Risk identification method for wind power system
By constructing a communication performance dataset and a system response efficiency index library, the degree of communication and response matching of the wind power system is evaluated, potential data tampering and unauthorized access risks are identified, and the problem of untimely synchronization of control commands and system response data in the wind power system is solved, thereby improving the operational stability and security of the system.
Patent Information
- Application Number
- CN202511488301.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-17
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-10-17
AI Technical Summary
In the event of a network attack or transmission delay, the control command data and system response data are not processed in a timely manner, leading to inaccurate operational data analysis and failure of predictive management, thus affecting the level of intelligent operation and management of the system.
By collecting control command timestamp data, a communication performance dataset and a system response efficiency index library are constructed to evaluate the matching degree between communication transmission and system response, generate an operational anomaly event record table, and, in conjunction with a network security anomaly pattern library, train an attack risk classification model to identify and generate risk prediction data.
It enables efficient synchronous monitoring of control data and system response data in wind power systems, improves the stability and security of network operation, and provides accurate risk prediction and monitoring information.
Smart Images

Figure CN120956540A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power safety monitoring data processing technology, and in particular to a risk identification method for wind power systems. Background Technology
[0002] Wind power systems adjust the operating parameters of their subsystems to adapt to environmental changes through data analysis and predictive management, ensuring the accuracy of system operation data and the reliability of management decisions. However, with the increasing digitalization of wind power system operations, cybersecurity risk identification and operational supervision have become increasingly prominent, becoming key factors affecting the integrity of operational data and the intelligent management of the system. Especially during data-intensive operations, malicious attackers may disrupt operational monitoring by damaging the overall network communication architecture. Attack methods include, but are not limited to, control command tampering, communication link disruption, and monitoring protocol interference, leading to inaccurate operational data analysis and predictive management failure. In this comprehensive cyber threat environment, the control links of the wind power system, as key operational data collection and execution nodes, are susceptible to operational risks during data transmission, particularly regarding control command data and system execution feedback data. This represents a typical manifestation of cybersecurity management risks, resulting in a decline in operational data quality. This not only threatens the accuracy of operational data analysis but may also cause deviations in predictive management models or failure of supervision mechanisms, affecting the overall level of intelligent operation and management of the system. Existing methods have significant limitations in ensuring the identification and management of cybersecurity risks in wind power systems. Traditional operation and management mechanisms often focus on data encryption or anomaly detection, but these methods frequently overlook the dynamic operational supervision characteristics of system response data synchronization during control command data transmission. For example, conventional management and monitoring methods may fail to detect in a timely manner the disconnect between control command data and system response data caused by data delays or tampering, especially during man-in-the-middle attacks, where this disconnect between control command data and execution feedback data becomes particularly pronounced. This limitation makes it difficult for wind power systems to maintain a close operational management correlation between control data and actual system response data in dynamic network environments. The core management challenge lies in ensuring efficient synchronous operational supervision between wind power system control data and actual system response data. During operational data processing, after control command data is issued by the system, the response data of each subsystem needs to be collected, managed, and verified within a specific time window to ensure the timeliness of network security risk identification. However, network attacks or transmission delays may prolong the operational data synchronization time, disrupting the synchronous operational supervision relationship between command data issuance and system adjustment data collection. This lack of operational data synchronization supervision directly affects the system's ability to analyze, predict, and manage changes in operating environment data. For example, when operating environment data changes suddenly, the control system requires each subsystem to update its data rapidly to match the current environment. However, if the data is delayed or tampered with, the system response data may not be fed back to the operation management system in a timely manner, causing the data analysis model to no longer match the actual environmental data. This can lead to a decrease in prediction accuracy or the failure of the operation monitoring mechanism. Therefore, how to monitor and ensure the synchronous processing of control data and system response data in real time in complex network environments has become a key operational issue for identifying and managing cybersecurity risks in wind power systems. Summary of the Invention
[0003] This invention provides a risk identification method for wind power systems, comprising: Collect timestamp data of control commands to build a communication performance dataset and a system response efficiency index library; Assess the matching degree between communication transmission and system response, and generate an operational anomaly event log table; A network security anomaly pattern library shall be constructed by combining the aforementioned operational anomaly event record table; Based on the aforementioned network security anomaly pattern library, an attack risk classification model is trained to generate a security risk classification profile. Collect equipment execution status data, calculate the degree of deviation between the actual execution status and the expected set status, and generate a comprehensive risk level; Based on the comprehensive risk level, operational disruption risks are identified, and risk prediction data containing risk types and probabilities of occurrence is generated to provide risk prediction information for operational management decisions.
[0004] Furthermore, the acquisition of control command timestamp data to construct a communication performance dataset and a system response efficiency index library specifically includes: The transmission and reception timestamp data of control commands are collected from the network communication links of the wind power system, the transmission time of each command is calculated, and a communication performance dataset is constructed. By identifying device response and adjustment completion timestamps through communication performance datasets, calculating the time difference between instruction issuance and device adjustment completion, a system response efficiency index library is formed.
[0005] Furthermore, the construction of the communication performance dataset includes: Collect command transmission logs from the control center, obtain the transmission timestamp and command sequence number, obtain the corresponding sequence number's reception timestamp from the field device port, calculate the difference between the reception timestamp and the transmission timestamp, and obtain the transmission delay value. For the transmission delay value, obtain the network load rate and data retransmission count, remove outliers with excessive retransmission counts, summarize the normal transmission delay value and network load rate, and generate a communication performance dataset.
[0006] Furthermore, the step of identifying device response and adjustment completion timestamps through communication performance datasets, calculating the time difference between instruction issuance and device adjustment completion, and forming a system response efficiency index library includes: By centralizing the instruction sequence number and sending timestamp in the communication performance data set, querying the device response confirmation timestamp and adjustment completion timestamp, calculating the time difference between the adjustment completion timestamp and the sending timestamp, the total execution time of the device is obtained. The total execution time of the equipment is summarized according to the categories of wind turbine pitch, yaw and power regulation. The total execution time exceeding the standard is recorded as a response timeout event. The execution time and timeout frequency of various controls are statistically analyzed to generate a system response efficiency index library.
[0007] Furthermore, the generation of the security risk classification file includes: By analyzing the offset of wind turbine power setpoints and the frequency of control command changes using an attack risk classification model, network security threat types are identified, and a security risk classification profile is generated based on these network security threat types.
[0008] Furthermore, the assessment of the matching degree between communication transmission and system response, and the generation of an operational anomaly event record table, includes: Using the system response efficiency index library, the matching degree between communication transmission time and system execution response delay within the monitoring period is evaluated. The average execution time of each control type in the system response efficiency index library is extracted, the correlation deviation between transmission efficiency and response efficiency is identified, the average transmission delay value of the corresponding period in the communication performance data is obtained, the difference between execution time and transmission delay is calculated, and the difference exceeding the standard is determined to be a mismatch event. For the mismatch event, extract the time series before and after the event, calculate the correlation coefficient between transmission delay and execution response, record the network load rate and device operating status below the threshold, and generate an operational anomaly event record table.
[0009] Furthermore, the step of constructing a network security anomaly pattern library by combining the operational anomaly event record table includes: Extract the time series of wind turbine speed, power and blade angle setpoints from historical communication logs, and combine them with the operation anomaly event record table to extract the variation pattern of control command transmission frequency and the characteristics of setpoint jump amplitude. Calculate the rate of change of the set value based on the changing pattern of the frequency of control command transmission and the characteristics of the jump amplitude of the set value, record the rate of change exceeding the standard as the abnormal jump point, and generate an abnormal fluctuation feature set. For the abnormal fluctuation feature set, the frequency of command sending is counted, the moving average and standard deviation of the frequency sequence are calculated, the source IP address, target wind turbine number and operation type of the exceeding frequency are extracted, and abnormal access behavior records are constructed. The isolated forest algorithm is used to detect abnormal access behavior, output anomaly scores, and generate data tampering, frequent operation and unauthorized access anomaly patterns by clustering, and build a network security anomaly pattern library.
[0010] Furthermore, the step of calculating the setpoint change rate based on the changing pattern of the control command sending frequency and the characteristics of the setpoint jump amplitude, recording the excessive change rate as an abnormal jump point, and generating an abnormal fluctuation feature set includes: Obtain the time series of speed and power setpoints from the historical database, calculate the rate of change, mark the rate of change exceeding the standard as a jump event, verify operation permissions, and generate an abnormal event set; The frequency of statistical command transmissions is compared with the standard operating frequency to extract the frequency of exceeding the standard and the percentage of deviation from the set value, and an abnormal feature group is generated. The blade angle, speed, and power deviation values are extracted from the equipment data. Abnormal control events with deviations exceeding the standard are recorded. The dynamic time warping algorithm is used to identify the correlation of abnormal time sequences and to build a tampering trace database.
[0011] Furthermore, the data collected from the device's execution status is used to calculate the deviation between the actual execution status and the expected set status, generating a comprehensive risk level, including: Collect actual values of fan speed, power output and blade angle, calculate the deviation from the set values, and generate a real-time deviation dataset. Query the threat level in the security risk classification file, obtain the allowable deviation range of parameters, record the deviation exceeding the standard as an abnormal state, calculate the execution response delay, and generate a comprehensive risk level.
[0012] Furthermore, the process involves querying the threat level in the security risk classification file, obtaining the allowable deviation range of parameters, recording deviations exceeding the limit as abnormal states, calculating the execution response latency, and generating a comprehensive risk level, including: The attack type identifier is extracted from the security risk classification file, the deviation rate between the actual value and the set value is calculated, the instruction execution delay is recorded, and status assessment data is generated. Calculate the speed and power safety margins, assess the impact of power fluctuations on the power grid, and determine stability risks; A comprehensive risk score is generated based on the weighted deviation rate of attack type severity, which is then mapped to the warning level to generate a graded warning signal.
[0013] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: This invention discloses a method for identifying network security risks in wind power systems, addressing the correlation analysis between communication performance, system response efficiency, and network security threats. By collecting the timestamps of control command transmission and reception, calculating transmission time, and establishing a communication performance dataset, combined with device response timestamps, a system response efficiency index library is generated to assess the matching degree between communication and execution response, and to identify abnormal events below management thresholds. Furthermore, this invention extracts command frequency changes and setpoint jump features from historical communication logs and abnormal event records, establishing a network security anomaly pattern library, constructing an attack risk classification model, analyzing power setpoint offsets and command frequency patterns, and identifying potential data tampering and unauthorized access risks. Based on the current device status and security profile, the deviation between actual and expected states is calculated, and a comprehensive risk level is generated by combining response latency, predicting the risk of operational interruption caused by network latency and security threats. This invention, by integrating communication performance, response efficiency, and security analysis, provides accurate risk prediction and monitoring information, improving the stability and security of wind power system network operation. Attached Figure Description
[0014] Figure 1 This is a flowchart of a risk identification method for wind power systems according to the present invention.
[0015] Figure 2 This is a schematic diagram of a risk identification method for wind power systems according to the present invention. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0017] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in this text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0018] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.
[0019] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0020] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.
[0021] It should be understood that in this application, "at least one (item)" means one or more. "More than one" means two or more. "At least two (items)" means two or three or more. "And / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural.
[0022] The character " / " generally indicates that the preceding and following objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any single or multiple items. For example, "at least one of a, b, or c" can be expressed as: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0023] Both "...when" and "if" indicate that a corresponding action will be taken under certain objective circumstances. They are not time limits, nor do they require a judgment action to be taken when the action is taken, nor do they imply any other limitations.
[0024] The method provided in this application embodiment can be executed by a risk identification device for wind power systems. This risk identification device for wind power systems can be an electronic device or a device applied within an electronic device, such as a risk identification module for wind power systems. The electronic device can refer to devices such as mobile phones or servers; this application embodiment does not limit this.
[0025] The technical solutions of the embodiments of the present invention will be clearly and thoroughly described below with reference to the accompanying drawings. The described embodiments are merely some embodiments of the present invention.
[0026] like Figure 1-2 This embodiment of a risk identification method for wind power systems may specifically include: Step S101: Collect the sending timestamp data and receiving timestamp data of control commands from the wind power system network communication link, identify the transmission time value of each control command, and establish a communication performance dataset.
[0027] Control command transmission logs are collected from the wind power system control center, and the transmission timestamp and sequence number of each command are read. Simultaneously, the reception timestamp of the corresponding sequence number is obtained from the field execution device port. The transmission delay value is calculated by the difference between the reception and transmission timestamps. For this transmission delay value, the current network load rate and data retransmission count are obtained from the communication link monitoring module. If the retransmission count exceeds a preset threshold, the transmission delay value within that time period is marked as an anomaly and removed. The transmission delay values and corresponding network load rates for normal time periods are summarized to form a communication performance dataset containing delay distribution characteristics and load correlations.
[0028] Specifically, in one implementation, the data acquisition server at the wind power system control center scans the control command transmission log file every 100 milliseconds, extracting the transmission time data in UNIX timestamp format and the 16-bit hexadecimal command sequence number. Simultaneously, upon receiving a control command, the PLC controller of the field execution equipment immediately returns an acknowledgment message to the control center, carrying the same command sequence number and the timestamp of the reception time. By matching transmission and reception records with the same sequence number, the difference between the two timestamps is calculated to obtain the transmission delay value of a single command.
[0029] Specifically, the anomaly identification of transmission delay values is based on statistical methods. The system maintains a sliding time window with a window size of 5 minutes, and updates the statistical characteristics of the delay data within the window every minute. When the transmission delay value of a certain instruction exceeds three times the standard deviation of the mean delay within the window, the value is determined to be an outlier.
[0030] It should be noted that the communication performance dataset is stored in a key-value pair structure, with time periods as keys and corresponding values including the average latency, latency standard deviation, mean network load rate, and correlation coefficient between latency and load within that time period. This data provides a foundation for subsequent network security risk assessment.
[0031] Step S102: Based on the communication performance dataset, obtain the timestamp records of device response and adjustment completion from the execution module, calculate the time difference between instruction issuance and device adjustment completion, and form a system response efficiency index library.
[0032] Based on the instruction sequence number and transmission timestamp centrally recorded in the communication performance dataset, the device response confirmation timestamp and parameter adjustment completion timestamp corresponding to the sequence number are retrieved from the wind turbine controller's execution log. The time difference between the adjustment completion timestamp and the transmission timestamp is calculated to obtain the total device execution time. The total device execution time is categorized and summarized according to three control types: wind turbine pitch, yaw, and power regulation. If the total execution time of a certain type of control exceeds a preset multiple of the historical average for that type, it is recorded as a response timeout event. The standard execution duration and timeout frequency of each type of control are statistically analyzed to form a system response efficiency index library containing response time distribution and execution completion rate.
[0033] Specifically, in one implementation, the wind turbine controller maintains three independent execution log files, corresponding to pitch control, yaw control, and power regulation control, respectively. Each log file records the receipt confirmation and execution completion events of control commands in chronological order. More specifically, in one implementation, the wind turbine controller maintains execution logs for different types of control. Pitch control, due to its mechanical involvement, has a relatively long execution time; yaw control requires rotating the entire nacelle, resulting in the longest execution time; power regulation is mainly achieved through electrical control, offering the fastest response speed. The entire process of the wind power control system from receiving control commands to completing parameter adjustments includes four stages: command parsing, safety verification, execution, and status feedback. The start and end times of each stage are recorded in the execution log, and the total execution time is obtained by accumulating the times of each stage. When the total execution time of a certain type of control exceeds 1.5 times its standard time, the system determines it as a response timeout event. This timeout usually indicates mechanical component wear or communication link congestion.
[0034] It should be noted that the system response efficiency index library adopts a hierarchical storage structure. The top layer is divided according to control type. Each control type includes four key indicators: average response time, standard deviation of duration, timeout frequency, and execution success rate, which provide a quantitative basis for subsequent risk assessment.
[0035] Step S103: Use the system response efficiency index library to evaluate the matching degree between communication transmission time and system execution response latency within the preset monitoring period, identify the correlation deviation between transmission efficiency and response efficiency, and generate an operational abnormal event record table when the matching degree is lower than the management benchmark threshold.
[0036] The system extracts average execution time data for each control type within the monitoring period from the system response efficiency index library. Simultaneously, it obtains the average transmission delay value for the corresponding period from the communication performance dataset. The difference between the execution time and the transmission delay is calculated. If the difference exceeds a preset allowable deviation threshold, it is determined to be a transmission-execution mismatch event. For the mismatch event, the transmission delay time series and execution response time series for 30 seconds before and after the event occurrence are extracted. The linear correlation between the two series is calculated. When the correlation coefficient is lower than a preset management benchmark threshold, the network load rate and equipment operating status parameters for that period are recorded, forming abnormal feature data containing deviation values and environmental parameters. Based on the magnitude and frequency of deviation values in the abnormal feature data, a hierarchical processing method is adopted. Continuously occurring abnormal features are aggregated by time windows, and the number of anomalies and cumulative deviation values within each window are counted to generate an operational abnormal event record table containing the anomaly occurrence time, deviation level, impact range, and duration.
[0037] Specifically, in one implementation, the determination of transmission-execution mismatch events is based on statistical analysis of time differences. Under normal operating conditions, there is a stable time relationship between the transmission delay of control commands and the equipment's execution response in a wind power system; typically, the execution time should be 1.5 to 2 times greater than the transmission delay. When this proportional relationship is disrupted, it indicates an anomaly in network communication or equipment execution.
[0038] Specifically, the matching degree between transmission delay and execution response is achieved through correlation analysis. The system extracts the transmission delay time series and execution response time series before and after the event occurrence, and calculates the correlation coefficient between the two series. Under normal circumstances, transmission delay and execution response are positively correlated, and the correlation coefficient should remain above 0.7. When the correlation coefficient drops below 0.5, it indicates an abnormal decoupling between the transport layer and the execution layer, which may foreshadow an attack or failure. At this time, the system extracts data such as packet retransmission rate and routing hop count changes from the network layer, as well as motor temperature and vibration amplitude from the execution layer, as environmental parameters to jointly constitute abnormal feature data.
[0039] It should be noted that the classification of abnormal features adopts a three-level standard. A deviation value less than the mean plus one standard deviation is considered a slight abnormality, between one and two standard deviations is considered a moderate abnormality, and more than two standard deviations is considered a severe abnormality.
[0040] Preferably, the aggregation period for the time window is set to 5 minutes, and the number of anomalies, the maximum deviation value, and the cumulative duration are counted within each window. When moderate or higher anomalies occur in three consecutive windows, the system determines it as a continuous operational risk event.
[0041] For example, the operation anomaly event log table adopts a structured storage format and includes seven fields: event number, start time, end time, anomaly level, peak deviation, affected wind turbine number, and possible cause classification. The possible cause classification includes three types: network latency, equipment aging, and malicious attack.
[0042] In one possible implementation, the system also records wind speed, wind direction, and power grid frequency data at the time of the abnormal event, which can be used for subsequent analysis of the correlation between the abnormal event and environmental factors, and to identify high-risk periods under specific environmental conditions.
[0043] Step S104: Collect historical communication log records, combine them with the operation anomaly event record table to identify abnormal fluctuation patterns in the historical change trajectory of wind power system setpoints, extract the characteristics of control command transmission frequency changes and setpoint value jump amplitude, and establish a network security anomaly pattern library to identify potential data tampering and unauthorized access behaviors.
[0044] The setpoint time series of wind turbine speed, power, and blade angle are extracted from historical communication logs. Combined with the time period markers in the operational anomaly event record table, the difference between adjacent sampling times for each setpoint is calculated and divided by the time interval to obtain the rate of change. If the rate of change exceeds a preset multiple of the historical average rate of change for that setpoint type, it is recorded as an abnormal jump point, forming an abnormal fluctuation feature set containing the jump time, jump amplitude, and setpoint type. For abnormal time periods in the abnormal fluctuation feature set, the hourly transmission frequency of control commands within the corresponding time period is statistically analyzed, and the moving average and standard deviation of the frequency sequence are calculated. When the frequency deviates from the average for a certain time period by more than a preset multiple of the standard deviation, the source IP address, target wind turbine number, and control operation type of all commands for that time period are extracted from the communication logs to construct an abnormal access behavior record. Based on the abnormal access behavior records, the Isolation Forest algorithm is used to detect anomalies in the multidimensional features of the access behavior. The magnitude of setpoint jumps, command sending frequency, and changes in the access source address are used as input features. An anomaly score is output for each record. Records with anomaly scores exceeding a threshold are clustered based on feature similarity to identify three types of anomaly patterns: data tampering, frequent operation, and unauthorized access. Based on these three types of anomaly patterns, typical feature vectors, trigger threshold conditions, and historical occurrence cases are extracted for each pattern. The anomaly pattern identification rules, risk level assessment criteria, and feature matching methods are associated and stored to establish a network security anomaly pattern library for real-time detection of potential data tampering and unauthorized access behavior.
[0045] Specifically, in one implementation, the historical communication log data extraction adopts a time-series database storage structure. Each log record contains five core fields: timestamp, control command type, setpoint parameter, sending source information, and execution result. The normal range of variation for the wind turbine speed setpoint is 0.1-0.3 revolutions per second, the normal adjustment range for the power setpoint is no more than 5% of the rated power each time, and the normal adjustment range for the blade angle is 1-3 degrees each time.
[0046] Specifically, the rate of change is calculated using the differential method. The system extracts the setpoint sequence at 100-millisecond sampling intervals. For the setpoint Vi at the i-th sampling point and the setpoint Vi+1 at the (i+1)-th sampling point, the rate of change is calculated as (Vi+1-Vi) / 0.1 seconds. When the fan is operating normally, the rate of change of the speed setpoint should be kept within 3 revolutions per second. If a sudden change of more than 10 revolutions per second occurs within 1 second, or if the power setpoint changes by more than 20% of the rated power within 100 milliseconds, the system determines it as an abnormal jump. Such abnormal jumps are usually caused by malicious tampering or equipment failure. The record of abnormal jump points includes not only the numerical information of the jump but also the setpoint sequence for 5 seconds before and after the jump, used to analyze the temporal characteristics of the abnormal mode.
[0047] It should be noted that the frequency of control command transmission is statistically analyzed based on a sliding time window, with a window size of 1 hour and a sliding step size of 10 minutes. Under normal operating conditions, the wind turbine transmits 20-50 control commands per hour, mainly concentrated during periods of significant wind speed variation.
[0048] Preferably, during the construction of abnormal access behavior records, the system focuses on three key types of information: the geographical location attribute of the source IP address, the distribution pattern of the target wind turbine numbers, and the timing pattern of the control operation type. When the same IP address sends the same control command to multiple wind turbines within a short period of time, or when an unauthorized IP address attempts to modify key operating parameters, these behaviors are marked as high-risk access.
[0049] In one possible implementation, the application of the Isolation Forest algorithm involves constructing a multi-dimensional feature space. Each access behavior record is mapped to an eight-dimensional feature vector, including the magnitude of setting value jumps, jump frequency, command sending frequency, frequency change rate, number of source IP changes, target device dispersion, operation type diversity, and time distribution uniformity. The Isolation Forest constructs the isolation tree by recursively and randomly selecting features and split values. Due to the extreme nature of their feature values, outliers can be isolated after fewer splits. The output anomaly score ranges from 0 to 1, with scores closer to 1 indicating a higher degree of anomaly. When the anomaly score exceeds 0.6, the access behavior is judged as abnormal. Through feature analysis of a large number of abnormal behaviors, the system identifies three typical anomaly patterns: data tampering, characterized by large changes in setting values and repeated modifications within a short period; frequent operation, characterized by an abnormally high frequency of control command sending, exceeding three times the normal frequency; and unauthorized access, characterized by access from unregistered IP addresses or abnormal operations outside of working hours.
[0050] For example, typical characteristics of data tampering-related anomaly modes include: speed setpoints changing by more than 50% of rated speed within one second; power setpoints showing negative values or exceeding 1.5 times the rated power; and blade angle setpoints exceeding physical limits. These anomalies are often accompanied by unauthorized acquisition of control privileges. Furthermore, frequent operation-related anomaly modes are mainly characterized by abnormally dense sending of control commands, exceeding 100 commands per minute. This mode may overload the control system and affect normal adjustment response. Unauthorized access anomalies are identified through IP address whitelisting mechanisms and access time window restrictions.
[0051] Understandably, the network security anomaly pattern library is organized using a hierarchical index structure. The top level is categorized into three anomaly patterns, with each pattern containing multiple specific anomaly cases. Each case record includes a feature vector value, environmental parameters at the time of triggering, the scope of impact, and the handling measures. The pattern library supports fast retrieval based on feature similarity. When a new anomaly occurs, the system calculates the Euclidean distance between its feature vector and each pattern in the library; the pattern with the smallest distance is considered the most likely anomaly type.
[0052] For example, in a cyberattack, an attacker modified the power setpoints of multiple wind turbines to abnormal values during off-peak hours in the early morning, causing abnormal power output at the wind farm. By analyzing access time, operation mode, and setpoint change characteristics, the system successfully identified the unauthorized access anomaly pattern, providing important reference for subsequent real-time detection.
[0053] The system acquires changes in speed and power setpoints from the historical setpoint records of the wind power system. It analyzes jump events where setpoints exceed normal variation ranges within a short period and time points of unauthorized modifications. It evaluates abnormal events where control command transmission frequency exceeds standard operating frequency and tampering traces where setpoint values deviate from their original values. It extracts tampering traces containing blade angle abrupt changes, generator speed deviations, and power to obtain a library of abnormal amplitude tampering traces.
[0054] The system acquires the time series of speed and power setpoints from the historical database of the wind power system. It calculates the rate of change by dividing the difference between adjacent sampling points by the sampling time interval. If the rate of change exceeds a threshold multiple of the historical average rate of change, it is marked as a jump event. Simultaneously, it queries the user login records and operation permission levels at that moment to verify whether the user has permission to modify parameters, resulting in an abnormal event set containing the jump time, change magnitude, and authorization status. Based on this abnormal event set, it counts the number of control commands sent per hour and compares this to the standard operating frequency specified in the wind farm operation and maintenance procedures. When the sending frequency exceeds a threshold multiple of the standard value, it extracts all setpoint modification records for that period and calculates the percentage deviation between the current setpoint and the initial operating value, forming an abnormal feature group containing the number of frequency exceedances and the degree of numerical deviation. For abnormal periods within the abnormal feature group, it extracts the measured values of blade angle, generator speed, and output power from the real-time monitoring data of the equipment. It calculates the deviation value by subtracting the measured value from the setpoint at the corresponding moment. If the blade angle deviation, speed deviation, or power deviation exceeds its respective allowable deviation range, it is determined as an abnormal control event, and the maximum value of each parameter deviation and the duration of the abnormality are recorded. Based on the abnormal control event records, the temporal correlation between different parameter anomalies is identified, and anomalies with the same time characteristics are grouped into one category. The features of each category are extracted, including the maximum value of parameter mutation amplitude, the total amount of accumulated deviation, and the total duration of the anomaly. A tampering trace library is constructed, which includes tampering type classification, anomaly severity quantification value, and temporal evolution characteristics.
[0055] Specifically, in one implementation, the wind power system historical database adopts a distributed time-series data storage architecture, storing all setting value change records using millisecond-level timestamps as indexes. The sampling frequency for the speed setting value is 10 times per second, and the sampling frequency for the power setting value is 5 times per second, ensuring that instantaneous parameter changes can be captured.
[0056] Specifically, the rate of change is calculated based on the principle of discrete differentiation. For the speed setpoint sequence, the system extracts the values Vi and Vi+1 of two consecutive sampling points Ti and Ti+1, and the rate of change is calculated as (Vi+1-Vi) / (Ti+1-Ti), where the time difference is typically 100 milliseconds. Under normal operating conditions, the fan speed is adjusted gradually, with each adjustment not exceeding 2% of the rated speed. When the rate of change at a sampling point exceeds three times the historical average rate of change, the system marks that point as a potential jump event. The determination of a jump event considers not only single-point anomalies but also the trends of the changes at the preceding and following 10 sampling points for comprehensive analysis. If more than three consecutive high rate of change points appear within 500 milliseconds, it is confirmed as a jump event. Such jumps usually indicate that the setpoint has been maliciously tampered with or that there is a serious malfunction in the control logic.
[0057] It should be noted that user login records and operation permission verification are implemented through a multi-level authentication mechanism. Wind farm operation and maintenance personnel are divided into three permission levels: monitor, operator, and administrator. Only operators and administrators have parameter modification permissions, and the scope of modification is strictly limited.
[0058] Preferably, the standard operating frequency defined in the wind farm operation and maintenance procedures varies depending on the time of day. The standard frequency during normal daytime operation is 30-50 operations per hour, decreasing to 10-20 operations per hour at night. When the number of operations detected in a certain hour exceeds twice the standard value, the system enters a high-frequency operation warning state.
[0059] In one possible implementation, deviation calculation involves a comprehensive evaluation of multiple parameters. The permissible deviation range for blade angle is ±2 degrees; exceeding this range indicates potential actuator jamming or abnormal control signals. The permissible deviation for generator speed is ±3% of rated speed, and the permissible deviation for power output is ±5% of rated power. The system compares the setpoint with the actual measured value every 100 milliseconds. When the deviation persists beyond the permissible range for more than 5 seconds, it is determined to be an abnormal control event. The maximum deviation value is recorded to assess the severity of the anomaly, while the duration reflects the system's ability to recover. A distance matrix is constructed to measure the similarity between two time series, allowing identification of inherent correlation patterns even if the two series have scaling or offsets on the time axis. First, the abnormal speed series, abnormal power series, and abnormal blade angle series are used as inputs to construct a cumulative distance matrix between each pair of the three series. A dynamic programming method is used to find the path with the minimum cumulative distance, which reflects the temporal correspondence between anomalies of different parameters. When the anomalous sequences of two parameters are highly correlated in time, i.e., the regular paths are close to the diagonal, it indicates that the anomalies of these two parameters are strongly correlated and are likely to originate from the same tampering event or fault source. The output correlation coefficient ranges from 0 to 1, and a coefficient greater than 0.7 is considered to indicate a significant correlation. Furthermore, the classification of anomalous features is based on cluster analysis. The system projects the feature vectors of all anomalous events into a multidimensional space, where the feature vectors include dimensions such as mutation magnitude, frequency anomaly degree, duration, and types of influencing parameters. By calculating the Euclidean distance between feature vectors, anomalies with similar distances are grouped into one category.
[0060] Understandably, the tampering trace database employs a three-layer architecture. The top layer is categorized into three main types based on tampering type: parameter mutation type, frequent operation type, and permission anomaly type. The middle layer records typical characteristic patterns for each type of tampering, including temporal characteristics, amplitude characteristics, and correlation characteristics. The bottom layer stores specific historical case data, with each case containing a complete sequence of abnormal parameters, environmental context information, and the handling result.
[0061] For example, in a typical case of parameter abrupt change tampering, the attacker instantly changed the speed setpoint of five wind turbines from 1500 revolutions per second to 0 at 3:00 AM, causing the turbines to brake suddenly and the mechanical components to withstand a huge impact. The characteristics of this case include: a change rate of 15,000 revolutions per second, no authorization verification records, and multiple units malfunctioning simultaneously. These characteristics were extracted and stored in the tampering trace database, becoming an important reference for identifying similar attacks.
[0062] Step S105: Establish an attack risk classification model based on the network security anomaly pattern library. Analyze the data patterns of wind turbine power setpoint offset and control command change frequency through the attack risk classification model to identify different types of network security threats and generate security risk classification files.
[0063] Feature data from historical attack cases is extracted from a network security anomaly pattern database. This data includes the power setpoint offset magnitude, offset duration, control command transmission interval, and frequency statistics. A random forest algorithm is used to train the mapping relationship between feature data and threat type labels, resulting in an attack risk classifier containing multiple decision trees and feature weights. The attack risk classifier is then used to process real-time collected wind turbine operating data. The difference between the power setpoint and rated power is calculated and divided by the rated power to obtain the offset percentage. The number of control commands transmitted per unit time is counted. If the offset percentage shows a step-like change or the command frequency fluctuates periodically, the peak value, mean, and standard deviation are extracted as attack behavior feature vectors. These attack behavior feature vectors are input into the classifier for matching calculations, outputting threat type prediction results and confidence scores. When the confidence score exceeds a preset threshold, the threat is determined to be service interference, parameter tampering, or command replay based on the feature pattern. The time of threat occurrence, the number of affected wind turbines, and the anomaly score are recorded. Based on the threat type determination results, multi-dimensional classification and coding are performed according to the attack source address, attack method characteristics and hazard level. Continuous attack events from the same source are associated in chronological order, and the attack frequency change trend and intensity increase pattern are extracted to construct a security risk classification file containing threat type identification code, risk level value and feature description text.
[0064] Specifically, in one implementation, historical attack cases in the network security anomaly pattern library are indexed and stored according to the attack occurrence time, duration, and scope of impact. Each case record includes the original power setting value sequence, control command logs, network traffic data, and the final threat characterization result. The feature extraction process calculates the percentage value of the power offset relative to the rated power, records the offset duration in seconds, and statistically analyzes the minimum, average, and standard deviation of the control command sending interval.
[0065] Specifically, the training process of the Random Forest algorithm involves ensemble learning of decision trees. A subset of samples is randomly selected from historical cases, and each subset is used to train a decision tree. The construction of a single decision tree uses information gain or the Gini coefficient as the node splitting criterion, randomly selecting some features for splitting decisions at each node. The splitting threshold for the power offset feature is determined by calculating the information gain at different split points, typically choosing the split value that maximizes purity improvement. The training process generates 100 to 500 decision trees, with the depth of each tree limited to 10 to 20 layers to prevent overfitting. The final classifier integrates the predictions of all decision trees through a voting mechanism. Each tree independently predicts the input sample, and the threat type with the most votes is taken as the final classification result. Feature weights are calculated by the average reduction in impurity for each feature across all decision trees; a larger weight indicates a greater contribution of the feature to the classification.
[0066] It should be noted that the power offset percentage is calculated using a sliding window method, with a window size of 10 seconds, sliding once per second. Within each window, the system extracts the maximum, minimum, and average values of the power setting, and calculates the ratio of the maximum offset to the rated power.
[0067] Preferably, the extraction of attack behavior feature vectors focuses on temporal pattern features. A step-change pattern is characterized by multiple equal-amplitude jumps in the power setpoint within a short period, with each jump occurring at equal intervals; this pattern is commonly found in automated attack scripts. A periodic fluctuation pattern is characterized by a regular alternation of high and low frequency of control command transmissions, with a fixed period length and stable amplitude.
[0068] In one possible implementation, threat type identification is based on feature pattern matching. Typical characteristics of service interference threats include: control command transmission frequency exceeding normal values by more than 10 times and duration exceeding 30 seconds, aiming to overload the control system and render it unresponsive to normal operation. These attacks do not directly modify setpoints but consume system resources through a large number of invalid commands. Parameter tampering threats manifest as power or speed setpoints being modified to abnormal values, such as negative power settings or exceeding 150% of rated power; such modifications may damage equipment. Command replay threats intercept and repeatedly transmit historical control commands, causing the fan to execute outdated control actions under inappropriate environmental conditions. The system identifies these threats by analyzing the timestamp continuity and content repetition of the command sequence. Confidence scores are calculated based on the degree of feature matching; a perfect match of typical feature patterns results in a confidence score of 1.0, while partial matches are calculated proportionally based on the number of matched features.
[0069] For example, the timing of a threat is recorded down to the millisecond, and the number of affected wind turbines is determined by statistically analyzing the turbine numbers that exhibited anomalies within the same time period. Anomaly severity is scored using a quantification scale of 0 to 10, where 0-3 is low risk, 4-6 is medium risk, and 7-10 is high risk. Scoring is based on factors including the degree of deviation, duration, and potential losses. Furthermore, the multi-dimensional classification coding system considers the needs of attack tracing and pattern recognition. The attack source address coding includes the geographic location and network affiliation information of the IP address, used to identify the geographical distribution patterns of attacks. The attack method feature coding uses binary bits to represent the combination of different attack techniques. The system sets a time threshold of 5 minutes; when the time interval between two attack events is less than this threshold and the source IP address is the same, it is considered a continuous attack. The attack frequency trend is obtained by calculating the rate of change of the number of attacks per unit time, and the intensity increase pattern is identified by comparing the anomaly severity scores of continuous attacks.
[0070] For example, in one actual attack case, the attacker first sent query commands at a frequency of 100 per second to disrupt the service. After the system response slowed down, the attacker changed the power setting to 0 in an attempt to shut down the wind turbine. Finally, the attacker attempted to restart the wind turbine under improper conditions by replaying historical startup commands. The entire attack lasted 15 minutes, involved 20 wind turbines, and was coded as a complex high-risk threat event.
[0071] Step S106: Collect current device execution status data, and identify the degree of deviation between the actual execution status and the expected set status by combining the safety risk classification file. When the actual status deviation exceeds the allowable range of operation and management and the system execution response delay exceeds the management threshold, a comprehensive risk level is generated.
[0072] The system collects the current actual values of wind turbine speed, power output, and blade angle from the equipment's real-time monitoring interface. Simultaneously, it extracts the corresponding setpoint values from the control center database, calculates the difference between the actual values and the setpoint values to obtain the deviation values for each parameter, and forms a real-time deviation dataset containing the deviation values and the collection time. When analyzing equipment status deviations, an attack risk classifier is used to classify the current abnormal patterns in real time. Based on the threat type and confidence score output by the classifier, the weight parameters of the risk assessment are dynamically adjusted. Furthermore, based on the real-time deviation dataset, the system queries the threat level for the corresponding time period in the security risk classification file and obtains the allowable deviation range for each parameter from the wind farm operation standards. If the speed deviation or power deviation exceeds the allowable range, it is recorded as a status anomaly. Simultaneously, the time interval from command issuance to equipment response completion is calculated as the execution response delay. For the aforementioned abnormal status and execution response delay, when the deviation continues to exceed the preset duration and the delay exceeds the management threshold, the risk score is obtained by dividing the deviation amplitude by the upper limit of the allowable range and multiplying it by the delay excess ratio. Based on the range in which the score falls, low, medium, and high risk levels are determined, and a comprehensive risk level including the abnormal parameter name, risk score, and level identifier is constructed.
[0073] Specifically, in one implementation, the equipment real-time monitoring interface uses the OPCUA protocol to acquire data, updating the wind turbine operating parameters every 100 milliseconds. The monitoring interface simultaneously reads real-time values from the speed sensor, power transmitter, and blade angle encoder in the SCADA system; these values are then filtered and used as the current actual values.
[0074] Specifically, the permissible deviation ranges defined in the wind farm operation standards are dynamically adjusted according to different operating conditions. When operating below the rated wind speed, the permissible deviation for rotational speed is ±5% of the rated speed, for power output it is ±8% of the rated power, and for blade angle it is ±3 degrees. When operating above the rated wind speed, because the wind turbine needs to perform power limiting and load control, the permissible deviation ranges are correspondingly narrowed, with rotational speed deviation reduced to ±3% and power deviation reduced to ±5%. This dynamic adjustment mechanism ensures accurate identification of abnormal conditions under different operating circumstances.
[0075] It should be noted that the calculation of the execution response delay starts from the moment the control command is generated at the SCADA master station and ends when the wind turbine field controller returns the execution completion confirmation signal. It includes three parts: network transmission delay, command parsing delay, and mechanical execution delay.
[0076] Preferably, a weighted scoring method is used to calculate the risk score. The ratio of the deviation magnitude to the upper limit of the allowable range is used as the deviation factor, with a value ranging from 1 to 3. The delay excess ratio is calculated as the ratio of the actual delay to the management threshold; when the delay is 1.5 times the management threshold, the excess ratio is 1.5. The risk score is equal to the product of the deviation factor and the excess ratio, multiplied by a base weighting coefficient of 10, resulting in a score ranging from 0 to 100. For example, a score of 0-30 corresponds to low risk, 30-70 to medium risk, and 70-100 to high risk. This quantitative method allows different types of anomalies to be compared and rated under a unified standard.
[0077] For example, when the fan speed deviation reaches 1.2 times the upper limit of the allowable range and the execution response delay reaches 1.8 times the management threshold, the risk score is calculated as 1.2 × 1.8 × 10 = 21.6, which is judged as a low risk level. The system records the anomaly but does not trigger emergency response.
[0078] In one possible implementation, the comprehensive risk level includes not only risk score and level identifier, but also records the duration of the anomaly, the trend of anomaly parameter changes, and the status of associated equipment, providing maintenance personnel with a comprehensive basis for risk assessment.
[0079] By identifying numerical tampering attacks and interference attacks through security risk classification files, the degree of deviation between the actual operating state of wind turbines and the expected control state, as well as the system response delay time, are analyzed. The equipment safety margin and the degree of grid stability risk under the impact of the attack are assessed. The severity of the attack type and the degree of system deviation are combined to generate graded early warning signals including wind turbine emergency shutdown, power limitation and equipment maintenance.
[0080] Attack type identifiers are extracted from the security risk classification file. Numerical tampering attacks are identified based on abnormal changes in power setpoints, and interference attacks are identified based on abnormal increases in command frequency. Simultaneously, actual wind turbine operating parameters are acquired, and the difference between the actual and setpoint values is calculated and divided by the setpoint to obtain the deviation rate. The delay from command issuance to execution completion is recorded, forming state assessment data containing attack type, deviation rate, and delay duration. Based on this state assessment data, the difference between the current speed and the overspeed protection value is calculated as the speed safety margin, and the difference between the rated power and the current power is calculated as the power safety margin. The impact of power fluctuation amplitude on grid frequency is assessed; if the fluctuation exceeds a preset threshold, it is judged as a high stability risk, obtaining the equipment safety margin value and the grid stability risk level. Based on the safety margin value and risk level, the severity of the attack type is assigned a weight coefficient: numerical tampering attacks have a weight of 0.8, and interference attacks have a weight of 0.5. These are multiplied by the system deviation rate and accumulated to obtain a comprehensive risk score, which is then mapped to a warning level range. Based on the comprehensive risk score, if the score exceeds the high-risk threshold, an emergency shutdown signal is triggered; if it is in the medium-risk range, a power limiting command is issued; and if it is in the low-risk range, a maintenance reminder is issued, thus constructing a graded early warning signal that includes the warning level, triggering conditions, and execution actions.
[0081] Specifically, in one implementation, the safety risk classification file is stored in a structured database. Each record includes an attack type identifier, an attack feature vector, historical occurrence frequency, and a hazard level score. The identification criteria for numerical tampering attacks include a sudden change in power setpoint to a negative value or exceeding 150% of the rated power, an instantaneous return of the speed setpoint to zero or exceeding the overspeed protection value, and a blade angle setpoint exceeding physical limits. The identification characteristics of interference attacks are mainly reflected in an abnormal increase in the frequency of control command transmission. Under normal circumstances, 3-5 control commands are sent per minute, but during interference attacks, the frequency can reach over 100 per minute.
[0082] Specifically, the deviation rate is calculated using the relative deviation method, which is the difference between the actual operating value and the set value, divided by the set value, and then multiplied by 100% to obtain the deviation rate as a percentage. For the speed parameter, the deviation rate calculation formula is (actual speed - set speed) / set speed × 100%. A positive deviation rate indicates that the actual value is higher than the set value, while a negative value indicates that the actual value is lower than the set value. The absolute value of the deviation rate reflects the magnitude of the deviation and is an important indicator for assessing the degree of abnormality in system operation.
[0083] It should be noted that the concept of safety margin originates from equipment protection theory, representing the safe distance between current operating parameters and equipment protection action values. The speed safety margin is calculated as the difference between the overspeed protection value and the current actual speed; the smaller this difference, the closer the equipment is to the protection action boundary, and the higher the safety risk. The power safety margin, on the other hand, is considered from the perspective of overload protection, calculating the difference between the rated power and the current output power.
[0084] Preferably, the grid stability risk assessment focuses on the impact of power fluctuations on grid frequency. Sudden changes in wind turbine power can cause grid frequency fluctuations, and when multiple wind turbines experience power anomalies simultaneously, the cumulative effect may exceed the grid's regulation capacity. During the assessment, the system calculates the proportion of power fluctuation amplitude to the total installed capacity of the wind farm. When this proportion exceeds 10%, it is classified as a moderate stability risk, and when it exceeds 20%, it is classified as a high stability risk. This assessment method considers the matching relationship between the scale of the wind farm and the grid's carrying capacity.
[0085] In one possible implementation, the comprehensive risk score is calculated using a weighted summation method. The severity weight of the attack type is determined based on the hazard levels of historical cases; numerical tampering attacks, which may damage equipment, are assigned a high weight of 0.8; interference attacks, which primarily affect system response efficiency, are assigned a medium weight of 0.5. The degree of system deviation is reflected by the absolute value of the deviation rate; for every 10% increase in the deviation rate, the risk contribution value increases by 1 point. Delay duration is included in the risk score at a rate of 0.5 points per second. The comprehensive risk score equals the attack type weight × 10 plus the deviation rate contribution value plus the delay contribution value. For example, the score range is set from 0 to 20 points. For instance, 0-6 points correspond to low risk, 7-13 points to medium risk, and 14-20 points to high risk. This quantitative scoring mechanism allows for a comprehensive assessment of risk factors across different dimensions within a unified framework, providing a clear basis for tiered early warning systems.
[0086] For example, when a numerical tampering attack is detected, the power deviation rate reaches 30%, and the response delay is 3 seconds, the comprehensive risk score is calculated to be 0.8 × 10 + 3 + 1.5 = 12.5 points, falling into the medium-risk range, and the system triggers a power limiting command. Furthermore, the execution actions of the graded warning signals have clear priorities and mutual exclusion relationships. The emergency shutdown signal has the highest priority; once triggered, it immediately executes the wind turbine braking procedure, including blade feathering, generator grid disconnection, and mechanical braking. The power limiting command reduces the wind turbine's output power to below 50% of its rated power while maintaining grid-connected operation. Equipment maintenance reminders send alarm information to maintenance personnel through the SCADA system, prompting them to arrange inspections within 24 hours.
[0087] Understandably, the warning signal also contains detailed records of abnormal events, including the time of attack, duration, type of influencing parameters, and peak deviation. These records are stored in a historical database to provide data support for subsequent incident analysis and optimization of protection strategies.
[0088] For example, when a wind farm was subjected to a cyberattack, the system identified that a numerical tampering attack had caused the power setting values of 5 wind turbines to be modified to 0, with a deviation rate of 100%, the safety margin dropped to the critical value, and the comprehensive risk score was 18 points, triggering an emergency shutdown warning. The 5 wind turbines completed a safe shutdown within 30 seconds, avoiding equipment damage and grid accidents.
[0089] Step S107: Based on the comprehensive risk level assessment, network latency and security threats are evaluated, the risk of operation and management interruption is identified, and the types and probabilities of potential security risks in the operation of the wind power system network are analyzed to provide risk prediction and security supervision information for operation and management decisions.
[0090] Based on the comprehensive risk level score and level identifier, the number of network transmission delay exceedances and their duration are extracted to identify the type and severity of security threats. The frequency of control failures caused by delays is calculated. If the frequency exceeds a preset threshold and the threat level is high, an operational interruption risk is identified, resulting in a risk assessment set containing delay characteristics, threat types, and interruption probabilities. Based on this risk assessment set, the triggering conditions and duration of historical interruption events are statistically analyzed to identify three types of risks: data transmission interruption, control response failure, and device communication offline. The conditional probability values and trigger thresholds for each type of risk are output. Based on the conditional probability values, combined with current network status parameters and the frequency of threat events, the probability of each type of risk occurring within a preset future time period is calculated. If the probability exceeds a management threshold, the key triggers and propagation paths of the risk are extracted, forming risk prediction data and evolution trends. For the risk prediction data, the risk type name, occurrence probability value, and potential impact range are integrated and prioritized according to probability and impact level to construct risk prediction information and security supervision guidance that includes risk description, probability value, and key supervision points.
[0091] Specifically, in one implementation, the network latency data included in the comprehensive risk level is processed using a time window statistical method. The system counts the number of latency exceeding the standard events every 5 minutes. When an event with a latency exceeding the normal value by 200 milliseconds occurs more than 3 times within the window, it is recorded as a latency anomaly. The criteria for determining whether latency leads to control failure are: no execution confirmation is received within a specified time after the control command is sent, or the execution result deviates from the expected range beyond the allowable range.
[0092] Specifically, the Bayesian network is constructed based on a historical outage event database. The network nodes include four parent nodes (latency frequency, threat level, device status, and network load) and one child node (operational outage). Each node has a discrete state space, with latency frequency categorized into low, medium, and high states, and threat level categorized into no threat, low risk, medium risk, and high risk. The conditional probability table is obtained by statistically analyzing the frequency of outage events under various combinations of conditions in historical data.
[0093] For example, when latency is high, threat level is high, equipment status is abnormal, and network load is overloaded, the conditional probability of operational interruption reaches 0.85. Based on the currently observed parent node status, the posterior probability of child nodes is calculated. This probabilistic reasoning method can handle uncertain information and still provide reasonable risk assessment results even when the status of some nodes is unknown.
[0094] It should be noted that the identification of the three types of risks is based on different characteristic patterns. Data transmission interruption risk manifests as the loss of multiple consecutive data packets, a disconnected communication link, and the cessation of real-time data updates. Control response failure risk is characterized by the successful transmission of control commands but the device failing to execute them, or the execution result not matching the command requirements. Device communication offline risk manifests as the loss of the device's heartbeat signal, making it impossible to obtain device status information.
[0095] Preferably, the probability of risk occurrence is calculated using a time series forecasting method. The system constructs a time interval model for risk occurrence based on the temporal distribution patterns of historical risk events. By analyzing the frequency and time intervals of various risks over the past 30 days, the average occurrence rate λ is calculated. Under the Poisson process assumption, the probability of a risk occurring k times within a future time period t is P(k) = (λt). k ×e (-λt) / k!. Where P(k) represents the probability of a risk occurring k times within time period t, λ represents the average rate of occurrence of the event per unit time (or unit space), t represents the duration, k represents the number of times the event occurs, e is the natural constant, and ! is the factorial symbol. When the calculated probability of a single occurrence exceeds 0.3, the risk is considered to be very likely to occur within the prediction period.
[0096] In one possible implementation, the formation of risk prediction data involves the integration of multi-dimensional information. The system extracts the key triggers for each type of risk, including the intensity of external attacks, internal system load, and changes in environmental factors. Propagation path analysis is achieved by constructing a risk propagation graph, where nodes represent system components and edges represent risk propagation relationships. When a component experiences a risk, potentially affected downstream components are identified by traversing the risk propagation graph. Evolutionary trends are obtained through time series analysis; the system records the curves of risk indicators changing over time, uses moving averages to smooth noise, and extracts trend components. An upward trend indicates that the risk is escalating, requiring a higher monitoring level; a downward trend indicates that the risk is mitigating, allowing for an appropriate reduction in alert level.
[0097] For example, when frequent network latency exceeding limits is detected, coupled with the presence of high-risk threat events, the system calculates a data transmission interruption probability of 0.42, a control response failure probability of 0.38, and a device communication offline probability of 0.25. Risk prediction shows a combined probability of operational disruption within the next two hours of 0.65. Furthermore, risk priority is assigned using a risk matrix method. The horizontal axis represents the probability of occurrence, categorized into five levels: extremely low, low, medium, high, and extremely high; the vertical axis represents the degree of impact, categorized into five levels: minor, relatively minor, moderate, severe, and catastrophic. High-probability, high-impact risks falling in the upper right corner of the matrix receive the highest priority.
[0098] Understandably, the safety supervision guidance includes key monitoring targets, recommended monitoring frequencies, anomaly detection thresholds, and emergency response plans. The system dynamically adjusts its supervision strategy based on the current risk situation, increasing monitoring frequency and lowering anomaly detection thresholds during high-risk periods to ensure timely detection and handling of risk events.
[0099] For example, during typhoon season, a wind farm predicted that the probability of network communication being affected by the weather would increase to 0.7. It recommended increasing the data collection frequency from once per minute to once every 10 seconds, reducing the latency threshold from 500 milliseconds to 300 milliseconds, and setting up a typhoon emergency plan, including measures such as switching local control modes and backing up critical data, which effectively reduced the risk of operational interruption caused by extreme weather.
[0100] It will be apparent to those skilled in the art that this application is not limited to the details of the exemplary embodiments described above, and that this application can be implemented in other specific forms without departing from the spirit or essential characteristics of this application. Therefore, the embodiments should be considered illustrative and non-limiting in all respects, and the scope of this application is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within this application. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A risk identification method for wind power systems, characterized in that, include: Acquire a communication performance dataset and a system response efficiency index library, which are formed based on control command timestamp data; Assess the matching degree between communication transmission and system response, and generate an operational anomaly event log table; A network security anomaly pattern library shall be constructed by combining the aforementioned operational anomaly event record table; Based on the aforementioned network security anomaly pattern library, an attack risk classification model is trained to generate a security risk classification profile. Based on the equipment's execution status data, the degree of deviation between the actual execution status and the expected set status is calculated, and a comprehensive risk level is generated; Based on the comprehensive risk level, operational interruption risks are identified, and risk prediction data containing risk types and probabilities of occurrence is generated. This risk prediction data is used to provide risk prediction information for operation and maintenance management decisions.
2. The risk identification method for wind power systems according to claim 1, characterized in that, The acquisition of the communication performance dataset and system response efficiency index library specifically includes: The transmission timestamp data of control commands are collected from the network communication link of the wind power system, the transmission time of each command is calculated, and a communication performance dataset is constructed. The system response efficiency index library is formed by identifying the device response and adjustment completion timestamps through the communication performance dataset, calculating the time difference between instruction issuance and device adjustment completion.
3. The risk identification method for wind power systems according to claim 2, characterized in that, The obtained communication performance dataset includes: The sending timestamp and sequence number of the instruction are obtained from the instruction sending log; the instruction sending log is collected from the control center. Obtain the receiving timestamp corresponding to the instruction sequence number from the field device port, calculate the difference between the receiving timestamp and the sending timestamp, and obtain the transmission delay value; For the transmission delay value, obtain the network load rate and data retransmission count, remove outliers with excessive retransmission counts, summarize the normal transmission delay value and network load rate, and generate the communication performance dataset.
4. The risk identification method for wind power systems according to claim 2, characterized in that, The step of identifying device response and adjustment completion timestamps through the communication performance dataset, calculating the time difference between instruction issuance and device adjustment completion, and forming the system response efficiency index library includes: By using the instruction sequence number and sending timestamp in the communication performance dataset, query the device response confirmation timestamp and adjustment completion timestamp; Calculate the time difference between the adjustment completion timestamp and the sending timestamp to obtain the total execution time of the device; The total execution time of the equipment is summarized according to the categories of wind turbine pitch, yaw and power regulation. The total execution time exceeding the standard is recorded as a response timeout event. The execution time and timeout frequency of various controls are statistically analyzed to generate a system response efficiency index library.
5. The risk identification method for wind power systems according to claim 1, characterized in that, The generation of the security risk classification file includes: By analyzing the offset of wind turbine power setpoints and the frequency of control command changes using an attack risk classification model, network security threat types are identified, and a security risk classification profile is generated based on these network security threat types.
6. The risk identification method for wind power systems according to claim 1, characterized in that, The assessment of the matching degree between communication transmission and system response, and the generation of an operational anomaly event record table, includes: Using the system response efficiency index library, the matching degree between communication transmission time and system execution response delay within the monitoring period is evaluated. The average execution time of each control type in the system response efficiency index library is extracted, the correlation deviation between transmission efficiency and response efficiency is identified, the average transmission delay value of the corresponding period in the communication performance data is obtained, the difference between execution time and transmission delay is calculated, and the difference exceeding the standard is determined to be a mismatch event. For the mismatch event, extract the time series before and after the event, calculate the correlation coefficient between transmission delay and execution response, record the network load rate and device operating status below the threshold, and generate an operational anomaly event record table.
7. The risk identification method for wind power systems according to claim 1, characterized in that, The construction of the network security anomaly pattern library by combining the aforementioned operational anomaly event record table includes: Extract the time series of wind turbine speed, power and blade angle setpoints from historical communication logs, and combine them with the operation anomaly event record table to extract the variation pattern of control command transmission frequency and the characteristics of setpoint jump amplitude. Calculate the rate of change of the set value based on the changing pattern of the frequency of control command transmission and the characteristics of the jump amplitude of the set value, record the rate of change exceeding the standard as the abnormal jump point, and generate an abnormal fluctuation feature set. For the abnormal fluctuation feature set, the frequency of command sending is counted, the moving average and standard deviation of the frequency sequence are calculated, the source IP address, target wind turbine number and operation type of the exceeding frequency are extracted, and abnormal access behavior records are constructed. The isolated forest algorithm is used to detect abnormal access behavior, output anomaly scores, and generate data tampering, frequent operation and unauthorized access anomaly patterns by clustering, and build a network security anomaly pattern library.
8. A risk identification method for wind power systems according to claim 7, characterized in that, The process involves calculating the setpoint change rate based on the frequency of control command transmissions and the characteristics of setpoint jump amplitudes, recording the rate of excessive change as an abnormal jump point, and generating an abnormal fluctuation feature set, including: Obtain the time series of speed and power setpoints from the historical database, calculate the rate of change, mark the rate of change exceeding the standard as a jump event, verify operation permissions, and generate an abnormal event set; The frequency of statistical command transmissions is compared with the standard operating frequency to extract the frequency of exceeding the standard and the percentage of deviation from the set value, and an abnormal feature group is generated. The blade angle, speed, and power deviation values are extracted from the equipment data. Abnormal control events with deviations exceeding the standard are recorded. The dynamic time warping algorithm is used to identify the correlation of abnormal time sequences and to build a tampering trace database.
9. A risk identification method for wind power systems according to claim 1, characterized in that, The step of calculating the deviation between the actual execution state and the expected set state based on the equipment execution status data, and generating a comprehensive risk level, includes: Collect actual values of fan speed, power output and blade angle, calculate the deviation from the set values, and generate a real-time deviation dataset. Query the threat level in the security risk classification file, obtain the allowable deviation range of parameters, record the deviation exceeding the standard as an abnormal state, calculate the execution response delay, and generate a comprehensive risk level.
10. A risk identification method for wind power systems according to claim 9, characterized in that, The system queries the threat level in the security risk classification file, obtains the allowable deviation range of parameters, records deviations exceeding the limit as abnormal states, calculates the execution response latency, and generates a comprehensive risk level, including: The attack type identifier is extracted from the security risk classification file, the deviation rate between the actual value and the set value is calculated, the instruction execution delay is recorded, and status assessment data is generated. Calculate the speed and power safety margins, assess the impact of power fluctuations on the power grid, and determine stability risks; A comprehensive risk score is generated based on the weighted deviation rate of the attack type severity, which is then mapped to the warning level to generate a graded warning signal.
Citation Information
Patent Citations
Network security perception early warning method and system for smart power plant
CN119363438A
Security protection system for cloud side end collaborative interaction of power distribution Internet of Things
CN119402235A
Artificial intelligence network security system based on multi-modal large model training
CN120281550A
Network security protection method and system of main control equipment for wind power generation
CN120614176A
System and method for cybersecurity threat detection and early warning
US20240106844A1
Cited By
Data security risk quantitative dynamic assessment method and system
CN121644199A