A method and system for identifying power access device anomalies by fusing feature deviation and temporal constraints

By constructing a digital twin of network behavior in the power cloud edge system, integrating feature deviation and time-series constraint checks, and adopting a twin neural network model, the problem that existing power access equipment security management methods cannot identify abnormal behavior in real time on edge agent devices is solved, achieving high-precision and low-overhead anomaly identification and handling.

CN121547294BActive Publication Date: 2026-03-27HUNAN KUANGAN NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-19
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing security management methods for power access equipment cannot effectively identify abnormal behavior of counterfeit or attacked devices, and have high computational overhead, making it difficult to achieve real-time detection on edge agent devices. Furthermore, the lack of unified modeling and quantitative analysis of the time-series relationships of power services leads to a disconnect between anomaly identification results and access management and handling.

Method used

By constructing a digital twin of network behavior on the device side, integrating feature deviation analysis and business timing constraint checks, and adopting a feature prediction model with a twin neural network architecture, the deviation between real-time observed features and expected features is calculated, and weighted fusion judgment is performed in combination with timing violation degree to achieve real-time identification and blocking of abnormal sessions.

Benefits of technology

It enhances the ability to identify counterfeit devices and abnormal behavior of attacked devices, reduces computational overhead, and achieves systematic identification of timing anomalies such as disordered business processes and premature or delayed control commands. It forms a closed-loop mechanism for detection, handling, and model evolution, meeting the real-time and security compliance requirements of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121547294B_ABST
    Figure CN121547294B_ABST
Patent Text Reader

Abstract

The application discloses a power access equipment anomaly identification method fusing feature deviation and timing constraints, which solves the problem that detection accuracy and real-time performance are difficult to be considered together under the condition of limited edge computing power by constructing a device-side network behavior digital twin on the edge proxy device in the power cloud edge system. Specifically, the method calculates the feature deviation between the actual behavior and the expected behavior; at the same time, the relative time difference-based service timing constraint is introduced. By fusing the feature deviation and the timing violation degree, the application can identify the abnormal behavior of malicious access equipment or attacked equipment in real time at the edge, and perform instant blocking and session control on the main service path, so as to realize the identification ability of high accuracy, high real-time and sustainable evolution of the abnormal behavior of the access layer equipment under the premise of meeting the real-time performance and safety compliance requirements of the power system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the field of power system network security and edge computing technology, and more particularly relates to a power access device anomaly identification method and system fusing feature deviation and timing constraints. BACKGROUND

[0002] With the development of new power systems and energy internet, a power cloud edge system is gradually formed, that is, a power cloud platform is responsible for centralized business processing and large-scale data analysis, and an edge proxy device is deployed at a substation, a distribution station, a ring network cabinet or a user side site, etc. to be responsible for the access of power terminal devices, protocol adaptation and part of edge computing tasks.

[0003] Under the above architecture, a large number of power terminal devices (such as protection and control devices, remote terminal units, smart meters, and distribution automation terminals) access the business network through the edge proxy device; these power terminal devices, as power access devices, have limited resources, long update cycles, and limited security protection capabilities; on the other hand, power business protocols (such as IEC61850, IEC60870-5-104, etc.) emphasize real-time and interoperability in design, and their security mechanisms are relatively weak; attackers can affect power control strategies and monitoring data by means of forging terminal devices, hijacking legitimate devices or injecting malicious messages, thereby threatening the safe and stable operation of the power system.

[0004] The existing power access device security management and control methods mainly include the following:

[0005] One is a power access device security management and control strategy based on a static white list or an access control list (Access Control List, abbreviated as ACL), which only filters device identity and IP / port network attributes; the second is a power access device security management and control strategy based on traffic statistical features or traditional anomaly detection algorithms, which relies on shallow statistical features such as message quantity, rate, connection frequency, or uses threshold judgment, simple classification, clustering, etc. Traditional detection models realize power access device security management and control.

[0006] However, the above two power access device security management and control methods have some defects that cannot be ignored:

[0007] (1) The above power access device security management and control strategy based on a static white list or an access control list only determines access according to device identity information or IP, port, etc. network attributes, lacks dynamic characterization ability of device communication behavior and business semantics, and therefore can only realize static and coarse-grained access control, and it is difficult to identify abnormal behaviors of fake devices or attacked devices at the business level in a timely manner;

[0008] (2) The power access device security management and control strategy realized based on the traffic statistical characteristics or the traditional anomaly detection algorithm has limited identification capability for the traffic with legal format but abnormal behavior, because it mainly focuses on the shallow statistical characteristics such as the number of messages and the rate, and does not combine the state changes and behavior patterns of the power service protocol; meanwhile, the calculation cost of some schemes introducing complex models is large, and it is difficult to realize real-time detection on the edge proxy device with limited computing power;

[0009] (3) The above two power access device security management and control schemes lack unified modeling and quantitative analysis of the time sequence relationship of the power service, and often rely on scattered rules or simple time thresholds for judgment, so it is difficult to systematically identify time sequence abnormal behaviors such as disorder of service flow, advance or delay of control instruction, and the abnormal identification result is disconnected with the access management and control disposal, and it is difficult to form a closed loop mechanism of rapid response and continuous evolution. SUMMARY

[0010] In view of the above defects or improvement needs of the prior art, the present application provides a power access device anomaly identification method and system fusing feature deviation and time sequence constraint, which aims to construct a device side network behavior digital twin, and fuse feature deviation degree analysis and service time sequence constraint check, to reduce the edge computing cost while ensuring the detection accuracy and explainability, realize real-time identification and localization disposal of abnormal access devices, thereby solving the technical problems that the existing power access device security management and control strategy realized based on static white list or access control list can only realize static and coarse-grained access control, and cannot identify abnormal behaviors of fake devices or attacked devices at the service level in a timely manner, because it only determines access according to device identity information or IP, port and other network attributes, and lacks dynamic description capability of device communication behavior and service semantics; the technical problems that the power access device security management and control strategy realized based on traffic statistical characteristics or traditional anomaly detection algorithm has limited identification capability for the traffic with legal format but abnormal behavior, because it mainly focuses on the shallow statistical characteristics such as the number of messages and the rate, and does not combine the state changes and behavior patterns of the power service protocol; meanwhile, the calculation cost of some schemes introducing complex models is large, and it is difficult to realize real-time detection on the edge proxy device with limited computing power; and the technical problems that the existing two power access device security management and control schemes lack unified modeling and quantitative analysis of the time sequence relationship of the power service, and often rely on scattered rules or simple time thresholds for judgment, so it is difficult to systematically identify time sequence abnormal behaviors such as disorder of service flow, advance or delay of control instruction, and the abnormal identification result is disconnected with the access management and control disposal, and it is difficult to form a closed loop mechanism of rapid response and continuous evolution.

[0011] To achieve the above object, according to one aspect of the present application, a power access equipment anomaly identification method fusing feature deviation and timing constraint is provided, which is applied to a side-end proxy device in a power cloud side-end system, and comprises the following steps:

[0012] (1) Obtain the communication traffic of the power equipment, perform protocol analysis on the obtained communication traffic to obtain a plurality of application layer protocol messages, and a five-tuple composed of a source IP address, a destination IP address, a source port number, a destination port number and a transmission layer protocol corresponding to each application layer protocol message in the application layer protocol message;

[0013] (2) Obtain a current application layer protocol message from all the application layer protocol messages obtained in step (1), and perform feature extraction on the current application layer protocol message to obtain a corresponding real-time observation feature vector and construct a timing feature sequence corresponding to the real-time observation feature vector;

[0014] (3) Input the timing feature sequence obtained in step (2) into two pre-trained feature prediction models and respectively to obtain corresponding expected feature vectors and respectively, calculate the feature deviation degrees and between the real-time observation feature vector obtained in step (2) and the two expected feature vectors respectively, and determine whether the feature deviation degrees and are both greater than a preset feature deviation threshold If yes, it means that the logical session corresponding to the current application layer protocol message has feature deviation, and the average value of the two feature deviation degrees is calculated as the final feature deviation degree Then go to step (4), otherwise set the final feature deviation degree to zero, and then go to step (4);

[0015] (4) Extract the key business events contained in the current application layer protocol message obtained in step (2) and the corresponding time, and obtain the timing violation degree of the current application layer protocol message according to the key business events and the corresponding time;

[0016] (5) Perform weighted fusion processing on the final feature deviation degree obtained in step (3) and the timing violation degree of the current application layer protocol message obtained in step (4) to obtain a comprehensive anomaly score , and determine whether the comprehensive anomaly score exceeds a preset comprehensive threshold If so, it means the current session is an abnormal session, and then proceed to step (6); otherwise, it means the current session is a normal session, and then the process ends.

[0017] (6) Control the edge agent device to perform blocking processing on abnormal sessions in order to terminate the data forwarding of abnormal sessions and cut off the session path between the abnormal session and the power equipment corresponding to the abnormal session;

[0018] (7) The real-time observation feature vector corresponding to the application layer protocol message of the abnormal session. Time-series characteristic sequences Final feature deviation Timing violation degree Stored in the local anomaly sample database.

[0019] Preferably, step (2) specifically includes the following sub-steps:

[0020] (2-1) Extract categorical features, numerical features, key business events and their corresponding times from application layer protocol messages;

[0021] (2-2) Use one-hot encoding to encode the categorical features extracted in step (2-1) to obtain the categorical feature vector, and normalize the numerical features extracted in step (2-1). Combine the categorical feature vector with the normalized numerical features to obtain the normalized real-time observation feature vector. ;

[0022] (2-3) Based on the quintuple corresponding to the application layer protocol message, the real-time observation feature vector corresponding to the current application layer protocol message obtained in step (2-2) is transformed. Associate it with the corresponding logical session stream and update the context state of that logical session stream to obtain the updated logical session stream;

[0023] (2-4) Construct real-time observation feature vectors based on the updated logical session flow obtained in step (2-3). Corresponding time-series feature sequences And determine whether the number of historical application layer protocol messages associated in the updated logical session stream is greater than or equal to 1. If so, then retrieve the current application layer protocol message from the updated logical session stream. The time-series feature sequence formed by multiple feature vectors corresponding to each message Then the process ends; otherwise, the time-series feature sequence is obtained by retrieving the sequence of features formed by multiple feature vectors corresponding to all existing application layer protocol messages in the updated logical session stream. Then the process ends; where the length of the time-series feature sequence is... is in the range of 3 to 10, t represents the time sequence index of the current application layer protocol message in the corresponding logical session flow, represents the feature vector corresponding to the application layer protocol message before the current application layer protocol message in the updated logical session flow.

[0024] Preferably, the categorical feature refers to a discrete attribute representing the behavior of a message or a service, including message type, function code, service type, and operation instruction category;

[0025] The numerical feature refers to a continuous attribute representing the behavior of a message or a session, including field length, data size, and time interval between request and response.

[0026] The key service event refers to an operation node with clear business semantics in the business process, including session establishment, parameter delivery, state query, control instruction execution, and parameter upload.

[0027] The logical session flow is used to represent the continuous communication behavior generated by the same power device in a business interaction process, and its context state includes the sequence of feature vectors associated with the session and the corresponding time sequence information. When associating the real-time observation feature vector with the logical session flow, the real-time observation feature vector is appended to the logical session flow according to the application layer protocol message arrival order, and the latest time index recorded in the logical session flow is updated synchronously.

[0028] Preferably, in step (3), the feature deviation degree between the real-time observation feature vector obtained in step (2) and the two expected feature vectors is calculated and The formula is as follows:

[0029] ;

[0030] ;

[0031] Wherein represents the Euclidean distance; the value range of the feature deviation threshold is 0.7 to 1.0.

[0032] Preferably, step (4) is specifically,

[0033] Firstly, the session to which the current application layer protocol message belongs is determined as the current session; the key service event contained in the current application layer protocol message is extracted, and the key service event is taken as a post-event to search for a plurality of key service event pairs matched with the key service event in the pre-constructed business time sequence constraint library; each key service event pair , wherein denotes the preceding event in the pair of key business events, denotes the succeeding event in the pair of key business events, denotes the lower bound of the allowed time window of the pair of key business events in the business timing constraint library, denotes the upper bound of the allowed time window of the pair of key business events in the business timing constraint library; then, for each matched pair of key business events, it is determined whether the preceding event in the pair of key business events occurs in the current session, and if yes, the time interval between the latest occurrence time of the preceding event in the current session and the latest occurrence time of the succeeding event in the current session is calculated, otherwise, the pair of key business events is skipped and does not participate in subsequent calculation.

[0034] Subsequently, for each pair of key business events participating in the calculation of the time interval, the time interval of the pair of key business events is compared with the corresponding allowed time window of the pair of key business events in the business timing constraint library , and the timing violation degree corresponding to the pair of key business events is obtained according to the comparison result :

[0035] ;

[0036] Finally, the timing violation degrees corresponding to all matched pairs of key business events are aggregated to obtain the timing violation degree corresponding to the current application layer protocol message .

[0037] Preferably, the comprehensive abnormality score is obtained by using the following formula:

[0038] ;

[0039] wherein and are preset non-negative weight coefficients, and satisfy , and the value range of the comprehensive threshold is 0.6 to 1.0.

[0040] Preferably, the two feature prediction models and ​​​The two feature prediction models are constructed using a twin neural network architecture. The network structures of the two feature prediction models are the same, but the model parameters are independent and not shared. The core of the sub-network corresponding to each feature prediction model is a temporal feature processing network, which is used to model and learn the temporal features in the session context. Preferably, the temporal feature processing network adopts a long short-term memory network LSTM.

[0041] Preferably, two feature prediction models and It was obtained through the following training steps:

[0042] (3-1) Obtain historical normal communication traffic data for multiple types of power equipment and their corresponding data. Perform protocol parsing on the obtained historical normal communication traffic data to obtain the five-tuples and application layer protocol messages in the communication traffic data. Divide the obtained application layer protocol messages into multiple complete business logic sessions based on the five-tuples. Extract message feature vectors from each business logic session in the order of arrival of application layer protocol messages within that session. All extracted message feature vectors constitute the time-series feature vector sequence corresponding to that business logic session. ,in This indicates the first [number] session in the business logic session. The feature vectors corresponding to each application layer protocol message, where T represents the total number of message feature vectors in the time-series feature vector sequence, and t∈[1,T];

[0043] (3-2) Construct a dataset from all the time-series feature vector sequences corresponding to all business logic sessions obtained in step (3-1), and divide the dataset into training set, validation set and test set in a ratio of 6:3:1;

[0044] (3-3) For each input sample in the training set obtained in step (3-2), input the input sample into the feature prediction model respectively. and To obtain the first expected feature vector corresponding to the input sample respectively. With the second expected eigenvector ;

[0045] (3-4) For each input sample in the training set obtained in step (3-2), based on the first expected feature vector corresponding to that input sample obtained in step (3-3) With the second expected eigenvector Obtain the loss value of the prediction model for each feature;

[0046] (3-5) Based on the loss value obtained in step (3-4), the two feature prediction models are iteratively trained using the stochastic gradient descent algorithm until the two feature prediction models reach the preset number of iterations or the loss value on the validation set tends to stabilize and no longer decreases significantly. The optimal parameters of the two feature prediction models at this time are obtained, thus obtaining the two feature prediction models that have been initially trained.

[0047] (3-6) Use the test set obtained in step (3-1) to test the two pre-trained feature prediction models obtained in step (3-5) to obtain the two final trained feature prediction models.

[0048] Preferably, in step (3-4), the root mean square loss function is used as the loss function to measure the difference between the predicted features and the target output of the input sample. The specific loss value is as follows:

[0049] ;

[0050] in This represents the target output of the input sample.

[0051] According to another aspect of the present invention, a power access device anomaly identification system integrating feature deviation and timing constraints is provided. This system is an edge proxy device applied in a power cloud edge-end system. The power access device anomaly identification system includes the following modules:

[0052] The first module is used to acquire the communication traffic of the power equipment, perform protocol parsing on the acquired communication traffic to obtain multiple application layer protocol messages, and the five-tuple corresponding to the application layer protocol message composed of the source IP address, destination IP address, source port number, destination port number, and transport layer protocol in each application layer protocol message.

[0053] The second module is used to obtain the current application layer protocol message from all application layer protocol messages obtained from the first module, and to extract features from the current application layer protocol message to obtain the corresponding real-time observation feature vector, and to construct the time-series feature sequence corresponding to the real-time observation feature vector.

[0054] The third module is used to process the time-series feature sequences obtained from the second module. Input the two pre-trained feature prediction models respectively and To obtain the corresponding expected feature vectors respectively. and The feature deviation between the real-time observed feature vector obtained from the second module and the two expected feature vectors is calculated respectively. and And determine the feature deviation. whether all are greater than a preset feature deviation threshold whether all are greater than a preset feature deviation threshold If yes, it indicates that the logical session corresponding to the current application layer protocol message occurs feature deviation, and the average value of the two feature deviation degrees is calculated as the final feature deviation degree Then, the process enters the fourth module, otherwise, the final feature deviation degree is set to zero, and then the process enters the fourth module Then, the process enters the fourth module, otherwise, the final feature deviation degree is set to zero, and then the process enters the fourth module

[0055] The fourth module is configured to extract the key business event contained in the current application layer protocol message obtained by the second module and the corresponding time, and obtain the timing violation degree of the current application layer protocol message according to the key business event and the corresponding time

[0056] The fifth module is configured to perform weighted fusion processing on the final feature deviation degree obtained by the third module and the timing violation degree of the current application layer protocol message obtained by the fourth module, to obtain a comprehensive abnormal score The fifth module is configured to perform weighted fusion processing on the final feature deviation degree obtained by the third module and the timing violation degree of the current application layer protocol message obtained by the fourth module, to obtain a comprehensive abnormal score The fifth module is configured to perform weighted fusion processing on the final feature deviation degree obtained by the third module and the timing violation degree of the current application layer protocol message obtained by the fourth module, to obtain a comprehensive abnormal score The fifth module is configured to perform weighted fusion processing on the final feature deviation degree obtained by the third module and the timing violation degree of the current application layer protocol message obtained by the fourth module, to obtain a comprehensive abnormal score The fifth module is configured to perform weighted fusion processing on the final feature deviation degree obtained by the third module and the timing violation degree of the current application layer protocol message obtained by the fourth module, to obtain a comprehensive abnormal score If yes, it indicates that the current session is an abnormal session, and then the process enters the sixth module, otherwise, it indicates that the current session is a normal session, and then the process ends

[0057] The sixth module is configured to control the edge-end proxy device to perform blocking processing on the abnormal session, to terminate data forwarding of the abnormal session, and cut off the session path between the power equipment corresponding to the abnormal session

[0058] The seventh module is configured to store the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session, the timing feature sequence, the final feature deviation degree, and the timing violation degree into a local abnormal sample library The seventh module is configured to store the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session, the timing feature sequence, the final feature deviation degree, and the timing violation degree into a local abnormal sample library The seventh module is configured to store the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session, the timing feature sequence, the final feature deviation degree, and the timing violation degree into a local abnormal sample library The seventh module is configured to store the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session, the timing feature sequence, the final feature deviation degree, and the timing violation degree into a local abnormal sample library The seventh module is configured to store the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session, the timing feature sequence, the final feature deviation degree, and the timing violation degree into a local abnormal sample library

[0059] Overall, compared with the prior art, the above technical solutions of the present application can achieve the following beneficial effects:

[0060] 1. The present application realizes dynamic abnormality identification based on actual business behavior by performing protocol analysis, session reconstruction and multi-dimensional feature extraction on the communication traffic of the power access equipment through steps (1) and (2), and constructs a device-side network behavior model in units of logical sessions, thereby effectively improving the identification ability of abnormal behavior of counterfeit devices and attacked devices

[0061] 2、The application introduces a feature prediction model based on a time sequence feature sequence through step (3), calculates the feature deviation between real-time observation features and expected features, and combines low-dimensional projection and a double-model consistency determination mechanism, thereby significantly reducing the calculation overhead while ensuring detection accuracy and robustness, and meeting the real-time detection needs of edge proxy devices;

[0062] 3、The application constructs a business time sequence constraint library through step (4), and calculates a normalized time sequence violation degree based on the relative time relationship between key business events, thereby realizing systematic identification of time sequence abnormalities such as business process disorder, control instruction advance or delay, and combining with the feature deviation in step (5), thereby improving the comprehensiveness and accuracy of abnormal identification;

[0063] 4、The application realizes real-time blocking of abnormal sessions and structured storage of abnormal samples at the edge through steps (6) and (7), forms a closed-loop mechanism combining detection, disposal and model evolution, and can be deployed in the power cloud edge system without changing the existing power terminal device, thereby having good engineering implementability, scalability and promotion value. BRIEF DESCRIPTION OF DRAWINGS

[0064] Figure 1 is a flowchart of the power access device abnormality identification method of the application. DETAILED DESCRIPTION

[0065] In order to make the purpose, technical scheme and advantages of the application clearer, the application is further described in detail below in combination with the drawings and examples. It should be understood that the specific examples described herein are only used to explain the application, and are not used to limit the application. In addition, the technical features involved in each embodiment of the application described below can be combined with each other as long as they do not conflict with each other.

[0066] It should be noted that in the description of the embodiments of the present application, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, article or apparatus that includes a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, article or apparatus comprising the element. The terms "upper", "lower" and the like indicate the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. For those of ordinary skill in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0067] In addition, the technical solutions of various embodiments of the present application can be combined with each other, but it must be based on the fact that a person of ordinary skill in the art can realize it, and when the combination of technical solutions appears contradictory or unachievable, it should be considered that the combination of technical solutions does not exist, nor is it within the scope of protection required by the present application.

[0068] The basic idea of the present application is to provide a power access device anomaly recognition method fusing feature deviation and timing constraint, which solves the problem that detection accuracy and real-time performance are difficult to balance under the condition of limited edge computing power in access device anomaly recognition by constructing a device side network behavior digital twin on the edge proxy device in the power cloud edge system. Specifically, the method calculates the feature deviation between the actual behavior and the expected behavior; at the same time, introduces a business timing constraint based on relative time difference. By fusing the feature deviation and the timing violation degree, the present application can identify the abnormal behavior of malicious access devices or attacked devices in real time at the edge, and perform immediate blocking and session control on the main business path, thereby realizing high-precision, high-real-time and sustainable evolution of the identification ability of access layer device abnormal behavior under the premise of meeting the real-time and security compliance requirements of the power system.

[0069] As shown in Figure 1 The present application provides a power access device anomaly recognition method fusing feature deviation and timing constraint, which is applied to an edge proxy device in a power cloud edge system, and the method comprises the following steps:

[0070] (1) Obtain the communication traffic of the power equipment, perform protocol analysis on the obtained communication traffic to obtain a plurality of application layer protocol messages, and a five-tuple composed of a source IP address, a destination IP address, a source port number, a destination port number, and a transport layer protocol corresponding to each application layer protocol message;

[0071] The advantage of this step (1) is that the five-tuple information is extracted through protocol analysis, providing a structured input data basis for subsequent session association and feature extraction, ensuring traceability of traffic and reconstruction of sessions.

[0072] (2) Obtain a current application layer protocol message from all application layer protocol messages obtained in step (1), and perform feature extraction on the current application layer protocol message to obtain a corresponding real-time observation feature vector and construct a time sequence feature sequence corresponding to the real-time observation feature vector;

[0073] Specifically, the current application layer protocol message refers to the application layer protocol message currently being processed;

[0074] This step specifically includes the following sub-steps:

[0075] (2-1) Extract category type features, numerical type features, and corresponding times of key business events in the application layer protocol message;

[0076] Specifically, the category type features refer to discrete attributes representing messages or business behaviors, including but not limited to message types, function codes, service types, operation instruction types, etc. The numerical type features refer to continuous attributes representing messages or session behaviors, including but not limited to field lengths, data sizes, time intervals between requests and responses, etc. The key business events refer to operation nodes with clear business semantics in the business process, including but not limited to session establishment, parameter issuance, state query, control instruction execution, parameter upload, etc.

[0077] (2-2) Encode the category type features extracted in step (2-1) using one-hot encoding to obtain a category feature vector, and normalize the numerical type features extracted in step (2-1). Combine the category feature vector and the normalized numerical type features to obtain a normalized real-time observation feature vector ;

[0078] (2-3) According to the five-tuple corresponding to the application layer protocol message, associate the real-time observation feature vector corresponding to the current application layer protocol message obtained in step (2-2) to the corresponding logical session flow, and update the context state of the logical session flow to obtain an updated logical session flow;

[0079] ​Specifically, the logical session flow is used to represent the continuous communication behavior of the same power device in a service interaction process, and the context state thereof includes a sequence of feature vectors associated with the session and corresponding time sequence information; when associating the real-time observation feature vector with the logical session flow, the real-time observation feature vector is appended to the logical session flow in the order of arrival of the application layer protocol message, and the latest time index recorded in the logical session flow is updated synchronously.

[0080] (2-4) constructing a real-time observation feature vector according to the updated logical session flow obtained in step (2-3) a corresponding time sequence feature sequence , and determining whether the number of historical application layer protocol messages associated in the updated logical session flow is greater than or equal to If yes, a time sequence feature sequence composed of a plurality of feature vectors corresponding to the last messages before the current application layer protocol message in the updated logical session flow is obtained , and the process ends, otherwise a time sequence feature sequence composed of a plurality of feature vectors corresponding to all the existing application layer protocol messages in the updated logical session flow is obtained , and the process ends; wherein the length of the time sequence feature sequence is in the range of 3 to 10, t represents the time sequence index of the current application layer protocol message in the corresponding logical session flow, represents the feature vector corresponding to the application layer protocol message before the current application layer protocol message in the updated logical session flow.

[0081] The above sub-steps (2-1) to (2-4) have the advantages of realizing the complete conversion process from the original message to the structured time sequence feature sequence, and providing high-quality, time sequence aligned input data for subsequent feature deviation prediction and time sequence constraint checking.

[0082] (3) inputting the time sequence feature sequence obtained in step (2) into two pre-trained feature prediction models and respectively to obtain corresponding expected feature vectors and respectively, calculating the feature deviation degrees and between the real-time observation feature vector obtained in step (2) and the two expected feature vectors respectively, and determining whether the feature deviation degrees and are both greater than a preset feature deviation threshold If so, it indicates that the logical session corresponding to the current application layer protocol message has deviated from its characteristics, and the average of the two characteristic deviations is calculated as the final characteristic deviation. Then proceed to step (4), otherwise set the final feature deviation. The result is zero, then proceed to step (4);

[0083] In this step, the feature deviation between the real-time observed feature vector obtained in step (2) and the two expected feature vectors is calculated. and The following formula is used:

[0084] ;

[0085] ;

[0086] in Indicates Euclidean distance. Feature deviation threshold. The value range is from 0.7 to 1.0, with 0.85 being preferred.

[0087] The advantage of this step (3) is that by using the dual-model independent prediction and consistency judgment mechanism, the robustness of feature deviation detection is effectively improved, the risk of misjudgment or overfitting of a single model is reduced, and by using threshold comparison and average calculation, the sensitive capture and quantification of subtle behavioral anomalies are achieved.

[0088] (4) Extract the key business events and their corresponding times contained in the current application layer protocol message obtained in step (2), and obtain the timing violation degree of the current application layer protocol message based on the key business events and their corresponding times;

[0089] Specifically, this step involves: first, identifying the session to which the current application layer protocol message belongs as the current session; extracting key business events contained in the current application layer protocol message, and using these key business events as follow-up events; retrieving multiple key business event pairs matching these key business events from a pre-built business timing constraint library; and then, for each key business event pair... ,in This refers to the preceding events in a key business event pair. This indicates a subsequent event in a critical business event pair. This indicates the lower bound of the allowed time window for critical business events in the business timing constraint library. This represents the upper bound of the allowed time window for key business event pairs in the business timing constraint library; then, for each matched key business event pair, it is determined whether the preceding event occurs in the current session. If so, the preceding event in the key business event pair is calculated. The most recent occurrence time in the current session and the post-event the latest occurrence time in the current logical session the time interval between , otherwise skip this key business event pair and do not participate in subsequent calculation;

[0090] The business timing constraint library in the application is constructed based on business specification documents and expert experience knowledge, and the timing constraint relationship between key business events is summarized by analyzing a normal business sample set to form a business timing constraint library. Each constraint rule in the business timing constraint library is stored in the form of a quadruple .

[0091] Subsequently, for each key business event pair participating in the above time interval calculation, the time interval of the key business event pair is compared with the corresponding allowed time window of the key business event pair in the business timing constraint library, and the corresponding timing violation degree of the key business event pair is obtained according to the comparison result:

[0092] ;

[0093] When the post-event occurs within the allowed time window, it is determined that the timing violation degree of the key business event pair is zero. When the post-event exceeds the allowed time window, the time deviation between the post-event and the time window boundary is calculated, and the greater the time deviation, the greater the timing violation degree.

[0094] Finally, the timing violation degrees of all matched key business event pairs are aggregated to obtain the timing violation degree of the current application layer protocol message.

[0095] Preferably, the aggregation processing in the above process adopts a maximum value or average value strategy.

[0096] The advantage of this step (4) is that by searching the business timing constraint library and calculating the normalized timing violation degree, the abnormal degree of the message in the business logic order and the time interval can be quantitatively and systematically calculated, and the attack behaviors such as timing disorder, replay, delay or advance which cannot be found by traditional feature detection can be effectively identified.

[0097] (5) The final feature deviation degree obtained in step (3) is weighted and fused with the timing violation degree of the current application layer protocol message obtained in step (4) to obtain a comprehensive abnormal score , and it is judged whether the comprehensive abnormal score exceeds a preset comprehensive threshold If so, it means the current session is an abnormal session, and then proceed to step (6); otherwise, it means the current session is a normal session, and then the process ends.

[0098] Specifically, obtaining a comprehensive anomaly score The following formula is used:

[0099] ;

[0100] in and The pre-defined non-negative weight coefficients satisfy the following conditions: The preferred value is , Comprehensive threshold The value range is from 0.6 to 1.0, with 0.8 being preferred.

[0101] The advantage of this step (5) is that by weighted fusion of feature deviation and temporal violation, a comprehensive evaluation of multi-dimensional abnormal evidence is achieved, taking into account the subtle differences in behavioral patterns and the temporal compliance of business logic, thereby improving the accuracy and comprehensiveness of abnormal judgment.

[0102] The advantage of the above steps (1) to (5) is that they together constitute a complete and collaborative anomaly detection pipeline, realizing end-to-end processing from traffic analysis, feature extraction, behavior prediction, timing check to comprehensive judgment, ensuring the efficiency, interpretability and high accuracy of the detection process.

[0103] (6) Control the edge agent device to perform blocking processing on abnormal sessions to terminate the data forwarding of abnormal sessions and cut off the session path between the abnormal session and the power equipment corresponding to the abnormal session.

[0104] The advantage of this step (6) is that it realizes a real-time closed loop of detection and handling, can quickly block abnormal sessions locally at the edge, effectively curb the spread of attacks, and meet the requirements of the power system for immediate response to security events.

[0105] (7) The real-time observation feature vector corresponding to the application layer protocol message of the abnormal session. Time-series characteristic sequences Final feature deviation Timing violation degree Stored in the local anomaly sample database.

[0106] The advantage of this step (7) is that by storing abnormal samples and related measurement data in a structured manner, it provides a high-quality data foundation for subsequent model optimization, rule base updates and attack analysis, supporting the continuous evolution of the system and the improvement of its adaptive capabilities.

[0107] Specifically, the two feature prediction models in the application and are constructed by adopting a twin neural network architecture, and the network structures of the two feature prediction models are the same but the model parameters are independent of each other and are not shared. The core of the subnetwork corresponding to each feature prediction model is a time sequence feature processing network, which is used to model and learn the time sequence features in the session context. Preferably, the time sequence feature processing network adopts a long short-term memory network (LSTM for short).

[0108] The two feature prediction models in the application and are trained by the following steps:

[0109] (3-1) Obtain a plurality of types of power equipment and their corresponding historical normal communication traffic data, perform protocol analysis on the obtained historical normal communication traffic data to obtain the five-tuple (including source IP address, destination IP address, source port number, destination port number, and transport layer protocol) and application layer protocol message in the communication traffic data, and divide the obtained application layer protocol message into a plurality of complete business logic sessions (each business logic session is used to represent a complete normal business interaction process) according to the five-tuple, and sequentially extract message feature vectors from the business logic session according to the arrival order of the application layer protocol messages in the business logic session, and all extracted message feature vectors constitute a time sequence feature vector sequence corresponding to the business logic session , wherein represents the feature vector corresponding to the t-th application layer protocol message in the business logic session, T represents the total number of message feature vectors in the time sequence feature vector sequence, and t∈[1, T].

[0110] (3-2) Construct all time sequence feature vector sequences corresponding to all business logic sessions obtained in step (3-1) into a data set, and divide the data set into a training set, a validation set and a test set according to a ratio of 6:3:1;

[0111] Specifically, the division is carried out in units of sessions to ensure that all data of the same session only appears in one set to maintain the time sequence independence. For the data in each set after division, input samples of the two feature prediction models are further constructed. The specific method is as follows: for the time sequence feature vector sequence , a standard sample is constructed by adopting a sliding time window method. The window length is set to , and the next feature vectors are selected as an input sample, and the next adjacent feature vector ​The target output of the input sample. Slide the window sequentially until the end of the sequence, thereby generating multiple time-series training samples within the same session.

[0112] (3-3) For each input sample in the training set obtained in step (3-2), input the input sample into the feature prediction model and respectively to obtain the first expected feature vector and the second expected feature vector corresponding to the input sample respectively;

[0113] (3-4) For each input sample in the training set obtained in step (3-2), obtain the loss value of each feature prediction model according to the first expected feature vector and the second expected feature vector corresponding to the input sample obtained in step (3-3);

[0114] In this step, the root mean square loss function is used as the loss function to measure the difference between the predicted features and the target output of the input sample. The loss value is specifically:

[0115] ;

[0116] Wherein represents the target output of the input sample.

[0117] The purpose of this step is to enable the feature prediction model to learn the ability to accurately predict future normal features based on historical session context.

[0118] (3-5) Based on the loss value obtained in step (3-4), use the stochastic gradient descent algorithm to iteratively train the two feature prediction models until the two feature prediction models respectively reach a preset number of iterations (in this case, 100 times) or the loss value on the validation set tends to be stable and no longer significantly decreases, and obtain the optimal parameters of the two feature prediction models at this time, thereby obtaining two feature prediction models that are preliminarily trained.

[0119] (3-6) Use the test set obtained in step (3-1) to test the two feature prediction models that are preliminarily trained in step (3-5) to obtain two feature prediction models that are finally trained.

[0120] The advantages of the above sub-steps (3-1) to (3-6) are that a method based on historical normal traffic, session-based, using sliding window and double independent model training is constructed, which ensures that the feature prediction model can accurately learn the time-series behavior pattern of the power equipment in normal business interaction, and provides a highly reliable behavior prediction benchmark for the online detection stage.

[0121] The application realizes real-time identification and localization disposal of abnormal access equipment by constructing a device side network behavior digital twin, and fusing feature deviation degree analysis and business timing constraint checking, while ensuring detection accuracy and explainability, reducing edge computing overhead.

[0122] Those skilled in the art will easily understand that the above description is only the preferred embodiment of the present application, and is not intended to limit the present application, and any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for identifying anomalies in power access equipment by integrating feature deviation and timing constraints, applied to edge agent devices in a power cloud edge-end system, characterized in that... The method for identifying anomalies in power access equipment includes the following steps: (1) Obtain the communication traffic of the power equipment, perform protocol parsing on the obtained communication traffic to obtain multiple application layer protocol messages, and the five-tuple corresponding to the application layer protocol message composed of the source IP address, destination IP address, source port number, destination port number, and transport layer protocol in each application layer protocol message; (2) Obtain the current application layer protocol message from all application layer protocol messages obtained in step (1), and extract features from the current application layer protocol message to obtain the corresponding real-time observation feature vector, and construct the time-series feature sequence corresponding to the real-time observation feature vector; (3) The time series feature sequence obtained in step (2) Input the two pre-trained feature prediction models respectively and To obtain the corresponding expected feature vectors respectively. and Calculate the feature deviation between the real-time observed feature vector obtained in step (2) and the two expected feature vectors respectively. and And determine the feature deviation. and Are they all greater than the preset feature deviation threshold? If so, it indicates that the logical session corresponding to the current application layer protocol message has deviated from its characteristics, and the average of the two characteristic deviations is calculated as the final characteristic deviation. Then proceed to step (4), otherwise set the final feature deviation. The result is zero, then proceed to step (4); (4) Extract the key business events and their corresponding times contained in the current application layer protocol message obtained in step (2), and obtain the timing violation degree of the current application layer protocol message based on the key business events and their corresponding times; step (4) specifically involves, First, the session to which the current application layer protocol message belongs is identified as the current session; key business events contained in the current application layer protocol message are extracted, and these key business events are used as follow-up events. Multiple key business event pairs matching these key business events are retrieved from a pre-built business timing constraint library; each key business event pair... ,in This refers to the preceding events in a key business event pair. This indicates a subsequent event in a critical business event pair. This indicates the lower bound of the allowed time window for critical business events in the business timing constraint library. This represents the upper bound of the allowed time window for key business event pairs in the business timing constraint library; then, for each matched key business event pair, it is determined whether the preceding event occurs in the current session. If so, the preceding event in the key business event pair is calculated. The most recent occurrence time in the current session and post-event The most recent occurrence time in the current logical session The time interval between Otherwise, skip this key business event pair and do not participate in subsequent calculations; Subsequently, for each key business event pair involved in the above time interval calculation, its time interval is... The allowable time window corresponding to this critical business event in the business timing constraint library. Compare the results and obtain the corresponding timing violation degree for the key business event. : ; Finally, all matching key business events are aggregated with their corresponding timing violation scores to obtain the timing violation score of the current application layer protocol message. ; (5) The final feature deviation obtained in step (3) Timing violation degree of the current application layer protocol message obtained in step (4) A weighted fusion process is performed to obtain a comprehensive anomaly score. And determine the comprehensive abnormality score. Exceeding the preset comprehensive threshold If so, it means the current session is an abnormal session, and then proceed to step (6); otherwise, it means the current session is a normal session, and then the process ends. (6) Control the edge agent device to perform blocking processing on abnormal sessions in order to terminate the data forwarding of abnormal sessions and cut off the session path between the abnormal session and the power equipment corresponding to the abnormal session; (7) The real-time observation feature vector corresponding to the application layer protocol message of the abnormal session. Time-series characteristic sequences Final feature deviation Timing violation degree Stored in the local anomaly sample database.

2. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 1, characterized in that, Step (2) specifically includes the following sub-steps: (2-1) Extract categorical features, numerical features, key business events and their corresponding times from application layer protocol messages; (2-2) Use one-hot encoding to encode the categorical features extracted in step (2-1) to obtain the categorical feature vector, and normalize the numerical features extracted in step (2-1). Combine the categorical feature vector with the normalized numerical features to obtain the normalized real-time observation feature vector. ; (2-3) Based on the quintuple corresponding to the application layer protocol message, the real-time observation feature vector corresponding to the current application layer protocol message obtained in step (2-2) is transformed. Associate it with the corresponding logical session stream and update the context state of that logical session stream to obtain the updated logical session stream; (2-4) Construct real-time observation feature vectors based on the updated logical session flow obtained in step (2-3). Corresponding time-series feature sequences And determine whether the number of historical application layer protocol messages associated in the updated logical session stream is greater than or equal to 1. If so, then retrieve the current application layer protocol message from the updated logical session stream. The time-series feature sequence formed by multiple feature vectors corresponding to each message Then the process ends; otherwise, the time-series feature sequence consisting of multiple feature vectors corresponding to all existing application layer protocol messages in the updated logical session stream is obtained. Then the process ends; where the length of the time-series feature sequence is... The value range is 3 to 10, where t represents the time sequence index of the current application layer protocol message in the corresponding logical session stream. This indicates the first message preceding the current application layer protocol message in the updated logical session flow. The feature vector corresponding to each application layer protocol message.

3. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 1 or 2, characterized in that, Categorical features refer to discrete attributes that characterize messages or business behaviors, including message type, function code, service type, and operation instruction class; Numerical features refer to continuous attributes that characterize message or session behavior, including field length, data size, and the time interval between requests and responses; Key business events refer to operational nodes in a business process that have clear business semantics, including session establishment, parameter issuance, status query, control command execution, and parameter upload; A logical session stream is used to characterize the continuous communication behavior generated by the same power equipment during a single business interaction. Its context state includes the sequence of feature vectors associated with the session and the corresponding time sequence information. When associating real-time observation feature vectors with a logical session stream, the real-time observation feature vectors are appended to the logical session stream in the order of arrival of application layer protocol messages, and the latest time index recorded in the logical session stream is updated synchronously.

4. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to any one of claims 1 to 3, characterized in that, In step (3), the feature deviation between the real-time observed feature vector obtained in step (2) and the two expected feature vectors is calculated. and The following formula is used: ; ; in Represents Euclidean distance; feature deviation threshold The value range is from 0.7 to 1.

0.

5. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 4, characterized in that, Obtain comprehensive anomaly score The following formula is used: ; in and The pre-defined non-negative weight coefficients satisfy the following conditions: Comprehensive threshold The value range is from 0.6 to 1.

0.

6. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 5, characterized in that, Two feature prediction models and The two feature prediction models are constructed using a twin neural network architecture. The network structures of the two feature prediction models are the same, but the model parameters are independent and not shared. The core of the sub-network corresponding to each feature prediction model is a temporal feature processing network, which is used to model and learn the temporal features in the session context. The temporal feature processing network adopts a long short-term memory network LSTM.

7. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 6, characterized in that, Two feature prediction models and It was obtained through the following training steps: (3-1) Obtain historical normal communication traffic data for multiple types of power equipment and their corresponding data. Perform protocol parsing on the obtained historical normal communication traffic data to obtain the five-tuples and application layer protocol messages in the communication traffic data. Divide the obtained application layer protocol messages into multiple complete business logic sessions based on the five-tuples. Extract message feature vectors from each business logic session in the order of arrival of application layer protocol messages within that session. All extracted message feature vectors constitute the time-series feature vector sequence corresponding to that business logic session. ,in This indicates the first [number] session in the business logic session. The feature vectors corresponding to each application layer protocol message, where T represents the total number of message feature vectors in the time-series feature vector sequence, and t∈[1,T]; (3-2) Construct a dataset from all the time-series feature vector sequences corresponding to all business logic sessions obtained in step (3-1), and divide the dataset into training set, validation set and test set in a ratio of 6:3:1; (3-3) For each input sample in the training set obtained in step (3-2), input the input sample into the feature prediction model respectively. and To obtain the first expected feature vector corresponding to the input sample respectively. With the second expected eigenvector ; (3-4) For each input sample in the training set obtained in step (3-2), based on the first expected feature vector corresponding to that input sample obtained in step (3-3) With the second expected eigenvector Obtain the loss value of the prediction model for each feature; (3-5) Based on the loss value obtained in step (3-4), the two feature prediction models are iteratively trained using the stochastic gradient descent algorithm until the two feature prediction models reach the preset number of iterations or the loss value on the validation set tends to stabilize and no longer decreases significantly. The optimal parameters of the two feature prediction models at this time are obtained, thus obtaining the two feature prediction models that have been initially trained. (3-6) Use the test set obtained in step (3-1) to test the two feature prediction models that were initially trained in step (3-5) to obtain the two final trained feature prediction models.

8. The method for identifying power access equipment anomalies based on fusion feature deviation and timing constraints according to claim 7, characterized in that, In steps (3-4), the root mean square loss function is used as the loss function to measure the difference between the predicted features and the target output of the input sample. The specific loss value is as follows: ; in This represents the target output of the input sample.

9. A power access equipment anomaly identification system integrating feature deviation and timing constraints, applied to an edge agent device in a power cloud edge-end system, characterized in that... The power access equipment anomaly identification system includes the following modules: The first module is used to acquire the communication traffic of the power equipment, perform protocol parsing on the acquired communication traffic to obtain multiple application layer protocol messages, and the five-tuple corresponding to the application layer protocol message composed of the source IP address, destination IP address, source port number, destination port number, and transport layer protocol in each application layer protocol message. The second module is used to obtain the current application layer protocol message from all application layer protocol messages obtained from the first module, and to extract features from the current application layer protocol message to obtain the corresponding real-time observation feature vector, and to construct the time-series feature sequence corresponding to the real-time observation feature vector. The third module is used to process the time-series feature sequences obtained from the second module. Input the two pre-trained feature prediction models respectively and To obtain the corresponding expected feature vectors respectively. and The feature deviation between the real-time observed feature vector obtained from the second module and the two expected feature vectors is calculated respectively. and And determine the feature deviation. and Are they all greater than the preset feature deviation threshold? If so, it indicates that the logical session corresponding to the current application layer protocol message has deviated from its characteristics, and the average of the two characteristic deviations is calculated as the final characteristic deviation. Then proceed to the fourth module; otherwise, set the final feature deviation. The value is zero, then proceed to the fourth module; The fourth module is used to extract key business events and their corresponding times from the current application layer protocol message obtained by the second module, and to obtain the timing violation degree of the current application layer protocol message based on the key business events and their corresponding times; the fourth module specifically includes, First, the session to which the current application layer protocol message belongs is identified as the current session; key business events contained in the current application layer protocol message are extracted, and these key business events are used as follow-up events. Multiple key business event pairs matching these key business events are retrieved from a pre-built business timing constraint library; each key business event pair... ,in This refers to the preceding events in a key business event pair. This indicates a subsequent event in a critical business event pair. This indicates the lower bound of the allowed time window for critical business events in the business timing constraint library. This indicates the upper bound of the allowed time window for critical business events in the business timing constraint library; Then, for each matching key business event pair, it is determined whether the preceding event appears in the current session. If so, the preceding event in the key business event pair is calculated. The most recent occurrence time in the current session and post-event The most recent occurrence time in the current logical session The time interval between Otherwise, skip this key business event pair and do not participate in subsequent calculations; Subsequently, for each key business event pair involved in the above time interval calculation, its time interval is... The allowable time window corresponding to this critical business event in the business timing constraint library. Compare the results and obtain the corresponding timing violation degree for the key business event. : ; Finally, all matching key business events are aggregated with their corresponding timing violation scores to obtain the timing violation score of the current application layer protocol message. ; The fifth module is used to evaluate the final feature deviation obtained from the third module. Timing violation of the current application layer protocol message obtained from the fourth module A weighted fusion process is performed to obtain a comprehensive anomaly score. And determine the comprehensive abnormality score. Exceeding the preset comprehensive threshold If so, it means the current session is an abnormal session, and then proceed to the sixth module; otherwise, it means the current session is a normal session, and then the process ends. The sixth module is used to control the edge agent device to block abnormal sessions, terminate the data forwarding of abnormal sessions, and cut off the session path between the abnormal session and the power equipment corresponding to the abnormal session. The seventh module is used to generate the real-time observation feature vector corresponding to the application layer protocol message of the abnormal session. Time-series characteristic sequences Final feature deviation Timing violation degree Stored in the local anomaly sample database.

Citation Information

Patent Citations

  • A packaging system

    IE61850B1

  • Passive optical fiber multi-parameter digital twin drive abnormal root cause positioning method and system

    CN121188579A

  • Edge device network threat detection method and system based on large electric power model

    CN121283664A