A power dispatch-oriented time service link intrusion detection system

By segmenting the timing link and implementing a dual-layer detection mechanism, combined with rapid edge detection and deep analysis, the problem of insufficient timeliness and accuracy of timing link detection in existing technologies is solved, achieving efficient and controllable intrusion detection and recovery.

CN121619256BActive Publication Date: 2026-05-01CHENGDU FUHE POWER AUTOMATION COMPLETE EQUIP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHENGDU FUHE POWER AUTOMATION COMPLETE EQUIP
Filing Date
2026-01-30
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies lack the ability to segment and coordinate across time synchronization links in power dispatching, resulting in insufficient timeliness, easy omissions or false alarms, high costs of in-depth analysis, and insufficient verifiability of evidence, making it difficult to achieve rapid, controllable and auditable recovery.

Method used

The timing link is segmented using a segmented processing module and combined with rapid edge detection and deep analysis detection. Two-layer detection is performed through an intrusion feature database and matching methods. A supplementary feature database is established to optimize the intrusion feature database. Backup links are built for rapid replacement. A third-node decentralized storage is introduced for information comparison to ensure the accuracy and auditability of the detection.

Benefits of technology

It achieves highly timely and accurate intrusion detection, improves coverage of complex and distributed attacks, enhances trust and traceability, ensures the security and controllability of the timing link, and reduces the impact of single point of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121619256B_ABST
    Figure CN121619256B_ABST
Patent Text Reader

Abstract

The application discloses a time service link intrusion detection system for power dispatching, and relates to the technical field of power dispatching. The system comprises an information acquisition module, which acquires information interfaces of time service links to obtain target interfaces, and the target interfaces are detection points. The application independently executes a double-layer detection process of rapid detection and deep detection for each segment, and realizes comprehensive judgment of the whole link through segment superposition, so that the accuracy and robustness of detection are improved. The output information of each segment is compared through the introduction of a third node storage to form an independent and tamper-proof evidence chain, the trustworthiness and auditability are enhanced, the impact of single-point failure and attack on the clock continuity and consistency of the system is reduced, the segment superposition double-layer detection mechanism can improve the timeliness and accuracy of detection, improve the coverage ability of complex and distributed attacks, enhance the consistency and traceability across segments, and realize the non-repudiation of evidence under the resistance attack through decentralization comparison.
Need to check novelty before this filing date? Find Prior Art

Description

A time-synchronization link intrusion detection system for power dispatching Technical Field

[0001] This invention relates to the field of power dispatching technology, specifically to a time-synchronization link intrusion detection system for power dispatching. Background Technology

[0002] Power dispatch is a process of real-time monitoring, forecasting, and optimization decision-making regarding the generation, transmission, distribution, and load of a power system. Its goal is to rationally allocate limited resources, coordinate multiple parties to maintain the frequency and voltage stability of the power grid, achieve peak-valley balance, respond quickly to changes in demand, and cope with uncertainties such as equipment failures, weather impacts, and market fluctuations, while ensuring the safety, reliability, and economy of power supply. In the process of power dispatch, time synchronization links are often used for high-precision time synchronization communication, which necessitates ensuring the security of the time synchronization links.

[0003] A method and apparatus for detecting timing link anomalies, disclosed in patent publication number CN120785731A, includes the following steps: S1, selecting a segment in the main timing link as a replacement segment, and replacing the replacement segment with a standard reference link as the detection timing link; S2, calculating the time difference between the receiving device receiving timing signals from the two timing links; S3, determining whether the replaced segment is normal based on the time difference; S4, removing the replacement segment from the main timing link as the remaining segment, replacing the remaining segment with a standard reference link as the detection timing link, and repeating S2-S3. The beneficial effects of this invention are: using a replacement link method can quickly narrow down the fault investigation scope, locating large-scale link problems into small segment problems, thereby finding abnormal devices within a fewer iterations; the introduction of a standard reference link allows the receiving end to accurately calculate the absolute time delay difference, enabling quantization of the time delay at the signal transmission time, thus improving the accuracy of detection.

[0004] Existing technologies often limit the security detection of the timing link to single-segment, single-layer detection or centralized comparison only at a central node, lacking segmented governance and cross-segment collaboration capabilities. This leads to the following shortcomings: insufficient timeliness, as rapid detection of a single segment often fails to cover distributed attacks across the entire link, easily resulting in missed or false alarms; high cost of in-depth analysis, limited by single-point resources, making it difficult to achieve high-precision causal inference and cross-source evidence integration in multi-source environments; insufficient verifiability and auditability of the evidence chain, often lacking a decentralized and trustworthy comparison mechanism, making it susceptible to forgery or tampering, reducing the credibility of evidence under adversarial attacks; and lack of structured and traceable design for replacement / repair paths, making it difficult to achieve rapid, controllable, and auditable recovery in intrusion incidents. Therefore, this invention is proposed. Summary of the Invention

[0005] The purpose of this invention is to provide a timing link intrusion detection system for power dispatching, so as to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a time-synchronization link intrusion detection system for power dispatching, the system comprising:

[0007] Information acquisition module: Obtains the target interface from the information interface of the timing link, and the target interface is the detection point;

[0008] Segmentation module: Based on the target interface, the timing link is segmented into several timing link segments using the segmentation processing method, and the timing link segments and detection points are integrated to obtain the detection object;

[0009] Layered detection module: Layered detection includes fast edge detection and deep analysis detection. Fast edge detection includes an intrusion feature library and matching methods. Based on the detection object and layered detection, intrusion detection is performed on the detection object through a detection combination method to obtain the detection result.

[0010] Result optimization module: When the detected object is not invaded, the detection result is no invasion; when the detected object is invaded, the detection result is invasion information. Based on the invasion information, a feature set of invasion information is established through feature establishment method to obtain a supplementary feature library. The information in the supplementary feature library is incorporated into the invasion feature library to complete the information supplementation of the invasion feature library. Based on the supplementary feature library, the invasion feature library is enriched and the edge fast detection is optimized.

[0011] Intrusion Removal Module: Based on the detection results, extract the timing link segment that the detected object has been intruded into the target segment, and replace the target segment by adding it to complete the intrusion removal;

[0012] Intrusion backstop module: It detects whether the information output by the time synchronization link segment has been tampered with by using an output detection method. When the judgment result is that the information output by the time synchronization link segment has been tampered with, the time synchronization link segment has been intruded.

[0013] Furthermore, the segmentation processing method includes: pre-setting segmentation logic, which includes time window granularity and event type granularity; segmenting the timing link based on the segmentation logic to obtain several timing link segments; when the segmentation logic is time window granularity, a fixed time window is preset; the timing link is segmented based on the fixed time window to obtain several timing link segments; when the segmentation logic is time type granularity, the timing link event stream is read, and the data is classified according to the event type to obtain several timing link segments.

[0014] Furthermore, the detection coordination method includes: establishing edge detection points based on the target interface; performing rapid edge detection on the information flowing through the target interface based on the edge detection points to obtain preliminary results, the preliminary results including preliminary no intrusion information, suspected intrusion information, or preliminary intrusion information; obtaining final results through deep analysis based on the suspected intrusion information, the final results including final no intrusion information or final intrusion information; and integrating the preliminary results and the final results to obtain the detection result.

[0015] Furthermore, the fast edge detection includes an intrusion feature library and a matching method. The method for establishing the intrusion feature library includes: obtaining features from past intrusion information to obtain past features, and establishing an intrusion information library to store past features to obtain the intrusion feature library. The matching method includes: obtaining the target interface of the timing link segment to obtain the detection interface, obtaining the sending and receiving information of the detection interface in real time to obtain the information to be detected, performing feature matching based on the information to be detected in conjunction with the intrusion feature library to obtain the matching result, and obtaining suspected information based on the matching result.

[0016] Furthermore, the in-depth analysis and detection includes: monitoring the time point of suspected information flow to obtain the specific time, monitoring the information changes that occur after the specific time to obtain the information change set, judging whether the information changes are reasonable based on the information change set to obtain a reasonable result, and when the reasonable result feedback indicates that the information changes in the information change set are unreasonable, the suspected information is judged as intrusion information.

[0017] Furthermore, the feature establishment method includes: extracting features from intrusion information to obtain supplementary features, obtaining the source of intrusion information to obtain the target source, extracting the timing link segment of the discovered intrusion information to obtain the specific segment, integrating the supplementary features and the target source to obtain supplementary information of the intrusion information, establishing a correspondence between the specific segment and the supplementary information, and establishing a supplementary feature library to store the supplementary information and the correspondence.

[0018] Furthermore, the addition method includes: establishing a backup link while establishing a time synchronization link; dividing the backup link into corresponding segments based on the segmentation of the time synchronization link to obtain several backup link segments; establishing an association between the time synchronization link segments and the backup link segments; extracting the corresponding backup link segments based on the target segment and the association to obtain the target road segment; and replacing the target segment with the target road segment based on the time synchronization link to complete the intrusion elimination.

[0019] Furthermore, the output detection method includes: obtaining target information based on information stored in the timing link segment; marking the target information in the timing link segment to obtain information tags; establishing a storage repository to store the target information and information tags; extracting output information to obtain information to be judged when information is output in the timing link segment; judging whether the information in the target information is consistent with the information to be judged based on the information tags to obtain a judgment result; when the information in the target information is inconsistent with the information to be judged, the information to be judged has been tampered with and the timing link segment has been compromised.

[0020] Compared with the prior art, the beneficial effects of the present invention are:

[0021] This time-synchronization link intrusion detection system for power dispatch employs a two-layer detection process—fast detection and deep detection—that independently executes for each segment, achieving comprehensive judgment across the entire link through segment overlay. The first layer, fast detection, uses a historical intrusion information feature database to initially screen suspected anomalies, ensuring high timeliness. The second layer performs deep analysis upon detecting a suspected intrusion, thereby improving detection accuracy and robustness. By introducing a third-node decentralized storage, the system compares the output information of each segment from multiple sources, forming an independent and tamper-proof chain of evidence, enhancing trustworthiness and auditability, while reducing the impact of single-point failures and attacks on the system's clock continuity and consistency. In summary, this segmented overlay two-layer detection mechanism improves detection timeliness and accuracy, enhances coverage against complex, distributed attacks, strengthens cross-segment consistency and traceability, and achieves non-repudiation of evidence under adversarial attacks through decentralized comparison.

[0022] Simultaneously, by establishing a third node to store information of the timing link segment through the set output detection method, and performing information matching to determine whether the information has been tampered with when the timing link segment outputs information, the system determines whether the timing link segment has been compromised. The entire process leverages centralization and immutability to enhance information security. Through the set feature establishment method, features of the intrusion information are extracted to obtain supplementary features, and the source of the intrusion information is obtained to obtain the target source. The two are merged to obtain supplementary information. Based on the supplementary information, the sample size can be increased, improving the accuracy of rapid edge detection. By establishing a correspondence between specific paragraphs and supplementary information, the supplementary information can be extracted specifically for rapid edge detection based on the specific paragraph, improving the efficiency and accuracy of intrusion detection.

[0023] Simultaneously, backup links are constructed while establishing the timing link. Based on the segmentation rules of the timing link, the backup links are also segmented accordingly, forming a one-to-one set of backup link segments, and a mapping relationship is established between the timing link segments and the backup link segments. When an intrusion is detected in a target segment, based on the correspondence between the target segment and its associated backup link segments, an equivalent replacement path is extracted from the backup link segments, replacing the target segment with a stable target path segment, thereby achieving rapid and controllable intrusion elimination and clock continuity restoration. Attached Figure Description

[0024] Figure 1 is a schematic diagram of the overall process of the present invention;

[0025] Figure 2 is a schematic diagram of the addition method of the present invention;

[0026] Figure 3 is a schematic diagram of the output detection method of the present invention;

[0027] Figure 4 is a schematic diagram of the output detection method of the present invention. Detailed Implementation

[0028] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] Time synchronization link intrusion detection is a security mechanism that continuously monitors and analyzes the clock source, message flow, and network transmission path in a time synchronization system. It aims to detect attacks such as time forgery, abnormal delays, authentication failures, and timing offsets, as well as time-related anomalies, to ensure the integrity, availability, and consistency of the time synchronization link. Time synchronization link intrusion detection for power dispatch is a security mechanism that continuously monitors, analyzes, and alerts master-slave clocks, time protocols (such as PTP / NTP, and related hardware time sources), and communication paths carrying timing information in the power system's time synchronization network. It aims to quickly detect attacks and anomalies such as time forgery, abnormal delays, authentication failures, and timing offsets, ensuring clock consistency, availability, and integrity, thereby guaranteeing the stable operation of critical power system functions such as protection, dispatching, and telemetry.

[0030] As shown in Figures 1-4, this invention provides a technical solution: a time-synchronization link intrusion detection system for power dispatching, the system comprising:

[0031] Information acquisition module: Obtains the target interface from the information interface of the timing link, and the target interface is the detection point;

[0032] It is important to note that the information interface of the time link is a set of interfaces exposed in the time synchronization system for obtaining clock-related information, including but not limited to timestamps, clock source status, authentication certificate status, link latency, jitter, path information, and observation data from the time synchronization source to the local node. The target interface is the interface for information exchange. The target interface is specifically expressed as an intrusion detection point. The "interface point" selected for detection from the information interface of the time synchronization link can also be any information interface, equivalent to a specific detection entry point. It represents the input or output information or state snapshot in a specific time point and a specific segment of the route, and is the object to be analyzed in subsequent detection.

[0033] Segmentation module: Based on the target interface, the timing link is segmented into several timing link segments using the segmentation processing method, and the timing link segments and detection points are integrated to obtain the detection object;

[0034] It is important to note that the timing link is logically segmented by setting a segmentation processing method, that is, the timing link is divided into multiple segments, in order to facilitate subsequent intrusion detection, improve detection efficiency, facilitate multi-threaded intrusion detection of the timing link, and also allow for targeted detection based on different timing link segments, depending on the actual use case.

[0035] Layered detection module: Layered detection includes fast edge detection and deep analysis detection. Fast edge detection includes an intrusion feature library and matching methods. Based on the detection object and layered detection, intrusion detection is performed on the detection object through a detection combination method to obtain the detection result.

[0036] It is important to note that the layered detection module provides dual-layer detection, specifically fast edge detection and deep analysis detection. Fast edge detection combines an intrusion feature library with a matching method. The matching method performs feature matching to quickly detect intrusions. By setting the detection combination method, the corresponding application of fast edge detection and deep analysis detection is obtained to obtain the detection results.

[0037] Result optimization module: When the detected object is not invaded, the detection result is no invasion; when the detected object is invaded, the detection result is invasion information. Based on the invasion information, a feature set of invasion information is established through feature establishment method to obtain a supplementary feature library. The information in the supplementary feature library is incorporated into the invasion feature library to complete the information supplementation of the invasion feature library. Based on the supplementary feature library, the invasion feature library is enriched and the edge fast detection is optimized.

[0038] It is important to note that by establishing a feature set for intrusion information through the set feature establishment method, a supplementary feature library is obtained. This supplementary feature library enriches the intrusion feature library, thereby optimizing fast edge detection and increasing the sample capacity for feature matching in fast edge detection.

[0039] Intrusion Removal Module: Based on the detection results, extract the timing link segment that the detected object has been intruded into the target segment, and replace the target segment by adding it to complete the intrusion removal;

[0040] It is important to note that by using the configured addition method, the compromised timing link segment can be replaced to eliminate the intrusion and ensure the security of the timing link operation.

[0041] Intrusion backstop module: It detects whether the information output by the time synchronization link segment has been tampered with by using an output detection method. When the judgment result is that the information output by the time synchronization link segment has been tampered with, the time synchronization link segment has been intruded.

[0042] It is important to note that by establishing a third node to store the information of the timing link segment through the set output detection method, and performing information matching to determine whether the information has been tampered with when the timing link segment outputs information, the system can determine whether the timing link segment has been compromised. The whole process uses centralization and immutability to improve information security.

[0043] As shown in Figure 1, the segmentation method includes: pre-setting segmentation logic, which includes time window granularity and event type granularity; segmenting the timing link based on the segmentation logic to obtain several timing link segments; when the segmentation logic is time window granularity, a fixed time window is preset; and the timing link is segmented based on the fixed time window to obtain several timing link segments; when the segmentation logic is time type granularity, the timing link event stream is read, and the data is classified according to the event type to obtain several timing link segments.

[0044] It is important to note the following: Time window granularity: Using a fixed time window as the unit, the timing link is divided into several consecutive time periods along the time dimension. Each segment covers the observation data within a time window. Key parameter: Time window length T, for example, T = 1 second, 10 milliseconds, 100 milliseconds, etc. Typical output: A set of sequential time periods, each segment containing the set of observation data and statistical characteristics within that time window; Time type granularity: Divided according to the event type in the timing link event stream, the data is divided into several segments according to the event type. Examples include: certificate updates, clock source switching, link disconnection, path changes, and abnormal jitter events. Key parameters include: event type set and event boundary judgment rules (such as creating new segments when a new event type appears, merging events of the same type, etc.). Typical output: a set of segments sorted by event type, each segment focusing on the characteristics and impact of an event family. Fixed time windows enable fast and continuous localized detection, facilitating rapid filtering from milliseconds to seconds, reducing the impact of noise comparisons caused by single sampling, and focusing on specific event types, which helps to perform in-depth analysis in event-driven attack scenarios (such as performing additional evidence alignment only when certificate / key related events occur). Different event types may have different baselines and abnormal patterns. Segmentation by type allows for the formulation of specific thresholds and detection strategies for each type of event, reducing false alarms caused by cross-type interference. Furthermore, the performance of the same event type in different link segments can be compared twice, making it easier to discover cross-segment consistency anomalies or coordinated attacks. During use, segmentation at both the time window granularity and event type granularity can be performed simultaneously to ensure the diversity of subsequent detection and improve detection accuracy.

[0045] As shown in Figure 1, the detection coordination method includes: establishing edge detection points based on the target interface; performing rapid edge detection on the information flowing through the target interface based on the edge detection points to obtain preliminary results; the preliminary results include preliminary no intrusion information, suspected intrusion information, or preliminary intrusion information; obtaining the final result through in-depth analysis based on the suspected intrusion information; the final result includes final no intrusion information or final intrusion information; and integrating the preliminary results and the final results to obtain the detection result.

[0046] It should be noted that the detection method is used to illustrate the process of using rapid edge detection and deep analysis detection. Specifically, rapid edge detection is used to screen circulating information, and when suspected information is found, deep analysis is used to complete the detection.

[0047] As shown in Figure 1, the fast edge detection includes an intrusion feature database and a matching method. The method for establishing the intrusion feature database includes: obtaining features from past intrusion information to obtain past features, and establishing an intrusion information database to store past features to obtain the intrusion feature database. The matching method includes: obtaining the target interface of the time-synchronized link segment to obtain the detection interface, obtaining the sending and receiving information of the detection interface in real time to obtain the information to be detected, performing feature matching based on the information to be detected in conjunction with the intrusion feature database to obtain the matching result, and obtaining suspected information based on the matching result.

[0048] It is important to note that the process of obtaining past intrusion information features involves acquiring the characteristics of past intrusion information, and also obtaining the source of the past intrusion information as a reference. The process of obtaining the target interface of the timing link segment to obtain the detection interface determines the detection location. The process of obtaining suspected information based on the matching results can set a similarity threshold for feature similarity matching. That is, when the similarity reaches 100%, it is confirmed as intrusion information, and when it is above 90%, it is suspected information. The specific threshold can be determined according to the actual use case. At the same time, the process of obtaining suspected information based on the matching results can also be handed over to staff for screening. The specific method used depends on the actual use case.

[0049] As shown in Figure 1, the in-depth analysis and detection includes: monitoring the time point of suspected information flow to obtain the specific time, monitoring the information changes that occur after the specific time to obtain the information change set, judging whether the information changes are reasonable based on the information change set to obtain a reasonable result, and when the reasonable result feedback indicates that the information changes in the information change set are unreasonable, the suspected information is judged as intrusion information.

[0050] It is important to note that the process of monitoring the time of suspected information flow to obtain the specific time (i.e., obtaining the time when the suspected information was generated), and the process of monitoring information changes after the specific time to obtain the information change set (i.e., extracting information changes after the specific time), and judging whether the suspected information is an intrusion based on the information changes, thus preventing the tampering of information in the time synchronization link, and the process of judging whether the information changes are reasonable based on the information change set to obtain a reasonable result, can be done by setting a change value for specific information items. When the actual change exceeds the change value, it is judged as unreasonable. Alternatively, the information change set can be directly given to staff for judgment based on the actual situation. The specific judgment on whether it is reasonable can be determined based on the actual usage.

[0051] The feature establishment method includes: extracting features from intrusion information to obtain supplementary features, obtaining the source of intrusion information to obtain the target source, extracting the timing link segment of the intrusion information to obtain the specific segment, integrating the supplementary features and the target source to obtain supplementary information of the intrusion information, establishing the correspondence between the specific segment and the supplementary information, and establishing a supplementary feature library to store the supplementary information and the correspondence.

[0052] It is important to note that by using the set feature establishment method, the features of the intrusion information are extracted to obtain supplementary features, and the source of the intrusion information is obtained to obtain the target source. The two are merged to obtain supplementary information. Based on the supplementary information, the sample size can be increased, and the accuracy of fast edge detection can be improved. By establishing the correspondence between specific paragraphs and supplementary information, the supplementary information can be extracted specifically for fast edge detection based on the specific paragraph, thereby improving the efficiency and accuracy of intrusion detection.

[0053] As shown in Figure 2, the addition method includes: establishing a backup link while establishing a time synchronization link; dividing the backup link into corresponding segments based on the segmentation of the time synchronization link to obtain several backup link segments; establishing the association between the time synchronization link segments and the backup link segments; extracting the corresponding backup link segments based on the target segment and the association to obtain the target road segment; and replacing the target segment with the target road segment based on the time synchronization link to complete the intrusion elimination.

[0054] It is important to note that backup links are constructed in parallel while establishing the timing link. Based on the segmentation rules of the timing link, the backup link is also segmented accordingly, forming a one-to-one set of backup link segments, and a mapping relationship is established between the timing link segments and the backup link segments. When an intrusion is detected in a target segment, based on the correspondence between the target segment and its associated backup link segments, an equivalent replacement path is extracted from the backup link segments, replacing the target segment with a stable target path segment. This achieves rapid and controllable intrusion elimination and clock continuity restoration, as shown in Figure 2. The overall backup link and backup link segments correspond to the timing link and timing link segments, respectively.

[0055] As shown in Figures 3 and 4, the output detection method includes: obtaining target information based on the information stored in the timing link segment; marking the target information in the timing link segment to obtain information tags; establishing a repository to store the target information and information tags; extracting the output information when the timing link segment outputs information to obtain the information to be judged; judging whether the information in the target information is consistent with the information to be judged based on the information tags to obtain the judgment result; when the information in the target information is inconsistent with the information to be judged, the information to be judged has been tampered with and the timing link segment has been compromised.

[0056] It is important to note that by using information tagging to provide guidance, it is easier to match the same information items and avoids randomly selecting information from the repository for matching. The repository is located on the third node, which is different from the central node of the timing link and the edge node of the information interface. By storing the information on the third node, it reflects decentralization and immutability, which helps to ensure the accuracy of information output and improves the accuracy of power grid dispatching instructions. As shown in Figure 4, the numbers after the target information in Figure 4 represent tags.

[0057] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended embodiments and their equivalents.

Claims

1. A time-synchronization link intrusion detection system for power dispatching, the system comprising: Information Acquisition Module: Acquires the information interface of the timing link to obtain the target interface, which is the detection point; characterized in that the system further includes: a segmentation processing module: Based on the target interface, the timing link is segmented using a segmentation processing method to obtain several timing link segments, and the timing link segments and detection points are integrated to obtain the detection object; a hierarchical detection module: Hierarchical detection includes fast edge detection and deep analysis detection, fast edge detection includes an intrusion feature library and a matching method, and the detection object is intruded upon using a detection coordination method based on the detection object and hierarchical detection to obtain the detection result; a result optimization module: When the detection object is not intruded, the detection result is no intrusion; when the detection object is intruded, the detection result is intrusion information, and a feature set of intrusion information is established based on the intrusion information using a feature establishment method to obtain a supplementary feature library, and the information in the supplementary feature library is incorporated into the intrusion feature library to complete the intrusion feature library information. The system includes: information supplementation, enriching the intrusion feature library based on supplementary feature libraries to optimize edge detection; an intrusion elimination module, which extracts the timing link segment that is identified as the intruded target based on the detection results, and replaces the target segment with an addition method to complete the intrusion elimination; and an intrusion backstop module, which detects whether the information output by the timing link segment has been tampered with using an output detection method. If the result indicates that the information output by the timing link segment has been tampered with, then the timing link segment has been intruded. The addition method includes: establishing a backup link while establishing the timing link; segmenting the backup link into several backup link segments based on the segmentation of the timing link; establishing a relationship between the timing link segments and the backup link segments; extracting the corresponding backup link segment based on the target segment and the relationship to obtain the target road segment; and replacing the target segment with the target road segment based on the timing link to complete the intrusion elimination.

2. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The segmentation processing method includes: pre-setting segmentation logic, which includes time window granularity and event type granularity; segmenting the timing link based on the segmentation logic to obtain several timing link segments; when the segmentation logic is time window granularity, a fixed time window is preset; the timing link is segmented based on the fixed time window to obtain several timing link segments; when the segmentation logic is time type granularity, the timing link event stream is read, and the data is classified according to the event type to obtain several timing link segments.

3. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The detection coordination method includes: establishing edge detection points based on the target interface; performing rapid edge detection on the information flowing through the target interface based on the edge detection points to obtain preliminary results, including preliminary no intrusion information, suspected intrusion information, or preliminary intrusion information; obtaining final results through in-depth analysis based on the suspected intrusion information, including final no intrusion information or final intrusion information; and integrating the preliminary results and the final results to obtain the detection result.

4. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The fast edge detection includes an intrusion feature database and a matching method. The method for establishing the intrusion feature database includes: obtaining features from past intrusion information to obtain past features, and establishing an intrusion information database to store past features to obtain the intrusion feature database. The matching method includes: obtaining the target interface of the time-synchronized link segment to obtain the detection interface, obtaining the transmission and reception information of the detection interface in real time to obtain the information to be detected, performing feature matching based on the information to be detected in conjunction with the intrusion feature database to obtain the matching result, and obtaining suspected information based on the matching result.

5. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The in-depth analysis and detection includes: monitoring the time point of suspected information flow to obtain the specific time, monitoring the information changes that occur after the specific time to obtain the information change set, judging whether the information changes are reasonable based on the information change set to obtain a reasonable result, and when the reasonable result feedback indicates that the information changes in the information change set are unreasonable, the suspected information is judged as intrusion information.

6. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The feature establishment method includes: extracting features from intrusion information to obtain supplementary features, obtaining the source of intrusion information to obtain the target source, extracting the timing link segment of the discovered intrusion information to obtain the specific segment, integrating the supplementary features and the target source to obtain supplementary information of the intrusion information, establishing the correspondence between the specific segment and the supplementary information, and establishing a supplementary feature library to store the supplementary information and the correspondence.

7. The time-synchronization link intrusion detection system for power dispatching according to claim 1, characterized in that: The output detection method includes: obtaining target information based on information stored in the timing link segment; marking the target information in the timing link segment to obtain information tags; establishing a storage repository to store the target information and information tags; extracting output information to obtain information to be judged when information is output in the timing link segment; judging whether the information in the target information is consistent with the information to be judged based on the information tags to obtain a judgment result; when the information in the target information is inconsistent with the information to be judged, the information to be judged has been tampered with and the timing link segment has been compromised.

Citation Information

Patent Citations

  • Time synchronization device for online monitoring of intelligent substation

    CN107425934A

  • Method and device for detecting abnormity of time service link

    CN120785731A