Terminal traffic anomaly detection method, device and equipment in smart power grid, storage medium and program product
By using a matrix long short-term neural network model to perform feature vectorization and behavior prediction of smart grid terminal traffic, and combining data processing strategies for different behaviors, the problem of terminal security protection in smart grids is solved, and efficient traffic anomaly detection and security response are achieved.
Patent Information
- Application Number
- CN202511109287.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-07
AI Technical Summary
The security protection of smart terminals in existing smart grids relies on attack characteristics, making it difficult to effectively detect variant attack behaviors at the traffic level and locate vulnerability attack details, resulting in security threats being difficult to effectively identify and prevent.
A matrix long short-term neural network model is used to vectorize terminal traffic characteristics, and a pre-set neural network model is used for behavior prediction. Based on the detection results, corresponding data processing strategies are implemented, including lightweight encryption, identity authentication, asymmetric encryption, and anomaly handling.
It improves the effectiveness and accuracy of terminal behavior modeling, enables efficient and accurate prediction of terminal behavior, enhances the security and controllability of terminal data transmission, and improves the efficiency of security risk response.
Smart Images

Figure CN120915534A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a terminal traffic anomaly detection method and device in a smart grid, a computer device, a computer readable storage medium and a computer program product. BACKGROUND
[0002] The smart grid is a complex information-physical system that deeply integrates advanced sensing technology, communication technology and physical power grid, and realizes the bidirectional and integrated flow of information flow and power flow. In the smart grid, the smart terminal plays an important role as an interface for data interaction between the information network and the power network. With the increase of smart grid business scenarios, various smart wireless terminal devices with wireless communication capabilities are widely introduced, such as smart handheld terminals, smart charging devices, micro-grid control units, smart meters, etc.
[0003] Although these smart wireless terminals bring the improvement of sensing and control capabilities to the smart grid and improve the digital level of the smart grid, they also face more security threats. The smart wireless terminal is easy to become an entry point for attackers to invade the smart grid, and attackers can cause state estimation errors or control decision errors through data tampering and interference attacks, which can cause unpredictable impact on the performance of the entire power grid. The security problems brought by the introduction of a large number of smart wireless terminals in the smart grid have become a prominent focus of the current smart grid security problem. In order to ensure the safe and stable operation of the smart grid, it is crucial to study the security technology of the smart grid wireless terminal device and prevent various attack behaviors in the smart grid.
[0004] At present, the security protection of intelligent terminals in the smart grid scenario basically adopts traditional security protection products, such as WAF (Web Application Firewall, website application level intrusion prevention system) application firewall, network traffic abnormal behavior threat perception, HIPS (Host Intrusion Prevent System, Host Intrusion Prevention System) unified security management system, NIPS (Network Intrusion Prevent System, Network Intrusion Prevention System) and the like, which make assumptions about how the request affects the operation and security of the application through intelligent terminal feature rules, and seriously rely on attack features to identify and prevent malicious behavior. However, in actual attack activities, attackers usually bypass the network level security protection device at the traffic level, such as adding additional encoding to the request to bypass the WAF protection, so that the WAF configuration rule cannot be normally matched, so as to execute the payload in the intelligent terminal, causing security threats. Therefore, the security protection capability of the intelligent terminal in the current smart grid scenario is limited, and it seriously relies on attack features to identify and explore malicious behavior, and there are problems such as difficulty in effectively detecting traffic level variant attack behavior and difficulty in locating vulnerability attack details. SUMMARY
[0005] Therefore, it is necessary to provide a terminal traffic anomaly detection method and device in a smart grid, computer equipment, computer readable storage medium and computer program product, which can detect abnormal traffic behavior and improve the security risk response efficiency.
[0006] In a first aspect, the present application provides a terminal traffic anomaly detection method in a smart grid, comprising:
[0007] Obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data;
[0008] Vectorizing the traffic features to obtain vector features;
[0009] Inputting the vector features into a preset neural network model to predict the terminal behavior at the next moment to obtain a behavior detection result; the preset neural network model is a matrix long short-term neural network model;
[0010] According to the behavior detection result, a corresponding data processing strategy is determined;
[0011] Processing the network traffic data based on the data processing strategy.
[0012] In one embodiment, the vectorization of the traffic features to obtain the vector features comprises:
[0013] obtain a word embedding model corresponding to the current service type; the word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model;
[0014] input the traffic feature into the word embedding model, perform vectorization processing on the traffic feature through the word embedding model, and obtain a vector feature.
[0015] In one of the embodiments, the behavior detection result includes any one of normal behavior, sensitive behavior and abnormal behavior.
[0016] In one of the embodiments, the network traffic data is processed based on the data processing strategy, including:
[0017] In a case where the behavior detection result is normal behavior, the network traffic data is processed based on a data processing strategy corresponding to the normal behavior, using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of a terminal device;
[0018] In a case where the behavior detection result is sensitive behavior, the network traffic data is processed using an asymmetric encryption strategy or an instruction set protection strategy;
[0019] In a case where the behavior detection result is abnormal behavior, the network traffic data is processed using an abnormal processing strategy; the abnormal processing strategy includes suspending data transmission, sending an abnormal signal, recording and delivering abnormal terminal device information through metadata.
[0020] In one of the embodiments, the traffic feature includes at least one of a network address, a port number, a packet type and a request field.
[0021] In one of the embodiments, the method further includes:
[0022] obtain traffic behavior sample data; the traffic behavior sample data includes a vector feature sample and a terminal behavior label corresponding to the vector feature sample; the vector feature sample is a vector feature obtained through pre-processing of the IP2Vec model;
[0023] pre-train the matrix long short-term neural network model based on the traffic behavior sample data, and obtain a preset neural network model.
[0024] In a second aspect, the application further provides a terminal traffic anomaly detection device in a smart grid, including:
[0025] an obtaining module configured to obtain network traffic data of a terminal device in a smart grid, and extract a traffic feature from the network traffic data;
[0026] The feature processing module is configured to perform vectorization processing on the traffic features to obtain vector features.
[0027] The behavior detection module is configured to input the vector features into a preset neural network model to predict terminal behaviors at a next time point and obtain behavior detection results. The preset neural network model is a matrix long short-term neural network model.
[0028] The data processing module is configured to determine a corresponding data processing strategy according to the behavior detection results, and process the network traffic data based on the data processing strategy.
[0029] In a third aspect, the present application further provides a computer device including a memory and a processor. The memory stores a computer program, and the processor implements the steps of the method according to the first aspect when executing the computer program.
[0030] In a fourth aspect, the present application further provides a computer readable storage medium having a computer program stored thereon. The computer program is executed by a processor to implement the steps of the method according to the first aspect.
[0031] In a fifth aspect, the present application further provides a computer program product including a computer program. The computer program is executed by a processor to implement the steps of the method according to the first aspect.
[0032] The terminal traffic anomaly detection method, device, computer device, computer readable storage medium and computer program product in the smart grid obtain network traffic data of terminal devices in the smart grid, extract traffic features from the network traffic data, perform vectorization processing on the traffic features to obtain vector features, input the vector features into a preset neural network model to predict terminal behaviors at a next time point and obtain behavior detection results, determine a corresponding data processing strategy according to the behavior detection results, and process the network traffic data based on the data processing strategy. In this way, the traffic features are vectorized to avoid relying on explicit attack features in traffic data packets. The matrix long short-term neural network model is used to realize complete parallelization calculation and large-scale storage through matrix memory and covariance update rules, improve the adaptability of the model to large-scale network traffic data scenarios, and effectively adapt the time sequence of network traffic data through the long short-term memory mechanism to model and classify terminal behaviors from the time characteristics, mine implicit attack rules, improve the effectiveness and accuracy of terminal behavior modeling, and efficiently and accurately predict terminal behaviors. Different data processing strategies are matched for different types of terminal behaviors to ensure the security and controllability of terminal data transmission and improve the security risk response efficiency. BRIEF DESCRIPTION OF DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application or the related art. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0034] Figure 1 An application environment diagram of the terminal traffic anomaly detection method in the smart grid in an embodiment;
[0035] Figure 2 A flowchart of the terminal traffic anomaly detection method in the smart grid in an embodiment;
[0036] Figure 3 A schematic diagram of IP address vectorization in an embodiment;
[0037] Figure 4 A flowchart of the step of processing network traffic data in an embodiment;
[0038] Figure 5 A flowchart of the terminal traffic anomaly detection method in the smart grid in another embodiment;
[0039] Figure 6 A structural block diagram of the terminal traffic anomaly detection device in the smart grid in an embodiment;
[0040] Figure 7 An internal structure diagram of the computer device in an embodiment. DETAILED DESCRIPTION
[0041] In order to make the purposes, technical solutions and advantages of the present application clearer, the following will further describe the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0042] The terminal traffic anomaly detection method in the smart grid provided by the embodiments of the present application can be applied in the application environment as shown in the figure. Figure 1 The terminal device 102 communicates with the server 106 through the communication network of the smart grid, and the security protection device 104 is arranged between the terminal device 102 and the server 106. The security protection device 104 can be a separate device, or a module integrated in the terminal device 102 or the server 106. The security protection device 104 can simultaneously perform security protection on multiple terminal devices 102 or servers 106. The data storage system can store the data required to be processed by the server 106. The data storage system can be integrated on the server 106, or placed on the cloud or other network servers.
[0043] The terminal device 102 can be, but is not limited to, various smart handheld terminals, smart charging stations, micro-grid control units, smart meters, etc. in a smart grid. The security protection device 104 can be, but is not limited to, a security gateway, an intrusion detection system, an intrusion prevention system, etc. The server 106 can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0044] In an exemplary embodiment, as shown in Figure 2 , a terminal traffic anomaly detection method in a smart grid is provided. The method is applied to the security protection device 104 in Figure 1 for illustration, including:
[0045] Step 202, obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data.
[0046] The network traffic data refers to the collection of all data packets and related metadata originating from or destined for a specific terminal device in the network communication process of a smart grid, which records the detailed information of the terminal device exchanging data with other network nodes (such as servers, other terminals, etc.) through network interfaces within a predetermined time period (such as a day, a week, etc.). There are pre-set traffic feature extraction rules based on which traffic features are extracted from network traffic data. Traffic features refer to measurable attributes that can distinguish between normal behavior and abnormal behavior.
[0047] In an exemplary embodiment, the traffic features include at least one of network address, port number, message type, and request field.
[0048] It can be understood that there can be the following attack behaviors in a smart grid: an attacker uses malicious nodes while copying the identity information of multiple legal nodes in the network, thereby achieving the purpose of controlling a large number of nodes in the network, and resisting the attack requires dual authentication of the identity information and the registration location information of the nodes. For the flood attack on the wireless network of a smart meter, an attacker causes a sharp increase in network control messages through IP address (Internet Protocol Address, hereinafter referred to as "network address") deception, achieving a denial-of-service attack on the smart meter network. Wormhole attacks, witch attacks, etc. in wireless sensor networks are also common attacks in smart grids. Based on this, in order to detect possible attack behaviors in a smart grid, at least one of the network address, port number, message type, and request field is extracted from the network traffic data based on the pre-set traffic feature extraction rules.
[0049] In step 204, the traffic features are vectorized to obtain vector features.
[0050] The extracted traffic features are converted into vector features through a feature encoding strategy. In an optional implementation, the traffic features include multiple field features, and each field feature is encoded based on a corresponding feature encoding strategy to obtain vector field features, which are spliced to obtain the vector features.
[0051] In an optional implementation, a word embedding model corresponding to different service types is pre-trained, and the extracted traffic features are processed according to the word embedding model corresponding to the current service type to obtain the vector features.
[0052] In step 206, the vector features are input into a preset neural network model to predict the terminal behavior at the next moment to obtain a behavior detection result. The preset neural network model is a matrix long-short term neural network model.
[0053] The matrix long-short term neural network model, also known as mLSTM model, extends the scalar memory unit of the traditional LSTM (Long-Short Term Memory) model to a matrix memory unit, can store more information in the form of a matrix, thereby improving the storage capacity of the model. At the same time, the mLSTM gives up the loop connection (memory mixing) between the hidden layers, allowing complete parallel processing, which can more efficiently train and infer. Therefore, the mLSTM model can effectively adapt to the access and processing of large-scale intelligent terminal data. The mLSTM model is extended and improved on the basis of a multi-layer fully connected standard LSTM model, including an input gate, a memory gate, an output gate, and a cell. Assuming that the sequence of input vector features is represented as (x1, x2, …, xt), the input gate, the memory gate, the output gate, the cell, and the mLSTM model output calculation formula at time t are as follows:
[0054] ;
[0055] ;
[0056] ;
[0057] ;
[0058] ;
[0059] ;
[0060] ;
[0061] ;
[0062] ;
[0063] wherein, is an input gate activation value, is a forget gate activation value, is an output gate activation value, is a memory cell state at t moment, is a hidden state at current moment, , , , is a weight matrix, , , , is a bias, is a Sigmoid activation function, is a natural exponential function.
[0064] wherein, the mLSTM model can be understood as an abnormal behavior detection model, input data of the mLSTM model is a normalized vector feature at t moment , and output data is a predicted terminal behavior at t+1 moment.
[0065] In an exemplary embodiment, the behavior detection result includes any one of normal behavior, sensitive behavior and abnormal behavior.
[0066] wherein, behavior modeling is performed in advance for different behavior types of the terminal device, and it can be understood that terminal behaviors of the terminal device under different service scenarios are divided into normal behavior, sensitive behavior and abnormal behavior. The normal behavior refers to an ordinary behavior of normally performing related services, the sensitive behavior refers to a behavior involving key instruction data, and the abnormal behavior refers to a behavior not meeting service needs or illegal behavior.
[0067] In an exemplary embodiment, the method further includes: obtaining traffic behavior sample data; the traffic behavior sample data includes vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are vector features obtained through pre-processing of an IP2Vec model; and the mLSTM model is pre-trained based on the traffic behavior sample data to obtain a preset neural network model.
[0068] The traffic behavior sample data includes normalized vector feature samples and corresponding terminal behavior labels. The vector feature samples are vector features obtained by preprocessing through an IP2Vec model. A matrix long short-term neural network model is pre-trained based on a large amount of traffic behavior sample data, and a trained preset neural network model is obtained. Through pre-training of the traffic behavior sample data, the preset neural network model can predict the terminal behavior at t+1 according to the vector feature sequence , and realize abnormal behavior detection and prevention. It can be understood that, considering the time sequence association between each period, the mLSTM model uses a residual network block to process complex sequence data, while improving the training stability of the model in the deep network. The residual network block alleviates the gradient vanishing problem in the training process of the deep neural network by introducing a skip connection.
[0069] Step 208, determining a corresponding data processing strategy according to the behavior detection result.
[0070] Step 210, processing the network traffic data based on the data processing strategy.
[0071] The data processing strategy corresponding to different terminal behavior types is set in the strategy library in advance, and the corresponding data processing strategy is matched in the strategy library after the current detection result is determined. According to the data processing strategy, the network traffic data is processed, realizing the safe transmission of network traffic data or the safe protection of abnormal network traffic data, and guaranteeing the safe and stable operation of the smart grid.
[0072] In the above-mentioned smart grid terminal traffic anomaly detection method, network traffic data of terminal devices in the smart grid is obtained, and traffic features are extracted from the network traffic data. The traffic features are vectorized to obtain vector features. The vector features are input into a preset neural network model to predict the terminal behavior at the next time to obtain a behavior detection result. The preset neural network model is a matrix long short-term neural network model. According to the behavior detection result, a corresponding data processing strategy is determined. Based on the data processing strategy, the network traffic data is processed. Through the above-mentioned manner, the traffic features are vectorized to avoid relying on explicit attack features in the traffic data packet. The matrix long short-term neural network model is used to realize complete parallelization calculation and large-scale storage through matrix memory and covariance update rules, which improves the adaptability of the model to large-scale network traffic data scenarios. The long short-term memory mechanism can effectively adapt to the time sequence of network traffic data, model and classify the terminal behavior from the time characteristics, mine the implicit attack rules, improve the effectiveness and accuracy of terminal behavior modeling, and realize efficient and accurate prediction of terminal behavior. Different data processing strategies are matched for different types of terminal behavior, which can guarantee the security and controllability of terminal data transmission and improve the security risk response efficiency.
[0073] In an example embodiment, step 204 comprises: obtaining a word embedding model corresponding to the current service type; the word embedding model corresponding to the current service type refers to a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model; and the traffic features are input into the word embedding model, the traffic features are vectorized by the word embedding model, and vector features are obtained.
[0074] In the embodiment, the corresponding word embedding model is trained in advance for a plurality of service types. In the process of vectorizing the current network traffic data, the current service type corresponding to the network traffic data is determined, the corresponding word embedding model is called according to the current service type, and the traffic features in the network traffic data are vectorized by the word embedding model to obtain vector features. The word embedding model can adopt an IP2Vec model (an improved model inspired by Word2Vec, used to convert IP addresses into vector form). The IP2Vec model of the embodiment is not only used for vectorizing network addresses, but also can be used for vectorizing port numbers, message types and request fields.
[0075] It can be understood that according to the word embedding model corresponding to the current service type, the traffic features are continuously processed in the direction of the service type by expanding the word vector, the traffic features are mapped to a high-dimensional continuous space, the correlation between the traffic information is measured according to the service type information, the service category correlation between the traffic features is learned, and the basis is provided for dividing the traffic behaviors of different services.
[0076] It should be noted that sample data under each service type is collected in advance. For a service type, the word embedding model is trained according to the sample data of the service type, the model parameters of the word embedding model are adjusted, and the trained word embedding model corresponding to the service type is obtained.
[0077] Referring to Figure 3Taking an IP address (i.e., a network address) as an example, a word embedding model (which can be an IP2Vec model) includes an input layer, a hidden layer, and an output layer, and a training process of the word embedding model and a process of IP address vectorization include: first, an IP address and a virtual label are coded into a V-dimensional initial vector, in the V-dimensional initial vector, only an index number of the IP in an IP address table corresponding element is marked as 1, and the rest of the elements are all 0. IPt(i) is coded into Vec[IPt(i)], and a label under a certain service type is initialized as a random vector Vec[Tt]. Next, the initial vector of the IP address in the training sample is input as the input layer, and the multiplication result of the initial vector and a weight matrix M of VxW is accumulated to obtain the weight of the hidden layer, and then the hidden layer result is multiplied by a weight matrix M' of WxV to obtain the output layer weight Vec[out]. In the training process, the weight matrices M and M' are continuously updated by a back propagation algorithm and a stochastic gradient descent, the difference between Vec[out] and Vec[Tt] is minimized, and finally the initial vector of the IP address is multiplied by the weight matrix M to calculate the IP vector of each IP. Through a method based on the service type, the IP address is mapped to a high-dimensional continuous space to obtain an IP vector capable of expressing network service category information, and vectorization processing of traffic feature data is realized.
[0078] In the embodiment, the data vectorization has adaptability, can automatically adjust the vector structure of different service types according to terminal information and service demand, realize more fine preprocessing of data, perceive semantic features under different service types, can improve the accuracy and efficiency of subsequent terminal behavior detection, and meet the safety and usability requirements of terminal devices in different service scenarios.
[0079] In one exemplary embodiment, step 210 includes:
[0080] Step 402, in the case that the behavior detection result is normal behavior, based on the data processing strategy corresponding to the normal behavior, a lightweight encryption strategy or an identity authentication strategy based on a media access control address of the terminal device is used to process the network traffic data.
[0081] In the case that the behavior detection result is normal behavior, if the network traffic data is sent to the terminal device, an identity authentication strategy based on a media access control address of the terminal device is used to process the network traffic data. Alternatively, the identity authentication strategy based on the media access control address of the terminal device includes: performing identity authentication on the network traffic data based on the MAC address of the terminal device, and after the identity authentication passes, transmitting the network traffic data to the terminal device. If the identity authentication fails, the transmission of the network traffic data is aborted.
[0082] In the case that the behavior detection result is normal behavior, if the network traffic data is from the terminal device, a lightweight encryption strategy is used to process the network traffic data. Optionally, the lightweight encryption strategy includes: using a lightweight encryption algorithm to encrypt the network traffic data, and continuing to transmit the encrypted data.
[0083] Step 404, in the case that the behavior detection result is sensitive behavior, an asymmetric encryption strategy or an instruction set protection strategy is used to process the network traffic data.
[0084] In the case that the behavior detection result is sensitive behavior, if the network traffic data is to the terminal device, an instruction set protection strategy is used to process the network traffic data. Optionally, the instruction set protection strategy includes: creating a trusted execution environment through hardware or software isolation technology, decrypting the network traffic data with a private key in the trusted execution environment, and transmitting the decrypted data to the terminal device.
[0085] In the case that the behavior detection result is sensitive behavior, if the network traffic data is from the terminal device, an asymmetric encryption strategy is used to process the network traffic data. Optionally, the asymmetric encryption strategy includes: using an asymmetric encryption algorithm to encrypt the network traffic data, and continuing to transmit the encrypted data.
[0086] Step 406, in the case that the behavior detection result is abnormal behavior, an exception handling strategy is used to process the network traffic data; the exception handling strategy includes suspending data transmission, sending an exception signal, recording and transmitting abnormal terminal device information through metadata.
[0087] In the case that the behavior detection result is abnormal behavior, the data transmission is suspended, the exception signal is sent, and the abnormal terminal device information is recorded and transmitted through metadata.
[0088] In this embodiment, for network traffic data generated by normal behavior of the terminal, a lightweight algorithm is used for encryption, and the terminal device MAC address is used for identity authentication. For network traffic data generated by sensitive behavior, instruction set protection technology and asymmetric encryption are used to ensure data confidentiality and ensure safe execution of instructions. For network traffic data generated by abnormal behavior, data transmission is suspended, an exception signal is sent, and abnormal terminal device information is recorded and transmitted through metadata, so as to strengthen the security protection and comprehensive management of vulnerable terminals.
[0089] In one exemplary embodiment, with reference to Figure 5The method for detecting terminal traffic anomaly in a smart grid comprises data vectorization, behavior modeling and anomaly detection. The data vectorization process comprises: using a word embedding model corresponding to a current service type to perform vectorization processing on traffic features in network traffic data to obtain vector features. The behavior modeling process comprises: dividing terminal behaviors of a terminal device in different service scenarios into normal behavior, sensitive behavior and abnormal behavior, and training an mLSTM model for detecting terminal behavior types based on these behavior labels. The anomaly detection process comprises: using a pre-trained mLSTM model to perform real-time detection on terminal behaviors of the terminal device, specifically, inputting the vector features of the terminal device after vectorization processing into the mLSTM model to detect the terminal behaviors. Different data processing strategies are used to process corresponding network traffic data for different terminal behaviors.
[0090] It should be understood that, although each step in the flowchart involved in each embodiment as described above is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0091] Based on the same inventive concept, the embodiments of the present application also provide an apparatus for implementing the above-mentioned method for detecting terminal traffic anomaly in a smart grid. The apparatus provides a solution to the problem similar to the implementation scheme described in the above method, so the specific limitations in one or more apparatus embodiments for detecting terminal traffic anomaly in a smart grid provided below can refer to the limitations of the method for detecting terminal traffic anomaly in a smart grid described above, which will not be repeated here.
[0092] In one exemplary embodiment, as shown in Figure 6 a device for detecting terminal traffic anomaly in a smart grid is provided, comprising:
[0093] The acquisition module 602 is configured to acquire network traffic data of a terminal device in a smart grid, and extract traffic features from the network traffic data.
[0094] The feature processing module 604 is configured to perform vectorization processing on the traffic features to obtain vector features.
[0095] The behavior detection module 606 is configured to input the vector feature into a preset neural network model, predict a terminal behavior at a next moment, and obtain a behavior detection result. The preset neural network model is a matrix long short-term neural network model.
[0096] The data processing module 608 is configured to determine a corresponding data processing strategy according to the behavior detection result, and process the network flow data based on the data processing strategy.
[0097] In the terminal flow anomaly detection device in the smart power grid, the flow feature is vectorized to avoid relying on explicit attack features in the flow data packet. The matrix long short-term neural network model is used to realize fully parallelized calculation and large-scale storage through matrix memory and covariance update rules, improve the adaptability of the model to large-scale network flow data scenarios, and effectively adapt the network flow data to the time sequence through the long short-term memory mechanism, model and classify the terminal behavior from the time characteristics, mine the implicit attack rules, improve the effectiveness and accuracy of the terminal behavior modeling, and realize efficient and accurate prediction of the terminal behavior. Different data processing strategies are matched for different types of terminal behaviors to ensure the security and controllability of the terminal data transmission and improve the security risk response efficiency.
[0098] In an example embodiment, the feature processing module 604 is further configured to obtain a word embedding model corresponding to a current service type. The word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type. The word embedding model adopts an IP2Vec model. The flow feature is input into the word embedding model, and the flow feature is vectorized by the word embedding model to obtain the vector feature.
[0099] In an example embodiment, the behavior detection result includes any one of normal behavior, sensitive behavior, and abnormal behavior.
[0100] In an example embodiment, the data processing module 608 is further configured to, in a case where the behavior detection result is normal behavior, process the network flow data based on a data processing strategy corresponding to the normal behavior, using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of a terminal device; in a case where the behavior detection result is sensitive behavior, process the network flow data using an asymmetric encryption strategy or an instruction set protection strategy; and in a case where the behavior detection result is abnormal behavior, process the network flow data using an abnormal processing strategy. The abnormal processing strategy includes suspending data transmission, sending an abnormal signal, recording and transferring abnormal terminal device information through metadata.
[0101] In an example embodiment, the flow feature includes at least one of a network address, a port number, a packet type, and a request field.
[0102] In an example embodiment, the terminal traffic anomaly detection apparatus in the smart grid further comprises a training module configured to obtain traffic behavior sample data; the traffic behavior sample data comprises vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are obtained by preprocessing the vector features through an IP2Vec model; and the preset neural network model is obtained by pre-training the matrix long short-term neural network model based on the traffic behavior sample data.
[0103] The modules in the terminal traffic anomaly detection apparatus in the smart grid described above can be implemented in whole or in part by software, hardware, and combinations thereof. The modules described above can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the modules.
[0104] In an example embodiment, a computer device is provided, which can be a security protection device, and an internal structure diagram thereof can be as shown in Figure 7 The computer device comprises a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device comprises a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to communicate with external terminals through network connection. The computer program is executed by the processor to implement a terminal traffic anomaly detection method in a smart grid.
[0105] Those skilled in the art can understand that Figure 7 the structure shown in the above
[0106] In an example embodiment, a computer device is provided, comprising a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program: obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data; performing vectorization processing on the traffic features to obtain vector features; inputting the vector features into a preset neural network model to predict a terminal behavior at a next time, and obtaining a behavior detection result; the preset neural network model is a matrix long short-term neural network model; determining a corresponding data processing strategy according to the behavior detection result; and processing the network traffic data based on the data processing strategy.
[0107] In an example embodiment, the processor further implements the following steps when executing the computer program: obtaining a word embedding model corresponding to a current service type; the word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model; and inputting the traffic features into the word embedding model to perform vectorization processing on the traffic features by the word embedding model to obtain the vector features.
[0108] In an example embodiment, the processor further implements the following steps when executing the computer program: in a case where the behavior detection result is a normal behavior, processing the network traffic data based on a data processing strategy corresponding to the normal behavior, using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of the terminal device; in a case where the behavior detection result is a sensitive behavior, processing the network traffic data using an asymmetric encryption strategy or an instruction set protection strategy; and in a case where the behavior detection result is an abnormal behavior, processing the network traffic data using an abnormal processing strategy; the abnormal processing strategy comprises suspending data transmission, sending an abnormal signal, recording and delivering abnormal terminal device information through metadata.
[0109] In an example embodiment, the processor further implements the following steps when executing the computer program: obtaining traffic behavior sample data; the traffic behavior sample data comprises vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are vector features obtained by preprocessing through an IP2Vec model; and pre-training the matrix long short-term neural network model based on the traffic behavior sample data to obtain the preset neural network model.
[0110] In one embodiment, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the following steps: obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data; performing vectorization processing on the traffic features to obtain vector features; inputting the vector features into a preset neural network model to predict a terminal behavior at a next time, and obtaining a behavior detection result; the preset neural network model is a matrix long short-term neural network model; determining a corresponding data processing strategy according to the behavior detection result; and processing the network traffic data based on the data processing strategy.
[0111] In one embodiment, the computer program is executed by the processor to further implement the following steps: obtaining a word embedding model corresponding to a current service type; the word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model; and inputting the traffic features into the word embedding model to perform vectorization processing on the traffic features by the word embedding model to obtain the vector features.
[0112] In one embodiment, the computer program is executed by the processor to further implement the following steps: in a case where the behavior detection result is a normal behavior, processing the network traffic data based on a data processing strategy corresponding to the normal behavior, using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of the terminal device; in a case where the behavior detection result is a sensitive behavior, processing the network traffic data using an asymmetric encryption strategy or an instruction set protection strategy; and in a case where the behavior detection result is an abnormal behavior, processing the network traffic data using an abnormal processing strategy; the abnormal processing strategy includes suspending data transmission, sending an abnormal signal, recording and delivering abnormal terminal device information through metadata.
[0113] In one embodiment, the computer program is executed by the processor to further implement the following steps: obtaining traffic behavior sample data; the traffic behavior sample data includes vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are vector features obtained by preprocessing through an IP2Vec model; and pre-training the matrix long short-term neural network model based on the traffic behavior sample data to obtain the preset neural network model.
[0114] In one embodiment, a computer program product is provided, comprising a computer program which, when executed by a processor, implements the following steps: obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data; performing vectorization processing on the traffic features to obtain vector features; inputting the vector features into a preset neural network model to predict a terminal behavior at a next time, and obtaining a behavior detection result; the preset neural network model is a matrix long short-term neural network model; determining a corresponding data processing strategy according to the behavior detection result; and processing the network traffic data based on the data processing strategy.
[0115] In one embodiment, the computer program, when executed by the processor, further implements the following steps: obtaining a word embedding model corresponding to a current service type; the word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model; and inputting the traffic features into the word embedding model to perform vectorization processing on the traffic features by the word embedding model to obtain the vector features.
[0116] In one embodiment, the computer program, when executed by the processor, further implements the following steps: in a case where the behavior detection result is a normal behavior, processing the network traffic data based on a data processing strategy corresponding to the normal behavior, using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of the terminal device; in a case where the behavior detection result is a sensitive behavior, processing the network traffic data using an asymmetric encryption strategy or an instruction set protection strategy; and in a case where the behavior detection result is an abnormal behavior, processing the network traffic data using an abnormal processing strategy; the abnormal processing strategy includes suspending data transmission, sending an abnormal signal, recording and delivering abnormal terminal device information through metadata.
[0117] In one embodiment, the computer program, when executed by the processor, further implements the following steps: obtaining traffic behavior sample data; the traffic behavior sample data includes vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are vector features obtained by preprocessing through an IP2Vec model; and pre-training the matrix long short-term neural network model based on the traffic behavior sample data to obtain the preset neural network model.
[0118] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.
[0119] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. In the embodiments provided in the present application, the memory, database or other medium mentioned can include at least one of a non-volatile memory and a volatile memory. The non-volatile memory can include a read-only memory (ROM), a magnetic tape, a floppy disk, a flash memory, an optical storage, a high-density embedded non-volatile memory, a resistive random access memory (ReRAM), a magnetoresistive random access memory (MRAM), a ferroelectric random access memory (FRAM), a phase change memory (PCM), a graphene memory, etc. The volatile memory can include a random access memory (RAM) or an external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as a static random access memory (SRAM) or a dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0120] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0121] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A method for detecting abnormal terminal traffic in a smart grid, characterized in that, The method comprises: obtaining network traffic data of a terminal device in a smart grid, and extracting traffic features from the network traffic data; vectorizing the traffic features to obtain vector features; inputting the vector features into a preset neural network model to predict a terminal behavior at a next moment and obtain a behavior detection result; the preset neural network model is a matrix long short-term neural network model; determining a corresponding data processing strategy according to the behavior detection result; processing the network traffic data based on the data processing strategy.
2. The method of claim 1, wherein, The vectorizing of the traffic features to obtain vector features comprises: obtaining a word embedding model corresponding to a current service type; the word embedding model corresponding to the current service type is a word embedding model trained based on sample data under the current service type; the word embedding model adopts an IP2Vec model; inputting the traffic features into the word embedding model to vectorize the traffic features by the word embedding model to obtain vector features.
3. The method of claim 1, wherein, The behavior detection result comprises any one of normal behavior, sensitive behavior and abnormal behavior.
4. The method of claim 3, wherein, The processing of the network traffic data based on the data processing strategy comprises: in a case where the behavior detection result is normal behavior, processing the network traffic data based on a data processing strategy corresponding to the normal behavior by using a lightweight encryption strategy or an identity authentication strategy based on a media access control address of the terminal device; in a case where the behavior detection result is sensitive behavior, processing the network traffic data by using an asymmetric encryption strategy or an instruction set protection strategy; in a case where the behavior detection result is abnormal behavior, processing the network traffic data by using an abnormal processing strategy; the abnormal processing strategy comprises suspending data transmission, sending an abnormal signal, recording and delivering abnormal terminal device information through metadata.
5. The method according to any one of claims 1 to 4, characterized in that, The traffic features comprise at least one of a network address, a port number, a packet type and a request field.
6. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: obtaining traffic behavior sample data; the traffic behavior sample data comprises vector feature samples and terminal behavior labels corresponding to the vector feature samples; the vector feature samples are vector features obtained by preprocessing by an IP2Vec model; pre-training the matrix long short-term neural network model based on the traffic behavior sample data to obtain a preset neural network model.
7. A terminal flow anomaly detection device in a smart grid, characterized in that, The device comprises: an obtaining module configured to obtain network traffic data of a terminal device in a smart grid, and extract traffic features from the network traffic data; a feature processing module configured to vectorize the traffic features to obtain vector features; a behavior detection module configured to input the vector features into a preset neural network model to predict a terminal behavior at a next moment and obtain a behavior detection result; the preset neural network model is a matrix long short-term neural network model; a data processing module configured to determine a corresponding data processing strategy according to the behavior detection result, and process the network traffic data based on the data processing strategy.
8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6.