Power target damage propagation path modeling method based on attack chain atlas
By constructing a power target damage propagation path modeling method based on attack chain graphs, collecting and optimizing multi-source heterogeneous data, constructing heterogeneous graphs, and identifying high-risk attack patterns, this method solves the fragmentation problem of cross-layer propagation path analysis in power systems, realizes full-link structured reconstruction of attack paths and accurate prediction of damage propagation, and improves the security protection capabilities of power systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-03-13
AI Technical Summary
Existing security modeling techniques cannot effectively link attack behaviors, system components, and business logic in power systems, resulting in fragmented cross-layer propagation path analysis and difficulty in predicting potential damage propagation paths. Traditional methods are difficult to adapt to the specialized equipment and business scenarios of the power OT layer and cannot characterize the cross-layer propagation logic of attack behaviors-system components-business damage.
By constructing a power target damage propagation path modeling method based on attack chain graphs, multi-source heterogeneous data is collected, standardized structure mapping and data quality optimization are performed, a heterogeneous graph is constructed, potential high-risk attack patterns are identified, damage propagation is predicted, and adaptive optimization is performed in combination with the business priorities of the power system.
It achieves full-link structured reconstruction of attack paths, improves the accuracy of attack tracing and damage attribution, enhances the ability to predict potential damage risks, optimizes the proactive defense strategy of power systems, can accurately locate the initial entry point and key jump node of an attack, predict the business scope and severity of potential damage spread, and provides comprehensive technical support for power systems.
Smart Images

Figure CN121664481A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of network attack propagation path analysis, and in particular to a method for modeling the damage propagation path of power targets based on attack chain graphs. Background Technology
[0002] Currently, the power system occupies a core position in critical infrastructure and is undergoing profound digital transformation. It undertakes the core functions of energy production, transmission, and distribution, and its security and stability are directly related to social welfare and security. With the advancement of "dual-carbon" goals and the construction of new power systems, traditional power physical systems are rapidly merging with information technology (IT) and operational technology (OT). A large number of industrial control systems, IoT devices, and edge nodes are connecting to the network, forming a complex system with deep coupling of "physical, information, and business." While this integration improves operational efficiency, it also breaks down the traditional "physical isolation" protection boundaries. The increase in remote operation and maintenance and cross-domain data interaction significantly expands the network attack surface, drastically increasing the difficulty of security protection. Power systems have become high-value targets for cyberattacks, with attack methods exhibiting professionalism, stealth, and chain-like characteristics. Attackers are no longer limited to data theft but are directly targeting core power operations, causing physical damage by disrupting critical equipment or tampering with business logic—for example, attackers may breach the IT layer through phishing emails, then infiltrate the OT layer via privilege escalation and lateral movement, ultimately altering PLC parameters to cause regional power outages. These attacks often form a cross-domain propagation chain of "IT-OT-Physical," exploiting vulnerabilities in power-specific protocols or employing "legitimate malicious" operations. Their actions are easily concealed by normal business operations, making traditional single-layer network monitoring and protection insufficient to cover the entire risk chain. Existing security modeling techniques have significant limitations in addressing these types of threats. Traditional methods often rely on a single data source, failing to link the functional attributes of system components with the dependencies of business logic, leading to a break in the chain of association between attack behavior and damage consequences. While mainstream attack chain models can describe the attack phases at the IT layer, they are not adapted to the specialized equipment and business scenarios at the power OT layer, and cannot depict the cross-layer propagation logic of "attack behavior - system component - business damage." Furthermore, existing security knowledge graphs are mostly static "entity-relationship" models, lacking a time dimension and contextual information, making it difficult to dynamically reconstruct the spatiotemporal evolution of attacks, and even more difficult to predict potential damage propagation paths, resulting in defense responses often lagging behind attack progress. Summary of the Invention
[0003] To address the limitation of existing attack chain analysis to a single dimension, this application provides a power target damage propagation path modeling method based on attack chain graphs. This method aims to accurately reconstruct attack paths and predict damage propagation trends. Through the deep integration of multi-dimensional information fusion, structured graph construction, spatiotemporal analysis, and graph reasoning techniques, a heterogeneous graph integrating attack behavior, system components, and business logic is constructed. This breaks down barriers between different dimensions, enabling structured reconstruction of attack paths and damage propagation reasoning, thus providing comprehensive technical support for power system security protection.
[0004] Firstly, the above-mentioned inventive objective of this application is achieved through the following technical solution: A method for modeling damage propagation paths of power targets based on attack chain graphs, the method comprising: Collect multi-source heterogeneous data from the power system, and perform standardized structure mapping and data quality optimization on the multi-source heterogeneous data to obtain standardized behavioral metadata; Heterogeneous nodes are extracted from the standardized behavioral metadata, and the relationships between heterogeneous nodes are defined to construct an initial graph. The initial graph is then optimized by a combination of manual verification and an automated deduplication mechanism to obtain a heterogeneous graph. Attack timing is anchored for attack behavior nodes in the heterogeneous graph, and the correlation between attack behavior, system components, and business logic in time and topology dimensions is explored to reconstruct the attack path across layers. Based on the reconstructed attack path and the heterogeneous graph, potential high-risk attack patterns are identified and damage propagation is predicted. The damage propagation prediction results are then adapted and optimized in conjunction with the service priorities of the power system.
[0005] In a preferred embodiment, this application can be further configured as follows: Extracting heterogeneous nodes from the standardized behavioral metadata and defining the relationships between heterogeneous nodes, constructing an initial graph, and optimizing the initial graph using a combination of manual verification and automated deduplication mechanisms to obtain a heterogeneous graph, specifically including: The standardized behavioral metadata is extracted for key metadata and transformed into heterogeneous nodes containing attack behaviors, system components, and business logic. Temporal feature and semantic association analysis are performed on the key metadata, the association edges between the heterogeneous nodes are defined, and the association relationship between the association edges and the heterogeneous nodes is analyzed to construct an initial graph; The manual verification results of the initial map are obtained, and the initial map is deduplicated using the set automatic deduplication mechanism. The initial map is then dynamically optimized to obtain a heterogeneous map.
[0006] In a preferred embodiment, this application can be further configured as follows: The step of anchoring the attack sequence of attack behavior nodes in the heterogeneous graph, and mining the correlation between attack behavior, system components, and business logic in the time and topology dimensions, and reconstructing the attack path across layers, specifically includes: Based on a pre-built attack phase labeling system, semantic matching is performed on the attack behavior nodes in the heterogeneous graph and attack phase labels are marked. The attack behavior nodes are then anchored in attack time sequence by combining the corresponding timestamps. The heterogeneous graph is divided into continuous time segment windows and the node interaction state is analyzed to identify the dynamic interaction between attack behavior and system components and to construct the time correlation between attack behavior and system components. By tracking state changes, the perturbation propagation relationship between system components and business logic can be obtained, thus revealing the state association relationship between system components and business logic. Based on the aforementioned time and state relationships, and combined with the pre-built topology association model, the attack behavior nodes anchored by the attack sequence are cross-validated in terms of time and topology, and the attack path is reconstructed across layers.
[0007] In a preferred embodiment, this application can be further configured as follows: based on the time correlation relationship and state correlation relationship, combined with the pre-built topological correlation model, the attack behavior nodes anchored by the attack sequence are cross-validated in terms of time and topological dimensions, and the cross-layer reconstruction of the attack path specifically includes: The attack behavior nodes are processed to locate the initial attack node, and subsequent nodes are filtered based on the trigger relationship edges and time order; Calculate the node importance score of the subsequent nodes, remove the subsequent nodes whose node importance score is lower than a set threshold, and associate the remaining subsequent nodes in chronological order to obtain the reconstructed attack path.
[0008] In a preferred embodiment, this application can be further configured as follows: after calculating the node importance score of the subsequent nodes, removing subsequent nodes whose node importance score is lower than a set threshold, associating the remaining subsequent nodes in chronological order to obtain the reconstructed attack path, the application further includes: By comparing and cross-validating the consistency of attack paths through multi-source data, and combining the results of manual review of attack paths, the correlation between subsequent nodes is corrected to obtain the verified and optimized attack paths.
[0009] In a preferred embodiment, this application can be further configured as follows: Based on the reconstructed attack path and the heterogeneous graph, identifying potential high-risk attack patterns and predicting damage propagation, and then adapting and optimizing the damage propagation prediction results in conjunction with the service priorities of the power system, specifically includes: The heterogeneous graph is subjected to heterogeneous node feature and edge feature extraction and quantization to obtain the graph features after feature enhancement. The graph features are then subjected to graph embedding and deep neural network fusion learning to construct a graph reasoning model. The reconstructed attack path is trained with potential attack nodes. Based on the training results, an attack behavior chain with potential attack risk is constructed and the corresponding attack pattern is identified to obtain the identification result of potential high-risk attack patterns. Based on the high-risk attack pattern identification results, the graph reasoning model is used to locate the damage nodes and analyze the propagation path of the relevant attack nodes to obtain the damage propagation prediction results. Based on the damage propagation prediction results and the service priorities of the power system, the core service nodes are weighted and the node damage scores are dynamically adjusted to optimize the damage propagation prediction results.
[0010] In a preferred embodiment, this application can be further configured as follows: the process of extracting and quantizing heterogeneous node and edge features from the heterogeneous graph to obtain enhanced graph features, and then performing graph embedding and deep neural network fusion learning on the graph features to construct the graph reasoning model includes: The heterogeneous node features are processed by graph embedding and vector mapping using the Node2Vec algorithm, and corresponding weight coefficients are set for the edge features to obtain node vectors and edge weight matrices. By using a pre-trained GAT model to learn the node vectors and edge weight matrices through a multi-head attention mechanism, the semantic and structural roles of nodes in the heterogeneous graph are inferred, thus constructing a graph reasoning model.
[0011] In a preferred embodiment, this application can be further configured as follows: training attack nodes for potential attacks on the reconstructed attack path, constructing attack behavior chains with potential attack risks based on the training results, identifying corresponding attack patterns, and obtaining potential high-risk attack pattern identification results, specifically including: Acquire historical high-risk attack data, mark the attack behavior node sequence in the reconstructed attack path that matches the historical high-risk attack data, and obtain the high-risk attack pattern identification result; Risk scoring is performed on unlabeled reconstructed attack paths. Potential attack nodes with scores higher than a set risk threshold are selected to construct attack behavior chains and identify corresponding attack patterns, thus obtaining the identification results of potential high-risk attack patterns.
[0012] In a preferred embodiment, this application can be further configured as follows: training attack nodes for potential attacks on the reconstructed attack path, constructing attack behavior chains with potential attack risks based on the training results, identifying corresponding attack patterns, and obtaining potential high-risk attack pattern identification results, further includes: A normal sequence distribution model of attack behavior is constructed by acquiring historical high-risk attack data, and the reconstruction error of the node sequence of the behavior to be detected in the heterogeneous graph is calculated. When the reconstruction error exceeds the set error threshold, the node to be detected is identified as a high-risk attack mode, and the graph location is located by subgraph matching to obtain the identification result of the potential high-risk attack mode.
[0013] Secondly, the above-mentioned inventive objective of this application is achieved through the following technical solutions: A power target damage propagation path modeling system based on attack chain graphs, the system being applied to the aforementioned power target damage propagation path modeling method based on attack chain graphs, the system comprising: The multi-source data acquisition and standardization module is used to acquire multi-source heterogeneous data from the power system, and to perform standardized structure mapping and data quality optimization processing on the multi-source heterogeneous data to obtain standardized behavioral metadata. The heterogeneous graph construction module is used to extract heterogeneous nodes from the standardized behavioral metadata and define the association between heterogeneous nodes to construct an initial graph. The initial graph is then optimized by a combination of manual verification and an automated deduplication mechanism to obtain the heterogeneous graph. The attack path reconstruction module is used to anchor the attack behavior nodes in the heterogeneous graph in terms of attack timing, and to mine the correlation between attack behavior, system components, and business logic in the time and topology dimensions, and reconstruct the attack path across layers. The risk reasoning and damage propagation prediction module is used to identify potential high-risk attack patterns and predict damage propagation based on the reconstructed attack path and the heterogeneous graph, and to adapt and optimize the damage propagation prediction results in combination with the business priorities of the power system.
[0014] In summary, this application includes at least one of the following beneficial technical effects: 1. This application achieves a structured reconstruction of the entire attack path. Traditional methods, due to isolated data and single dimensions, struggle to connect attack behaviors with deep relationships between system components and business logic. This method, however, eliminates semantic differences in heterogeneous data such as traffic, logs, and permission configurations through multi-source data abstraction. Combined with graph layering, it incorporates scattered attack actions, device status, and business processes into a unified framework, clearly presenting the cross-domain propagation chain and solving the problem of "fragmentation" in IT-OT cross-layer attack paths. 2. This application improves the accuracy of attack attribution and damage tracing. Utilizing spatiotemporal correlation analysis technology, this method combines the MITRE ATT&CK framework to annotate attack phases. By reconstructing the temporal progression and cross-node interactions of the attack through time slicing and logical topology, it can accurately locate the initial entry point, key jump-board nodes, and points of direct impact on business operations. For example, when an attack causes relay protection anomalies, the attack can be traced through graphs to how it breached the office network via phishing emails, gained server privileges, and then infiltrated the PLC, ultimately tampering with the protection logic. This clarifies the responsible nodes and root causes of vulnerabilities at each stage, providing structured evidence for attribution and evidence collection. 3. This application enhances the predictive capability of potential damage risks. Through graph reasoning, this method can start from known attack behaviors or failure nodes, and mine high-risk behavior chain patterns based on the "influence / trigger / dependency" relationships in the graph to predict the business scope and severity of potential damage spread. For example, when an intrusion is detected in a substation server, the communication dependency relationship between it and adjacent substations can be inferred through the graph, predicting that the attack may spread to the load control module through scheduling protocol vulnerabilities, thereby causing regional power supply imbalance, providing decision support for early attack prevention; 4. This application optimizes the proactive defense strategy for power systems. This method not only reconstructs attack paths but also identifies high-risk propagation nodes and their associated vulnerabilities, providing precise guidance for vulnerability patching and access control optimization. Furthermore, its dynamic graph updating and reasoning capabilities adapt to the dynamic changes in power operations, continuously outputting the latest risk assessment results. This drives a shift in defense mode from "passive response" to "proactive early warning," effectively enhancing the resilience and security of power systems under complex network threats. Attached Figure Description
[0015] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.
[0016] Figure 1 This is a flowchart illustrating the implementation of the power target damage propagation path modeling method based on attack chain graphs in this embodiment.
[0017] Figure 2 This is a flowchart illustrating the implementation of step S20 of the power target damage propagation path modeling method in this embodiment.
[0018] Figure 3 This is a flowchart illustrating the implementation of step S30 of the power target damage propagation path modeling method in this embodiment.
[0019] Figure 4 This is a flowchart illustrating the implementation of step S40 of the power target damage propagation path modeling method in this embodiment.
[0020] Figure 5 This is a structural block diagram of the power target damage propagation path modeling system in this embodiment. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0023] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0024] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0025] In one embodiment, such as Figure 1 As shown, this application discloses a method for modeling the damage propagation path of an electric target based on an attack chain graph, which specifically includes the following steps: S10: Collect multi-source heterogeneous data from the power system, and perform standardized structure mapping and data quality optimization on the multi-source heterogeneous data to obtain standardized behavioral metadata.
[0026] Specifically, step S10, as the data foundation of this method, aims to break down the "island effect" and "format barriers" of power system attack-related data. Through full data collection, standardized conversion, and quality optimization, it provides high-quality and highly consistent foundational data for subsequent map construction. Step S10 unfolds around a three-layer architecture of "comprehensive collection - precise conversion - quality assurance," forming a complete data processing closed loop.
[0027] This embodiment focuses on collecting multi-source heterogeneous data to cover all dimensions of data sources required for power system attack analysis. It achieves centralized aggregation of cross-system and cross-level data through diverse collection methods, ensuring data integrity and timeliness. Addressing the deep coupling between "IT-OT-Physical" in power systems, it includes four core data sources: network traffic data, device operation logs, permission configuration data, and business process data. Network traffic data encompasses abnormal connection records from the IT layer office network and data center, as well as dedicated protocol communication data from the OT layer industrial control network, collected in real-time through network traffic probes and industrial firewall log auditing functions. Device operation logs include login logs, operation records, and alarm information from IT devices, and operating status logs and parameter modification records from OT devices, obtained in batches through the log API interface of the device management system. Permission configuration data extracts structured information such as user role definitions and operation permission matrices from the power system's IAM system and OT device permission configuration modules. Business process data is obtained by parsing the process definition files and technical specification documents of the business management system to obtain the logical rule documents of core businesses and the device function association graph. The data acquisition technology adopts a hybrid "real-time + batch" mode. Dynamic data is accessed in real time through a Kafka message queue, while static data is synchronized to the database in batches through scheduled tasks. For dedicated protocol data of OT devices, a protocol parsing plugin is developed to ensure that the semantics of the original messages are parseable.
[0028] Furthermore, this embodiment defines a unified behavioral meta-model to map heterogeneous data into a standardized structure, eliminating semantic differences and achieving precise connection between "data and graph".
[0029] Specifically, the standardized structure in this embodiment is a five-tuple structure of <behavior object, action, timestamp, location, context>. The meaning and extraction rules of each field are clearly defined as follows: the behavior object is defined as the initiator or recipient of the behavior, and the entity identifier is extracted from the original data; the action is based on the MITRE ATT&CK attack technique and power business operation specifications to build an action dictionary, covering types such as network attacks, equipment operations, and status changes; the timestamp uniformly adopts the UTC time format, extracted and converted from the time field of the original data; the location is defined by combining physical and logical dimensions, including geographical coordinates, network segment information, or business links; the context supplements the key attributes associated with the behavior, such as operation permission level, equipment status, business rule constraints, etc. Special mapping logic is formulated for different data sources. For example, abnormal connection records in network traffic are mapped to brute-force attack attempts by attackers, and parameter modification records in PLC operation logs are associated with the operation behavior of engineers, ensuring that all types of data can be accurately adapted to the five-tuple structure.
[0030] Furthermore, the data quality optimization in this embodiment includes data cleaning, verification, and fusion processing. Through cleaning, verification, and fusion processing, the accuracy and consistency of standardized data are improved, laying a reliable foundation for subsequent map construction.
[0031] Specifically, a rule engine is used to filter and repair noise, duplicate data, and missing values in the original data. For example, duplicate traffic records are deleted, and device logs with missing context are marked as "to be supplemented" and manual verification is triggered. Semantic verification is based on the knowledge graph of the power system domain to perform legality verification on the meta-model fields to avoid semantic conflicts. Data fusion is used to associate and integrate multi-source descriptions of the same behavior, associating network traffic with the same login behavior recorded in server logs as a complete event, supplementing the complete five-tuple information, eliminating data redundancy, and thus obtaining standardized behavioral metadata.
[0032] It should be noted that the standardized behavioral metadata in this embodiment has the characteristics of "uniform format, clear semantics, and complete association," and can be directly used as input for the heterogeneous graph construction in step S20, supporting the accurate extraction of attack behaviors, system components, business logic nodes, and related relationships. Step S10 addresses the pain points of power system data being "incomplete, unclear, and unusable," providing a high-quality data foundation for the entire modeling method and ensuring the accuracy and reliability of subsequent graph construction, path reconstruction, and risk prediction.
[0033] S20: Extract heterogeneous nodes from standardized behavioral metadata and define the relationships between heterogeneous nodes to construct an initial graph. Optimize the initial graph using a combination of manual verification and automated deduplication mechanisms to obtain a heterogeneous graph.
[0034] Specifically, step S20, acting as a bridge connecting standardized data and attack chain analysis, aims to transform the five-tuple metadata from the multi-source data collection and standardization module output in S1 into a structured topological graph containing three types of nodes—attack behavior, system components, and business logic—as well as various types of related edges. This provides a computable knowledge carrier for subsequent attack path reconstruction and damage inference. Step S20 unfolds around the process of "precise node extraction - relationship definition - dynamic graph optimization." Specifically, as... Figure 2 As shown, step S20 includes: S201: Extract key metadata from standardized behavioral metadata and transform it into heterogeneous nodes containing attack behaviors, system components, and business logic.
[0035] Specifically, the extraction of heterogeneous nodes is the foundation of graph construction. It requires the accurate identification and definition of three types of heterogeneous nodes from standardized behavioral metadata to ensure semantic integrity and domain adaptability. The extraction of attack behavior nodes is based on the MITREATT&CK framework, extracting key metadata such as the "action" field from standardized behavioral metadata. Specifically, attack technology tags are extracted from the "action" field for heterogeneous node transformation; for example, "exploiting vulnerabilities to gain server privileges" is mapped to a "privilege escalation (vulnerability exploitation)" node, and associated with the corresponding attack stage and technology number, while supplementing contextual information such as attack tools and vulnerability numbers. The extraction of system component nodes focuses on key entities in the power system, identifying IT layer devices, OT layer devices, and physical layer devices from the "behavior object" field. Each node is labeled with a unique asset identifier, functional attributes, layer, and deployment location to ensure that the physical and logical attributes of the devices are clearly identifiable. The extraction of business logic nodes needs to be deeply integrated with the process characteristics of the core power business. Accurate extraction can be achieved through a three-step method of "document parsing - process decomposition - metadata association" to ensure that the nodes can not only reflect the business function objectives, but also be associated with the actual system components that are executed.
[0036] Specifically, the data source for business logic nodes encompasses two core types of information: first, the business process documents of the power system; and second, the "context" fields related to business operations in standardized metadata. In the extraction process, firstly, natural language processing (NLP) technology is used to parse the business documents: keyword extraction and semantic segmentation are performed on the operation specifications to identify core business objectives; the logic flowchart is structurally transformed, converting visual process nodes into text-described business steps; and rules are extracted from the parameter configuration table to clarify the triggering conditions of the business logic. Secondly, the process is layered and decomposed based on business objectives, forming a node system of "core module - sub-step". Subsequently, standardized attributes need to be defined for each business logic node, including: business objectives, input parameters, output parameters, execution rules, etc. Finally, the association between business logic nodes and system components is established through the "context" fields of the metadata. For example, in the metadata, "behavior object = PLC-023, action = parameter modification, context = voltage regulation command execution", the "voltage regulation command execution sub-step" node can be associated with the "PLC-023" system component node, clarifying that this business sub-step is executed by a specific PLC device.
[0037] S202: Perform temporal feature and semantic association analysis on key metadata, define the association edges between heterogeneous nodes, analyze the association relationship between the association edges and heterogeneous nodes, and construct an initial graph.
[0038] Specifically, the definition and extraction of related edges are key to constructing graph topological relationships. Based on the temporal characteristics and semantic associations of key metadata, three types of edges with clear physical or logical meanings need to be defined to characterize the dynamic interaction relationships between nodes, including influence relationship edges, trigger relationship edges, and dependency relationship edges.
[0039] Furthermore, influence edges primarily capture the impact of actions on entity state changes, extracted from the causal relationships of "action-behavior object" in metadata. For example, when the key metadata record states "an attacker modifies PLC parameters through remote code execution," an influence edge is generated from the "remote code execution" attack node to the "PLC-023" system component node, with the influence type and degree marked. Trigger edges focus on the time-driven nature of attack behaviors, identifying the causal chain of preceding and subsequent actions from the "timestamp" sequence of key metadata, such as the time sequence of "vulnerability scanning -> PLC vulnerability discovery -> remote code execution," corresponding to the generation of trigger edges for "vulnerability scanning" -> "PLC vulnerability discovery" -> "remote code execution," with time intervals recorded to reflect the attack rhythm. Dependency edges reflect the supporting logic between entities, extracted from business process documents and equipment configuration information, including the support of system components for business logic and the process dependencies between business logics, ensuring the integrity of business processes is traceable in the graph.
[0040] The graph construction process in this embodiment requires the combination of automated extraction and domain knowledge verification to achieve accurate mapping and dynamic optimization from metadata to the graph. Specifically, firstly, the automatic generation of nodes and edges is achieved through a rule engine: based on predefined node mapping rules, node attributes are extracted in batches from the five-tuple metadata, triggering relationships are identified through temporal association, and influence and dependency relationships are identified through semantic matching to generate the initial graph.
[0041] S203: Obtain the manual verification results of the initial spectrum, and perform deduplication processing on the initial spectrum in combination with the set automatic deduplication mechanism, and dynamically optimize the initial spectrum to obtain a heterogeneous spectrum.
[0042] Specifically, after the initial graph is generated, optimization is achieved through manual verification and automated deduplication. For example, a verification team composed of power system operation and maintenance experts and cybersecurity analysts focuses on reviewing the accuracy of dependencies between business logic nodes and associations with high-risk attack behaviors, generating manual verification results. Simultaneously, an automated deduplication mechanism is used to remove duplicate nodes and redundant edges from the graph and supplement missing key associations, resulting in an optimized heterogeneous graph. Furthermore, the graph supports a dynamic update mechanism; when new metadata is input or the system topology changes, incremental updates of nodes and edges are automatically triggered, ensuring the timeliness and completeness of the graph.
[0043] The heterogeneous graph generated in this embodiment presents the attack techniques, entity components, and business logic of the power system, along with their relationships, in a structured form. Each node contains rich attribute labels, and each edge carries additional information such as association type, weight, and timestamp. This graph not only provides a topological foundation for subsequent spatiotemporal reconstruction of attack paths but also achieves full-link knowledge modeling of "how attack behaviors affect system components and how system failures propagate to business damage" through the organic integration of heterogeneous nodes and multi-type edges. It becomes the core knowledge carrier supporting the damage propagation analysis of power targets.
[0044] S30: Anchor the attack timing of attack behavior nodes in the heterogeneous graph, and explore the correlation between attack behavior, system components, and business logic in the time and topology dimensions to reconstruct the attack path across layers.
[0045] Specifically, the core objective of step S30 is to connect discrete attack behaviors, component state changes, and business disturbances into a complete and continuous attack propagation chain through deep fusion analysis of time dimensions and topological relationships, based on heterogeneous graphs and standardized metadata, accurately reconstructing the entire chain process of the attack from initial access to business impact. Step S30 revolves around three core aspects: "attack phase time sequence anchoring - dynamic correlation pattern mining - cross-layer path structured reconstruction." Specifically, such as... Figure 3 As shown, step S30 includes: S301: Based on a pre-built attack stage labeling system, semantic matching is performed on attack behavior nodes in heterogeneous graphs and attack stage labels are marked. The attack behavior nodes are then anchored to the attack time sequence by combining the corresponding timestamps.
[0046] Specifically, attack phase timing anchoring is the foundation of path reconstruction, requiring the combination of technical characteristics and timestamp information of attack behavior nodes to clarify the evolution logic of the attack at different stages. First, based on the MITRE ATT&CK framework, an attack phase labeling system is constructed, covering seven core phases: "reconnaissance and detection -> initial access -> privilege escalation -> lateral movement -> OT layer penetration -> target operation -> business impact," each corresponding to specific technical characteristics. For attack behavior nodes in the heterogeneous graph, attack phase labels are automatically labeled through semantic matching. Simultaneously, combined with timestamps in the metadata, precise temporal coordinates are added to each attack behavior node, forming a triple association of "attack behavior - phase label - time point," laying the foundation for subsequent temporal analysis. In this embodiment, for ambiguous behaviors across phases, a confidence scoring mechanism is introduced, combined with rules to determine the main phase label, ensuring the accuracy of timing anchoring.
[0047] S302: Divide the heterogeneous graph into continuous time segment windows and analyze the node interaction state to identify the dynamic interaction between attack behavior and system components, and construct the temporal correlation between attack behavior and system components.
[0048] Specifically, in terms of time dimension, a sliding time window algorithm is used to divide the graph into continuous time segments, analyze the node interactions within each window, and identify the dynamic role of "behavior-component" through temporal association rules. For example, after the "privilege escalation" behavior in window t1, the permission status of "server A" in window t2 changes to "administrator privileges", thus establishing a temporal association between the attack behavior and system components.
[0049] S303: By tracking state changes, obtain the disturbance propagation relationship between system components and business logic, and obtain the state association relationship between system components and business logic.
[0050] Specifically, the disturbance transmission relationship between "components and services" is captured by tracking state changes. For example, after the "PLC-023" parameter in window t3 becomes abnormal, the output deviation of the "voltage regulation module" in window t4 exceeds the threshold, forming a state association record.
[0051] S304: Based on time and state relationships, and combined with a pre-built topology relationship model, cross-validate the attack behavior nodes anchored by the attack sequence in terms of time and topology, and reconstruct the attack path across layers.
[0052] Specifically, at the topological level, a "node-neighborhood" association model is constructed by combining the physical and business topologies of the power system. For example, for IT layer nodes, directly reachable devices are identified based on the network topology; for OT layer nodes, their communication range is determined based on the industrial control network topology; and for business logic nodes, their upstream and downstream links are located based on the process dependency chain. Combining temporal and state associations, cross-validation of attack behavior nodes anchored to attack sequences is performed across time and topology dimensions to filter out false node pairs with no actual association, retain real and valid dynamic associations, and reconstruct the attack path across layers through the retained attack behavior nodes.
[0053] In this embodiment, based on time-series anchoring and dynamic correlation results, a complete propagation chain from the attack source to the business impact is constructed. The cross-layer reconstruction of the attack path specifically includes: S3041: Locate the initial attack node for the attack behavior node and filter subsequent nodes based on the trigger relationship edge and time sequence.
[0054] Specifically, the "starting point identification" algorithm is used to locate the initial node of the attack. For example, in terms of time sequence, the attack behavior node with the earliest timestamp is selected; in terms of topology, it is verified whether the node is located in the boundary area of the power system; and combined with the "context" field of the metadata, the initial access point of the attack is confirmed.
[0055] Furthermore, a "greedy search + pruning" strategy is adopted to expand the path along the timeline and topology chain. Specifically, starting from the initial node, subsequent attack behavior nodes are screened based on the trigger relationship edges and the time sequence; affected system components are associated through the influence relationship edges; propagation across the IT-OT layer is tracked based on the dependency relationship edges; and finally, the business-affected nodes are located through the "component-business" influence relationship.
[0056] S3042: Calculate the node importance score of subsequent nodes, remove subsequent nodes whose node importance score is lower than the set threshold, and associate the remaining subsequent nodes in chronological order to obtain the reconstructed attack path.
[0057] Specifically, during the path expansion process, a "critical node filtering" mechanism is introduced: nodes that play a decisive role in propagation, such as IT-OT boundary devices and core business components, are prioritized for retention, while redundant intermediate forwarding devices are eliminated. The node importance score calculation expression in this embodiment is as follows: (1) in, Represents a node The importance score in the propagation chain, d is the damping factor representing the probability of a node being randomly visited, N is the total number of nodes in the attack propagation chain, and In(u) is the set of predecessor nodes pointing to node u. Let be the edge weight from node v to node u. Let v be the set of all successor nodes. Represents the path from node v to node v. The edge weights are calculated based on the node importance scores. Subsequent nodes with scores below a set threshold will be pruned or removed to ensure the simplicity of the path and the prominence of key information. The remaining subsequent nodes will be associated to form a reconstructed attack path.
[0058] Following S3042 in this embodiment, the following is also included: S3043: By comparing and cross-validating the consistency of the attack path through multi-source data, and combining the results of manual review of the attack path, the association relationship of subsequent nodes is corrected to obtain the verified and optimized attack path.
[0059] Specifically, to ensure the accuracy of the reconstructed path, a path verification and optimization mechanism is included: on the one hand, the consistency of the path is verified by comparing multi-source data; on the other hand, high-risk paths are manually reviewed by power system security experts to obtain the results and correct any misjudged relationships in subsequent nodes. The final output attack path is presented in a structured chain form, including the attack behavior, affected components, business disturbances, timestamps, and correlation strength at each stage. A visual interface dynamically displays the cross-domain propagation process of the attack from the IT layer to the OT layer and then to the business layer, providing an intuitive and accurate basis for attack tracing, liability delineation, and defense strategy formulation.
[0060] S40: Based on the reconstructed attack path and heterogeneous graph, identify potential high-risk attack patterns and predict damage propagation. Adapt and optimize the damage propagation prediction results in conjunction with the business priorities of the power system.
[0061] Specifically, step S40, as the "intelligent decision-making core" of the entire modeling method, aims to, based on the heterogeneous graph and attack path reconstruction results, use graph representation learning and deep inference techniques to uncover potential high-risk attack patterns, accurately predict the propagation path and severity of damage from affected nodes to related services, and provide forward-looking decision support for power system security protection. Step S40 unfolds around the entire process of "graph feature enhancement - graph inference model construction - high-risk pattern recognition - damage propagation prediction - result adaptation and optimization," such as... Figure 4 As shown, step S40 includes: S401: Extract and quantize heterogeneous node and edge features from the heterogeneous graph to obtain enhanced graph features. Then, perform graph embedding and deep neural network fusion learning on the graph features to construct a graph reasoning model.
[0062] Specifically, graph feature enhancement is fundamental to achieving accurate inference. It requires multi-dimensional feature extraction and quantification of nodes and edges in heterogeneous graphs to provide rich input information for subsequent models. First, attribute structuring is performed on three types of heterogeneous nodes: attack behavior nodes extract features such as attack stage, technical complexity, and historical frequency; system component nodes extract features such as device importance level, network partition, and historical failure records; and business logic nodes extract features such as business priority, scope of affected users, and recovery difficulty. For edge features, the focus is on quantifying association strength. Specifically, influence relationships are weighted based on the degree of influence and duration; trigger relationships are quantified based on time interval and causal certainty; and dependency relationships are scored based on the tightness of dependency. Simultaneously, to capture the topological location features of nodes, the degree centrality (number of connected edges), betweenness centrality (path transit frequency), and closeness centrality (average distance to other nodes) are calculated to supplement structural feature vectors, achieving a fusion representation of "attribute features + topological features."
[0063] Furthermore, this application combines graph embedding with deep neural networks to achieve the learning and inference of global graph features. A two-level modeling architecture of "Node2Vec + GAT (Graph Attention Network)" is used to construct the graph inference model. The graph inference model construction process includes: S4011: The Node2Vec algorithm is used to perform graph embedding and vector mapping on heterogeneous node features, and corresponding weight coefficients are set for edge features to obtain node vectors and edge weight matrices.
[0064] Specifically, the Node2Vec algorithm is used to embed heterogeneous graphs. Node sequences are generated through biased random walks, and the Skip-gram model is used to map the features of heterogeneous nodes into low-dimensional dense vectors, resulting in node vectors. These vectors retain both the attribute features of the nodes and the topological relationships. To address the characteristics of heterogeneous edges, weight coefficients are set for different types of edges during the walk to construct an edge weight matrix, ensuring that the differentiated effects of heterogeneous relationships are fully learned.
[0065] S4012: By learning the multi-head attention mechanism of node vectors and edge weight matrices through a pre-trained GAT model, the semantic and structural roles of nodes in heterogeneous graphs are inferred, and a graph reasoning model is constructed.
[0066] Specifically, a pre-trained GAT model is constructed to perform deep processing on the embedded vectors. The model input consists of node vectors and edge weight matrices generated by Node2Vec. A multi-head attention mechanism is used to learn the attention a node pays to its neighbors. Specifically, for attack behavior nodes, the focus is on the subsequent behaviors they trigger and the system components they affect; for system component nodes, their dependencies on business logic nodes are prioritized; and for business logic nodes, the association weights with upstream and downstream links are strengthened. Through feature aggregation across multiple GAT layers, the model can learn the semantic and structural roles of nodes in the global graph, construct a graph reasoning model, and output node representation vectors containing global information, providing high-order feature support for risk identification and prediction.
[0067] S402: Train the attack nodes of potential attacks on the reconstructed attack path, construct the attack behavior chain with potential attack risk based on the training results, identify the corresponding attack patterns, and obtain the identification results of potential high-risk attack patterns.
[0068] Specifically, high-risk pattern recognition focuses on mining potentially dangerous attack behavior chains from the graph, providing precise targets for defense. The module, based on node representations output by GAT, employs two complementary strategies: supervised pattern matching and unsupervised anomaly detection. The supervised pattern matching complementary strategy specifically includes: S4021: Obtain historical high-risk attack data, mark the attack behavior node sequences in the reconstructed attack path that match the historical high-risk attack data, and obtain the high-risk attack pattern identification results.
[0069] Specifically, historical high-risk attack data is obtained by collecting historical high-risk attack cases. The corresponding attack behavior node sequences are marked as positive samples in the heterogeneous graph after reconstructing the attack path, which serve as the results of high-risk attack pattern identification.
[0070] S4022: Perform risk scoring on unlabeled reconstructed attack paths, screen potential attack nodes with scores higher than the set risk threshold, construct attack behavior chains, and identify corresponding attack patterns to obtain potential high-risk attack pattern identification results.
[0071] Specifically, the corresponding attack chain is obtained from the unlabeled reconstructed attack path, and the attack nodes on the attack chain are risk-scored. A BiLSTM classifier is trained to filter potential attack nodes with scores higher than a set risk threshold. The attack behavior chain is reconstructed, and the attack pattern of the current attack behavior chain is identified with reference to the high-risk attack pattern identification result, thus obtaining the potential high-risk attack pattern identification result.
[0072] The risk score calculation expression is as follows: (2) in, This represents the risk score of the attack chain; a higher value indicates a higher risk. It is the sigmoid activation function, which maps the output to the 0-1 interval, facilitating risk threshold determination. L is the length of the attack behavior node sequence. It is the weight coefficient of the i-th node. is the GAT representation vector of the i-th attack node, and b is the bias term used to adjust the scoring baseline.
[0073] The complementary strategy for unsupervised anomaly detection in this embodiment specifically includes: S4023: Obtain historical high-risk attack data to construct a normal sequence distribution model of attack behavior, and calculate the reconstruction error of the node sequence of the behavior to be detected in the heterogeneous graph.
[0074] Specifically, using historical high-risk attack data as a reference, a normal sequence distribution model of attack behavior is constructed, the attack behavior to be detected sequence in the heterogeneous spectrum is obtained, and the reconstruction error of the to be detected sequence is calculated.
[0075] S4024: When the reconstruction error exceeds the set error threshold, the node to be detected is identified as a high-risk attack mode, and the graph location is located by subgraph matching to obtain the identification result of the potential high-risk attack mode.
[0076] Specifically, when the reconstruction error exceeds a set error threshold, the corresponding node to be detected is determined to be an abnormal high-risk pattern. For the identified high-risk patterns, subgraph matching is used to locate their specific position in the global graph, extract the system components and business nodes involved, form a risk list of "attack chain - affected components - related business", and mark the core vulnerabilities of the pattern to form the identification results of potential high-risk attack patterns.
[0077] S403: Based on the high-risk attack pattern identification results, damage node location and propagation path analysis are performed on the relevant attack nodes through graph reasoning model to obtain damage propagation prediction results.
[0078] Specifically, based on known attack nodes or failed components, the propagation path and final impact of damage in the business logic are inferred. According to the high-risk attack pattern identification results, corresponding known attack nodes or failed components are obtained. In this embodiment, a bidirectional reasoning mechanism of "reverse tracing + forward prediction" is used for damage propagation prediction. Specifically, reverse tracing starts from the confirmed abnormal business nodes, uses the attention weights of the GAT model to reverse locate key influencing nodes, and then traces back to upstream system components along dependency edges to clarify the source and intermediate transmission nodes of the damage. Forward prediction starts from the known attack nodes, and uses an improved damage propagation probability formula to calculate the damage propagation probability of node u in the (t+1)th iteration based on the weights of the influence relationship edges and the business dependency chain. Initially, the damage probability of this node is set to 1.0, and then it is propagated to neighboring nodes according to the edge weight ratio. After multiple iterations, the converged probability value is the probability that each node is damaged. Simultaneously, the time decay factor formula is used to simulate the evolution of damage over time to obtain the damage propagation prediction result. The prediction result not only includes the damage propagation path but also quantifies the damage degree of each link and marks the shortest propagation time.
[0079] The improved formula for calculating the damage diffusion probability is shown below: (3) in, It is the probability of node v being damaged in the t-th iteration; The propagation coefficient is the efficiency of damage propagation along the edge; Let V be the edge weight from node v to node u. Let be the initial damage probability of node u.
[0080] The formula for the time decay factor is as follows: (4) in, Let be the attenuation coefficient at time t. t represents the decay rate, and t represents the time after the attack occurs.
[0081] S404: Based on the damage propagation prediction results and the business priorities of the power system, the core business nodes are weighted and the node damage scores are dynamically adjusted to optimize the damage propagation prediction results.
[0082] Specifically, the result adaptation and optimization process needs to be tailored to the actual business needs of the power system, making targeted adjustments to the inference and prediction results to improve the practicality of decision-making. Step S404 introduces a business priority weighting mechanism, assigning higher weight to the prediction results of core business nodes to ensure that the risks of high-value targets are given priority attention; and dynamically adjusting the damage severity score based on real-time operating status. Simultaneously, it supports conflict detection and correction. When the prediction results conflict with the physical constraints of the power system, it automatically corrects the propagation path and probability value, triggers a manual review process, and performs multiple optimizations on the damage propagation prediction results. The final output includes: a list of high-risk attack patterns, a damage propagation path topology map, and a core business impact assessment report, and is linked with the power dispatch system through an API interface.
[0083] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0084] In one embodiment, a power target damage propagation path modeling system based on attack chain graphs is provided. This system corresponds one-to-one with the power target damage propagation path modeling method based on attack chain graphs described in the above embodiments. Figure 5 As shown, this power target damage propagation path modeling system based on attack chain graphs includes a multi-source data acquisition and standardization module, a heterogeneous graph construction module, an attack path reconstruction module, and a risk reasoning and damage propagation prediction module. Detailed descriptions of each functional module are as follows: The multi-source data acquisition and standardization module is used to acquire multi-source heterogeneous data from the power system, and to perform standardized structure mapping and data quality optimization on the multi-source heterogeneous data to obtain standardized behavioral metadata. The heterogeneous graph construction module is used to extract heterogeneous nodes from standardized behavioral metadata and define the relationships between heterogeneous nodes to build an initial graph. The initial graph is then optimized by a combination of manual verification and an automated deduplication mechanism to obtain the heterogeneous graph. The attack path reconstruction module is used to anchor the attack sequence of attack behavior nodes in the heterogeneous graph, and to explore the correlation between attack behavior, system components, and business logic in the time and topology dimensions, and reconstruct the attack path across layers. The risk reasoning and damage propagation prediction module is used to identify potential high-risk attack patterns and predict damage propagation based on the reconstructed attack path and heterogeneous graph. The damage propagation prediction results are then adapted and optimized in conjunction with the business priorities of the power system.
[0085] This system, centered on the core objectives of accurately reconstructing attack paths and predicting damage propagation trends, constructs a comprehensive technical system encompassing "data standardization - graph construction - path reconstruction - risk prediction." Specifically, through a multi-source data collection and standardization module, heterogeneous data such as network traffic, device logs, permission configurations, and business documents are transformed into five-tuple metadata of <behavior object, action, timestamp, location, context>, eliminating semantic differences. Relying on a heterogeneous graph construction module, it accurately extracts three types of nodes: attack behavior, system components, and business logic, defining three types of relational edges: impact, trigger, and dependency, forming a structured topology graph. With the help of an attack path reconstruction module, combined with time-series anchoring and dynamic correlation analysis, it reconstructs the cross-IT-OT layer attack propagation chain from initial access to business impact. Through a risk reasoning and damage propagation prediction module, it utilizes Node2Vec graph embedding and GAT... The model learns graph features, identifies high-risk attack patterns, predicts damage propagation paths and severity based on a two-way reasoning mechanism, and optimizes the results by combining business priorities. Ultimately, it achieves closed-loop support from data collection to security decision-making, builds an attack damage propagation analysis system for the power system, and enhances the security protection capabilities and resilience of critical infrastructure.
[0086] Specific limitations regarding the power target damage propagation path modeling system based on attack chain graphs can be found in the limitations of the power target damage propagation path modeling method based on attack chain graphs mentioned above, and will not be repeated here. Each module in the aforementioned power target damage propagation path modeling system based on attack chain graphs can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0087] Those skilled in the art will recognize that the units of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application of the technical solution and the constraints involved. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.
[0088] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical functional division. In actual implementation, there may be other division methods, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored.
[0089] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0090] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0091] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.
Claims
1. A method for modeling the damage propagation path of an electric target based on an attack chain graph, characterized in that, The method includes: Collect multi-source heterogeneous data from the power system, and perform standardized structure mapping and data quality optimization on the multi-source heterogeneous data to obtain standardized behavioral metadata; Heterogeneous nodes are extracted from the standardized behavioral metadata, and the relationships between heterogeneous nodes are defined to construct an initial graph. The initial graph is then optimized by a combination of manual verification and an automated deduplication mechanism to obtain a heterogeneous graph. Attack timing is anchored for attack behavior nodes in the heterogeneous graph, and the correlation between attack behavior, system components, and business logic in time and topology dimensions is explored to reconstruct the attack path across layers. Based on the reconstructed attack path and the heterogeneous graph, potential high-risk attack patterns are identified and damage propagation is predicted. The damage propagation prediction results are then adapted and optimized in conjunction with the service priorities of the power system.
2. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 1, characterized in that, The process of extracting heterogeneous nodes from the standardized behavioral metadata and defining the relationships between these nodes to construct an initial graph, followed by optimization of the initial graph using a combination of manual verification and automated deduplication mechanisms to obtain a heterogeneous graph, specifically includes: The standardized behavioral metadata is extracted for key metadata and transformed into heterogeneous nodes containing attack behaviors, system components, and business logic. Temporal feature and semantic association analysis are performed on the key metadata, the association edges between the heterogeneous nodes are defined, and the association relationship between the association edges and the heterogeneous nodes is analyzed to construct an initial graph; The manual verification results of the initial map are obtained, and the initial map is deduplicated using the set automatic deduplication mechanism. The initial map is then dynamically optimized to obtain a heterogeneous map.
3. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 1, characterized in that, The process of anchoring the attack sequence of attack behavior nodes in the heterogeneous graph, mining the correlation between attack behavior, system components, and business logic in terms of time and topology, and reconstructing the attack path across layers specifically includes: Based on a pre-built attack phase labeling system, semantic matching is performed on the attack behavior nodes in the heterogeneous graph and attack phase labels are marked. The attack behavior nodes are then anchored in attack time sequence by combining the corresponding timestamps. The heterogeneous graph is divided into continuous time segment windows and the node interaction state is analyzed to identify the dynamic interaction between attack behavior and system components and to construct the time correlation between attack behavior and system components. By tracking state changes, the perturbation propagation relationship between system components and business logic can be obtained, thus revealing the state association relationship between system components and business logic. Based on the aforementioned time and state relationships, and combined with the pre-built topology association model, the attack behavior nodes anchored by the attack sequence are cross-validated in terms of time and topology, and the attack path is reconstructed across layers.
4. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 3, characterized in that, Based on the aforementioned time and state correlations, and combined with a pre-built topological correlation model, the attack behavior nodes anchored to the attack sequence undergo cross-validation in terms of time and topological dimensions. This cross-layer attack path reconstruction specifically includes: The attack behavior nodes are processed to locate the initial attack node, and subsequent nodes are filtered based on the trigger relationship edges and time order; Calculate the node importance score of the subsequent nodes, remove the subsequent nodes whose node importance score is lower than a set threshold, and associate the remaining subsequent nodes in chronological order to obtain the reconstructed attack path.
5. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 4, characterized in that, After calculating the node importance score of the subsequent nodes, removing subsequent nodes with node importance scores below a set threshold, and associating the remaining subsequent nodes in chronological order to obtain the reconstructed attack path, the process further includes: By comparing and cross-validating the consistency of attack paths through multi-source data, and combining the results of manual review of attack paths, the correlation between subsequent nodes is corrected to obtain the verified and optimized attack paths.
6. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 1, characterized in that, The process of identifying potential high-risk attack patterns and predicting damage propagation based on the reconstructed attack path and the heterogeneous graph, and then adapting and optimizing the damage propagation prediction results in conjunction with the service priorities of the power system, specifically includes: The heterogeneous graph is subjected to heterogeneous node feature and edge feature extraction and quantization to obtain the graph features after feature enhancement. The graph features are then subjected to graph embedding and deep neural network fusion learning to construct a graph reasoning model. The reconstructed attack path is trained with potential attack nodes. Based on the training results, an attack behavior chain with potential attack risk is constructed and the corresponding attack pattern is identified to obtain the identification result of potential high-risk attack patterns. Based on the high-risk attack pattern identification results, the graph reasoning model is used to locate the damage nodes and analyze the propagation path of the relevant attack nodes to obtain the damage propagation prediction results. Based on the damage propagation prediction results and the service priorities of the power system, the core service nodes are weighted and the node damage scores are dynamically adjusted to optimize the damage propagation prediction results.
7. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 6, characterized in that, The process of extracting and quantizing heterogeneous node and edge features from the heterogeneous graph to obtain enhanced graph features, and then performing graph embedding and deep neural network fusion learning on the graph features to construct the graph reasoning model includes: The heterogeneous node features are processed by graph embedding and vector mapping using the Node2Vec algorithm, and corresponding weight coefficients are set for the edge features to obtain node vectors and edge weight matrices. By using a pre-trained GAT model to learn the node vectors and edge weight matrices through a multi-head attention mechanism, the semantic and structural roles of nodes in the heterogeneous graph are inferred, thus constructing a graph reasoning model.
8. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 6, characterized in that, The process of training attack nodes for potential attacks on the reconstructed attack path, constructing attack behavior chains with potential attack risks based on the training results, identifying corresponding attack patterns, and obtaining potential high-risk attack pattern identification results specifically includes: Acquire historical high-risk attack data, mark the attack behavior node sequence in the reconstructed attack path that matches the historical high-risk attack data, and obtain the high-risk attack pattern identification result; Risk scoring is performed on unlabeled reconstructed attack paths. Potential attack nodes with scores higher than a set risk threshold are selected to construct attack behavior chains and identify corresponding attack patterns, thus obtaining the identification results of potential high-risk attack patterns.
9. The method for modeling the damage propagation path of an electric target based on an attack chain graph according to claim 8, characterized in that, The step of training attack nodes for potential attacks on the reconstructed attack path, constructing attack behavior chains with potential attack risks based on the training results, identifying corresponding attack patterns, and obtaining potential high-risk attack pattern identification results also includes: A normal sequence distribution model of attack behavior is constructed by acquiring historical high-risk attack data, and the reconstruction error of the node sequence of the behavior to be detected in the heterogeneous graph is calculated. When the reconstruction error exceeds the set error threshold, the node to be detected is identified as a high-risk attack mode, and the graph location is located by subgraph matching to obtain the identification result of the potential high-risk attack mode.
10. A power target damage propagation path modeling system based on attack chain graphs, characterized in that, The system is applied to the power target damage propagation path modeling method based on attack chain graphs as described in any one of claims 1-9, and the system comprises: The multi-source data acquisition and standardization module is used to acquire multi-source heterogeneous data from the power system, and to perform standardized structure mapping and data quality optimization processing on the multi-source heterogeneous data to obtain standardized behavioral metadata. The heterogeneous graph construction module is used to extract heterogeneous nodes from the standardized behavioral metadata and define the association between heterogeneous nodes to construct an initial graph. The initial graph is then optimized by a combination of manual verification and an automated deduplication mechanism to obtain the heterogeneous graph. The attack path reconstruction module is used to anchor the attack behavior nodes in the heterogeneous graph in terms of attack timing, and to mine the correlation between attack behavior, system components, and business logic in the time and topology dimensions, and reconstruct the attack path across layers. The risk reasoning and damage propagation prediction module is used to identify potential high-risk attack patterns and predict damage propagation based on the reconstructed attack path and the heterogeneous graph, and to adapt and optimize the damage propagation prediction results in combination with the business priorities of the power system.
Citation Information
Cited By
Multi-dimensional intention feature-based power grid malicious code attack chain construction method and system
CN122120027A
Power grid malicious code attack chain construction method and system based on multi-dimensional intention features
CN122120027B