, establishing a continuous information attack model based on the power cyber-physical system architecture, wherein:

[0077] It should be noted that when the power cyber-physical system architecture is obtained, the continuous information attack model can be established based thereon. The establishment of the model needs to consider multiple factors to accurately simulate the influence of continuous information attack on the power grid.

[0078] ​In some specific embodiments, the establishment of a continuous information attack model based on the power information physical system architecture can consider attack scenarios, attack paths, and attack strengths, etc. For attack scenarios, not only single type of information attacks such as network virus attacks, data tampering attacks, etc. are considered, but also complex scenarios of combination of multiple attack means and changes of continuous attacks in different time periods are considered. For example, an attacker may first infect information nodes through a network virus to disrupt the normal operation of the system, and then perform data tampering when the system is chaotic to further damage the control and scheduling of the power grid.

[0079] In some specific embodiments, on the attack path, the characteristics of the information physical interaction layer are fully considered, and how the attack penetrates from the information network to the physical network and how it propagates and spreads in the physical network are analyzed. Since there is a coupling relationship between information nodes and physical nodes, information attacks may cause failures of physical devices, such as tampering of sensor data may cause errors in control instructions, and thus affect the output power of power generation equipment or the switching state of power transmission lines. Therefore, it is necessary to analyze in detail the propagation path of information attacks between information networks and physical networks, and the influence of coupling degrees of different nodes on attack propagation.

[0080] In some specific embodiments, in terms of attack strength, the duration of the attack, the frequency of the attack, and the severity of the attack are considered. Continuous information attacks may cause cumulative damage to the power grid, and the longer the duration of the attack and the higher the frequency, the greater the impact on the power grid. At the same time, different types of attacks have different degrees of damage to the power grid, such as a serious data tampering attack may cause local or even global paralysis of the power grid, while a slight network interference attack may only affect the normal operation of part of the equipment. Therefore, it is necessary to quantitatively evaluate the attack strength so that targeted countermeasures can be taken when formulating defense strategies.

[0081] In some specific embodiments, historical attack data and real-time monitoring data can be combined to establish a continuous information attack model. Historical attack data can provide patterns and rules of attacks, helping the present invention to understand the common means and strategies of attackers. Real-time monitoring data can reflect the current operating state of the power grid and potential security risks, and timely detect potential attack behaviors. Through analysis and mining of these data, a more accurate and effective continuous information attack model can be established to provide a reliable basis for subsequent defense strategy formulation.

[0082] In the embodiments of the present invention, the continuous information attack model includes a plurality of preset security zones, and each security zone is configured with an electronic security perimeter device, an information attack model is matched for each electronic security perimeter device, and the information attack models of all electronic security perimeter devices are integrated as a continuous information attack model.

[0083] In the embodiments of the present application, the continuous information attack model based on the power information physical system architecture comprises:

[0084] The continuous information attack model further comprises a defense device type category representing the ability of the node to resist information attacks, the number of operation and maintenance personnel and related factors on each electronic security perimeter device;

[0085] The attack strength of the information attack model is represented by using attack resources;

[0086] The continuous information attack model is represented by the defense capability and the attack strength.

[0087] In the embodiments of the present application, the continuous information attack model based on the power information physical system architecture further comprises:

[0088] When the information node fails, it is determined that the target power system can no longer independently cope with information attacks, and the end of the continuous attack;

[0089] When the continuous information attack model attack is successful and causes the physical node to fail, it is determined that the information physical system fails, and the communication loss cannot be recovered.

[0090] Specifically, in the implementation process, the typical defense configuration scheme includes deploying a multi-level defense-in-depth system with an electronic security perimeter (ESP) as the core in each security area of the smart grid. The system adopts a layered protection architecture, and devices such as next-generation firewalls (NGFW) and intrusion prevention systems (IPS) are deployed in the boundary protection layer to realize network traffic filtering; the deep learning-based intrusion detection system (IDS) and network behavior analysis system (NBAD) are configured in the deep detection layer to realize abnormal behavior identification through traffic mirroring and log analysis; and the data encryption gateway and access control system are set in the core protection layer to ensure the security of critical business data. The defense capability of each ESP node is a comprehensive embodiment of its resource configuration, which depends on the following factors: 1) the technical advancement of hardware defense devices, such as whether they have AI-driven threat detection capabilities; 2) the intelligence level of software systems, including whether they support automated response and linked protection; 3) the professional qualifications and response efficiency of the operation and maintenance team, such as whether they have obtained professional certifications such as CISSP; and 4) the fine management level of security policies, such as whether they have implemented fine-grained access control based on business scenarios. In actual deployment, each ESP node adopts the mode of "basic protection + customized strategy", and the basic protection components include uniformly configured boundary firewalls and intrusion detection devices, while the customized strategy is adjusted according to the security level and business characteristics of the protected area, for example, more stringent access control and more frequent security audit are adopted for dispatch control areas. This defense system design not only ensures the wide coverage of security protection, but also implements precise protection according to the risk characteristics of different security areas, effectively improving the ability of power grid information systems to respond to advanced persistent threats (APT). At the same time, by establishing a quantitative model of defense resources and protection effectiveness, the optimal allocation of security investment can be realized, maximizing the overall defense effect under limited resources. When attackers carry out information attacks, they must break through the specific defense mechanism matched by the target ESP, and the type and category of defense devices installed on each ESP device, the number of operation and maintenance personnel and related factors determine the ability of the node to resist information attacks. And there is a positive correlation between these defense resources and defense capabilities. For the attack strength of information attacks, the present application also abstracts it as attack resources. Therefore, the present application proposes the following continuous information attack model:

[0091]

[0092] where D i represents the defense capability of node i, θ represents the conversion coefficient, R i represents the defense resources of node i, p i represents the probability of node failure caused by information attacks, and A i represents the attack strength of node i.

[0093] It needs to be explained that when the information attack is successful and causes the physical node to fail, it means that information-physical coordination failure occurs here, which is manifested as the load of the physical node being set to 0 and being unable to recover due to the loss of communication.

[0094] In the embodiments of the present application, the present application studies the calculation of the current after each change of the structure of the power grid by the direct current optimal power flow (DC-OPF), and the reasons are as follows:

[0095] First of all, the present application focuses on the loss of load in the power system. The focus is on the current of the active power in the power system. In the case of only considering active power, DC-OPF can well solve this problem.

[0096] Secondly, the existing DC-OPF is widely used due to its simplicity, speed, and ease of real-time calculation. In the information attack scenario, the requirement for calculation time is very high. This is because the information attack occurs very quickly and needs to make a quick judgment in a very short time,

[0097] Therefore, the advantages of DC-OPF need to be exerted. In this scenario, the defense strategy often needs to predict the attack that may occur in the future, so DC-OPF is a relatively suitable method.

[0098] Further, the failure of the information node may lead to the emergence of an islanded power grid in the power system. The present application believes that the emergence of an islanded power grid means that the power system can no longer independently cope with information attacks, so the emergence of an islanded power grid means the end of a sustained attack.

[0099] Further, the present application takes the proportion of the loss of load in the normal state to the total load as the loss function:

[0100]

[0101] Wherein, loss is the current load loss, and load is the total load in the normal state.

[0102] The detailed attack and defense flow chart is shown in Figure 3 First, the model is generated. This step may involve creating physical and information models of the power grid, and establishing information-physical interaction layer models, etc., to provide a basis for subsequent steps. Then, the defense strategy is set. This includes defense measures based on node coupling degree analysis, such as configuring electronic security perimeter devices, allocating defense resources, etc. Then, the attack strategy is set. This step simulates the behavior of potential attackers, defines the target, strength and way of attack, so as to test and verify in the subsequent attack and defense process.

[0103] Enter the attack and defense process stage, which is the core part of the whole process, and is specifically divided into the following steps:

[0104] Step 1.1: Check for node or line faults

[0105] If no faults, continue loop check.

[0106] If faults, proceed to next step.

[0107] Step 1.2: Update network parameters

[0108] When faults are detected, network parameters need to be updated to reflect changes in current state.

[0109] Step 1.3: Determine if participating in island operation

[0110] If not participating in island operation, proceed directly to DC-OPF (Direct Current Optimal Power Flow) calculation.

[0111] If participating in island operation, return to previous step and re-evaluate network state.

[0112] Step 1.4: DC-OPF calculation

[0113] Perform DC-OPF calculation to optimize power system operating state.

[0114] Step 1.5: Determine if converged

[0115] If converged, proceed to next step.

[0116] If not converged, mark as load loss and return to DC-OPF calculation step to reattempt optimization.

[0117] Step 1.6: Calculate loss function

[0118] If converged successfully, calculate loss function to assess system loss under current state.

[0119] Step 1.7: Determine if maximum allowed loss reached

[0120] If maximum allowed loss not reached, return to step of checking for node or line faults and continue monitoring and adjusting.

[0121] If maximum allowed loss reached, process ends.

[0122] Step 1.8: When system loss reaches maximum allowed value, process reaches "End", indicating end of this attack-defense process.

[0123] It should be noted that the establishment of a continuous information attack model based on the power information physical system architecture can accurately simulate the attack scene and provide reliable basis for the development of defense strategies. With this model, the influence of different attack scenes, paths and intensities on the power grid can be more clearly understood, so that the allocation of defense resources and the deployment of defense measures can be targeted.

[0124] In S103, the coupling degree of a plurality of nodes in the power information physical system architecture is characterized, and a defense strategy based on the coupling degree is established, wherein:

[0125] It should be noted that when the power information physical system architecture is obtained, a more effective defense strategy can be developed by analyzing the coupling degree between nodes. The node coupling degree reflects the degree of association between physical nodes and information nodes, as well as the degree of mutual influence between different physical nodes or information nodes. The higher the coupling degree, the greater the influence on other nodes when a node fails or is attacked.

[0126] In the present application, the coupling degree of the nodes will be characterized from the following aspects. First, the physical connection coupling degree, which reflects the degree of electrical connection between physical nodes. For example, in a power grid, by analyzing the number, capacity and connection mode of transmission lines, the physical connection coupling degree between physical nodes can be quantified. The closer the connection and the larger the transmission line capacity, the higher the physical connection coupling degree.

[0127] Second, the information interaction coupling degree, which measures the frequency and depth of information exchange between information nodes and between information nodes and physical nodes. In a smart grid, real-time transmission and sharing of information is crucial for stable operation of the power grid. By monitoring the data transmission volume, communication frequency and importance of data between information devices, the information interaction coupling degree can be evaluated. The more frequent the information interaction and the more critical the data, the higher the information interaction coupling degree.

[0128] Based on the above-mentioned characterization of node coupling degree, the present application will establish a corresponding defense strategy. For nodes with high coupling degree, key protection measures are taken. For example, increase the defense resource investment of these nodes, including installing higher level firewalls, intrusion detection systems, etc., to improve their ability to resist information attacks. At the same time, real-time monitoring of these nodes is strengthened to timely detect potential attack behavior.

[0129] For nodes with low coupling degree, the allocation of defense resources can be appropriately reduced, but a certain monitoring intensity should be maintained. Because in some cases, low coupling degree nodes may also become a breakthrough for attackers, thereby affecting the safety of the entire power grid.

[0130] In addition, the defense strategy can be adjusted in real time according to the dynamic change of the coupling degree of the node. When the operating state of the power grid changes, such as partial line maintenance, load fluctuation, etc., the coupling degree of the node will also change accordingly. At this time, the allocation of defense resources and the strength of defense measures are timely adjusted to ensure that the power grid can maintain high defense capability under various conditions.

[0131] By characterizing the coupling degree of the node and establishing a defense strategy based on the coupling degree, the defense resources can be more scientifically and reasonably allocated, and the overall defense capability and reliability of the power grid under continuous information attack can be improved.

[0132] In the embodiment of the present application, the coupling degree of the nodes in the power information physical system architecture comprises:

[0133] The coupling degree of the nodes comprises the coupling degree between the physical nodes and the information nodes corresponding to the physical nodes;

[0134] The coupling degree is used to characterize the damage degree caused by the failure of the physical node, the failure of the information node and the joint failure of the physical node and the information node to the power distribution network;

[0135] If the joint failure occurs and the damage caused by the joint failure to the target power system is greater than the sum of the damage caused by the failure of the two independent nodes of the physical node and the information node, it is determined as a cooperative failure;

[0136] Otherwise, the joint failure is determined as the basic failure of the two independent nodes of the physical node and the information node.

[0137] In the embodiment of the present application, the defense strategy based on the coupling degree comprises:

[0138] If the physical node fails and the information node is normal, it is determined that the continuous information attack model has not successfully attacked the physical node and the information node;

[0139] If the physical node is normal and the information node fails, it is determined that the continuous information attack model successfully attacks and causes the information node to fail;

[0140] If the physical node fails and the information node fails, it is determined that the continuous information attack model successfully attacks and causes the information node to fail, and causes the physical node to fail.

[0141] It should be noted that in the actual operation of power grid defense, according to the above continuous information attack model and the defense strategy based on node coupling degree, the effective monitoring and dynamic protection of power grid security can be realized. By monitoring the defense resources, attack strength and other parameters in real time, combined with the change of node coupling degree, the defense measures are continuously adjusted. For example, when it is monitored that the attack strength of an information node in a certain area suddenly increases, the coupling degree of the node and the surrounding physical nodes can be quickly evaluated, and if the coupling degree is high, the defense resources in the area can be immediately strengthened, such as enhancing the firewall protection, increasing the monitoring frequency of operation and maintenance personnel, etc.

[0142] In some specific embodiments, in the testing process, first, diversified attack scenarios are designed according to the previously established continuous information attack model. These scenarios should cover different attack targets, attack strengths and attack methods, such as high-intensity attacks on key nodes, multi-node coordinated attacks, and continuous low-intensity harassment attacks. At the same time, different attack times and attack frequencies should be considered to simulate the complex and variable attack situations in reality.

[0143] It should be noted that testing the defense strategy based on the continuous information attack model is a key link to ensure the effectiveness and reliability of the strategy. By simulating various possible attack scenarios, the performance of the defense strategy under different conditions can be fully evaluated, potential vulnerabilities and shortcomings can be found out, and timely adjustments and optimizations can be made.

[0144] In some specific embodiments, for each attack scenario, the response of the defense strategy is recorded. This includes whether the defense system can detect the attack in time, whether the defense measures taken are effective, the loss of the system during the attack, etc. Various monitoring indicators can be set to quantify these response situations, such as attack detection time, attack blocking rate, system loss rate, etc.

[0145] In some specific embodiments, according to the recorded data, the defense strategy is analyzed and evaluated in detail. The performance of the defense strategy under different attack scenarios is compared to find out which scenarios it performs well in and which scenarios it has deficiencies in. For example, if the attack blocking rate of the defense system is low in the multi-node coordinated attack scenario, it indicates that the strategy may have defects in dealing with complex attacks and needs to be further optimized.

[0146] In some specific embodiments, for the problems found in the evaluation, the defense strategy needs to be adjusted and improved in time. This may include increasing the defense resource input of certain nodes, adjusting the priority of defense measures, optimizing the attack detection algorithm, etc. The adjusted strategy needs to be tested again to verify the effect of the improvement.

[0147] In some specific embodiments, for the problems found in the evaluation, the defense strategy needs to be adjusted and improved in time. This may include increasing the defense resource input of certain nodes, adjusting the priority of defense measures, optimizing the attack detection algorithm, etc. The adjusted strategy needs to be tested again to verify the effect of the improvement. In some specific embodiments, for the problems found in the evaluation, the defense strategy needs to be adjusted and improved in time. This may include increasing the defense resource input of certain nodes, adjusting the priority of defense measures, optimizing the attack detection algorithm, etc. The adjusted strategy needs to be tested again to verify the effect of the improvement.

[0148] In some specific embodiments, the test results can also be compared with previous expectations to analyze whether the expected defense target is achieved. If the expected target is not achieved, in-depth analysis is needed to find out whether the model setting is unreasonable, the strategy formulation has problems, or other factors cause it.

[0149] It should be noted that through continuous testing, evaluation and improvement, the defense strategy can be improved, the overall defense capability and reliability of the power grid under continuous information attacks can be improved, and the safe and stable operation of the power system can be ensured.

[0150] In summary, the present application proposes a power grid continuous information attack defense method based on node coupling degree. In the power grid information physical system, physical nodes and information nodes are related and influence each other. The present application can more accurately evaluate the damage degree of various fault conditions to the distribution network through the characterization and analysis of their coupling degree. In terms of attack defense, the present application constructs a continuous information attack model. This model not only considers the division of the security zone and the configuration of the electronic security perimeter device, but also combines related factors such as the type of defense equipment, the number of operation and maintenance personnel, and comprehensively describes the process and strength of information attacks. This makes the formulation of defense strategies more targeted and effective, and can take appropriate defense measures according to different attack scenarios and node coupling conditions. At the same time, through the test of the defense strategy, the defense scheme can be continuously optimized and improved, and the resilience of the power grid CPS to malicious information attacks can be improved.

[0151] In one preferred embodiment, the coupling accurately describes the coupling degree between different systems or components, which is a key indicator. In the power CPS, it is crucial to consider the interaction and dependency between nodes. The present application regards the nodes and information devices in the power CPS as nodes.

[0152] In order to effectively measure the correlation between these nodes, it is appropriate to introduce the concept of mutual information in information theory. Mutual information quantifies the amount of information shared between two variables, reflecting the degree of their dependence. Based on this concept, the present application proposes a node coupling degree (NCD) to quantify the propagation of node failures and their impact on the network. Through NCD, the present application can better understand how these coupling relationships affect the stability and reliability of the overall network.

[0153] NCD is used to quantify the tightness of the coupling between physical nodes and information nodes. By calculating the fault hazard gain caused by the mutual cooperation of physical failures and network failures, the specific value of NCD can be obtained. This number provides an intuitive representation of the degree of association between two nodes.

[0154]

[0155] where NCD i is the coupling degree between physical node pi and its corresponding information node ci, respectively representing the damage caused by the failure of pi, the failure of ci, and the joint failure of pi and ci to the power distribution network. is the criterion for whether the joint failure of pi and ci is a cooperative failure. If the damage caused by the joint failure to the system is greater than the sum of the damage caused by the failure of two independent nodes, it is determined that the basic failure is a cooperative failure;

[0156] Otherwise, the failures of pi and ci are two independent basic failures.

[0157] In some specific embodiments, in the planning and maintenance of the power distribution network, the conventional evaluation method usually focuses on the impact of a single node being disturbed or failing on the entire system, so as to judge its vulnerability. However, an attacker may choose to attack multiple nodes with relatively high vulnerability, thereby inducing information-physical coordination failure, and further causing significant impact on the power distribution network. For example, the communication interruption caused by the attack on the information node will not directly affect the operation of the power distribution network, but when combined with the line attack, the scope of the failure will be significantly expanded. Therefore, the NCD index introduced in the present application can help the planning and maintenance personnel accurately identify those key nodes that may trigger a cooperative failure.

[0158] In the scenario set by the present application, the meaning of NCD needs to be further clarified. For the state of physical node pi and its information node ci during the information attack process, the present application makes the following classification.

[0159] First, pi fails and ci is normal. This indicates that the information attack has not successfully attacked ci and pi, but has failed due to other reasons. Since ci exists, the cloud platform can monitor the state of pi in real time and control it, so it is believed that the failure will not further expand. which can be expressed as follows:

[0160]

[0161] where load i represents the load of pi,

[0162] Second, pi is normal and ci fails. In this case, it indicates that the information attack causes ci to fail, but pi will not fail as a result. In this case, there is no obvious failure in the physical network. which can be expressed as follows:

[0163]

[0164] Third, pi failure, ci failure. This shows that the information attack leads to ci failure, and pi also fails. Due to the failure of ci, the cloud platform cannot monitor the state of pi and take action. At this time, it is considered that the failure of pi spreads to its neighborhood, may be expressed as follows:

[0165]

[0166] wherein, refers to the sum of the loads of the nodes directly connected to the pi.

[0167] In the information attack, the NCD can effectively reflect the coupling degree between the physical node and the information node, and can explain the importance of the node under the information physical coupling. In addition, the load of the physical node itself can directly explain its importance, so the defense strategy of the present application considers the above two values at the same time, which is expressed as follows:

[0168]

[0169] wherein, R i represents the defense resources of pi, n represents the number of nodes in the grid, and F represents the total amount of defense resources invested.

[0170] It should be noted that the NCD and the load rate of the node are used as indicators of the importance of the node in the present application, and the defense resources are deployed according to these indicators. This deployment method can effectively improve the utilization rate of the defense resources and reduce the harm of the information attack.

[0171] Embodiment 3, refer to Figure 4 In this embodiment, a power grid continuous information attack defense system based on node coupling degree is also provided, comprising:

[0172] The architecture establishment module is used to obtain the power grid structure of the target power system, and establish the power information physical system architecture based on the power grid structure;

[0173] The power information physical system architecture comprises a physical system model, an information system model and an information physical interaction layer model.

[0174] The attack model establishment module is used to establish a continuous information attack model based on the power information physical system architecture;

[0175] The continuous information attack model comprises a plurality of preset security zones, and each security zone is configured with an electronic security perimeter device. The information attack model is matched for each electronic security perimeter device, and the information attack models of all electronic security perimeter devices are integrated as the continuous information attack model.

[0176] A defense strategy establishment module is configured to represent coupling degrees of a plurality of nodes in a power information physical system architecture and establish a defense strategy based on the coupling degrees.

[0177] A test module is configured to test the defense strategy based on the continuous information attack model.

[0178] The above modules can be embedded in or independent of a processor in the electronic device in hardware form, or stored in a memory in the electronic device in software form, so as to be called and executed by the processor to perform the operations corresponding to the above modules.

[0179] The embodiment also provides an electronic device, which can be a terminal, and an internal structure diagram of the electronic device can be as shown in Figure 4 The electronic device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. The processor of the electronic device is configured to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The communication interface of the electronic device is configured to perform wired or wireless communication with an external terminal. The wireless communication can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The computer program is executed by the processor to implement a power grid continuous information attack defense method based on node coupling degrees. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen. The input device of the electronic device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the electronic device, or an external keyboard, touchpad or mouse, etc.

[0180] The embodiment also provides a computer readable storage medium having a computer program stored thereon, and the computer program is executed by the processor to implement the following steps:

[0181] Obtaining a power grid structure of a target power system, and establishing a power information physical system architecture based on the power grid structure;

[0182] The power information physical system architecture includes a physical system model, an information system model and an information physical interaction layer model.

[0183] Establishing a continuous information attack model based on the power information physical system architecture;

[0184] The continuous information attack model includes a plurality of preset security zones, and each security zone is configured with an electronic security perimeter device. An information attack model is matched for each electronic security perimeter device, and information attack models of all electronic security perimeter devices are integrated as the continuous information attack model.

[0185] Characterize the coupling degree of several nodes in a cyber-physical power system architecture and establish a defense strategy based on the coupling degree;

[0186] Test the defense strategy based on a continuous information attack model.

[0187] It should be noted that the above examples are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and all modifications and replacements should be included in the scope of the claims of the present application.

[0188] Although the preferred embodiments of the present application have been described, those skilled in the art can make further changes and modifications to these embodiments once they understand the basic inventive concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all modifications and modifications falling within the scope of the present application.

[0189] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application also intends to include these modifications and variations.

Claims

1. A method for defending against continuous information attacks on power grids based on node coupling, characterized in that: include: Obtaining a grid structure of a target power system, and establishing a power cyber-physical system architecture based on the grid structure; The power cyber-physical system architecture includes a physical system model, an information system model, and a cyber-physical interaction layer model; Establishing a continuous information attack model based on the power cyber-physical system architecture; The continuous information attack model includes presetting a number of security zones, each of which is equipped with an electronic security perimeter device, matching an information attack model for each electronic security perimeter device, and integrating the information attack models of all electronic security perimeter devices as a continuous information attack model; Characterizing the coupling degree of several nodes in the power cyber-physical system architecture and establishing a defense strategy based on the coupling degree; The defense strategy is tested based on the continuous information attack model.

2. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 1, characterized in that: The establishing of a continuous information attack model based on the power cyber-physical system architecture includes: The continuous information attack model also includes configuring on each electronic security perimeter device the type of defense equipment, the number of operation and maintenance personnel, and related factors that characterize the node's ability to resist information attacks; Use attack resources to characterize the attack intensity of the information attack model; The continuous information attack model is characterized by defense capability and attack intensity.

3. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 2, characterized in that: The establishing of a continuous information attack model based on the power cyber-physical system architecture further includes: When an information node fails, it is determined that the target power system can no longer independently cope with the information attack, and the continuous attack ends; When the continuous information attack model attacks successfully and causes the physical node to fail, it is considered that the information-physical collaboration has failed and the communication loss cannot be recovered.

4. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 3, characterized in that: The coupling degree characterizing the plurality of nodes in the power cyber-physical system architecture includes: The coupling degrees of the plurality of nodes include coupling degrees between a plurality of physical nodes and information nodes corresponding to the physical nodes; The coupling degree is used to characterize the degree of damage to the distribution network caused by physical node failure, information node failure, and joint failure of physical node and information node; If a joint fault occurs and the damage caused by the joint fault to the target power system is greater than the sum of the damage caused by the failure of two independent nodes, the physical node and the information node, it is determined to be a coordinated fault; Otherwise, the joint fault is determined to be a basic fault of two independent nodes, the physical node and the information node.

5. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 4, characterized in that: The establishing of the defense strategy based on the coupling degree includes: If the physical node fails and the information node is normal, it is determined that the continuous information attack model has not successfully attacked the physical node and the information node; If the physical node is normal and the information node fails, it is considered that the continuous information attack model has successfully attacked and caused the information node to fail; If the physical node fails and the information node fails, it is considered that the continuous information attack model successfully attacks and causes the information node to fail, and causes the physical node to fail.

6. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 5, characterized in that: The power cyber-physical system architecture includes: Each physical node in the grid structure of the target power system is composed into a physical system model; All information devices of each physical node in the power grid structure of the target power system are assembled into an information node. This information node forms an information-physical coupling with its corresponding physical node, and all information nodes form an information system model.

7. A method for defending against continuous information attacks on a power grid based on node coupling as claimed in claim 6, characterized in that: The power cyber-physical system architecture also includes recording the results of all cyber-physical couplings as a cyber-physical interaction layer model.

8. A power grid continuous information attack defense system based on node coupling degree, applying the method according to any one of claims 1 to 7, characterized in that: include: An architecture establishment module, configured to obtain a grid structure of a target power system and establish a power cyber-physical system architecture based on the grid structure; The power cyber-physical system architecture includes a physical system model, an information system model, and a cyber-physical interaction layer model; An attack model building module, used to build a continuous information attack model based on the power cyber-physical system architecture; The continuous information attack model includes presetting a number of security zones, each of which is equipped with an electronic security perimeter device, matching an information attack model for each electronic security perimeter device, and integrating the information attack models of all electronic security perimeter devices as a continuous information attack model; a defense strategy formulation module, configured to characterize the coupling degree of a plurality of nodes in the power cyber-physical system architecture and establish a defense strategy based on the coupling degree; A testing module is used to test the defense strategy based on the continuous information attack model.

9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of a method for defending against continuous information attacks on a power grid based on node coupling degree according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of a method for defending against continuous information attacks on a power grid based on node coupling degree according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • AI security agent automatic defense system and method

    CN121509114A