Power system protection efficiency dynamic evaluation method and system based on attack and defense confrontation

The protection effectiveness assessment method, which uses real-time data acquisition and dynamic weight adjustment, solves the problems of lagging assessment results and resource waste in existing technologies. It enables high-frequency, real-time, and comprehensive assessment of the protection effectiveness of power systems, ensuring that the assessment results are synchronized with actual combat effectiveness and providing timely suggestions for optimizing protection strategies.

CN121792385APending Publication Date: 2026-04-03NARI INFORMATION & COMM TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing methods for evaluating the effectiveness of cybersecurity defenses suffer from poor dynamic adaptability, one-sided evaluation dimensions, rigid weighting mechanisms, and insufficient real-time performance when facing dynamic and intelligent cybersecurity attacks and defenses. They are unable to respond promptly to high-frequency and dynamic attack changes, resulting in delayed evaluation results and wasted resources.

Method used

By employing a data collection frequency of seconds, a multi-dimensional dynamic indicator set is generated. An attack risk level is calculated through a weighted scoring model, and the indicator weights are dynamically adjusted according to the risk level. Combined with sliding window and historical data calibration, the protection effectiveness can be evaluated in real time.

Benefits of technology

The assessment cycle has been shortened from 24 hours to 10 seconds, and the assessment results are synchronized with actual combat effectiveness. It comprehensively covers attack penetration capabilities, defense blocking effects, and resource consumption, improving the accuracy and timeliness of the assessment and providing timely basis for the optimization of defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792385A_ABST
    Figure CN121792385A_ABST
Patent Text Reader

Abstract

The invention discloses a power system protection efficiency dynamic evaluation method and system based on attack and defense confrontation, which are used for solving the technical problems of staticization, single index, weight distribution solidification and insufficient real-time performance of the traditional evaluation method. According to the method, a multi-dimensional dynamic index system of attack breakthrough ability, protection blocking effect, resource consumption and service adaptation is constructed, index weights are dynamically adjusted according to attack risk levels, and a high-frequency update efficiency value of a model is calculated in real time in combination with a sliding window, so that dynamic quantitative evaluation of protection efficiency is realized. According to the method, attack and defense changes can be accurately captured, protection and service costs are balanced, a timely decision basis is provided for protection strategy optimization, and the actual combat capability of network security protection of the power system is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for dynamic evaluation of protection effectiveness, and more particularly to a method and system for dynamic evaluation of power system protection effectiveness based on offensive and defensive confrontation. Background Technology

[0002] As cybersecurity offense and defense enter a dynamic and intelligent phase, critical information infrastructures such as energy and power, and industrial control face increasingly severe threats. Attack methods have evolved from traditional port scanning and password brute-force attacks to more complex forms such as protocol message forgery, exploitation of zero-day vulnerabilities, and cross-regional coordinated attacks. These attacks are highly adaptable and stealthy, placing extremely high demands on the real-time response and dynamic adjustment capabilities of protection systems. Against this backdrop, accurately assessing the practical effectiveness of protection systems and promptly identifying and optimizing defense strategies have become core challenges in ensuring the continuity of critical business operations.

[0003] Currently, the commonly used methods for evaluating protective effectiveness in this field are still based on static indicators and fixed weights. However, this traditional approach is increasingly showing its technical limitations when dealing with high-frequency, dynamic, and combat-oriented attacks, mainly due to the following inherent defects:

[0004] 1. Poor dynamic adaptability, and the assessment is seriously lagging behind actual combat: Because the indicator design does not link dynamic parameters such as attack mutation speed and real-time interception effect, the assessment results cannot reflect the real-time status of attack and defense confrontation.

[0005] 2. One-sided evaluation dimensions, neglecting business continuity assurance: Existing solutions focus too much on protection effectiveness indicators such as attack interception rate, while completely ignoring the resource consumption of the protection measures themselves and their impact on normal business.

[0006] 3. Rigid weighting mechanism, unable to adapt to dynamic risk changes: The fixed weight allocation cannot be adjusted according to the real-time level of attack threats. Facing low-risk port scanning attacks, focusing on the interception rate with high weights leads to wasted resources; while when encountering high-risk command spoofing attacks, the weights of relevant indicators are not increased to focus on core protection targets, resulting in a mismatch between the assessment focus and the current greatest risk.

[0007] 4. Severe lack of real-time capability, making timely decision-making difficult: The 24-hour assessment cycle is completely inadequate to handle new attacks that mutate at minute or even second-level speeds. The optimization and adjustment of protection strategies are severely delayed, often only being discovered through periodic reports after an attack has occurred and caused impact, thus missing the golden window of opportunity for proactive defense. Summary of the Invention

[0008] Purpose of the invention: The first purpose of the invention is to provide a dynamic evaluation method for protection effectiveness that is highly adaptable, comprehensive in evaluation dimensions, flexibly adjustable in weights, and reliable in evaluation results, and can adapt to different attack risks; the second purpose of the invention is to provide a system for implementing the method.

[0009] Technical solution: The dynamic evaluation method for power system protection effectiveness based on offensive and defensive confrontation described in this invention includes the following steps:

[0010] (1) Data collection: At a preset collection frequency of seconds or sub-seconds, attack behavior data, protection status data and business operation data are collected in real time during the attack and defense confrontation process;

[0011] (2) Indicator processing: The collected data is cleaned and standardized to generate a multi-dimensional dynamic indicator set, including attack breakthrough capability indicators, protection and blocking effect indicators, and resource consumption and business adaptation indicators.

[0012] (3) Weight Adaptive: Based on the attack mutation rate, attack link breakthrough success rate, target business importance and business response delay increment, the attack risk score is calculated through a weighted scoring model, and the attack risk score is used to determine the low-risk, medium-risk or high-risk level; then, according to the preset weight mapping strategy, the weights are dynamically assigned to the multi-dimensional dynamic indicator set; the strategy is configured such that the higher the risk level, the higher the total weight of the attack breakthrough capability indicator and the protection blocking effect indicator.

[0013] (4) Performance calculation: A sliding time window with a preset window length of tens of seconds is used. The sliding is performed at a preset sliding frequency of several seconds to tens of seconds. The weighted sum of each index within the window is calculated to obtain the preliminary performance value. The preliminary performance value is then corrected based on the calibration factor matched from the pre-built historical database, and the final protection performance value is output.

[0014] Preferably, the attack behavior data in step (1) includes attack protocol messages, attack path records and attack mutation characteristics; the protection status data includes protection device resource usage, attack interception records and protection rule update status; and the business operation data includes normal business response delay, business interruption records and key physical quantities.

[0015] Preferably, the attack behavior data in step (1) is collected by deploying a traffic mirroring port and a protocol parsing proxy.

[0016] Preferably, the preset acquisition frequency in step (1) is 10 seconds / time.

[0017] Preferably, the attack breakthrough capability indicators in step (2) include the attack breakthrough success rate and attack mutation speed; the protection blocking effect indicators include the attack packet interception rate, malicious behavior termination rate and false alarm rate; the resource consumption and service adaptation indicators include the protection resource consumption ratio, service response delay increment and attack recovery time.

[0018] Preferably, the calculation formula for the weighted scoring model in step (3) is:

[0019] Risk score = 0.3 × attack mutation rate standardized value + 0.3 × attack link breakthrough success rate + 0.2 × target business importance assignment + 0.2 × business response delay increment standardized value;

[0020] Specifically, an attack is classified as low-risk when the risk score is less than 0.4, medium-risk when the risk score is less than 0.7 when the risk score is less than 0.4 when the risk score is less than 0.7 when the risk score is greater than or equal to ... less than 0.4 when the

[0021] Preferably, the weight mapping strategy in step (3) is as follows: under low-risk attacks, the highest weight is assigned to the resource consumption and business adaptation indicators; under high-risk attacks, the highest total weight is assigned to the protection and blocking effect indicators and the attack breakthrough capability indicators; under medium-risk attacks, the weights of various indicators are evenly distributed.

[0022] Preferably, the weight adaptation in step (3) also includes a weight smooth transition mechanism: when the attack risk level changes, the weights of each indicator are updated linearly and gradually to the new weights of the target risk level through a preset number of updates.

[0023] Preferably, the preset window length in step (4) is 30 seconds and the preset sliding frequency is 10 seconds / time.

[0024] The protective effectiveness dynamic evaluation system of the present invention includes a data acquisition module, an index processing module, a weight adaptive module, and an effectiveness calculation module that communicate with each other.

[0025] The data acquisition module is configured to collect attack behavior data, protection status data, and business operation data in real time at a second-level or sub-second-level acquisition frequency.

[0026] The indicator processing module is configured to clean and standardize the collected data to generate a multi-dimensional dynamic indicator set for use by the weight adaptation module.

[0027] The weight adaptive module includes an attack risk level determination submodule and a weight mapping submodule. The attack risk level determination submodule is configured to perform weighted scoring model calculation; the weight mapping submodule is configured to store and call weight mapping strategies.

[0028] The performance calculation module is configured to perform sliding window calculations and performance value calibration.

[0029] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages: (1) The evaluation cycle is shortened from the traditional 24 hours to 10 seconds, which can respond to the changes in attacks in a timely manner and ensure that the evaluation results are synchronized with the actual combat effectiveness; (2) The evaluation dimensions are comprehensive, covering three major categories of indicators: attack breakthrough capability, protection blocking effect, resource consumption and business adaptation, which can simultaneously quantify the protection effect and business impact; (3) The evaluation focus is dynamically adjusted according to the attack risk level, solving the defect of fixed weights and improving the accuracy of evaluation; (4) The effectiveness value can be updated frequently, providing a timely basis for the optimization of protection strategies. Attached Figure Description

[0030] Figure 1 This is the overall technical architecture of the present invention;

[0031] Figure 2 This is the flow of the weight adaptive adjustment algorithm of the present invention. Detailed Implementation

[0032] The technical solution of the present invention will be further described below with reference to the accompanying drawings and verification examples.

[0033] As shown in the attached figure, the technical architecture of the present invention includes four layers: a data acquisition layer, an indicator processing layer, a weight adaptive layer, and a performance calculation layer.

[0034] I. Data Acquisition Layer (A)

[0035] It includes an attack behavior data collection module (A1), a protection status data collection module (A2), and a business operation data collection module (A3), which respectively collect attack traces, protection device status, and business operation parameters during the attack and defense confrontation process, achieving full-domain data coverage. At the same time, the data collection frequency is 10 seconds / time to ensure real-time performance. The specific collection content and interfaces are as follows:

[0036] 1. Attack Behavior Data Acquisition Module (A1)

[0037] (1) Collection content: attack protocol messages (such as IEC 61850 MMS / GOOSE, Modbus, extract "message tampering fields, forged signatures, and sending frequency"), attack path records (source IP / destination IP, attack link breakthrough status), and attack mutation characteristics (number of times attack message characteristics change per unit time).

[0038] (2) Data collection interface: Deploy traffic mirroring port (mirroring communication traffic from the core switch), protocol parsing agent (parsing industrial control protocol fields), and data collection frequency of 1ms / time (message level) and 10 seconds / time (statistical level).

[0039] 2. Protection Status Data Acquisition Module (A2)

[0040] (1) Data collected: resource usage of protection equipment (CPU / memory / bandwidth usage), attack interception records (number of intercepted packets, number of terminated malicious processes), and protection rule update status (number of new rules, rule matching success rate).

[0041] (2) Data collection interface: Connects to firewalls and intrusion detection systems via SNMP protocol, and reads logs from protection devices via API interface, with a collection frequency of 10 seconds / time;

[0042] 3. Business Operation Data Acquisition Module (A3)

[0043] (1) Collection content: normal business response delay (such as AGC command transmission delay, distribution network data collection delay), business interruption record (number of times normal data was mistakenly intercepted, business recovery time), key physical quantities (such as grid frequency, inverter output);

[0044] (2) Data acquisition interface: Connect to power EMS system and industrial SCADA system, with a data acquisition frequency of 50ms / time (real-time business) and 10 seconds / time (statistical business).

[0045] II. Indicator Processing Layer

[0046] Invalid data is filtered out using the indicator cleaning submodule (B1), and the indicators are normalized to the [0,1] interval using the indicator standardization submodule (B2) to eliminate dimensional differences. Based on the collected data, three categories of eight dynamic indicators are designed. The indicator definitions, calculation methods, and thresholds are shown in the table below:

[0047]

[0048]

[0049] III. Weight Adaptive Layer (C)

[0050] The attack risk level determination submodule (C1) determines the risk level based on the attack intent, scope of impact, etc., and the weight mapping submodule (C2) calls the preset "risk-weight" mapping matrix to output dynamic weights.

[0051] 1. Attack Risk Level Determination (Core Logic of C1 Submodule)

[0052] The attack risk level determination submodule constructs a "multi-dimensional risk assessment model" and combines attack behavior data with business impact correlation analysis to classify attack risks into three levels: low, medium, and high. The specific determination rules are as follows:

[0053] (1) Input parameters: attack mutation rate (S2), attack link breakthrough success rate (S1), target service importance (assigned according to the power system service type, such as 1.0 for dispatch instruction transmission service and 0.5 for ordinary data acquisition service), and service response delay increment (R2).

[0054] (2) Risk score calculation: The risk score is calculated using a weighted summation formula. The formula is:

[0055]

[0056] in, The normalized value for the attack mutation rate is calculated through linear normalization: when When the original value is between 0 and 0.05 times / second (inclusive), it is mapped to the interval [0, 0.5]; when... When the original value is greater than 0.05 times / second (including the endpoint), it is mapped to the interval [0.5, 1.0]; if Original value = 0.05 times / second, normalized value = 0.5.

[0057] Assign a value (0.5-1.0) to the target business importance.

[0058] The normalized value for the incremental delay of the service response is calculated through linear normalization: when the original value of R2 is between 0 and 10 milliseconds (inclusive), it is mapped to the interval [0, 0.3]; when the original value of R2 is between 10 and 100 milliseconds (inclusive), it is mapped to the interval [0.3, 0.7]; when the original value of R2 is greater than 100 milliseconds, it is mapped to the interval [0.7, 1.0]. The critical value is handled as follows: if the original value of R2 is equal to 10 milliseconds, the normalized value is 0.3; if it is equal to 100 milliseconds, the normalized value is 0.7.

[0059] (3) Level determination threshold: when When the value is less than 0.4, it is considered a low-risk attack; when 0.4 ≤ When <0.7, it is judged as a medium-risk attack; when If the value is ≥0.7, it is considered a high-risk attack.

[0060] For example, a certain attack =0.03 times / second ( S1=20%, =0.8、 =8ms ( ),but =0.3×0.3+0.3×0.2+0.2×0.8+0.2×0.2=0.33, which is judged as a low-risk attack.

[0061] 2. Risk-Weight Mapping (Core Logic of C2 Submodule)

[0062] The weight mapping submodule dynamically allocates the weights of 8 indicators across 3 categories based on a preset "risk level - indicator weight" mapping matrix and the risk level output by the C1 submodule. The mapping matrix is ​​shown in the table below:

[0063]

[0064]

[0065] Mapping logic explanation: Under low-risk attacks, priority is given to resource consumption and business adaptability (weight 0.5) to avoid excessive protection consuming business resources; under high-risk attacks, priority is given to the protection blocking effect (weight 0.5) and attack breakthrough capability (weight 0.4) to ensure that core business is not damaged by attacks; under medium-risk attacks, the weights of the three types of indicators are evenly distributed to take into account both protection effect and business impact.

[0066] 3. Dynamic weight adjustment mechanism

[0067] When the attack risk level changes (e.g., a low-risk attack evolves into a medium-risk attack), the weight mapping submodule updates the indicator weights in real time, with an update delay of ≤1 second. Simultaneously, a "weight smooth transition" logic is implemented to prevent performance value fluctuations caused by sudden weight changes: if the current weight is... The target weight is Then the weights after the t-th update (t=1,2,...,10) After 10 updates, the target weight is completely switched. For example, when switching from low risk to medium risk, the R1 weight transitions from 0.2 to 0.15, with the first update being 0.195, the second being 0.19, ..., and the tenth being 0.15.

[0068] IV. Performance Calculation Layer (D)

[0069] The sliding window calculation submodule (D1) calculates the performance value by weighted summation with a 30-second window. The performance value calibration submodule (D2) corrects the calculation deviation based on historical data (such as performance value anomalies caused by data fluctuations in the early stages of an attack).

[0070] 1. Sliding window calculation submodule (D1)

[0071] (1) Window settings: Use a fixed time window (default 30 seconds), slide once every 10 seconds, that is, window 1 covers the data of "0-30 seconds", window 2 covers the data of "10-40 seconds", and so on, to ensure that the latest performance value is output once every 10 seconds.

[0072] (2) Indicator Score Calculation: Calculate the score for the standardized indicator data (after processing by the B2 submodule) within the window according to the indicator type:

[0073] (3) Positive indicators (P1, P2): Score = Standardized value × 100 (e.g., if the standardized value of P1 is 0.92, the score = 92 points);

[0074] (4) Negative indicators (S1, S2, P3, R1, R2, R3): Score = (1 - standardized value) × 100 (e.g., if the standardized value of S1 is 0.2, the score = 80 points).

[0075] (5) Preliminary calculation of performance value: Based on the dynamic weights output by the weighted adaptive layer, the scores of each indicator within the window are weighted and summed to obtain the preliminary performance value. The formula is ( The dynamic weight of the i-th indicator is... (Window score for the i-th indicator)

[0076] 2. Performance Value Calibration Submodule (D2)

[0077] (1) Calibration Factor Calculation: A "calibration factor library" is constructed based on historical data to store performance value correction coefficients for different attack types and business scenarios. The calculation basis of calibration factor K is "the degree of matching between historical window performance values ​​and actual attack consequences". If a certain window's performance value is... =85 points, but a minor business interruption actually occurred (consequence level 1), then a correction factor K=0.95 will be applied based on historical data; if If the score is 70 and there are no actual consequences of the attack (consequence level 0), then K = 1.05.

[0078] (2) Calculation of final performance value: final performance value And constrain the results to the interval of 0-100 (if If >100, take 100; if <0, take 0). For example, a certain window =82 points, the matching calibration factor K=0.98, then =82×0.98=80.36 points.

[0079] Verification Example

[0080] Taking a scenario where a provincial power dispatch center encountered a "forged IEC 61850 GOOSE message attack" as an example, the entire process from data collection to optimization suggestion output is fully demonstrated. The implementation period is from 08:00 to 08:30 on May 20, 2024 (30 minutes in total).

[0081] 1. Data acquisition layer operation (08:00:00-08:00:10)

[0082] (1) Attack behavior data collection: The traffic mirroring port of the core switch captured the first forged GOOSE packet (source IP: 192.168.10.25, destination IP: 192.168.20.5, the packet tampering field is "trip command code") at 08:00:00. The edge computing node parses the packet characteristics through the pysnmp library and records the attack mutation speed (as of 08:00:10, the number of mutations V=2 times, the time window ∆t=10 seconds, S2=0.2 times / second) and the attack link breakthrough status (the "firewall access control list" link has been broken, the "IDS feature detection" link has not been broken, the number of protection links n=2, the number of breakthroughs C1=1, C2=0, the total number of attacks T1=1, T2=1, S1=(1 / 2)×[(1 / 1)+(0 / 1)]=50%).

[0083] (2) Protection status data collection: At 08:00:10, the firewall log showed that the number of blocked attack packets I=8 times and the number of missed packets L=2 times (P1=8 / (8+2)×100%=80%); the IDS recorded the number of terminated malicious processes K=3 times and the number of unterminated processes M=1 time (P2=3 / (3+1)×100%=75%); protection device resource usage: firewall CPU utilization C p =65%, Memory utilization rate M p =40%, bandwidth utilization B p =30%, attacker consumes CPU resources C a =15%, Memory Resources M a =10%, Bandwidth Resources B a =5%, and we can calculate R1=(0.4×65+0.3×40+0.3×30) / (0.4×15+0.3×10+0.3×5) = (26+12+9) / (6+3+1.5)=47 / 10.5≈4.48.

[0084] (3) Business operation data acquisition: The power EMS system displays the AGC command transmission delay D when protection is activated. p=18ms, delay D0=8ms when protection is turned off (R2=18-8=10ms); number of normal GOOSE packets mistakenly blocked W=1 time, number of packets correctly allowed Z=99 times (P3=1 / (1+99)×100%=1%); attack did not cause protection function to malfunction, attack recovery time R3=0 seconds.

[0085] 2. Indicator processing layer operation (08:00:10-08:00:20)

[0086] Indicator Cleaning: After receiving the above data at 08:00:10, the indicator cleaning service detected that "attack mutation rate S2 = 0.2 times / second" exceeded the normal range (0-0.1 times / second). However, by comparing it with the historical attack data of the threat intelligence platform (a similar attack occurred in March 2024, with S2 = 0.18 times / second), the data was determined to be valid and no filtering was required; no missing data was found and no interpolation was required.

[0087] Indicator Standardization: The original values ​​of each indicator were processed using the Min-Max normalization algorithm. The specific results are as follows:

[0088] S1=50%: Normalized value = (50-0) / (50-0) = 1.0 (negative indicator, upper threshold 50%).

[0089] S2 = 0.2 times / second: Normalized value = (0.2-0) / (0.1-0) = 1.0 (exceeding the threshold limit of 0.1 times / second, treated as 1.0, a negative indicator);

[0090] P1=80%: Normalized value = (80-0) / (100-0) = 0.8 (positive indicator);

[0091] P2=75%: Normalized value = (75-0) / (100-0) = 0.75 (positive indicator);

[0092] P3=1%: Normalized value = (1-0) / (2-0) = 0.5 (negative indicator, upper threshold 2%).

[0093] R1=4.48: Normalized value = (4.48-1) / (10-1)=0.387 (negative indicator, threshold range 1-10).

[0094] R2=10ms: Normalized value = (10-0) / (10-0) = 1.0 (10ms is the upper limit of the threshold in industrial scenarios, a negative indicator).

[0095] R3=0 seconds: Normalized value = (0-0) / (300-0) = 0 (negative indicator).

[0096] 3. Weighted adaptive layer operation (08:00:20-08:00:30)

[0097] (1) Attack risk level determination: Calculate R using the risk scoring formula. sore The input parameters include:

[0098] S 2norm =1.0 (S2's original value is 0.2 times / second, linearly normalized according to ">0.05 times / second → 0.5-1.0", here it exceeds the upper limit of the threshold, so we take 1.0).

[0099] S1 = 50% (i.e., 0.5);

[0100] Bᵢ mp =1.0 (Scheduling instruction transmission service, assigned value 1.0);

[0101] R 2no ᵣ m =1.0 (The original value of R2 is 10ms. After linear normalization according to "0-10ms→0-0.3", the upper threshold is reached here, so it is corrected to 0.3. The original normalization rule is "0-10ms→0-0.3", therefore, when R2=10ms, R...) 2no ᵣ m =(10-0) / (10-0)×0.3=0.3).

[0102] Substitute into the formula: R so ᵣ e =0.3×1.0 + 0.3×0.5 + 0.2×1.0 + 0.2×0.3=0.3+0.15+0.2+0.06=0.71, because R so ᵣ e A value ≥0.7 is considered a high-risk attack.

[0103] (2) Risk-Weight Mapping: Call the "Risk Level - Indicator Weight" mapping matrix (high-risk attack), and assign the weights of each indicator as follows:

[0104] Attack breakthrough capability index (total weight 0.4): S1=0.2, S2=0.2;

[0105] Protective and blocking effectiveness indicators (total weight 0.5): P1=0.25, P2=0.2, P3=0.05;

[0106] Resource consumption and business compatibility metrics (total weight 0.1): R1=0.05, R2=0.03, R3=0.02.

[0107] (3) Dynamic weight adjustment: Since the current attack is initially determined to be high-risk, there is no need for a smooth transition (the initial weight is the default low-risk weight, and the first adjustment directly adopts the target weight). The weight update delay is 0.8 seconds (meeting the requirement of ≤1 second).

[0108] 4. Performance calculation layer operation (08:00:30-08:01:00)

[0109] (1) Sliding window calculation: The first sliding window covers the data from "08:00:00 to 08:00:30" and calculates the scores for each indicator:

[0110] Positive indicators: P1 score = 0.8 × 100 = 80 points; P2 score = 0.75 × 100 = 75 points;

[0111] Negative indicators: S1 score = (1-1.0)×100 = 0 points; S2 score = (1-1.0)×100 = 0 points; P3 score = (1-0.5)×100 = 50 points; R1 score = (1-0.387)×100≈61.3 points; R2 score = (1-0.3)×100 = 70 points; R3 score = (1-0)×100 = 100 points;

[0112] Preliminary performance value E p ᵣ e =0.2×0 + 0.2×0 + 0.25×80 + 0.2×75 + 0.05×50 + 0.05×61.3 + 0.03×70 + 0.02×100=0+0+20+15+2.5+3.065+2.1+2=44.665 points.

[0113] (2) Performance value calibration: Match historical data of the "high-risk attack + GOOSE message attack" scenario from the calibration factor library. In this scenario, E p ᵣ e A score of 44.665 corresponds to the actual attack consequence of "no equipment tripping, but service latency approaching the threshold," matching the calibration factor K=1.02 (because in similar historical scenarios, this E...). p ᵣ e The actual performance is slightly higher than the calculated value, resulting in a final performance value. =44.665×1.02≈45.56 points (constrained within the 0-100 point range, no adjustment required).

Claims

1. A dynamic evaluation method for the protection effectiveness of power systems based on offensive and defensive confrontation, characterized in that, Includes the following steps: (1) Data collection: At a preset collection frequency of seconds or sub-seconds, attack behavior data, protection status data and business operation data are collected in real time during the attack and defense confrontation process; (2) Indicator processing: The collected data is cleaned and standardized to generate a multi-dimensional dynamic indicator set, including attack breakthrough capability indicators, protection and blocking effect indicators, and resource consumption and business adaptation indicators. (3) Weight Adaptive: Based on the attack mutation rate, attack link breakthrough success rate, target business importance and business response delay increment, the attack risk score is calculated through a weighted scoring model, and the low-risk, medium-risk or high-risk level is determined according to the attack risk score. Then, according to the preset weight mapping strategy, weights are dynamically assigned to the multi-dimensional dynamic indicator set; the strategy is configured such that the higher the risk level, the higher the sum of the weights of the attack breakthrough capability indicator and the protection blocking effect indicator. (4) Performance calculation: A sliding time window with a preset window length of tens of seconds is used. The sliding is performed at a preset sliding frequency of several seconds to tens of seconds. The weighted sum of each index within the window is calculated to obtain the preliminary performance value. The preliminary performance value is then corrected based on the calibration factor matched from the pre-built historical database, and the final protection performance value is output.

2. The method according to claim 1, characterized in that, The attack behavior data mentioned in step (1) includes attack protocol messages, attack path records and attack mutation characteristics; the protection status data includes protection device resource usage, attack interception records and protection rule update status; and the business operation data includes normal business response delay, business interruption records and key physical quantities.

3. The method according to claim 1, characterized in that, The attack behavior data mentioned in step (1) is collected by deploying traffic mirroring ports and protocol parsing proxies.

4. The method according to claim 1, characterized in that, The preset acquisition frequency in step (1) is 10 seconds / time.

5. The method according to claim 1, characterized in that, The attack breakthrough capability indicators mentioned in step (2) include the attack breakthrough success rate and attack mutation speed; the protection blocking effect indicators include the attack packet interception rate, malicious behavior termination rate and false alarm rate; the resource consumption and service adaptation indicators include the protection resource consumption ratio, service response delay increment and attack recovery time.

6. The method according to claim 1, characterized in that, The calculation formula for the weighted scoring model mentioned in step (3) is as follows: Risk score = 0.3 × attack mutation rate standardized value + 0.3 × attack link breakthrough success rate + 0.2 × target business importance assignment + 0.2 × business response delay increment standardized value; Specifically, an attack is classified as low-risk when the risk score is less than 0.4, medium-risk when the risk score is less than 0.7 when the risk score is less than 0.4 when the risk score is less than 0.7 when the risk score is greater than or equal to ... less than 0.4 when the 7. The method according to claim 1, characterized in that, The weight mapping strategy described in step (3) is as follows: under low-risk attacks, the highest weight is assigned to the resource consumption and business adaptation indicators; under high-risk attacks, the highest total weight is assigned to the protection and blocking effect indicators and the attack breakthrough capability indicators; under medium-risk attacks, the weights of various indicators are evenly distributed.

8. The method according to claim 1, characterized in that, The weight adaptation mentioned in step (3) also includes a weight smooth transition mechanism: when the attack risk level changes, the weights of each indicator are updated linearly and gradually to the new weights of the target risk level through a preset number of updates.

9. The method according to claim 1, characterized in that, The preset window length in step (4) is 30 seconds, and the preset sliding frequency is 10 seconds / time.

10. A dynamic evaluation system for protective effectiveness in implementing the method according to any one of claims 1-9, characterized in that, It includes a data acquisition module that communicates with each other, an indicator processing module, a weight adaptive module, and a performance calculation module; The data acquisition module is configured to collect attack behavior data, protection status data, and business operation data in real time at a second-level or sub-second-level acquisition frequency. The indicator processing module is configured to clean and standardize the collected data to generate a multi-dimensional dynamic indicator set for use by the weight adaptation module. The weight adaptive module includes an attack risk level determination submodule and a weight mapping submodule. The attack risk level determination submodule is configured to perform weighted scoring model calculation; the weight mapping submodule is configured to store and call weight mapping strategies. The performance calculation module is configured to perform sliding window calculations and performance value calibration.