Power system network security protection method based on flexible grayscale adaptive control
By using a flexible gray-scale adaptive control method, power system data is collected and analyzed in real time, multi-dimensional feature factors are extracted, comprehensive security risk gray values are calculated, and protection strategies are dynamically adjusted. This solves the shortcomings of traditional power system network security protection and ensures system stability and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-04-14
AI Technical Summary
Traditional power system cybersecurity protection methods cannot effectively identify advanced persistent threats and fake data injection attacks, leading to power system instability and potentially causing frequency fluctuations, malfunctions of protection devices, power flow oscillations, or even large-scale power outages.
The method based on flexible gray-scale adaptive control extracts multi-dimensional security feature factors by collecting network traffic, operation status and security log data in real time, performs fusion calculation using flexible gray-scale adaptive control algorithm, outputs continuous comprehensive security risk gray-scale values, and determines flexible security protection strategies based on risk levels.
Effectively resist cyberattacks, ensure the continuous and stable operation of the power system, avoid unnecessary load losses or system instability caused by misjudgment, and achieve precise protection and response strategies.
Smart Images

Figure CN121864356A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power network security technology, and in particular to a power system network security protection method based on flexible grayscale adaptive control. Background Technology
[0002] Traditional power system cybersecurity protection systems are primarily built upon rule-based blacklist / whitelist filtering, signature-based matching, and static threshold alerts. The core of these methods is a simple binary judgment of network behavior and security events, categorizing them as normal or abnormal, allowing or blocking access. However, as critical information infrastructure, power systems face new characteristics in cyberattacks, including increased stealth, gradual penetration, and a high degree of correlation with the physical system's state. Examples include advanced persistent threats (APTs) and decoy injection attacks.
[0003] Advanced persistent threat (APS) attacks exhibit a pattern of behavior that is dispersed over long periods and often disguises itself as normal operations, making them difficult to identify promptly by matching known attack signatures or static rules. Data injection attacks, by controlling data, may neither trigger firewall rules nor alter packet characteristics, but can still cause the control system to make erroneous decisions based on false information. Traditional rigid protection strategies are highly susceptible to misjudgment in power systems, leading to serious consequences. If normal operational commands are mistakenly identified as abnormal and blocked, or if genuine malicious commands are not identified in time, it will directly disrupt the stable operation of the power system. This can range from minor issues like unnecessary load losses or frequency fluctuations to more serious problems such as malfunctioning protection devices, severe power flow oscillations, or even large-scale power outages, thus posing a direct threat to the reliability and security of power supply. Summary of the Invention
[0004] This invention provides a power system network security protection method based on flexible grayscale adaptive control, which is used to solve the problem of power system instability caused by insufficient network attack security protection.
[0005] This invention provides a power system network security protection method based on flexible grayscale adaptive control, comprising: Real-time acquisition of network traffic data, operational status data, and safety log data of the power system; the operational status data includes real-time grid frequency, active power flow of key transmission lines, bus voltage of hub substations, and the activation / deactivation status of major protection devices. Based on the network traffic data, operational status data, and security log data, multi-dimensional security feature factors are extracted to quantitatively assess the potential impact of network events on the stable operation of the power system. These multi-dimensional security feature factors include: the matching degree factor between control commands and the current power grid operation mode, the latency and packet loss rate factor of key control business communication channels, the static security margin factor of the system based on real-time power flow, the abruptness factor of the deviation between load forecast and actual demand, and the correlation factor between distributed energy output fluctuations and network attack activities. A flexible grayscale adaptive control algorithm is used to fuse and calculate the multi-dimensional security feature factors, and output a continuous comprehensive security risk grayscale value. The overall security risk grayscale value is compared with a preset risk threshold range to determine the current network security risk level; The corresponding flexible security protection response strategy is determined based on the current network security risk level.
[0006] Furthermore, the matching factor between the extracted control command and the current power grid operation mode includes: Based on the network traffic data, the received remote control commands are parsed; Based on the aforementioned operational status data, a real-time operational model of the current power grid is constructed. The remote control command is substituted as a disturbance into the real-time operation mode model to perform power flow calculation, and the simulated system state after the command is executed is obtained. The deviation between the simulated state of the system and the predefined power grid safety operation constraints is calculated, and a matching factor between the control command and the current power grid operation mode is generated based on the deviation value through a mapping function.
[0007] Furthermore, the extraction of latency and packet loss rate factors for key control service communication channels includes: Based on the network traffic data, identify and monitor communication sessions related to relay protection and safety and stability control devices; Real-time statistics on message transmission delay and packet loss rate of the communication session; The statistically obtained latency and packet loss rate are compared with a communication performance baseline established based on historical normal data; wherein, the performance baseline is a dynamic baseline that changes over time. Based on the degree of deviation of the delay value from the delay performance baseline and the degree of deviation of the packet loss rate from the packet loss rate performance baseline, and combined with the priority of the key services in power system stability control, a weighted calculation is performed to generate the delay and packet loss rate factors of the key control service communication channel.
[0008] Furthermore, the extraction of the system static safety margin factor based on real-time power flow includes: Based on the active power flow data of key transmission lines and the bus voltage data of hub substations in the aforementioned operational status data, an N-1 static security analysis is performed. Traverse the predetermined fault set and simulate the load rate of each critical line and the voltage deviation of each hub node after any single component in the power system is disconnected without fault. Based on the maximum line load rate and maximum voltage deviation calculated under all simulated fault scenarios, the overall static safety margin of the current system is evaluated. The safety margin is normalized to generate a system static safety margin factor based on real-time power flow.
[0009] Furthermore, the extraction of abrupt change factors in the deviation between load forecast and actual demand includes: Based on the operational status data, short-term load forecast values and corresponding actual measured values are obtained, and the deviation between the short-term load forecast values and the actual measured values is calculated to form a deviation time series. Perform a first-order difference operation on the deviation time series to obtain the deviation change rate series; The absolute value of the deviation change rate sequence is input into a predefined transient energy function model for calculation, and the abrupt change factor of the deviation between the load forecast and the actual demand is output.
[0010] Furthermore, the extraction of correlation factors between distributed energy output fluctuations and cyberattack activities includes: Based on the aforementioned operational status data, a time series of fluctuations in distributed energy output is obtained. Based on the security log data, obtain the time series of network attack activity alarm information; Calculate the time-series correlation coefficient between the distributed energy output fluctuation time series and the network attack activity alarm time series, and use this coefficient as the base value of the correlation factor between distributed energy output fluctuation and network attack activity.
[0011] Furthermore, the extraction of correlation factors between distributed energy output fluctuations and cyberattack activities also includes: Identify the network topology distance or geographical region correlation between the distributed energy unit experiencing power output fluctuations and the source IP address initiating the network attack. Based on the network topology distance or geographical region correlation, the base value of the time-series correlation coefficient is spatially weighted and corrected to generate the final correlation factor between distributed energy output fluctuations and network attack activities.
[0012] Furthermore, the flexible grayscale adaptive control algorithm is used to fuse and calculate the multi-dimensional security feature factors, outputting a continuous comprehensive security risk grayscale value, including: Based on the current real-time operating conditions of the power system, calculate the real-time stability margin quantitative indicators of the system. Based on the real-time stability margin quantification index of the system, the adaptive weights of each security feature factor are dynamically determined through a predefined weight mapping function. The adaptive weights are used to perform weighted fusion calculations on the multi-dimensional security feature factors to generate a comprehensive security risk grayscale value.
[0013] Furthermore, the real-time stable margin quantification index of the computing system adopts the following formula: in: This is a quantitative indicator for the real-time stability margin of the system, and its value range is... The lower the value, the worse the system stability margin; For the first Real-time active power flow of a key transmission line For the first The thermal stability limit of a key transmission line For the first Real-time voltage of the busbars of each hub substation For the first The rated voltage of the busbar of each hub substation For the first The maximum allowable deviation range of bus voltage for each hub substation. For the real-time frequency of the power grid, The rated frequency of the power grid. This represents the maximum allowable frequency deviation of the power grid. , , These are the weight coefficients, and they satisfy the constraints. .
[0014] Furthermore, the step of comparing the comprehensive security risk grayscale value with a preset risk threshold range to determine the current network security risk level includes: The comprehensive security risk grayscale value is compared with a first risk threshold, a second risk threshold, and a third risk threshold; wherein the first risk threshold is greater than the second risk threshold, and the second risk threshold is greater than the third risk threshold. If the overall security risk grayscale value is greater than or equal to the first risk threshold, then the current network security risk level is determined to be high risk. If the first risk threshold > the comprehensive security risk gray value ≥ the second risk threshold, then the current network security risk level is determined to be medium risk. If the second risk threshold > the comprehensive security risk gray value ≥ the third risk threshold, then the current network security risk level is determined to be low risk level; If the overall security risk grayscale value is less than the third risk threshold, then the current network security risk level is determined to be a negligible risk level.
[0015] As can be seen from the above technical solutions, the present invention has the following advantages: This invention, after collecting network traffic data, operational status data, and security log data from the power system, extracts multi-dimensional security feature factors based on the collected data to quantitatively assess the potential impact of network events on the stable operation of the power system. Next, a flexible gray-scale adaptive control algorithm is used to fuse and calculate these multi-dimensional security feature factors, outputting a continuous summation of security risk gray-scale values. This comprehensive security risk gray-scale value is then compared with a preset risk threshold range to determine the current network security risk level. Finally, a corresponding flexible security protection response strategy is determined based on the determined level. This invention, through flexible gray-scale adaptive control to determine the security risk level, can effectively resist network attacks while maximizing the continuous and stable operation of the power system. Attached Figure Description
[0016] Figure 1 This is a schematic flowchart of an embodiment of a power system network security protection method based on flexible grayscale adaptive control according to the present invention; Figure 2 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention; Figure 3 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention; Figure 4 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention; Figure 5 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention; Figure 6 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention; Figure 7 This is a schematic flowchart of another embodiment of a power system network security protection method based on flexible grayscale adaptive control in this invention. Detailed Implementation
[0017] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “corresponding to,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0018] Example 1 The implementation method in this embodiment can be implemented in a system, on a server, or on a terminal; no specific limitation is made. The following section will describe the power system network security protection method based on flexible grayscale adaptive control from the perspective of system implementation. Please refer to... Figures 1 to 7 The method provided in this application includes the following steps: S1. Real-time acquisition of network traffic data, operation status data and safety log data of the power system; operation status data includes real-time grid frequency, active power flow of key transmission lines, bus voltage of hub substations and the activation / deactivation status of major protection devices. Network traffic data is obtained by deploying traffic mirroring probes or splitters at key nodes such as the gateways communicating between the substation monitoring system and the master station in the power production control area, and the power plant control unit exits, to losslessly copy all network packets flowing through the system. Deep packet inspection (DIP) technology is used to analyze the copied traffic in real time, primarily collecting communication packets based on power system-specific protocols, including but not limited to: remote control, remote adjustment, remote signaling, and remote measurement data between the master station and substation remote terminal units; manufacturing messages between protection, measurement, and control equipment within smart substations; general object-oriented substation events; and sampled value data.
[0019] Operational status data is received in real-time from telemetry data from all power plants and substations across the network via the data acquisition and monitoring system and the wide-area measurement system of the dispatch center. This operational status data directly reflects the operational status of the power physical system and includes: real-time grid frequency (reflecting the instantaneous balance of active power); active power flow on key transmission lines (directly determining line load rates and system stability limits); bus voltage at key substations (reflecting reactive power balance and voltage stability); and the status of major protection devices (such as the status of soft-plate switches for line main protection and failure protection, directly reflecting the current configuration and protection capabilities of secondary equipment). This data is the fundamental basis for assessing the real-time stability margin of the power grid and constructing real-time operation mode models. All subsequent safety risk assessment algorithms must be based on this real physical status data.
[0020] Security log data is collected from security event logs generated by intrusion detection systems, firewalls, host protection systems, and network auditing systems deployed in the production control zone network. Log content includes, but is not limited to: unauthorized access attempts, abnormal login behavior, alerts triggered by specific malicious code characteristics, protocol violation alerts, and abnormal host behavior logs of critical servers / workstations.
[0021] S2. Based on network traffic data, operational status data, and security log data, extract multi-dimensional security feature factors for quantitatively assessing the potential impact of network events on the stable operation of the power system. These multi-dimensional security feature factors include: the matching degree factor between control commands and the current power grid operation mode, the latency and packet loss rate factor of key control business communication channels, the static security margin factor of the system based on real-time power flow, the abrupt change factor of the deviation between load forecast and actual demand, and the correlation factor between distributed energy output fluctuations and network attack activities. In this embodiment, the matching factor between the control command and the current power grid operation mode is extracted, including the following: S211. Based on network traffic data, parse the received remote control commands; S212. Based on the operating status data, construct a real-time operating mode model of the current power grid; S213. Substitute the remote control command as a disturbance into the real-time operation mode model to perform power flow calculation and obtain the simulated state of the system after the command is executed; S214. Calculate the deviation between the simulated system state and the predefined power grid safety operation constraints, and generate a matching factor between the control command and the current power grid operation mode based on the deviation value through a mapping function.
[0022] First, deep packet inspection (DPC) technology is used to monitor and filter network packets in the power system in real time, identifying remote control commands that conform to the power system communication protocol. After parsing, key parameters of the commands are extracted, such as the control target object, control type, and control value. A real-time operation model of the current power grid is constructed, using real-time collected data on grid frequency, active power flow of key transmission lines, and bus voltage of key substations as initial boundary conditions. This model accurately reflects the current topology and power flow of the power grid. Essentially, this model is a node admittance matrix used for subsequent power flow calculations.
[0023] Specifically, the parsed control commands are applied to the real-time operation model, and power flow calculations are performed to obtain the simulated power of each line, the simulated voltage of each bus, and the system frequency after command execution. Finally, the deviation between the simulated system state and the predefined power grid safety operation constraints is calculated, and a matching factor between the control commands and the current power grid operation mode is generated based on the deviation value through a mapping function. The calculation formula is as follows: Total deviation : Line power over-limit deviation : Bus voltage over-limit deviation : System frequency over-limit deviation : Matching factor : in: , , These are the weighting coefficients, satisfying... It is used to adjust the degree of influence of line power constraints, bus voltage constraints, and system frequency constraints on the total deviation; This represents the total number of critical transmission lines. For the first The simulated power of the critical circuit after the control command is executed; This refers to the total number of busbars in the hub substation. For the first The simulated voltage of the hub bus after the control command is executed. For the first Rated voltage of the hub busbar; To control the system's simulated frequency after the command is executed; It is a natural constant. This is the attenuation coefficient, used to control the rate at which the matching degree decreases as the total deviation increases. The larger the value, the more sensitive the system is to minor overreach behaviors.
[0024] In this embodiment, the latency and packet loss rate factors of the key control service communication channel are extracted, including the following: S221. Based on network traffic data, identify and monitor communication sessions related to relay protection and safety and stability control devices; S222. Real-time statistics on message transmission delay and packet loss rate of communication sessions; S223. Compare the statistically obtained latency and packet loss rate with the communication performance baseline established based on historical normal data; wherein, the performance baseline is a dynamic baseline that changes over time; S224. Based on the degree of deviation of the delay value from the delay performance baseline and the degree of deviation of the packet loss rate from the packet loss rate performance baseline, and combined with the priority of key services in power system stability control, a weighted calculation is performed to generate the delay and packet loss rate factors of the key control service communication channel.
[0025] First, deep packet inspection (DPI) technology, combined with port numbers, destination IP addresses, and application layer identifiers of power system-specific communication protocols, accurately identifies communication data streams belonging to critical services such as relay protection differential messages and stability control device commands from network traffic. A monitoring context is established for each independent service session for subsequent continuous performance measurement. For latency statistics, assuming both communicating parties use IEEE 1588 precision clock synchronization, the difference between the message reception timestamp and the transmission timestamp is calculated to obtain a latency sample. Within a predetermined statistical time window (e.g., 5 minutes), the average of all samples is taken to obtain the average latency of the session within the current window. For packet loss rate statistics, by analyzing the sequence number continuity of messages, the number of lost packets within the time window is counted, and the ratio of this number to the total number of messages to be transmitted is calculated to obtain the current packet loss rate.
[0026] The performance baseline here is not a fixed value, but a dynamic range derived by learning from historical performance data during normal periods using machine learning algorithms; the latency baseline and packet loss rate baseline can be expressed as functions of time. Finally, based on the degree of deviation of the latency value from the latency performance baseline and the degree of deviation of the packet loss rate from the packet loss rate performance baseline, and combined with the priority of critical services in power system stability control, a weighted calculation is performed to generate a latency and packet loss rate factor for the communication channel of critical control services. This factor is a comprehensive health indicator, and its calculation formula is as follows: Delay deviation : Packet loss rate deviation : Overall performance deviation : Health Factor : in: This represents the average latency within the current statistical time window. This serves as a dynamic upper limit for the latency performance baseline. This represents the packet loss rate within the current statistical time window. This is a dynamic upper limit for the packet loss rate performance baseline; Security priority weights for communication session services. This is a balancing coefficient used to adjust the relative importance of delay deviation and packet loss rate deviation in the overall evaluation; These are shape parameters used to control the rate at which health deteriorates as the overall performance deviation increases. The larger the value, the more sensitive the health score is to changes in deviation.
[0027] In this embodiment, the system static safety margin factor based on real-time power flow is extracted, including the following: S231. Based on the active power flow data of key transmission lines and the bus voltage data of hub substations in the operation status data, perform N-1 static security analysis; S232. Traverse the predetermined fault set and simulate the load rate of each critical line and the voltage deviation of each hub node after any single component in the power system is disconnected without fault. S233. Based on the maximum line load rate and maximum voltage deviation calculated under all simulated fault scenarios, evaluate the overall static safety margin of the current system; S234. Normalize the safety margin to generate a system static safety margin factor based on real-time power flow.
[0028] First, using real-time acquired power grid telemetry data as the initial power flow profile, a ground-state power flow model for the current operating mode is constructed. This model serves as the benchmark for all subsequent simulation calculations. The fault set is predefined here, including simulated interruptions of all main transformers, important transmission lines, large-capacity generator units, and other critical components. For each fault Based on the ground-state power flow, the component is simulated to be disconnected, and the system state is re-solved using the fast decomposition power flow method or optimal power flow calculation to obtain the power of each component and the voltage of each node after the fault. The most severe fault consequence, i.e., the system's weakest link, is identified; the maximum load rate of the critical line and the maximum voltage deviation of the hub node are calculated under all fault scenarios. Finally, the safety margin is normalized to generate a system static safety margin factor based on real-time power flow. The calculation of this factor aims to synthesize a complex safety assessment of multiple constraints and multiple fault scenarios into a standardized metric value between 0 and 1. Its calculation formula is as follows: Line power safety margin : Voltage safety margin : Integrated system static safety margin factor : in: The maximum load rate of the critical path in all N-1 fault scenarios. This is the safe threshold for line load rate. ,but The line has sufficient margin; if it exceeds this threshold, Follow Linearly decreasing; The maximum voltage deviation of the hub node in all N-1 fault scenarios. The safe threshold for voltage deviation, This is the maximum permissible threshold for voltage deviation. ,but The voltage margin is sufficient, if , Linearly decreasing, if ,but ; The smaller value between the line power safety margin and the voltage safety margin is chosen, reflecting that the overall system safety margin is determined by the weakest link. This is a severity coefficient, introduced to make... As it approaches the unsafe boundary, it exhibits a nonlinear accelerated descent characteristic.
[0029] In this embodiment, the abrupt change factor of the deviation between load forecast and actual demand is extracted, including the following: S241. Based on the operating status data, obtain the short-term load forecast value and the corresponding actual measurement value, and calculate the deviation between the short-term load forecast value and the actual measurement value to form a deviation time series; S242. Perform a first-order difference operation on the deviation time series to obtain the deviation change rate series; S243. Input the absolute value of the deviation change rate sequence into the predefined transient energy function model for calculation, and output the abrupt change factor of the deviation between the load forecast and the actual demand.
[0030] First, obtain short-term load forecasts for the current and recent multiple sampling periods from the energy management system or advanced metering system. and actual measured value For each time point Calculate its absolute deviation : Multiple consecutive time points That is, to form a biased time series It captures the dynamic trend of deviation changes and identifies whether it suddenly increases. The first-order difference calculation formula is as follows: ;in, That is, time. The rate of change of the deviation is represented by a positive value indicating that the deviation is widening, and a negative value indicating that the deviation is converging. The sequence is obtained through continuous calculation. .
[0031] Finally, the absolute values of the deviation change rate sequence are input into a predefined transient energy function model for calculation, outputting the abrupt change factor of the deviation between load forecast and actual demand. The calculation formula is as follows: Accumulated transient energy : relative energy ratio : Mutagenic factors : in: To assess the time window for mutation, For a moment The absolute value of the rate of change of load forecast deviation. The time decay factor, The attenuation coefficient; The baseline energy is the statistical average of the accumulated transient energy within the same time window under normal, attack-free operating conditions. for The steepness coefficient of the curve controls the transition speed of the function from 0 to 1; for The center point of the type function is set to 1; when hour, ;like This means that the accumulated energy is far below the normal fluctuation level. Approaching 0 indicates no mutation; if This means that the accumulated energy is significantly higher than normal fluctuations. Approaching 1, a dramatic mutation occurred.
[0032] In this embodiment, the correlation factors between distributed energy output fluctuations and cyberattack activities are extracted, including the following: S251. Based on operational status data, obtain the time series of fluctuations in distributed energy output; S252. Obtain the time series of network attack activity alarm information based on security log data; S253. Calculate the time series correlation coefficient between the time series of distributed energy output fluctuations and the time series of network attack activity alarms, and use this coefficient as the basic value of the correlation factor between distributed energy output fluctuations and network attack activities.
[0033] First, output data from distributed photovoltaic power stations, wind farms, and other units sampled at specific time intervals are obtained from the distributed energy monitoring system. To eliminate the inherent natural fluctuations, a high-pass digital filter is used or the deviation from short-term predicted values is calculated to obtain a pure fluctuation component time series. Attack alarms related to the power control system are parsed and extracted from security logs of network security situation awareness platforms or intrusion detection systems. Different types of alarms are assigned different weights according to their severity; for example, scanning alarms have a weight of 1, penetration attempt alarms have a weight of 3, and control command tampering alarms have a weight of 5. The weights are summed within the same time interval to generate a quantitative time series characterizing the intensity of network attack activities. The temporal correlation coefficient between the distributed energy output fluctuation time series and the network attack activity alarm time series is calculated, and this coefficient is used as the base value of the correlation factor. To highlight the importance of recent correlations, a weighted Pearson correlation coefficient is used for calculation, the formula of which is as follows: Weighted covariance : Weighted variance of distributed energy fluctuation series : Weighted variance of network attack alert sequences : Weighted time series correlation coefficient : in: The time decay weighting function is of the form: , The time decay coefficient, This assigns greater weight to data points closer to the current moment, enhancing sensitivity to sudden events and short-term correlations. For a moment The fluctuation component of distributed energy output is obtained from the deviation between measured values and short-term forecast values, or from the fluctuation amount extracted by high-pass filtering. For a moment The quantitative value of the intensity of cyberattack activities is obtained by summing the weights of different types of attack alerts, with the weights set according to the severity. For distributed energy fluctuation sequences within a time window The weighted average within, For network attack alert sequences within a time window The weighted average within.
[0034] In addition to the steps described above, the following are also included: 1. Identify the network topology distance or geographical region correlation between the distributed energy unit experiencing power output fluctuations and the source IP address initiating the network attack; 2. Based on network topology distance or geographical region correlation, the base value of the temporal correlation coefficient is spatially weighted and corrected to generate the final correlation factor between distributed energy output fluctuation and network attack activities.
[0035] Specifically, the routing hop count between the source IP address and the target DER control unit IP is obtained through the network management system; the physical distance between the source IP and the DER unit is calculated using the IP geolocation database and the DER unit's geographic information system coordinates. Alternatively, more simply, it is determined whether they are located in the same substation, the same feeder, or the same administrative region. Based on network topology distance or geographic region correlation, the baseline value of the temporal correlation coefficient is spatially weighted and corrected to generate the final comprehensive correlation factor. The aim is to define a spatial proximity function whose value decreases as distance increases. Spatial proximity function : Comprehensive correlation factors : in: The spatial attenuation coefficient, Controlling the rate at which spatial correlation decays with distance For network topology distance, As an indicator of geographic regional correlation, This is a harmonic parameter used to balance the importance of network topological distance and geographical distance in spatial association assessment.
[0036] The correlation factor calculated above is a continuous value between 0 and 1; The closer the value is to 1, the more synchronized the output fluctuations of distributed energy sources are with cyberattacks in time, and the closer they are in space, suggesting a high probability of malicious causal relationship. The closer the value is to 0, the less related the two factors are. This factor, through spatiotemporal dual-dimensional fusion analysis, effectively overcomes the false alarms that may occur when relying solely on time series analysis, and greatly improves the accuracy of identifying coordinated network attacks.
[0037] S3. A flexible grayscale adaptive control algorithm is adopted to fuse and calculate multi-dimensional security feature factors and output a continuous comprehensive security risk grayscale value. The comprehensive security risk grayscale value calculated above is not a simple "yes / no" alarm signal, but a continuously varying risk grayscale value within the range [0,1]. This value intuitively represents the potential threat level of the current network security status to the stable operation of the power system. The higher the value, the greater the risk, providing accurate data for the subsequent implementation of precise and tiered "flexible" protection and response strategies. The specific implementation of this fusion calculation process is as follows: S31. Calculate the real-time stability margin quantitative index of the power system based on the current real-time operating conditions of the power system; S32. Based on the real-time stability margin quantification index of the system, the adaptive weights of each safety feature factor are dynamically determined through a predefined weight mapping function; S33. Use adaptive weights to perform weighted fusion calculations on multi-dimensional security feature factors to generate a comprehensive security risk gray value.
[0038] The real-time stability margin quantification index of the calculation system is expressed by the following formula: in: This is a quantitative indicator for the real-time stability margin of the system, and its value range is... The lower the value, the worse the system stability margin; For the first Real-time active power flow of a key transmission line For the first The thermal stability limit of a key transmission line For the first Real-time voltage of the busbars of each hub substation For the first The rated voltage of the busbar of each hub substation For the first The maximum allowable deviation range of bus voltage for each hub substation. For the real-time frequency of the power grid, The rated frequency of the power grid. This represents the maximum allowable frequency deviation of the power grid. , , These are the weight coefficients, and they satisfy the constraints. .
[0039] A weight mapping strategy is predefined, which has a real-time stability margin. The input is used to dynamically output the weights of each feature factor. The specific strategy is as follows: when Lower values (e.g.) When the value is less than 0.3, it indicates that the system is very fragile and has insufficient stability margin. In this case, the algorithm will automatically increase the weights of the matching factor between the control command and the current power grid operation mode, as well as the weights of the system's static safety margin factor based on real-time power flow. Because in this state, even a small malicious control command or an additional disturbance can easily trigger system instability, the assessment of the command's legitimacy and the system's current vulnerability is crucial.
[0040] when Higher values (e.g.) When the value is greater than 0.7, it indicates that the system is very robust and has sufficient stability margin. At this point, the algorithm will automatically increase the weight of the abrupt change factor of the deviation between load forecast and actual demand, and the correlation factor between distributed energy output fluctuations and network attack activities. Because the system is capable of withstanding a certain amount of disturbance, it focuses more on detecting and warning of potential, hidden, and possibly brewing coordinated attacks.
[0041] when When the value falls within the intermediate range, a set of preset benchmark weights is used. Through this mapping function, the algorithm achieves deep coupling and dynamic adjustment between the risk assessment strategy and the physical operating state of the power grid.
[0042] Finally, the five normalized security feature factor values ( , , , , This forms a feature vector, which is then weighted and synthesized with the dynamic weight vector obtained in step S32. The overall security risk grayscale value is then calculated. The calculation formula is as follows: in: , , , , These are the normalized eigenvalues. , , , , The outputs of step S32, respectively, and the current stability margin The corresponding dynamic weights. The final grayscale value. It is a continuous scalar that enables precise and unified quantification of complex and multi-dimensional risk states.
[0043] S4. Compare the overall security risk grayscale value with the preset risk threshold range to determine the current network security risk level; The continuous comprehensive safety risk gray value obtained in the previous step This is mapped to discrete, actionable decision levels, triggering corresponding gradient response measures. The overall security risk grayscale value is compared with a preset risk threshold range, the principle of which is as follows: The system presets three risk thresholds, which constitute four risk level ranges: The overall security risk gray value is compared with the first risk threshold, the second risk threshold, and the third risk threshold; wherein the first risk threshold is greater than the second risk threshold, and the second risk threshold is greater than the third risk threshold. The aforementioned first risk threshold is a high-risk critical threshold; once the grayscale value... Exceeding this threshold indicates severe anomalies in multiple dimensions of security characteristics, suggesting the system may be in a vulnerable state, and a cyberattack could potentially cause substantial and immediate damage to the stable operation of the power system. The second risk threshold is the medium-risk threshold, when... When the threshold falls between this threshold and the first risk threshold, it indicates that a clear and potentially harmful anomalous activity has been detected, but its urgency or certainty has not yet reached the highest level. The third risk threshold is a low-risk threshold. Values below this threshold are considered negligible risks or normal system fluctuations.
[0044] Based on the comparison results, the risk level is determined as follows: 1. If the overall security risk grayscale value is greater than or equal to the first risk threshold, the current network security risk level is determined to be high risk; this indicates that the system is facing an imminent serious network attack threat and the most stringent protective measures must be taken. 2. If the first risk threshold > the comprehensive security risk gray value ≥ the second risk threshold, then the current network security risk level is determined to be medium risk; this indicates that the system has detected clear malicious activity or anomalies, and intervention measures need to be taken to prevent the situation from deteriorating. 3. If the second risk threshold > the comprehensive security risk gray value ≥ the third risk threshold, then the current network security risk level is determined to be low risk level; this indicates that the system has detected a minor anomaly or uncertain threat, and monitoring needs to be strengthened and response prepared. 4. If the overall security risk gray value is less than the third risk threshold, the current network security risk level is determined to be a negligible risk level; this indicates that all indicators are within the normal range and no special security actions are required.
[0045] S5. Determine the corresponding flexible security protection response strategy based on the current network security risk level.
[0046] The system predefines response policy sets for each risk level. Once the risk level is determined, the corresponding preset actions will be automatically triggered: For negligible risk levels, the policy is to allow passage, allowing all network traffic and control commands to proceed normally. The security system only maintains regular monitoring log records, without any additional impact on system operation. For low-risk levels, the policy is to enhance monitoring and alerts, automatically raising the monitoring log level of relevant network sessions and system components, sending warning messages to security operations personnel to alert them to related anomalies, but not implementing network-level blocking operations at this time. For medium-risk levels, the policy is to implement a phased rollout; this is the core flexible policy and may specifically include: Impose power or rate limits on suspicious control commands. For example, allow commands to adjust generator output, but limit the adjustment to a safe range. Add short delays to critical protection commands to allow a window for secondary verification by the safety analysis system, while simultaneously activating backup protection logic. Switch control to redundant channels or local autonomous mode to bypass suspected compromised communication paths.
[0047] For high-risk scenarios, the strategy is to block and isolate, immediately blocking the source IP addresses of network sessions determined to be malicious. Simultaneously, the power control system is activated to execute necessary power operations to forcibly isolate the risk. Examples include disconnecting load lines identified as under attack, shunt substations that may endanger the main grid's security, or adjusting power generation plans to compensate for power shortages. This measure aims to ensure the security and stability of the entire main grid at the cost of localized, controllable losses.
[0048] The above embodiments quantify the potential impact of network events on the stability of the power physical system and introduce dynamic weight allocation and continuous risk gray value calculation, realizing the transformation of security protection strategies from rigid and binary to flexible and gradual, thereby effectively resisting network attacks while maximizing the continuous and stable operation of the power system.
[0049] It is understood that those skilled in the art can combine various implementation methods in the above embodiments under the guidance of the above examples to obtain technical solutions with multiple implementation methods.
[0050] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A power system network security protection method based on flexible grayscale adaptive control, characterized in that, include: Real-time collection of network traffic data, operational status data, and safety log data from the power system; The operational status data includes the real-time frequency of the power grid, the active power flow of key transmission lines, the bus voltage of hub substations, and the activation / deactivation status of major protection devices. Based on the network traffic data, operational status data, and security log data, multi-dimensional security feature factors are extracted to quantitatively assess the potential impact of network events on the stable operation of the power system. These multi-dimensional security feature factors include: the matching degree factor between control commands and the current power grid operation mode, the latency and packet loss rate factor of key control business communication channels, the static security margin factor of the system based on real-time power flow, the abruptness factor of the deviation between load forecast and actual demand, and the correlation factor between distributed energy output fluctuations and network attack activities. A flexible grayscale adaptive control algorithm is used to fuse and calculate the multi-dimensional security feature factors, and output a continuous comprehensive security risk grayscale value. The overall security risk grayscale value is compared with a preset risk threshold range to determine the current network security risk level; The corresponding flexible security protection response strategy is determined based on the current network security risk level.
2. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The matching factor between the extracted control command and the current power grid operation mode includes: Based on the network traffic data, the received remote control commands are parsed; Based on the aforementioned operational status data, a real-time operational model of the current power grid is constructed. The remote control command is substituted as a disturbance into the real-time operation mode model to perform power flow calculation, and the simulated system state after the command is executed is obtained. The deviation between the simulated state of the system and the predefined power grid safety operation constraints is calculated, and a matching factor between the control command and the current power grid operation mode is generated based on the deviation value through a mapping function.
3. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The extraction of latency and packet loss rate factors for key control service communication channels includes: Based on the network traffic data, identify and monitor communication sessions related to relay protection and safety and stability control devices; Real-time statistics on message transmission delay and packet loss rate of the communication session; The statistically obtained latency and packet loss rate are compared with a communication performance baseline established based on historical normal data; wherein, the performance baseline is a dynamic baseline that changes over time. Based on the degree of deviation of the delay value from the delay performance baseline and the degree of deviation of the packet loss rate from the packet loss rate performance baseline, and combined with the priority of the key services in power system stability control, a weighted calculation is performed to generate the delay and packet loss rate factors of the key control service communication channel.
4. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The extraction of the system static safety margin factor based on real-time power flow includes: Based on the active power flow data of key transmission lines and the bus voltage data of hub substations in the aforementioned operational status data, an N-1 static security analysis is performed. Traverse the predetermined fault set and simulate the load rate of each critical line and the voltage deviation of each hub node after any single component in the power system is disconnected without fault. Based on the maximum line load rate and maximum voltage deviation calculated under all simulated fault scenarios, the overall static safety margin of the current system is evaluated. The safety margin is normalized to generate a system static safety margin factor based on real-time power flow.
5. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The extraction of abrupt change factors in the deviation between load forecast and actual demand includes: Based on the operational status data, short-term load forecast values and corresponding actual measured values are obtained, and the deviation between the short-term load forecast values and the actual measured values is calculated to form a deviation time series. Perform a first-order difference operation on the deviation time series to obtain the deviation change rate series; The absolute value of the deviation change rate sequence is input into a predefined transient energy function model for calculation, and the abrupt change factor of the deviation between the load forecast and the actual demand is output.
6. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The extraction of correlation factors between distributed energy output fluctuations and cyberattack activities includes: Based on the aforementioned operational status data, a time series of fluctuations in distributed energy output is obtained. Based on the security log data, obtain the time series of network attack activity alarm information; Calculate the time-series correlation coefficient between the distributed energy output fluctuation time series and the network attack activity alarm time series, and use this coefficient as the base value of the correlation factor between distributed energy output fluctuation and network attack activity.
7. The power system network security protection method based on flexible grayscale adaptive control according to claim 6, characterized in that, The extraction of correlation factors between distributed energy output fluctuations and cyberattack activities also includes: Identify the network topology distance or geographical region correlation between the distributed energy unit experiencing power output fluctuations and the source IP address initiating the network attack. Based on the network topology distance or geographical region correlation, the base value of the time-series correlation coefficient is spatially weighted and corrected to generate the final correlation factor between distributed energy output fluctuations and network attack activities.
8. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The method employs a flexible grayscale adaptive control algorithm to fuse and calculate the multi-dimensional security feature factors, outputting a continuous comprehensive security risk grayscale value, including: Based on the current real-time operating conditions of the power system, calculate the real-time stability margin quantitative indicators of the system. Based on the real-time stability margin quantification index of the system, the adaptive weights of each security feature factor are dynamically determined through a predefined weight mapping function. The adaptive weights are used to perform weighted fusion calculations on the multi-dimensional security feature factors to generate a comprehensive security risk grayscale value.
9. The power system network security protection method based on flexible grayscale adaptive control according to claim 8, characterized in that, The real-time stable margin quantification index of the calculation system adopts the following formula: in: This is a quantitative indicator for the real-time stability margin of the system, and its value range is... The lower the value, the worse the system stability margin; For the first Real-time active power flow of a key transmission line For the first The thermal stability limit of a key transmission line For the first Real-time voltage of the busbars of each hub substation For the first The rated voltage of the busbar of each hub substation For the first The maximum allowable deviation range of bus voltage for each hub substation. For the real-time frequency of the power grid, The rated frequency of the power grid. This represents the maximum allowable frequency deviation of the power grid. , , These are the weighting coefficients, and they satisfy the constraints. .
10. The power system network security protection method based on flexible grayscale adaptive control according to claim 1, characterized in that, The step of comparing the comprehensive security risk grayscale value with a preset risk threshold range to determine the current network security risk level includes: The comprehensive security risk grayscale value is compared with a first risk threshold, a second risk threshold, and a third risk threshold; wherein the first risk threshold is greater than the second risk threshold, and the second risk threshold is greater than the third risk threshold. If the overall security risk grayscale value is greater than or equal to the first risk threshold, then the current network security risk level is determined to be high risk. If the first risk threshold > the comprehensive security risk gray value ≥ the second risk threshold, then the current network security risk level is determined to be medium risk. If the second risk threshold > the comprehensive security risk gray value ≥ the third risk threshold, then the current network security risk level is determined to be low risk level; If the overall security risk grayscale value is less than the third risk threshold, then the current network security risk level is determined to be a negligible risk level.