Network security protection method and device for pulling and fusing multi-source information data
By using a multi-source intelligence data retrieval and fusion method, and leveraging machine learning to construct a message rationality analyzer and an integrated malicious analyzer, the problem of insufficient identification of new threats in power system network security protection was solved. This enabled early and accurate protection against flood attacks, improving the security and real-time performance of the power system network.
Patent Information
- Application Number
- CN202511394692.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2025-12-12
AI Technical Summary
Existing power system network security protection technologies are unable to accurately identify the dynamic changes and high concealment of new threats, resulting in high false alarm rates and high false negative rates, which affect network stability and normal use.
By using a multi-source intelligence data retrieval and fusion method, a message rationality analyzer is constructed using machine learning. Combined with historical time series parameters, a flood attack probability analysis is performed. An integrated malicious analyzer is used for dynamic evaluation and weighted discrimination, thereby achieving multi-dimensional adaptive analysis of message characteristics.
It significantly improves the early identification accuracy and real-time protection of power systems against flood attacks, reduces the false interception rate and the risk of missed detection, and ensures the accuracy and real-time performance of network security.
Smart Images

Figure CN121125283A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protection technology, specifically to a network security protection method and apparatus for multi-source intelligence data retrieval and fusion. Background Technology
[0002] In the field of power system network security, traditional protection technologies mainly rely on static rule bases or single-dimensional anomaly detection mechanisms, such as traffic monitoring based on fixed thresholds. These methods identify attack behavior by analyzing packet content in isolation or by using predefined traffic monitoring. However, with the evolution of attack techniques, new threats exhibit dynamic characteristics: attack information can simulate normal business patterns, making them difficult to identify and leading to an increased false positive rate for detection based on fixed rules; at the same time, attackers launch attacks through distributed nodes, rendering traditional detection mechanisms based on traffic mutations ineffective. Existing technologies cannot accurately identify new threats or cope with their dynamic changes and high concealment, resulting in a deficiency of both false positives and false negatives in existing security protection, causing delayed or excessive blocking of protection responses, disrupting the stability of the power system network, and ultimately affecting the normal operation of the power system. Summary of the Invention
[0003] This application provides a network security protection method and apparatus for multi-source intelligence data retrieval and fusion, which is used to address the technical problem of inaccurate network security protection processing in the prior art.
[0004] In view of the above problems, this application provides a network security protection method and device for multi-source intelligence data retrieval and fusion.
[0005] Firstly, this application provides a network security protection method for multi-source intelligence data retrieval and fusion, the method comprising: Obtain message information received by the power system, perform message rationality analysis, and obtain message rationality parameters; Based on the historical message rationality parameter sequence within a preset time range, the unreasonable message density is obtained, and flood attack probability analysis is performed to obtain the flood attack probability. Based on the flood attack probability, perform integrated malicious analysis of the message information to obtain the malicious probability; Based on the malicious probability and flood attack probability, the attack probability is calculated, and the message information is then protected and judged.
[0006] Secondly, this application provides a network security protection device for multi-source intelligence data retrieval and fusion, comprising: The rationality analysis module is used to acquire message information received by the power system, perform message rationality analysis, and obtain message rationality parameters; The flood attack probability analysis module is used to process and obtain unreasonable packet density based on the historical packet rationality parameter sequence within a preset time range, and perform flood attack probability analysis to obtain the flood attack probability. The malicious probability analysis module is used to perform integrated malicious analysis of the packet information based on the flood attack probability to obtain the malicious probability; The protection discrimination processing module is used to calculate the attack probability based on the malicious probability and flood attack probability, and to perform protection processing discrimination on the message information.
[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages: This application proposes a network security protection method and device that integrates multi-source intelligence data retrieval. By dynamically constructing a message rationality analyzer to quantify message credibility, generating attack density features based on historical time-series parameters, and integrating a multi-dimensional malicious analysis model for adaptive weighted discrimination, it significantly improves the early identification accuracy and real-time protection performance of power systems against flooding attacks. Compared to traditional methods, the technical solution provided in this application significantly overcomes the shortcomings of static rules in misjudging masquerading traffic. It utilizes a machine learning-driven rationality parameter analyzer to dynamically assess the compliance of message features, avoiding the misinterpretation of legitimate abnormal messages as malicious attacks. By introducing historical message rationality parameter sequences, it effectively captures the persistence characteristics of attacks, significantly reducing the risk of missed detection of covert flooding attacks. The dynamic selection strategy of integrating a malicious analyzer adaptively adjusts the ratio of analysis models based on real-time attack probabilities, minimizing computational power consumption while maintaining stable malicious behavior identification capabilities. Finally, through weighted fusion calculation of attack probabilities and a threshold discrimination mechanism, it achieves precise control over the timing of protection, avoiding business interruptions caused by excessive interception and triggering protection before the attack behavior causes substantial harm.
[0008] This application achieves the technical effect of improving the accuracy, real-time performance, and adaptability of power system network security protection. Attached Figure Description
[0009] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 A flowchart illustrating a network security protection method for multi-source intelligence data retrieval and fusion provided in this application embodiment; Figure 2This is a schematic diagram of a network security protection device for multi-source intelligence data retrieval and fusion, provided as an embodiment of this application.
[0011] The components represented by each number in the attached diagram are explained below: Reasonableness analysis module 100, flood attack probability analysis module 200, malice probability analysis module 300, protection judgment and processing module 400. Detailed Implementation
[0012] This application provides a network security protection method and apparatus for multi-source intelligence data retrieval and fusion, which is used to address the technical problem of inaccurate network security protection processing in the prior art.
[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0014] It should be noted that the terms "comprising" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to these processes, methods, products, or devices.
[0015] Example 1, as Figure 1 As shown, this application provides a network security protection method for multi-source intelligence data retrieval and fusion, wherein the method includes: S10: Obtain message information received by the power system, perform message rationality analysis, and obtain message rationality parameters.
[0016] Traditional power system protection mechanisms rely on predefined rule bases or fixed feature thresholds in the message detection stage, failing to dynamically assess the reasonableness of the coordination of message content, timing characteristics, and data scale. When attackers forge messages with legitimate business appearances, such as tampering with load data while retaining compliant message headers, static detection, lacking the ability to understand the multi-dimensional coupling relationships of message features, is prone to two types of misjudgments: misidentifying maliciously forged messages as legitimate business flows, or over-intercepting sudden abnormal messages in normal business processes, such as abnormal data triggered by equipment failures, thus hindering the normal operation of the power system.
[0017] Step S10 in the method provided in this application embodiment includes: Obtain message information received by the power system; Extract the message feature parameters of the message information; The message feature parameters are input into the message rationality analyzer, and the message rationality parameters are output. The message rationality analyzer is trained using the following steps: Based on historical security protection data of the power system, a set of characteristic parameters for sample messages was collected. Based on the proportion of normal messages under the characteristic parameters of each sample message, a set of reasonableness parameters for the sample messages is obtained by labeling. A message rationality analyzer is built based on machine learning. The message rationality analyzer is trained under supervised iterative training until it passes the test using the sample message feature parameter set and the sample message rationality parameter set.
[0018] In this embodiment of the application, message information received by the power system is obtained.
[0019] Extract message feature parameters from the message information, such as message content, message sending time, and message size.
[0020] Based on historical security protection data of the power system, a set of sample message characteristic parameters is collected. The set of sample message characteristic parameters includes message content, message sending time, and message size.
[0021] Based on the proportion of normal messages under each sample message characteristic parameter, a set of sample message rationality parameters is obtained. For example, a threshold of 80% for the proportion of normal messages is set. Specifically, messages containing actual business content have a normal message proportion of over 95%; messages sent between 8:00 and 9:00 have a normal message proportion of over 80%; and messages within 1400 bytes have a normal message proportion of over 85%. If the proportion of normal messages for the above message characteristic parameters exceeds the pre-set threshold, then the rationality parameter for messages containing actual business content is set to 95% and marked; the rationality parameter for messages sent between 8:00 and 9:00 is set to 80% and marked; and the rationality parameter for messages within 1400 bytes is set to 85% and marked. This process is repeated to collect the sample message characteristic parameter set and obtain the sample message rationality parameters.
[0022] Based on machine learning, a message rationality analyzer is constructed. For example, a three-layer neural network is used to construct the message rationality analyzer. The input layer has 3 nodes to input 3 kinds of message rationality parameters, the hidden layer has 8 nodes and uses the ReLU function for activation, and the output layer uses the Sigmoid activation function to output rationality parameters with values ranging from 0 to 1.
[0023] The message rationality analyzer is trained in a supervised iterative manner using a set of sample message feature parameters and a set of sample message rationality parameters until the error of the output message rationality parameters is within ±5%, which is considered a pass and the training of the message rationality analyzer is complete.
[0024] Input the message characteristic parameters into the message rationality analyzer, and output the message rationality parameters.
[0025] This application utilizes a machine learning-driven message plausibility analyzer to dynamically quantify message credibility and achieve coupled evaluation of multi-dimensional features. This enables the system to accurately identify the characteristics of attack messages beneath their business manifestations, while tolerating non-malicious abnormal messages in scenarios such as equipment failure, thereby fundamentally reducing false interception rates and missed detection risks.
[0026] S20: Based on the historical message rationality parameter sequence within a preset time range, process to obtain the unreasonable message density, perform flood attack probability analysis, and obtain the flood attack probability.
[0027] Current flood attack detection relies on instantaneous traffic thresholds or isolated packet analysis, failing to consider the temporal continuity of attack behavior. Faced with distributed, low-frequency attacks, traditional methods, focusing only on the rationality of a single point of attack, cannot perceive the cumulative effect of historically irrational packets. This may lead to misjudging persistent, low-intensity attacks as occasional business anomalies, or prematurely disabling protection during attack intervals.
[0028] Step S20 in the method provided in this application embodiment includes: Obtain the sequence of historical message rationality parameters for processing records within a preset time range; Combining the historical message rationality parameter sequence and message rationality parameters, the proportion of message rationality parameters that are less than the preset rationality parameter threshold is statistically analyzed and used as the message unreasonableness density. Based on the unreasonable density of the messages, a flood attack probability analysis is performed to obtain the flood attack probability; Among them, based on the unreasonable density of the messages, a flood attack probability analysis is performed to obtain the flood attack probability, including: Based on historical network attack protection data, obtain the average unreasonable packet density when flood attacks occur; Determine whether the unreasonable packet density is greater than or equal to the average unreasonable packet density. If so, the flood attack probability is 1. If not, the ratio of the unreasonable packet density to the average unreasonable packet density is calculated as the flooding attack probability.
[0029] In this embodiment of the application, a sequence of historical message rationality parameters for processing records within a preset time range is obtained, and the preset time range is exemplarily set to 2 hours.
[0030] By combining historical message rationality parameter sequences and message rationality parameters, the proportion of messages with rationality parameters below a preset rationality parameter threshold is statistically analyzed and used as the message irrationality density. For example, if the rationality parameter threshold is set to 85%, then the message irrationality density = number of messages with rationality parameters less than 85% ÷ number of messages in the message rationality parameter sequence. For instance, if there are 15 messages in the message rationality parameter sequence, and 6 of them have rationality parameters less than 85%, then the message irrationality density = 6 ÷ 15 = 0.4.
[0031] Based on network attack protection data over a historical period, the system retrieves unreasonable packet densities from historical logs during multiple flood attacks, calculates the arithmetic mean, and obtains the average unreasonable packet density recorded during flood attacks.
[0032] Based on the unreasonable density of messages, a flood attack probability analysis is performed.
[0033] Determine if the unreasonable packet density is greater than or equal to the average unreasonable packet density. If so, the probability of a flood attack is 1.
[0034] If not, meaning the unreasonable packet density is less than the average unreasonable packet density, then the ratio of the unreasonable packet density to the average unreasonable packet density is calculated as the flood attack probability. For example, when the unreasonable packet density is 0.4 and the average unreasonable packet density is 0.5, the flood attack probability = unreasonable packet density ÷ average unreasonable packet density = 0.4 ÷ 0.5 = 0.8.
[0035] This application introduces a time-series modeling mechanism based on the reasonableness parameter sequence of historical messages. By calculating the unreasonable density, the system can keenly identify the persistent characteristics of attacks and trigger protection in the early stages of an attack. At the same time, it avoids false alarms caused by instantaneous anomalies, significantly improving the real-time early warning and status persistence perception capabilities for covert flood attacks.
[0036] S30: Based on the flood attack probability, perform integrated malicious analysis of the message information to obtain the malicious probability.
[0037] Traditional malware analysis methods employ a fixed structure, which cannot adaptively enhance detection capabilities during periods of high incidence of flood attacks. When attackers launch flood attacks, a single model suffers from limited feature processing bandwidth and a lack of dynamic expansion mechanisms, resulting in key malicious features not being accurately detected. In low-threat scenarios, however, running multiple fixed models in parallel leads to a waste of computing power.
[0038] Step S30 in the method provided in this application embodiment includes: An integrated malicious analyzer is obtained, wherein the integrated malicious analyzer includes multiple malicious analyzers, each of which is constructed using machine learning and trained based on sample packet feature parameters and sample malicious probability. Based on the flood attack probability, a malicious analyzer with the proportion of the flood attack probability is selected in the integrated malicious analyzer. The packet feature parameters are input, and multiple integrated malicious probabilities are obtained by identification and output. Calculate the mean of multiple integrated malicious probabilities to obtain the malicious probability.
[0039] In this embodiment, machine learning is employed to construct multiple malicious analyzers. Each malicious analyzer uses a three-layer structure: the input layer has three nodes that receive three types of packet feature information; the hidden layer has six nodes activated using the ReLU function; and the output layer has one node activated using the Sigmoid function. The output value ranges from 0 to 1, representing a malicious probability. The loss function is binary cross-entropy. Sample packet feature parameters and manually judged sample malicious probabilities are collected. A stochastic gradient descent optimizer is used to supervise the training of the malicious analyzer until the model converges. That is, the malicious analyzer is considered successfully trained when the error of the output malicious probability is within ±0.1. Multiple trained malicious analyzers are then integrated to obtain an integrated malicious analyzer.
[0040] Based on the flood attack probability, a malicious analyzer with a flood attack probability percentage is selected from the integrated malicious analyzer. Packet feature parameters are input, and multiple integrated malicious probabilities are obtained from the output. For example, if the flood attack probability is 0.8 and there are 20 malicious analyzers in the integrated malicious analyzer, then the number of randomly selected malicious analyzers is equal to the flood attack probability multiplied by the total number of malicious analyzers (0.8 × 20 = 16). If the result is not an integer, it is rounded up. The packet feature parameters are then input into these 16 malicious analyzers, resulting in 16 integrated malicious probabilities.
[0041] Calculate the arithmetic mean of the 16 integrated malicious probabilities to obtain the malicious probability.
[0042] Based on the probability of flooding attacks, the participation scale of the integrated analyzer is dynamically adjusted to achieve an adaptive balance between detection accuracy and resource consumption. Under high attack probabilities, more analyzers are invoked to enhance the identification of complex malicious payloads; under low probabilities, the number of models is reduced to ensure efficiency and ensure the system can effectively capture covert malicious behavior while avoiding redundant computational load in low-threat scenarios.
[0043] S40: Based on the malicious probability and flood attack probability, calculate the attack probability and perform protection processing and discrimination on the message information.
[0044] Existing methods sever the coupling relationship between the maliciousness of individual messages and the probability of attacks in the environment, resulting in a mismatch between protection actions and the actual risk level, leading to over-protection or protection delays.
[0045] Step S40 in the method provided in this application embodiment includes: The attack probability is obtained by weighting the malicious probability and the flood attack probability. If the attack probability is greater than or equal to the attack probability threshold, network security protection processing is performed on the message information; otherwise, no protection processing is performed.
[0046] In this embodiment of the application, the attack probability is obtained by weighting the probability of malicious attack and the probability of flooding attack. For example, if the weight of malicious attack probability is set to 0.6 and the weight of flooding attack probability is set to 0.4, then when the probability of malicious attack is 0.6 and the probability of flooding attack is 0.8, the attack probability = malicious attack probability weight × malicious attack probability + flooding attack probability weight × flooding attack probability = 0.6 × 0.6 + 0.8 × 0.4 = 0.68.
[0047] The system determines whether the attack probability is greater than or equal to an attack probability threshold. If so, network security protection is applied to the message; otherwise, no protection is applied. For example, if the attack probability threshold is set to 0.6, then when the attack probability is 0.68, which is greater than the threshold, network security protection is applied to the message. Optionally, the current message can be discarded, an alarm message can be sent to the management terminal, and subsequent connections from the message's source IP can be blocked.
[0048] This application constructs a multi-dimensional risk assessment model for attack probability by weighted fusion of malicious attack probability and flood attack probability. This enables protection judgment to consider both the strength of the malicious characteristics of the packet itself and the macro-level impact of the current network attack situation, achieving rapid interception in high-threat scenarios and tolerance and allowance in low-risk scenarios, thereby improving the attack blocking rate while maximizing business continuity.
[0049] Example 2, as Figure 2 As shown, based on the same inventive concept as the network security protection method for multi-source intelligence data retrieval and fusion provided in Embodiment 1, this embodiment of the invention also provides a network security protection device for multi-source intelligence data retrieval and fusion, comprising: The rationality analysis module 100 is used to acquire message information received by the power system, perform message rationality analysis, and obtain message rationality parameters. The flood attack probability analysis module 200 is used to process and obtain the unreasonable density of packets based on the historical packet rationality parameter sequence within a preset time range, and to perform flood attack probability analysis to obtain the flood attack probability. The malicious probability analysis module 300 is used to perform integrated malicious analysis of the packet information based on the flood attack probability to obtain the malicious probability; The protection discrimination processing module 400 is used to calculate the attack probability based on the malicious probability and the flood attack probability, and to perform protection processing discrimination on the message information.
[0050] In one embodiment, the rationality analysis module 100 is further configured to: Obtain message information received by the power system; Extract the message feature parameters of the message information; The message feature parameters are input into the message rationality analyzer, and the message rationality parameters are output. The message rationality analyzer is trained using the following steps: Based on historical security protection data of the power system, a set of characteristic parameters for sample messages was collected. Based on the proportion of normal messages under the characteristic parameters of each sample message, a set of reasonableness parameters for the sample messages is obtained by labeling. A message rationality analyzer is built based on machine learning. The message rationality analyzer is trained under supervised iterative training until it passes the test using the sample message feature parameter set and the sample message rationality parameter set.
[0051] In one embodiment, the flood attack probability analysis module 200 is further used for: Obtain the sequence of historical message rationality parameters for processing records within a preset time range; Combining the historical message rationality parameter sequence and message rationality parameters, the proportion of message rationality parameters that are less than the preset rationality parameter threshold is statistically analyzed and used as the message unreasonableness density. Based on the unreasonable density of the messages, a flood attack probability analysis is performed to obtain the flood attack probability; Among them, based on the unreasonable density of the messages, a flood attack probability analysis is performed to obtain the flood attack probability, including: Based on historical network attack protection data, obtain the average unreasonable packet density when flood attacks occur; Determine whether the unreasonable packet density is greater than or equal to the average unreasonable packet density. If so, the flood attack probability is 1. If not, the ratio of the unreasonable packet density to the average unreasonable packet density is calculated as the flooding attack probability.
[0052] In one embodiment, the malicious probability analysis module 300 is further configured to: An integrated malicious analyzer is obtained, wherein the integrated malicious analyzer includes multiple malicious analyzers, each of which is constructed using machine learning and trained based on sample packet feature parameters and sample malicious probability. Based on the flood attack probability, a malicious analyzer with the proportion of the flood attack probability is selected in the integrated malicious analyzer. The packet feature parameters are input, and multiple integrated malicious probabilities are obtained by identification and output. Calculate the mean of multiple integrated malicious probabilities to obtain the malicious probability.
[0053] In one embodiment, the protection discrimination processing module 400 is further configured to: The attack probability is obtained by weighting the malicious probability and the flood attack probability. If the attack probability is greater than or equal to the attack probability threshold, network security protection processing is performed on the message information; otherwise, no protection processing is performed.
[0054] In summary, the embodiments of this application have at least the following technical effects: This application proposes a network security protection method and device that integrates multi-source intelligence data retrieval. By dynamically constructing a message rationality analyzer to quantify message credibility, generating attack density features based on historical time-series parameters, and integrating a multi-dimensional malicious analysis model for adaptive weighted discrimination, it significantly improves the early identification accuracy and real-time protection performance of power systems against flooding attacks. Compared to traditional methods, the technical solution provided in this application significantly overcomes the shortcomings of static rules in misjudging masquerading traffic. It utilizes a machine learning-driven rationality parameter analyzer to dynamically assess the compliance of message features, avoiding the misinterpretation of legitimate abnormal messages as malicious attacks. By introducing historical message rationality parameter sequences, it effectively captures the persistence characteristics of attacks, significantly reducing the risk of missed detection of covert flooding attacks. The dynamic selection strategy of integrating a malicious analyzer adaptively adjusts the ratio of analysis models based on real-time attack probabilities, minimizing computational power consumption while maintaining stable malicious behavior identification capabilities. Finally, through weighted fusion calculation of attack probabilities and a threshold discrimination mechanism, it achieves precise control over the timing of protection, avoiding business interruptions caused by excessive interception and triggering protection before the attack behavior causes substantial harm.
[0055] This application achieves the technical effect of improving the accuracy, real-time performance, and adaptability of power system network security protection.
[0056] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0057] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
[0058] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.
Claims
1. A network security protection method for multi-source intelligence data retrieval and fusion, characterized in that, The method includes: Obtain message information received by the power system, perform message rationality analysis, and obtain message rationality parameters; Based on the historical message rationality parameter sequence within a preset time range, the unreasonable message density is obtained, and flood attack probability analysis is performed to obtain the flood attack probability. Based on the flood attack probability, perform integrated malicious analysis of the message information to obtain the malicious probability; Based on the malicious probability and flood attack probability, the attack probability is calculated, and the message information is then protected and judged.
2. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 1, characterized in that, Obtain message information received by the power system, perform message rationality analysis, and obtain message rationality parameters, including: Obtain message information received by the power system; Extract the message feature parameters of the message information; The message feature parameters are input into the message rationality analyzer, and the message rationality parameters are output.
3. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 2, characterized in that, The message rationality analyzer is trained using the following steps: Based on historical security protection data of the power system, a set of characteristic parameters for sample messages was collected. Based on the proportion of normal messages under the characteristic parameters of each sample message, a set of reasonableness parameters for the sample messages is obtained by labeling. A message rationality analyzer is built based on machine learning. The message rationality analyzer is trained under supervised iterative training until it passes the test using the sample message feature parameter set and the sample message rationality parameter set.
4. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 1, characterized in that, Based on the historical packet rationality parameter sequence within a preset time range, the unreasonable packet density is obtained, and flood attack probability analysis is performed to obtain the flood attack probability, including: Obtain the sequence of historical message rationality parameters for processing records within a preset time range; Combining the historical message rationality parameter sequence and message rationality parameters, the proportion of message rationality parameters that are less than the preset rationality parameter threshold is statistically analyzed and used as the message unreasonableness density. Based on the unreasonable density of the messages, a flood attack probability analysis is performed to obtain the flood attack probability.
5. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 4, characterized in that, Based on the unreasonable message density, a flood attack probability analysis is performed to obtain the flood attack probability, including: Based on historical network attack protection data, obtain the average unreasonable packet density when flood attacks occur; Determine whether the unreasonable packet density is greater than or equal to the average unreasonable packet density. If so, the flooding attack probability is 1. If not, the ratio of the unreasonable packet density to the average unreasonable packet density is calculated as the flooding attack probability.
6. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 1, characterized in that, Based on the flooding attack probability, perform integrated malicious analysis of the packet information to obtain the malicious probability, including: An integrated malicious analyzer is obtained, wherein the integrated malicious analyzer includes multiple malicious analyzers, each of which is constructed using machine learning and trained based on sample packet feature parameters and sample malicious probability. Based on the flood attack probability, a malicious analyzer with the proportion of the flood attack probability is selected in the integrated malicious analyzer. The packet feature parameters are input, and multiple integrated malicious probabilities are obtained by identification and output. Calculate the mean of multiple integrated malicious probabilities to obtain the malicious probability.
7. The network security protection method for multi-source intelligence data retrieval and fusion according to claim 1, characterized in that, Based on the aforementioned malicious probability and flood attack probability, an attack probability is calculated, and protective processing and judgment are performed on the message information, including: The attack probability is obtained by weighting the malicious probability and the flood attack probability. If the attack probability is greater than or equal to the attack probability threshold, network security protection processing is performed on the message information; otherwise, no protection processing is performed.
8. A network security protection device for multi-source intelligence data retrieval and fusion, characterized in that, For implementing the network security protection method for multi-source intelligence data retrieval and fusion according to any one of claims 1-7, the apparatus comprises: The rationality analysis module is used to acquire message information received by the power system, perform message rationality analysis, and obtain message rationality parameters; The flood attack probability analysis module is used to process and obtain unreasonable packet density based on the historical packet rationality parameter sequence within a preset time range, and perform flood attack probability analysis to obtain the flood attack probability. The malicious probability analysis module is used to perform integrated malicious analysis of the packet information based on the flood attack probability to obtain the malicious probability; The protection discrimination processing module is used to calculate the attack probability based on the malicious probability and flood attack probability, and to perform protection processing discrimination on the message information.