Intelligent defense method for power terminal based on digital twinborn body
By establishing a digital twin of the power terminal and combining reinforcement learning and data analysis technologies, potential attack behaviors can be monitored and identified in real time, and optimal defense strategies can be generated. This solves the problem of identifying and defending against unknown attack behaviors in existing technologies and improves the security and defense efficiency of the power terminal.
Patent Information
- Application Number
- CN202511440510.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-10-10
AI Technical Summary
Existing power terminal security measures are ineffective in responding to unknown attacks, resulting in false alarms and missed alarms.
By establishing a digital twin of the power terminal, reinforcement learning, Bayesian formula, wavelet transform and GARCH model are used to monitor the terminal's operating status in real time, generate the optimal defense strategy, and combine it with a BP neural network to judge potential attack behaviors.
It enables real-time monitoring of power terminals and accurate identification of potential attack behaviors, generates dynamic defense strategies, improves security and defense efficiency, and avoids false alarms and missed alarms.
Smart Images

Figure CN120896802A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intelligent defense, more particularly, the present application relates to a power terminal intelligent defense method based on digital twin. BACKGROUND
[0002] With the development of smart power systems, more and more power terminal devices (such as smart meters, power distribution switches, and relay protection devices) are connected to the power network and exchange data with the dispatch center through communication protocols. Although the smart power system improves work efficiency and management level, it also brings new network security challenges. Power terminals may be subject to various network attacks (such as malicious data injection and denial of service attacks), which can cause device failure, data leakage, or even system paralysis, seriously affecting power supply and social security. Currently, most security protection measures for power terminals focus on rule-based monitoring and intrusion detection systems. These systems rely on static rules and predefined attack patterns, but cannot respond to unknown attack behaviors and have false positives and false negatives. SUMMARY
[0003] In order to overcome the above-mentioned defects of the prior art, the embodiments of the present application provide a power terminal intelligent defense method based on digital twin to solve the problems raised in the background art.
[0004] To achieve the above-mentioned purpose, the present application provides the following technical scheme:
[0005] A power terminal intelligent defense method based on digital twin, specifically comprising the following steps:
[0006] S1: Collecting the operation data of the power terminal, establishing a power terminal digital twin, ensuring that the power terminal digital twin and the power terminal are in a synchronous operation state, and simulating an attack chain in the twin environment through reinforcement learning to generate an optimal defense strategy, and dynamically issuing the verified strategy to the physical terminal;
[0007] S2: Comparing the real-time operation data of the power terminal in the monitoring interval with the historical training data of the power terminal digital twin, and determining the operation difference information of the power terminal using the Bayes formula;
[0008] S3: Analyzing the continuous change data in the power terminal operation data through wavelet transform and GARCH model to determine the operation trend information of the power terminal;
[0009] S4: Comprehensive analysis of the operation difference information and operation trend information of the power terminal, construction of an operation evaluation model in the power terminal twin through BP neural network, and judgment of whether there is a potential attack behavior in the power terminal operation data.
[0010] In a preferred embodiment, the operation difference information and the operation trend information of the power terminal are determined, including:
[0011] The operation difference information of the power terminal is represented by a data probability analysis coefficient, and the operation trend information of the power terminal is represented by a frequency domain data local anomaly coefficient and an overall data anomaly fluctuation coefficient, wherein, the data probability analysis coefficient is, the anomaly data proportion coefficient of the i-th continuous change data is, and the overall data anomaly fluctuation coefficient is.
[0012] In a preferred embodiment, the data probability analysis coefficient is obtained by the following logic:
[0013] The operation characteristics of the power terminal in the monitoring interval are determined, and the operation characteristics of the power terminal in the monitoring interval are compared with the operation characteristics of the historical training data of the power terminal twin, and the historical similar operation characteristics are determined according to the cosine similarity calculation, and the calculation formula of the cosine similarity is: ; wherein, the cosine similarity of the operation characteristics of the power terminal in the monitoring interval and the operation characteristics of the historical training data is A, and the operation characteristics of the power terminal in the monitoring interval are, the operation characteristics of the historical training data are, n = 1, 2, 3, …, N, N is a positive integer, and n is the number of the operation characteristics of the historical training data;
[0014] The index of the historical similar operation characteristics in the historical training data is determined, and the calculation formula is: ; wherein, XS is the index of the historical similar operation characteristics in the historical training data;
[0015] Based on the historical training data, the prior probability of the power terminal twin occurring potential attack behavior is determined, and the prior probability of the power terminal twin occurring potential attack behavior is marked as: , and the historical training data is smoothed by using kernel density estimation, the probability of the historical similar operation characteristics in the historical training data is determined, and the probability of the historical similar operation characteristics in the historical training data is marked as: , the probability of the power terminal twin occurring potential attack behavior under the historical similar operation characteristics is obtained, and the probability of the power terminal twin occurring potential attack behavior under the historical similar operation characteristics is marked as: ;
[0016] The data probability analysis coefficient is calculated by the Bayes formula, and the calculation formula is: .
[0017] In a preferred embodiment, the acquisition logic of the frequency domain data local anomaly coefficient is:
[0018] The data type with continuous variation characteristics is extracted from the power terminal operation data in the monitoring interval, and the time series of the continuous variation data type in the monitoring interval is obtained. The continuous variation data type in the monitoring interval is analyzed by wavelet transform, and the wavelet variation expression of the continuous variation data type in the monitoring interval is: ; wherein, is the data of the i-th continuous variation data in the monitoring interval through wavelet transform, is the data of the i-th continuous variation data in the time domain, a is the scale parameter of the wavelet function, and b is the translation parameter of the wavelet function, is the wavelet function of the i-th continuous variation data, i=1, 2, 3, …, I, I is a positive integer, and i is the number of continuous variation data types;
[0019] The peak frequency and center frequency of the continuous variation data type in the monitoring interval after wavelet variation are determined, the frequency offset coefficient of different types of continuous variation data is calculated, and the calculation formula is: ; wherein, is the frequency offset coefficient of the i-th continuous variation data, is the center frequency of the i-th continuous variation data;
[0020] The wavelet coefficient threshold of different continuous variation data types is set, and the abnormal data proportion coefficient is calculated, and the calculation formula is: ; wherein, is the time period in the monitoring interval greater than the wavelet coefficient threshold of different continuous variation data types;
[0021] The frequency domain data local anomaly coefficient is calculated, and the calculation formula is: ; wherein, is the frequency domain data local anomaly coefficient, is the weight of different continuous variation data types.
[0022] In a preferred embodiment, the acquisition logic of the overall data anomaly fluctuation coefficient is:
[0023] Based on the continuous variation data type of the power terminal in the monitoring interval, the time series of the continuous variation data type is used as the input data of the GARCH model, the GARCH model is used to fit different types of continuous variation data in the monitoring interval, the conditional variance of different types of continuous variation data in the monitoring interval at different time points and different time lags is obtained, and the conditional variance of different types of continuous variation data in the monitoring interval at different time points and different time lags is uniformly marked as: ; wherein, f = 1, 2, 3, …, F, F is a positive integer, f is the order of the GARCH model, when f = 0, is the conditional variance of the current time point in the GARCH model of different kinds of continuous change data;
[0024] The conditional variance threshold of different kinds of continuous change data is set, the conditional variances of different kinds of continuous change data at different time points and different time lags in the monitoring interval are compared with the conditional variance threshold, the number of conditional variances greater than the conditional variance threshold in the monitoring interval is counted, and the number of conditional variances greater than the conditional variance threshold is marked as: ;
[0025] The overall data anomaly fluctuation coefficient is calculated, and the calculation formula is: .
[0026] In a preferred embodiment, an operation evaluation model is constructed in the power terminal twin through a BP neural network, including:
[0027] The operation difference information and the operation trend information of the power terminal are comprehensively analyzed, the normalized data probability analysis coefficient, the frequency domain data local anomaly coefficient and the overall data anomaly fluctuation coefficient are used to construct an operation evaluation model in the power terminal twin through a BP neural network, and an operation evaluation coefficient is generated. The calculation formula of the operation evaluation coefficient is: ; wherein, is the operation evaluation coefficient, , , are the proportional coefficients of the data probability analysis coefficient, the frequency domain data local anomaly coefficient and the overall data anomaly fluctuation coefficient respectively, , , are all greater than 0.
[0028] In a preferred embodiment, whether the power terminal operation data has a potential attack behavior is judged, including:
[0029] The operation evaluation coefficient threshold is set, and the operation evaluation coefficient of the monitoring interval is compared with the operation evaluation coefficient threshold;
[0030] If the operation evaluation coefficient is greater than the operation evaluation coefficient threshold value, the power terminal twin generates an early warning signal, the power terminal operation data in the monitoring interval is regarded as a potential attack behavior in the power terminal twin, the power terminal twin simulates the potential attack chain through reinforcement learning technology and verifies whether the potential attack behavior is a new attack behavior, if it is determined to be a known potential attack behavior, the known defense strategy is used to respond, if it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in time, and the new attack behavior is regarded as a potential attack behavior in the twin to train the defense strategy through reinforcement learning.
[0031] If the operation evaluation coefficient is less than the operation evaluation coefficient threshold value, no early warning signal is generated, and the operation data of the power terminal in the monitoring interval is regarded as normal operation data.
[0032] The technical effects and advantages of the present application are:
[0033] The present application establishes the digital twin of the power terminal, and combines reinforcement learning, Bayesian formula, wavelet transform, GARCH model and other technologies to monitor the operation state of the power terminal in real time, detect potential attack behaviors, first, the operation data of the power terminal is collected, the digital twin is constructed and its operation state is synchronized, then the operation difference information of the power terminal is determined by comparing the historical training data with the real-time data, the continuous change data is analyzed by wavelet transform and GARCH model to obtain the operation trend information, finally, the operation evaluation model is constructed by BP neural network combined with the operation difference and trend information to judge whether there is a potential attack behavior, the present application uses the digital twin of the power terminal to simulate different potential attack behaviors through reinforcement learning to generate the optimal defense strategy, and ensures that the twin environment can accurately identify the attack behavior. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to facilitate those skilled in the art to understand, the present application will be further described below in conjunction with the drawings;
[0035] Figure 1 The flowchart of the present application is shown in the figure. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application, obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0037] Embodiment 1
[0038] Figure 1 A flowchart of a power terminal intelligent defense method based on a digital twin for the application, specifically comprising the following steps:
[0039] S1: By collecting the operation data of the power terminal, a digital twin of the power terminal is established to ensure that the digital twin of the power terminal is in a synchronous operation state with the power terminal, and an attack chain is simulated in the twin environment through reinforcement learning to generate an optimal defense strategy, and the verified strategy is dynamically issued to the physical terminal;
[0040] S2: By comparing the real-time operation data of the power terminal in the monitoring interval with the historical training data of the digital twin of the power terminal, the operation difference information of the power terminal is determined using the Bayes formula;
[0041] S3: The continuous change data in the operation data of the power terminal is analyzed by wavelet transform and GARCH model to determine the operation trend information of the power terminal;
[0042] S4: The operation difference information and operation trend information of the power terminal are comprehensively analyzed, and an operation evaluation model is constructed in the power terminal twin through BP neural network to determine whether there is a potential attack behavior in the operation data of the power terminal.
[0043] On the power terminal such as a smart meter, a power distribution switch, and a relay protection device, an edge gateway or a security agent is deployed, and the operation data of the power terminal is collected to establish a digital twin model on the edge side, i.e., a "full virtual copy" of the terminal, which covers data input, operation logic, and control interface. The operation data includes physical layer data such as voltage, current, frequency, power factor, and harmonic information, communication data such as messages, control instructions, and heartbeat packets between the terminal and the main station / distribution center, and operation state data such as logs, alarm information, and device internal register state.
[0044] The operation data of the physical terminal is continuously input into the twin through a real-time stream data bus (such as MQTT, OPC UA, or IEC 104 protocol analysis module), and the twin updates its model according to the collected data to ensure that its operation state is consistent with that of the physical terminal. For example, if the physical terminal receives a switch closing instruction from the dispatch center, the twin will also "receive and execute" the instruction.
[0045] The twin of the power terminal is based on the historical operation data of the power terminal to establish a normal operation behavior portrait of the power terminal in the monitoring interval. Once the operation data of the power terminal deviates from the normal operation behavior portrait, the potential attack behavior is blocked to prevent it from attacking the power terminal.
[0046] It should be noted that the power terminal operation data itself may have transient fluctuations (such as load surge, voltage short-time jitter, communication delay), if each single point data is judged, it will cause too many false positives, by setting the monitoring interval, the short-term fluctuation is distinguished from the real abnormality, the reliability of the judgment is improved, and the normal operation behavior portrait is usually based on the mode trained by historical statistical characteristics or model, if the single point data is directly used for comparison, it will be difficult to match the portrait, because the instantaneous data may deviate from the mean but still belong to normal fluctuation, and the monitoring interval contains continuous data, which is convenient for twin body simulation attack, training reinforcement learning strategy.
[0047] Based on different potential attack behaviors, the twin body of the power terminal simulates different potential attack behaviors through reinforcement learning to generate the optimal defense strategy, including twin environment preparation, attack chain simulation and strategy verification, etc., wherein:
[0048] The twin environment preparation includes state definition, action definition and reward function, the state definition obtains the state of the power terminal at each time point in the twin body, the state of the whole monitoring interval can be represented in the form of vector or tensor, the action definition constructs a set of defense actions, such as adjusting firewall rules, limiting abnormal control instruction execution, etc., the positive reward in the reward function includes preventing attack success, keeping the device normal operation, reducing false positive rate, etc., and the negative reward includes attack success leading to abnormality, false sealing normal operation, causing service interruption;
[0049] Attack chain simulation includes injecting potential attack behaviors in the twin body of the power terminal, including virtual injection of current / voltage data offset, pseudo abnormal high frequency message access, etc., the attack can be single step or multi-step chain attack, and reinforcement learning responds by exploring different defense action combinations;
[0050] Strategy verification tests the effect of potential attack behaviors in the twin body of the power terminal, and the evaluation indexes include false positive rate, system performance overhead, etc., only the strategies that pass the verification are issued to the physical terminal.
[0051] It should be noted that after the defense strategy is trained in the twin body, strict verification test will be carried out first to ensure that the strategy can effectively defend against the simulated attack scenario and will not cause adverse reactions of the system.
[0052] Based on the known potential attack behaviors in the twin environment of the power terminal, the twin body of the power terminal compares the historical training data and new attack behavior signs to judge whether the new attack belongs to the existing potential attack behavior, if it is determined that the new attack belongs to the known potential attack behavior, the known defense strategy is directly used to respond, if the new attack behavior does not match the existing attack pattern, the new attack behavior is taken as a potential attack behavior in the twin body to train the defense strategy through reinforcement learning.
[0053] Based on the real-time synchronization data of the twin and the power terminal, an operation evaluation model is constructed in the power terminal twin, that is, the real-time data is analyzed by the operation evaluation model to determine whether the operation data of the power terminal in the monitoring interval is a potential attack behavior, wherein the operation difference information and the operation trend information of the power terminal are determined by analyzing the operation data of the power terminal, the operation difference information of the power terminal is represented by a data probability analysis coefficient, and the operation trend information of the power terminal is represented by a frequency domain data local anomaly coefficient and an overall data anomaly fluctuation coefficient.
[0054] The data probability analysis coefficient has the following advantages:
[0055] The data probability analysis coefficient combines the similarity of the operation data of the power terminal in the current monitoring interval and the historical data, and can determine whether the operation state of the power terminal deviates from the normal range in real time. With the generation of new operation data, the system will continuously train and update the prior and posterior probabilities to improve the accuracy of attack behavior identification.
[0056] The historical training data includes normal behavior and potential attack behavior. In the twin environment, the system gradually learns how to make the optimal decision according to the historical data through reinforcement learning. With training, the system can continuously distinguish between potential attack behavior and normal operation state, thereby improving the effectiveness of the defense strategy and avoiding the limitations of manually setting rules. The system completely relies on historical data and actual operation environment to ensure the scientificity of the decision.
[0057] The data probability analysis coefficient considers various operation characteristics such as electrical parameters and control states, and combines historical data analysis to more comprehensively identify potential attacks. The data probability analysis coefficient can model the operation data of the power terminal through accurate probability distribution, thereby helping to identify abnormal or potential attack behavior.
[0058] The acquisition logic of the data probability analysis coefficient is as follows: the operation characteristics of the power terminal in the monitoring interval are determined, the operation characteristics of the power terminal in the monitoring interval are compared with the operation characteristics of the historical training data of the power terminal twin, the historical similar operation characteristics are determined according to the cosine similarity calculation, and the calculation formula of the cosine similarity is as follows: ; wherein, is the cosine similarity of the operation characteristics of the power terminal in the monitoring interval and the operation characteristics of the historical training data, A is the operation characteristics of the power terminal in the monitoring interval, is the operation characteristics of the historical training data, n = 1, 2, 3, …, N, N is a positive integer, and n is the number of the operation characteristics of the historical training data;
[0059] The index of the historical similar operation characteristics in the historical training data is determined, and the calculation formula is as follows: ; wherein, XS is the index of the historical similar operation feature in the historical training data;
[0060] It should be noted that the operation features of the power terminal include electrical parameters and control states, such as current, voltage, power, frequency, etc., and the operation features of the power terminal can directly reflect various physical quantities and operating parameters of the power terminal in normal or abnormal operating states;
[0061] The historical training data refers to the data used in the reinforcement learning training process in the twin environment, which is generated from the historical data of the power terminal, including historical normal data and historical potential attack behavior data of the power terminal. In the process of reinforcement learning, through simulation and training, the system can distinguish between normal behavior and potential attack behavior, and gradually learn how to make the best decision based on historical data.
[0062] Based on the historical training data, the prior probability of the power terminal twin body occurring potential attack behavior is determined, and the prior probability of the power terminal twin body occurring potential attack behavior is marked as: , and the historical training data is smoothed using kernel density estimation, the probability of the historical similar operation feature in the historical training data is determined, and the probability of the historical similar operation feature in the historical training data is marked as: , the probability of the power terminal twin body occurring potential attack behavior under the historical similar operation feature is obtained, and the probability of the power terminal twin body occurring potential attack behavior under the historical similar operation feature is marked as: ;
[0063] The data probability analysis coefficient is calculated by the Bayes formula, and the calculation formula is: ; wherein, is the data probability analysis coefficient.
[0064] As can be seen from the formula, the larger the data probability analysis coefficient, the more likely it is that the operation data of the power terminal in the monitoring interval is a potential attack behavior, that is, the operation data of the current power terminal is more similar to the potential attack behavior data in the historical training data.
[0065] The local anomaly coefficient of frequency domain data has the following advantages:
[0066] The local anomaly coefficient of frequency domain data helps to capture the mutation of non-stationary signals. In power systems, many potential attack behaviors or faults may cause instantaneous changes in signals, especially in the time domain, which are difficult to detect. Frequency domain analysis can highlight these sudden changes.
[0067] By assigning different weights to different data types, the frequency domain data local anomaly coefficient can more accurately and efficiently identify potential attack behaviors in the power system. False data injection attacks may cause abnormal fluctuations in current and voltage, while DDoS attacks may affect communication networks and data traffic. By assigning weights to each data type, the system can adapt to changes in different attack patterns and improve detection sensitivity.
[0068] The frequency domain data local anomaly coefficient can reveal local mutations in signals, such as sudden changes in power terminal operation data at a certain time (such as instantaneous power fluctuations or current peaks), which are usually caused by abnormal fluctuations in attack behaviors (such as false data injection, denial-of-service attacks, etc.). It is suitable for discovering instantaneous attack behaviors or faults.
[0069] The acquisition logic of the frequency domain data local anomaly coefficient is as follows: from the power terminal operation data in the monitoring interval, extract the data type with continuous change characteristics, and obtain the time series of the continuous change data type in the monitoring interval. The wavelet transform is used to analyze the continuous change data type in the monitoring interval, and the wavelet change expression of the continuous change data type in the monitoring interval is: ; wherein, is the data of the ith continuous change data in the monitoring interval through wavelet transform, is the data of the ith continuous change data in the monitoring interval in the time domain, a is the scale parameter of the wavelet function, and b is the translation parameter of the wavelet function, is the wavelet function of the ith continuous change data, i = 1, 2, 3, …, I, I is a positive integer, and i is the number of continuous change data types;
[0070] It should be noted that through wavelet transform, continuous change data can be converted from time domain to frequency domain, capturing high-frequency mutations or low-frequency trends in data, thereby helping to detect anomalies. The scale and translation parameters are usually determined by professionals through actual data analysis and experience based on the characteristics of power terminal data, ensuring that the anomalies or change characteristics in the signal can be effectively extracted;
[0071] Data types with continuous change characteristics usually refer to those that do not experience dramatic fluctuations or irregular jumps under normal working conditions, but exhibit smooth changes, gradual changes, or periodic fluctuations, including voltage, current, power, load, etc. Therefore, by analyzing data types with continuous change characteristics, potential attack behaviors can be effectively determined. Through wavelet changes, sudden fluctuations and short-term anomalies can be analyzed, and local changes in data can be analyzed, which helps to capture abnormal behaviors that usually exhibit mutations, fluctuations, such as malicious data injection attacks.
[0072] The peak frequency and center frequency of the continuous change data type after wavelet change in the monitoring interval are determined, the frequency offset coefficient of different types of continuous change data is calculated, and the calculation formula is: ; wherein, is the frequency offset coefficient of the ith type of continuous change data, is the center frequency of the ith type of continuous change data;
[0073] The wavelet coefficient threshold of different continuous change data types is set, and the abnormal data proportion coefficient is calculated, and the calculation formula is: ; wherein, is the abnormal data proportion coefficient of the ith type of continuous change data, is the time period greater than the wavelet coefficient threshold of different continuous change data types in the monitoring interval;
[0074] The local abnormal coefficient of frequency domain data is calculated, and the calculation formula is: ; wherein, is the local abnormal coefficient of frequency domain data, is the weight of different continuous change data types;
[0075] It should be noted that some data types such as load have large local changes under certain working conditions, because the power system may have certain fluctuations during load change, equipment adjustment or operation process, and these fluctuations do not necessarily mean potential attack behavior, on the other hand, key data types such as voltage and current should maintain certain smooth fluctuations in the normal operation of the system, and the sharp change in a short time is more likely to mean that the system has suffered malicious attack, therefore the weight of different continuous change data types reflects the sensitivity of each data type and the relationship between it and potential attack behavior.
[0076] As can be seen from the formula, the greater the local abnormal coefficient of frequency domain data, the greater the local change of the power terminal operation data in the monitoring interval, that is, the operation data of the power terminal in the monitoring interval has a sudden change in some frequency bands, which may indicate that the system has suffered potential attack behavior.
[0077] The overall data abnormal fluctuation coefficient has the following advantages:
[0078] The overall data abnormal fluctuation coefficient captures the volatility clustering effect of the power terminal system under attack or abnormal state through the GARCH model, helps to detect potential attack behavior in real time, and accurately judges whether the current fluctuation is outside the normal fluctuation range and judges potential attack;
[0079] The overall data abnormal fluctuation coefficient changes with the state of the power terminal, adjusts the prediction result in real time, can more accurately reflect the dynamic change of data, can more respond to the volatility change caused by attacks, and can dynamically adjust the conditional variance according to real-time data, has strong adaptability and accuracy.
[0080] The acquisition logic of the overall data abnormal fluctuation coefficient is: based on the continuous change data type of the power terminal in the monitoring interval, taking the time sequence of the continuous change data type as the input data of the GARCH model, using the GARCH model to fit different kinds of continuous change data in the monitoring interval, obtaining the conditional variance of different kinds of continuous change data in the monitoring interval at different time points and different time lags, and uniformly marking the conditional variance of different kinds of continuous change data in the monitoring interval at different time points and different time lags as: ; wherein f=1, 2, 3, …, F, F is a positive integer, f is the order of the GARCH model, when f=0, is the conditional variance of the GARCH model of different kinds of continuous change data at the current time point;
[0081] It should be noted that in the data analysis of the power terminal, the conditional variance is a predicted value based on historical data, used to measure the volatility at the current time, and the attack behavior will cause the volatility of the data to increase dramatically.
[0082] The conditional variance threshold of different kinds of continuous change data is set, the conditional variance of different kinds of continuous change data in the monitoring interval at different time points and different time lags is compared with the conditional variance threshold, the number of conditional variances greater than the conditional variance threshold in the monitoring interval is counted, and the number of conditional variances greater than the conditional variance threshold is marked as: ;
[0083] It should be noted that the conditional variance threshold of different kinds of continuous change data is based on the conditional variance level of the normal operation data in the power terminal twin, which can be set by the distribution of the training data.
[0084] The overall data abnormal fluctuation coefficient is calculated, and the calculation formula is: ; wherein is the overall data abnormal fluctuation coefficient.
[0085] As can be seen from the formula, the larger the overall data abnormal fluctuation coefficient, the greater the volatility of the power terminal operation data in the monitoring interval, and there may be potential attack behavior.
[0086] The operation difference information and operation trend information of the power terminal are comprehensively analyzed, the normalized data probability analysis coefficient, the frequency domain data local anomaly coefficient and the overall data anomaly fluctuation coefficient are constructed into an operation evaluation model in the power terminal twin through a BP neural network, an operation evaluation coefficient is generated, and a calculation formula of the operation evaluation coefficient is: ; wherein, is the operation evaluation coefficient, , , are proportional coefficients of the data probability analysis coefficient, the frequency domain data local anomaly coefficient and the overall data anomaly fluctuation coefficient respectively, , , are all greater than 0.
[0087] As can be seen from the formula, the greater the data probability analysis coefficient, the frequency domain data local anomaly coefficient and the overall data anomaly fluctuation coefficient, the greater the operation evaluation coefficient, and the higher the safety risk of the power terminal in the monitoring interval, and the more likely the potential attack behavior occurs.
[0088] The operation evaluation coefficient threshold is set, the operation evaluation coefficient of the monitoring interval is compared with the operation evaluation coefficient threshold, if the operation evaluation coefficient is greater than the operation evaluation coefficient threshold, the power terminal twin generates an early warning signal, the synchronous power terminal operation data in the monitoring interval is taken as a potential attack behavior in the power terminal twin, the power terminal twin further analyzes the potential attack behavior, simulates the potential attack chain through reinforcement learning technology and verifies whether the potential attack behavior is a new attack behavior, if it is determined to be a known potential attack behavior, the known defense strategy is used to cope with it, if it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in time, and the new attack behavior is taken as a potential attack behavior in the twin to train the defense strategy through reinforcement learning, if the operation evaluation coefficient is less than the operation evaluation coefficient threshold, no early warning signal is generated, and the operation data of the power terminal in the monitoring interval is regarded as normal operation data.
[0089] It should be noted that the setting of the operation evaluation coefficient threshold is combined with reinforcement learning to optimize and adjust, that is, if the reinforcement learning judges that the potential attack behavior is not a new attack behavior and has no attack, the threshold is increased to avoid excessive false positives.
[0090] The above formulas are all dimensionless values, the formula is obtained by software simulation of a large amount of data to obtain a formula of the nearest real situation, and the preset parameters in the formula are set by the person skilled in the art according to the actual situation.
[0091] The above-described embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.
[0092] It should be understood that the size of the sequence number of each process described above in various embodiments of the present application does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0093] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be realized in electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0094] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.
[0095] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiments is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0096] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and various other media that can store program codes.
[0097] The above describes only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A smart defense method for power terminals based on digital twins, characterized in that, Specifically, the following steps are included: S1: By collecting the operating data of the power terminal, a digital twin of the power terminal is established to ensure that the digital twin of the power terminal operates synchronously with the power terminal. Then, through reinforcement learning, an attack chain is simulated in the twin environment to generate the optimal defense strategy, and the verified strategy is dynamically distributed to the physical terminal. S2: By comparing the real-time operating data of the power terminals within the monitoring range with the historical training data of the digital twins of the power terminals, the Bayesian formula is used to determine the operating difference information of the power terminals. S3: Analyze the continuously changing data in the power terminal operation data through wavelet transform and GARCH model to determine the operation trend information of the power terminal; S4: Conduct a comprehensive analysis of the operational differences and trends of the power terminals, and construct an operational evaluation model in the power terminal twin using a BP neural network to determine whether there are potential attack behaviors in the power terminal operational data.
2. The intelligent defense method for power terminals based on digital twins according to claim 1, characterized in that, Determine the operational differences and trends of power terminals, including: The operational differences of power terminals are represented by data probability analysis coefficients, and the operational trends of power terminals are represented by local anomaly coefficients and overall data anomaly fluctuation coefficients in the frequency domain. For data probability analysis coefficients, Let be the coefficient representing the proportion of outlier data in the i-th type of continuously changing data. This represents the coefficient for abnormal fluctuations in the overall data.
3. The intelligent defense method for power terminals based on digital twins according to claim 2, characterized in that, The logic for obtaining the data probability analysis coefficients is as follows: The operational characteristics of power terminals within the monitoring interval are determined. These characteristics are then compared with the operational characteristics of historical training data from the power terminal twins. Historically similar operational characteristics are determined based on cosine similarity calculations. The formula for calculating cosine similarity is as follows: ;in, To measure the cosine similarity between the operating characteristics of power terminals within the monitoring interval and the operating characteristics of historical training data, let A represent the operating characteristics of power terminals within the monitoring interval. The running characteristics of the historical training data are n = 1, 2, 3, ..., N, where N is a positive integer and n is the number of the running characteristics of the historical training data. The index of historically similar operational features in the historical training data is determined by the following formula: Where XS is the index of historically similar running features in historical training data; Based on historical training data, the prior probability of a potential attack by a power terminal twin is determined, and this prior probability is denoted as: Furthermore, kernel density estimation is used to smooth the historical training data, and the probability of historically similar running features in the historical training data is determined. The probability of historically similar running features in the historical training data is labeled as follows: The probability of a power terminal twin engaging in potential attack behavior under historically similar operating characteristics is obtained, and this probability is denoted as: ; The probability analysis coefficients of the data are calculated using Bayes' theorem. The formula is as follows: .
4. The intelligent defense method for power terminals based on digital twins according to claim 3, characterized in that, The logic for obtaining the local anomaly coefficients of the frequency domain data is as follows: Data types with continuously changing characteristics are extracted from the power terminal operation data within the monitoring interval, and the time series of these continuously changing data types within the monitoring interval is obtained. Wavelet transform is then used to analyze these continuously changing data types within the monitoring interval. The wavelet transform expression for these continuously changing data types within the monitoring interval is as follows: ;in, To monitor the data of the i-th continuously changing data within the monitoring interval through wavelet transform, To monitor the i-th continuously varying data within the interval in the time domain, 'a' represents the scaling parameter of the wavelet function, and 'b' represents the translation parameter of the wavelet function. Let i be the wavelet function for the i-th type of continuously changing data, where i = 1, 2, 3, ..., I, where I is a positive integer and i is the number of the type of continuously changing data. Determine the peak and center frequencies of continuously changing data types within the monitoring interval after wavelet transformation, and calculate the frequency shift coefficients for different types of continuously changing data. The calculation formula is as follows: ;in, For the i-th type of continuously varying data, the frequency offset coefficient is... The center frequency of the i-th continuously changing data; Set threshold values for wavelet coefficients for different continuously changing data types, and calculate the outlier data ratio coefficient using the following formula: ;in, The time period within the monitoring interval that exceeds the threshold of wavelet coefficients for different continuously changing data types; The formula for calculating the local anomaly coefficient of frequency domain data is as follows: ;in, These are the local anomaly coefficients of the frequency domain data. Weights for different continuously changing data types.
5. The intelligent defense method for power terminals based on digital twins according to claim 4, characterized in that, The logic for obtaining the overall data abnormal fluctuation coefficient is as follows: Based on the continuously changing data type of power terminals within the monitoring interval, the time series of continuously changing data types are used as input data for the GARCH model. The GARCH model is used to fit different types of continuously changing data within the monitoring interval, obtaining the conditional variances of different types of continuously changing data at different time points and different time lags within the monitoring interval. The conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags are uniformly labeled as: Where f = 1, 2, 3, ..., F, F is a positive integer, and f is the order of the GARCH model. When f = 0, The conditional variance at the current time point in a GARCH model for different types of continuously varying data; Set conditional variance thresholds for different types of continuously changing data. Compare the conditional variances of different types of continuously changing data within the monitoring interval at different time points and different time lags with the conditional variance thresholds. Count the number of conditional variances within the monitoring interval that exceed the conditional variance thresholds. Mark the number of conditional variances that exceed the conditional variance thresholds as: ; The formula for calculating the overall data anomaly fluctuation coefficient is as follows: .
6. The intelligent defense method for power terminals based on digital twins according to claim 5, characterized in that, An operational evaluation model is constructed in a power terminal twin using a backpropagation neural network, including: By comprehensively analyzing the operational difference and trend information of power terminals, the normalized data probability analysis coefficients, frequency domain data local anomaly coefficients, and overall data anomaly fluctuation coefficients are used to construct an operational evaluation model in the power terminal twin using a BP neural network, generating operational evaluation coefficients. The calculation formula for the operational evaluation coefficients is as follows: ;in, For operational evaluation coefficients, , , These are the proportional coefficients for data probability analysis coefficients, local anomaly coefficients in frequency domain data, and overall data anomaly fluctuation coefficients, respectively. , , All are greater than 0.
7. A smart defense method for power terminals based on digital twins according to claim 6, characterized in that, Determining whether there are potential attacks on the power terminal's operational data includes: Set an operational evaluation coefficient threshold and compare the operational evaluation coefficient of the monitoring interval with the operational evaluation coefficient threshold; If the operation evaluation coefficient is greater than the operation evaluation coefficient threshold, the power terminal twin generates an early warning signal. In the power terminal twin, the synchronous power terminal operation data within the monitoring range is taken as potential attack behavior. The power terminal twin simulates the potential attack chain and verifies whether the potential attack behavior is a new attack behavior through reinforcement learning technology. If it is determined to be a known potential attack behavior, the known defense strategy is used to deal with it. If it is a new attack behavior, the new attack behavior is blocked from continuing to attack the power terminal in time. The new attack behavior is taken as a potential attack behavior and the defense strategy is trained in the twin through reinforcement learning. If the operation evaluation coefficient is less than the operation evaluation coefficient threshold, no warning signal will be generated, and the operation data of the power terminals within the monitoring range will be regarded as normal operation data.
Citation Information
Patent Citations
Construction method and equipment of digital twinborn model of power data communication network, and medium
CN115801594A
Dynamic water resource monitoring method and system based on digital twinning
CN118886663A
Network attack and defense decision support method and system based on artificial intelligence
CN119155099A
Harbor district power load boundary prediction system based on two-stage model and regulation and control method
CN120430445A
Substation automation system network security monitoring method and system
CN120498909A
Cited By
Microgrid security defense method and system based on digital twinning, medium and product
CN122247759A
Power system fault prediction method based on digital twinning
CN122307239A