Power grid network similar attack behavior analysis method and system based on AI model

By constructing an AI-based method for analyzing similar attack behaviors in power grid networks, and utilizing network traffic, system logs, and user behavior data, similar attack behaviors can be identified and evaluated. This solves the problem of insufficient identification accuracy in existing technologies, enabling rapid response and optimization of power grid network security defense.

CN121907494APending Publication Date: 2026-04-21GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-04-21

Smart Images

  • Figure CN121907494A_ABST
    Figure CN121907494A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid network similar attack behavior analysis method and system based on an AI model, and the method comprises the steps: respectively obtaining network flow data, system log data and user behavior data of a power grid network, carrying out the data preprocessing, and carrying out the data association with a power grid visitor IP as an association point, thereby obtaining access association data; analyzing the user behavior baseline and performing data training on the related access associated data to construct a behavior analysis AI model, acquiring attack associated data of historical attack behaviors, inputting the attack associated data into the behavior analysis AI model for attack behavior analysis, outputting attack behavior characteristics of each attack behavior, and outputting the attack behavior characteristics of each attack behavior; and analyzing the attack behavior baseline of each historical attack behavior, calculating the attack behavior similarity, and evaluating similar attack behaviors in the current access behaviors according to the attack behavior similarity to obtain a similar attack behavior analysis result of the power grid network. The method has the effect of improving the recognition accuracy of similar attack behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of power grid security protection, and in particular to a method and system for analyzing similar attack behaviors in power grid networks based on an AI model. Background Technology

[0002] Currently, with the continuous advancement of the digital wave, the probability of various industries being threatened by attacks such as data breaches, ransomware, and account hijacking has greatly increased during the digital development process. Cybersecurity has become one of the unavoidable issues in digital development. In particular, for enterprises such as power grids that have massive amounts of user data and are related to the normal operation of users' daily lives, power grid cybersecurity has become an urgent problem to be solved in the transformation of smart grids and digital grids.

[0003] Existing power grid network security protection measures typically involve using firewalls, antivirus software, and rule-based intrusion detection systems to detect and protect against power grid network attacks. However, with the development of digitalization, network attack methods have become more complex and varied. Traditional attack protection methods that rely on setting static protection rules are unable to accurately identify similar attack behaviors, and the protection response speed cannot keep up with the speed of change in attack methods. The aforementioned related technologies have the drawback of being unable to accurately identify similar attack behaviors. Summary of the Invention

[0004] To address the problem of difficulty in accurately identifying similar attack behaviors in existing technologies, this invention provides a method and system for analyzing similar attack behaviors in power grids based on an AI model, which can improve the accuracy of similar attack behavior identification.

[0005] Firstly, the aforementioned inventive objective of this application is achieved through the following technical solutions: A method for analyzing similar attack behaviors in power grid networks based on an AI model, the method comprising: The network traffic data, system log data, and user behavior data of the power grid network are obtained and preprocessed. The data are then associated with the IP address of the visitor in the power grid network to obtain access association data. Analyze the user behavior baseline of the access-related data, and use the user behavior baseline as a benchmark to train the relevant access-related data to build a behavior analysis AI model. Acquire attack correlation data of historical attack behaviors, input them into the behavior analysis AI model for attack behavior analysis, and output the attack behavior characteristics of each attack behavior; The baseline of each historical attack behavior is analyzed and the similarity of the attack behavior is calculated. Based on the similarity of the attack behavior, similar attack behaviors in the current access behavior are evaluated to obtain the analysis results of similar attack behaviors in the power grid network.

[0006] In a preferred embodiment, this application can be further configured as follows: the user behavior baseline for analyzing the access-related data is used as a benchmark to train the relevant access-related data and construct a behavior analysis AI model, specifically including: The access association data is processed to associate access behavior, and the corresponding user access path is analyzed according to the access behavior association order to obtain the user behavior baseline. Based on the user behavior baseline, a graph neural network is trained on the access-related data to extract access behavior features and analyze the relationship between access behaviors to construct a behavioral neural network architecture, thereby obtaining a behavioral analysis AI model.

[0007] In a preferred embodiment, this application can be further configured as follows: the acquisition of attack correlation data of historical attack behaviors, inputting it into the behavior analysis AI model for attack behavior analysis, and outputting the attack behavior characteristics of each attack behavior, specifically includes: Acquire attack association data of historical attack behaviors, input the attack association data into the behavior analysis AI model and compare it with user access behavior, and identify historical attack behaviors based on the comparison results; By comparing the user access behavior data, behavioral feature analysis is performed on the historical attack behaviors to obtain the attack behavior features of each historical attack behavior, wherein the behavioral features include behavioral distribution features, time features, semantic features and behavioral association features.

[0008] In a preferred embodiment, this application can be further configured as follows: obtaining attack-related data of historical attack behaviors, inputting the attack-related data into the behavior analysis AI model for data comparison with user access behavior, and identifying historical attack behaviors based on the comparison results, specifically includes: By comparing network traffic data, abnormal traffic and abnormal domains of the historical attack behavior are identified, and abnormal traffic data of the historical attack behavior is obtained. By comparing system log data, abnormal operations and abnormal processes of the historical attack behavior are identified, and abnormal log data of the historical attack behavior is obtained. By comparing user behavior data, abnormal sensitive operations and abnormal sensitive information of the historical attack behavior are identified, and abnormal user behavior data of the historical attack behavior is obtained. By combining the power grid intrusion detection results of the historical attack behaviors, the abnormal traffic identification data, abnormal log data, and abnormal user behavior data are correlated in multiple dimensions, and historical attack behaviors are identified based on the data correlation results.

[0009] In a preferred embodiment, this application can be further configured as follows: the analysis of the attack behavior baseline for each historical attack behavior and the calculation of attack behavior similarity, the evaluation of similar attack behaviors in the current access behavior based on the attack behavior similarity, and the obtaining of similar attack behavior analysis results for the power grid network, specifically include: Based on the attack behavior characteristics, predict the attack direction and attack intent of the historical attack behavior; based on the attack direction and attack intent, perform behavioral correlation on the historical attack behavior to obtain the attack behavior baseline. Based on the type of behavioral characteristics, the similarity of behavioral characteristics of adjacent attack behaviors on the baseline of the attack behavior is calculated to obtain the attack behavior similarity of the historical attack behaviors. The similarity of access behavior between adjacent access nodes of the current access behavior of the power grid network is calculated, and the similarity comparison results are used to evaluate the similar attack behavior in the current access behavior. The similar attack behaviors are compared with the historical attack behaviors in terms of behavioral feature similarity. Based on the comparison results, the hidden attack behavior features in the similar attack behaviors are labeled to obtain the similar attack behavior analysis results.

[0010] In a preferred embodiment, this application can be further configured as follows: the process of calculating the similarity of access behaviors among adjacent access nodes that calculate the current access behavior of the power grid network, and evaluating similar attack behaviors in the current access behavior based on the similarity comparison results, specifically includes: Collaborative federated learning is used to perform collaborative learning on multiple similar attack behaviors of the same attack type. The similarity confidence of each similar attack behavior feature is calculated based on the similarity of the behavioral features, and the similarity confidence is sorted. Based on the confidence ranking results, high-confidence behavioral features are prioritized for clustering, and similar attack behavior threat intelligence for the current attack type is generated based on the clustering results of behavioral features. Based on the threat intelligence of similar attack behaviors, the current access behavior is compared with the characteristics of similar attack behaviors, and the similar attack behaviors that match the historical attack behaviors in the current access behavior are evaluated based on the comparison results.

[0011] In a preferred embodiment, this application can be further configured as follows: after analyzing the attack behavior baseline of each historical attack behavior and calculating the attack behavior similarity, evaluating similar attack behaviors in the current access behavior based on the attack behavior similarity, and obtaining the similar attack behavior analysis results of the power grid network, it further includes: Based on the hidden attack behavior characteristics, identify similar attack patterns of similar attack behaviors, and perform attack path tracking on the similar attack behaviors to obtain the hidden attack paths of the similar attack behaviors; Based on the hidden attack path, predict the attack intent of the similar attack behaviors and predict the next attack node; based on the similar attack patterns, pre-match the attack response mechanism for the next attack node and execute it. The effectiveness of the detection and response strategy for similar attack behaviors is evaluated based on the attack defense results of the next attack node, and the attack response mechanism for subsequent attack nodes is adjusted based on the effectiveness evaluation results.

[0012] Secondly, the above-mentioned inventive objective of this application is achieved through the following technical solutions: A power grid network similarity attack behavior analysis system based on an AI model, the system being applied to the aforementioned power grid network similarity attack behavior analysis method based on an AI model, the system comprising: The access data acquisition module is used to acquire network traffic data, system log data and user behavior data of the power grid network respectively, and perform data preprocessing. It uses the visitor IP of the power grid network as the association point to associate the data and obtain access association data. The model building module is used to analyze the user behavior baseline of the access-related data, and to train the relevant access-related data based on the user behavior baseline to build a behavior analysis AI model. The feature analysis module is used to acquire attack correlation data of historical attack behaviors, input it into the behavior analysis AI model for attack behavior analysis, and output the attack behavior features of each attack behavior. The similar behavior analysis module is used to analyze the baseline of each historical attack behavior and calculate the attack behavior similarity. Based on the attack behavior similarity, it evaluates the similar attack behaviors in the current access behavior and obtains the similar attack behavior analysis results of the power grid network.

[0013] Thirdly, the above-mentioned objectives of this application are achieved through the following technical solutions: A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described AI model-based power grid network similar attack behavior analysis method.

[0014] Fourthly, the above-mentioned objectives of this application are achieved through the following technical solutions: A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described AI-based power grid network similar attack behavior analysis method.

[0015] In summary, this application includes at least one of the following beneficial technical effects: 1. This application uses normal access data of the power grid network as samples and user behavior baseline as a benchmark for data training to build a behavior analysis AI model. Historical attack behaviors are used as real attack samples to input into the behavior analysis AI model for attack behavior feature identification. The attack identification strategy of the behavior analysis AI model is optimized. Through comprehensive training of normal access data samples and real attack samples, the attack behavior identification accuracy of the AI ​​model is improved, and the attack behavior identification results of the AI ​​model are made more realistic. The optimized behavior analysis AI model can quickly evaluate similar attack behaviors in the current access behavior that reach the preset similarity value with the attack behavior, thereby improving the accuracy and efficiency of similar attack behavior identification of the AI ​​model. 2. This application conducts a comprehensive behavioral feature analysis of historical attack behaviors through multiple attack behavior features such as behavioral distribution features, time features, semantic features, and behavioral association features, extracts relevant behavioral judgment rules, optimizes the judgment rules of similar attack behaviors in the behavior analysis AI model, improves the accuracy of similarity judgment of the AI ​​model, and uses threat intelligence as a clue to accurately spread the detection of similar attack behaviors from the access behavior level. 3. This application identifies similar attack patterns based on hidden attack behavior characteristics and tracks attack paths. It comprehensively tracks disguised hidden attack paths and pre-matches and executes attack response mechanisms at the next attack node by predicting attack intent. This proactively prevents and controls hidden attack behaviors, helps to block the probability of hidden attack behaviors, and continuously adjusts the attack response mechanisms of subsequent attack nodes through the effectiveness evaluation of the defense structure. This adaptively optimizes the network security defense mechanism of the power grid network and improves the intelligence of power grid network security defense. Attached Figure Description

[0016] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.

[0017] Figure 1 This is a flowchart illustrating the implementation of the AI ​​model-based power grid network similar attack behavior analysis method in this embodiment.

[0018] Figure 2 This is a flowchart illustrating the implementation of step S20 of the power grid network similar attack behavior analysis method in this embodiment.

[0019] Figure 3 This is a flowchart illustrating the implementation of step S30 of the power grid network similar attack behavior analysis method in this embodiment.

[0020] Figure 4 This is a flowchart illustrating the implementation of step S301 of the power grid network similar attack behavior analysis method in this embodiment.

[0021] Figure 5 This is a flowchart illustrating the implementation of step S40 of the power grid network similar attack behavior analysis method in this embodiment.

[0022] Figure 6 This is a schematic diagram of the similar attack behavior evaluation process of the power grid network similar attack behavior analysis method in this embodiment.

[0023] Figure 7 This is a schematic diagram of the attack response mechanism optimization process of the power grid network similar attack behavior analysis method in this embodiment.

[0024] Figure 8 This is a block diagram of the AI-based power grid network similar attack behavior analysis system in this embodiment.

[0025] Figure 9 This is a schematic diagram of the internal structure of a computer device used to implement a method for analyzing similar attack behaviors in power grid networks. Detailed Implementation

[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0028] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0029] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0030] In one embodiment, such as Figure 1 As shown, this application discloses a method for analyzing similar attack behaviors in power grid networks based on an AI model, which specifically includes the following steps: S10: Obtain network traffic data, system log data, and user behavior data from the power grid network respectively, perform data preprocessing, and associate the data with the IP address of the visitor from the power grid network to obtain access association data.

[0031] Specifically, network traffic data includes data packet size, transmission rate, connection frequency, etc.; system log data includes user access count, access location, unauthorized file viewing and modification records, etc.; user behavior data includes login frequency, operation sequence, permission changes, etc.; after data cleaning, noise reduction, standardization and other preprocessing, data is correlated using the visitor IP of the power grid network as the correlation point to obtain visitor IP access correlation data.

[0032] S20: Analyze the user behavior baseline of access-related data, and use the user behavior baseline as a benchmark to train the relevant access-related data to build a behavior analysis AI model.

[0033] Specifically, such as Figure 2 As shown, step S20 includes: S201: Perform access behavior association processing on access-related data, analyze the corresponding user access paths according to the access behavior association order, and obtain the user behavior baseline.

[0034] Specifically, based on the access behavior of the visitor's IP, the access behavior association data of each access node is associated, and the access path of the user to the power grid network is analyzed according to the association order of the access behavior, that is, the access order of the visitor, to form a user behavior baseline.

[0035] S202: Train a graph neural network on the access-related data based on the user behavior baseline, extract access behavior features, analyze the relationship between access behaviors, construct a behavioral neural network architecture, and obtain a behavioral analysis AI model.

[0036] Specifically, based on user behavior baselines, graph neural networks are trained on access-related data. Access behavior features are extracted based on the training results. The changing trends of access behavior features between adjacent access behaviors are analyzed based on user behavior baselines to construct access behavior relationships. Then, the access behavior relationships of each user behavior baseline are used as data training samples to construct a behavior neural network architecture and obtain a behavior analysis AI model.

[0037] S30: Obtain attack correlation data of historical attack behaviors, input it into the behavior analysis AI model for attack behavior analysis, and output the attack behavior characteristics of each attack behavior.

[0038] Specifically, such as Figure 3 As shown, step S30 includes: S301: Obtain attack correlation data of historical attack behaviors, input the attack correlation data into the behavior analysis AI model, compare it with user access behavior, and identify historical attack behaviors based on the comparison results.

[0039] Specifically, such as Figure 4 As shown, step S301 includes: S3011: By comparing network traffic data, identify abnormal traffic and abnormal domains of historical attack behaviors, and obtain abnormal traffic data of historical attack behaviors.

[0040] Specifically, network traffic data is compared between historical attack behaviors and user access behaviors in the model to identify abnormal traffic and abnormal domains in historical attack behaviors that are different from user access behaviors. Abnormal traffic includes abnormal traffic peaks during off-peak periods or unauthorized connection requests on specific ports, etc., to obtain abnormal traffic data of historical attack behaviors.

[0041] S3012: By comparing system log data, identify abnormal operations and processes of historical attack behaviors and obtain abnormal log data of historical attack behaviors.

[0042] Specifically, the system log data is compared between historical attack behaviors and user access behaviors in the model to identify abnormal login attempts such as logins from different locations or successful logins after multiple failed attempts, as well as abnormal operations such as unauthorized file modification records, and abnormal process data such as unknown processes, abnormal memory or CPU usage in normally running processes, thus obtaining abnormal log data of historical attack behaviors.

[0043] S3013: By comparing user behavior data, identify abnormal sensitive operations and abnormal sensitive information of historical attack behaviors to obtain abnormal user behavior data of historical attack behaviors.

[0044] Specifically, the user behavior data is compared with historical attack behaviors and user access behaviors in the model to identify abnormal and sensitive operations in historical attack behaviors, such as executing unauthorized commands, clicking on unverified links in suspicious emails, phone calls or messages, or accessing unauthorized areas, thus obtaining abnormal user behavior data.

[0045] S3014: Combine the power grid intrusion detection results of historical attack behaviors to perform multi-dimensional data correlation on abnormal traffic identification data, abnormal log data, and abnormal user behavior data, and identify historical attack behaviors based on the data correlation results.

[0046] Specifically, through the intrusion detection or prevention system of the power grid network, the power grid intrusion detection results of historical attack behaviors are obtained. The abnormal traffic identification data, abnormal log data, abnormal user behavior data, etc. are correlated with the corresponding power grid intrusion detection results in multiple dimensions. Based on the correlation results, the attack behavior identification strategy of the behavior analysis AI model is trained in the behavior analysis AI model to obtain the historical attack behaviors that can be identified by the behavior analysis AI model.

[0047] S302: Compare user access behavior data, perform behavioral feature analysis on historical attack behaviors, and obtain the attack behavior characteristics of each historical attack behavior. Among them, the behavioral characteristics include behavioral distribution characteristics, time characteristics, semantic characteristics, and behavioral association characteristics.

[0048] Specifically, the user access data in the behavior analysis model is used as a normal access data sample. The abnormal data of historical attack behavior is filtered by comparing the user access behavior data. Attack behavior feature analysis is performed based on the abnormal data that is different from the user access behavior, including multiple attack behavior features such as the distribution of behavioral feature values, attack time, semantic relationship, and behavioral correlation.

[0049] S40: Analyze the baseline of each historical attack behavior and calculate the attack behavior similarity. Based on the attack behavior similarity, evaluate the similar attack behaviors in the current access behavior to obtain the analysis results of similar attack behaviors in the power grid network.

[0050] Specifically, such as Figure 5 As shown, step S40 includes: S401: Predict the attack direction and attack intent of historical attack behaviors based on attack behavior characteristics, and obtain the attack behavior baseline by correlating historical attack behaviors based on the attack direction and attack intent.

[0051] Specifically, based on the changing trends of attack behavior characteristics, attack direction and attack intent are predicted for each historical attack behavior. The attack intent is the data asset that the historical attack behavior wants to access. According to the attack intent prediction results, the historical attack behaviors in the attack direction that go to the location of the data asset corresponding to the attack intent are correlated to obtain the attack behavior baseline.

[0052] S402: Based on the type of behavioral characteristics, calculate the similarity of behavioral characteristics between adjacent attack behaviors on the baseline of attack behavior to obtain the similarity of attack behaviors in historical attack behaviors.

[0053] Specifically, based on the type of behavioral feature, the similarity of behavioral features between adjacent attack behaviors on the attack behavior baseline is calculated. The expression for calculating the similarity of behavioral features is as follows: (1) in, The cosine similarity between adjacent attack behaviors is ( , ), ( , ) represent the coordinate values ​​obtained by mapping each behavioral feature of adjacent attack behaviors onto the two-dimensional coordinate axes.

[0054] S403: Calculate the similarity of access behavior between adjacent access nodes of the current access behavior of the power grid network, and evaluate the similar attack behavior in the current access behavior through the similarity comparison results.

[0055] Specifically, the access behavior features of adjacent access nodes of the current access behavior are mapped onto a two-dimensional coordinate axis to obtain the two-dimensional coordinates of each access behavior feature. The access behavior similarity is calculated according to formula (1), and the behavior similarity between adjacent attack behaviors and user access behaviors at the same access location is analyzed. For example Figure 6 As shown, the similar attack behavior assessment process includes: S4031: Perform collaborative federated learning on multiple similar attack behaviors of the same attack type, calculate the similarity confidence of each similar attack behavior feature based on the similarity of the behavioral features, and sort the similarity confidence.

[0056] Specifically, collaborative federated learning is performed on multiple similar attack behaviors of the same attack type to extract behavioral features of multiple similar attack behaviors, and the similarity confidence of each similar attack behavior feature is calculated. Based on the similarity confidence, multiple similar attack behaviors under the current attack type are ranked to obtain the confidence ranking result.

[0057] The similarity confidence calculation expression in this embodiment is as follows: (2) in, Indicates the first Similarity confidence of similar attack behavior features This represents the mean of similar attack behavior characteristics. Indicates the first Confidence scores for similar attack behavior characteristics This represents the total number of similar attack behavior characteristics. Indicates the first Sample observations of similar attack behavior characteristics.

[0058] S4032: Prioritize clustering of high-confidence behavioral features based on confidence ranking results, and generate threat intelligence for similar attack behaviors of the current attack type based on the clustering results of behavioral features.

[0059] Specifically, based on the confidence ranking results, high-confidence behavioral features are prioritized for clustering. The mean confidence score of each clustered sample is calculated based on the clustering results of the behavioral features. High-confidence anomalous samples are marked as high-threat, generating threat intelligence on similar attack behaviors of the current attack type.

[0060] S4033: Based on threat intelligence of similar attack behaviors, compare the current access behavior with the characteristics of similar attack behaviors, and evaluate the similar attack behaviors in the current access behavior that match the historical attack behaviors based on the comparison results.

[0061] Specifically, based on threat intelligence regarding similar attack behaviors, the current access behavior is compared with the characteristics of similar attack behaviors. If the similarity with the characteristics of similar attack behaviors marked as high threat exceeds a preset threshold, the current access behavior is marked as a similar attack behavior that matches the historical attack behaviors.

[0062] S404: Compare the behavioral feature similarity between similar attack behaviors and historical attack behaviors, and label the hidden attack behavior features in similar attack behaviors based on the comparison results to obtain the analysis results of similar attack behaviors.

[0063] Specifically, similar attack behaviors at the same location are compared with historical attack behaviors in terms of behavioral feature similarity. Based on the comparison results, behavioral features in similar attack behaviors that reach a preset similarity threshold with historical attack behaviors are marked as hidden attack behavior features, thus obtaining the similar attack behavior analysis results. In this embodiment, the feature similarity threshold is dynamically set according to the importance of the data assets at the access location of the power grid network.

[0064] Specifically, such as Figure 7 As shown, step S40 further includes: S405: Identify similar attack patterns based on the characteristics of hidden attack behaviors, and track the attack paths of similar attack behaviors to obtain the hidden attack paths of similar attack behaviors.

[0065] Specifically, based on the characteristics of hidden attack behaviors, similar attack methods are compared with the attack patterns of similar attack methods to obtain similar attack patterns. Attack paths of similar attack behaviors are then tracked, that is, the access locations of similar attack behaviors to the power grid network are tracked to obtain the hidden attack paths of similar attack behaviors.

[0066] S406: Predict the attack intent of similar attack behaviors based on the hidden attack path and predict the next attack node. Match the attack response mechanism for the next attack node in advance based on the similar attack pattern and execute it.

[0067] Specifically, based on the hidden attack path, the attack intent of similar attack behaviors is predicted, that is, the final access data assets of similar attack behaviors. Based on the location of the data assets of the attack intent and the hidden attack path, the next attack node, i.e. the access point, is predicted. According to the similar attack pattern, the attack response mechanism of the next attack node is pre-matched and executed.

[0068] S407: Evaluate the effectiveness of detection and response strategies for similar attack behaviors based on the attack defense results of the next attack node, and adjust the attack response mechanism for subsequent attack nodes based on the effectiveness evaluation results.

[0069] Specifically, the execution results of the attack response mechanism are analyzed to assess the attack defense effectiveness of the next attack node, and the effectiveness of the behavior detection and attack response strategies for similar attack behaviors is evaluated. If the attack behavior is correctly detected and matches an effective attack response strategy, access to the power grid network by similar attack behaviors is blocked. If similar attack behaviors are still active, it indicates that the behavior detection and attack response strategies are ineffective. Subsequent attack nodes of similar attack behaviors are then identified, and the behavior detection and attack response strategies for these subsequent attack nodes are adjusted until access by similar attack behaviors is blocked. The attack response mechanism in this embodiment includes blocking IP addresses, isolating infected terminal devices, disabling compromised user accounts, or adjusting the attacker's access permissions.

[0070] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0071] In one embodiment, an AI model-based power grid network similar attack behavior analysis system is provided, which corresponds one-to-one with the AI ​​model-based power grid network similar attack behavior analysis method described in the above embodiments. For example... Figure 8 As shown, this AI-based power grid network similar attack behavior analysis system includes an access data acquisition module, a model building module, a feature analysis module, and a similar behavior analysis module. Detailed descriptions of each functional module are as follows: The access data acquisition module is used to acquire network traffic data, system log data, and user behavior data of the power grid network, respectively, and perform data preprocessing. It then uses the visitor's IP address in the power grid network as the association point to obtain access association data.

[0072] The model building module is used to analyze the baseline of user behavior when accessing related data, and to train the relevant access-related data based on the baseline of user behavior to build a behavior analysis AI model.

[0073] The feature analysis module is used to obtain attack correlation data of historical attack behaviors, input them into the behavior analysis AI model for attack behavior analysis, and output the attack behavior features of each attack behavior.

[0074] The similar behavior analysis module is used to analyze the baseline of each historical attack behavior and calculate the attack behavior similarity. Based on the attack behavior similarity, it evaluates the similar attack behaviors in the current access behavior and obtains the similar attack behavior analysis results of the power grid network.

[0075] Preferably, the model building module specifically includes: The behavior baseline analysis submodule is used to perform access behavior association processing on access-related data, analyze the corresponding user access paths according to the access behavior association order, and obtain the user behavior baseline.

[0076] The model building submodule is used to train a graph neural network on access-related data based on user behavior baselines, extract access behavior features, analyze the relationship between access behaviors, build a behavioral neural network architecture, and obtain a behavioral analysis AI model.

[0077] Preferably, the feature analysis module specifically includes: The behavior recognition submodule is used to acquire attack correlation data of historical attack behaviors, input the attack correlation data into the behavior analysis AI model, compare it with user access behavior, and identify historical attack behaviors based on the comparison results.

[0078] The feature recognition submodule is used to compare user access behavior data, perform behavioral feature analysis on historical attack behaviors, and obtain the attack behavior features of each historical attack behavior. The behavioral features include behavioral distribution features, time features, semantic features, and behavioral association features.

[0079] Preferably, the behavior recognition submodule specifically includes: The traffic feature identification unit is used to identify abnormal traffic and abnormal domains of historical attack behaviors by comparing network traffic data, and to obtain abnormal traffic data of historical attack behaviors.

[0080] The log feature recognition unit is used to identify abnormal operations and processes of historical attack behaviors by comparing system log data, and to obtain abnormal log data of historical attack behaviors.

[0081] The user behavior feature recognition unit is used to identify abnormal and sensitive operations and information of historical attack behaviors by comparing user behavior data, and to obtain abnormal user behavior data of historical attack behaviors.

[0082] The data association unit is used to combine the power grid intrusion detection results of historical attack behaviors to perform multi-dimensional data association on abnormal traffic identification data, abnormal log data, and abnormal user behavior data, and to identify historical attack behaviors based on the data association results.

[0083] Preferably, the similar behavior analysis module specifically includes: The attack baseline analysis submodule is used to predict the attack direction and attack intent of historical attack behaviors based on attack behavior characteristics, and to obtain the attack behavior baseline by correlating historical attack behaviors based on the attack direction and attack intent.

[0084] The attack similarity analysis submodule is used to calculate the similarity of adjacent attack behaviors on the attack behavior baseline according to the behavior feature type, so as to obtain the attack behavior similarity of historical attack behaviors.

[0085] The similar behavior evaluation submodule is used to calculate the similarity of the current access behavior of adjacent access nodes in the power grid network, and evaluate the similar attack behavior in the current access behavior based on the similarity comparison results.

[0086] The feature annotation submodule is used to compare the behavioral feature similarity between similar attack behaviors and historical attack behaviors, and to annotate the hidden attack behavior features in similar attack behaviors based on the comparison results, so as to obtain the analysis results of similar attack behaviors.

[0087] Preferably, the similar behavior assessment submodule specifically includes: The confidence ranking unit is used to perform collaborative federated learning on multiple similar attack behaviors of the same attack type. It calculates the similarity confidence of each similar attack behavior feature based on the similarity of the behavior features and performs similarity confidence ranking.

[0088] The feature clustering unit is used to prioritize the clustering of high-confidence behavioral features based on the confidence ranking results, and generate threat intelligence of similar attack behaviors for the current attack type based on the clustering results of behavioral features.

[0089] The similarity assessment unit is used to compare the characteristics of similar attack behaviors with those of the current access behavior based on threat intelligence of similar attack behaviors, and to assess the similar attack behaviors in the current access behavior that match the historical attack behaviors based on the comparison results.

[0090] Preferably, after the similar behavior analysis module, it also includes: The hidden path tracing submodule is used to identify similar attack patterns based on the characteristics of hidden attack behaviors, and to trace the attack paths of similar attack behaviors to obtain the hidden attack paths of similar attack behaviors.

[0091] The response mechanism matching submodule is used to predict the attack intent of similar attack behaviors based on the hidden attack path and predict the next attack node. Based on the similar attack pattern, the next attack node is pre-matched with the attack response mechanism and executed.

[0092] The corresponding mechanism optimization submodule is used to evaluate the effectiveness of detection and response strategies for similar attack behaviors based on the attack defense results of the next attack node, and adjust the attack response mechanism of subsequent attack nodes based on the effectiveness evaluation results.

[0093] Specific limitations regarding the AI ​​model-based power grid network similarity attack behavior analysis system can be found in the limitations of the AI ​​model-based power grid network similarity attack behavior analysis method described above, and will not be repeated here. Each module in the aforementioned AI model-based power grid network similarity attack behavior analysis system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0094] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 9 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data on similar attack behaviors in power grid networks. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements an AI model-based method for analyzing similar attack behaviors in power grid networks.

[0095] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of a method for analyzing similar attack behaviors in power grid networks based on an AI model.

[0096] Those skilled in the art will recognize that the units of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.

[0097] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical functional division. In actual implementation, there may be other division methods, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored.

[0098] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0099] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.

Claims

1. A method for analyzing similar attack behaviors in power grid networks based on an AI model, characterized in that, The method includes: The network traffic data, system log data, and user behavior data of the power grid network are obtained and preprocessed. The data are then associated with the IP address of the visitor in the power grid network to obtain access association data. Analyze the user behavior baseline of the access-related data, and use the user behavior baseline as a benchmark to train the relevant access-related data to build a behavior analysis AI model. The attack association data of historical attack behaviors are obtained and input into the behavior analysis AI model for attack behavior analysis, and the attack behavior characteristics of each attack behavior are output. The baseline of each historical attack behavior is analyzed and the similarity of the attack behavior is calculated. Based on the similarity of the attack behavior, similar attack behaviors in the current access behavior are evaluated to obtain the analysis results of similar attack behaviors in the power grid network.

2. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 1, characterized in that, The analysis of the user behavior baseline of the access-related data, using the user behavior baseline as a benchmark, trains the relevant access-related data to construct a behavior analysis AI model, specifically including: The access association data is processed to associate access behavior, and the corresponding user access path is analyzed according to the access behavior association order to obtain the user behavior baseline. Based on the user behavior baseline, a graph neural network is trained on the access-related data to extract access behavior features and analyze the relationship between access behaviors to construct a behavioral neural network architecture, thereby obtaining a behavioral analysis AI model.

3. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 1, characterized in that, The process of acquiring attack correlation data of historical attack behaviors, inputting it into the behavior analysis AI model for attack behavior analysis, and outputting the attack behavior characteristics of each attack behavior specifically includes: Acquire attack association data of historical attack behaviors, input the attack association data into the behavior analysis AI model and compare it with user access behavior, and identify historical attack behaviors based on the comparison results; By comparing the user access behavior data, behavioral feature analysis is performed on the historical attack behaviors to obtain the attack behavior features of each historical attack behavior, wherein the behavioral features include behavioral distribution features, time features, semantic features and behavioral association features.

4. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 3, characterized in that, The process of acquiring attack correlation data of historical attack behaviors, inputting the attack correlation data into the behavior analysis AI model, comparing it with user access behavior, and identifying historical attack behaviors based on the comparison results specifically includes: By comparing network traffic data, abnormal traffic and abnormal domains of the historical attack behavior are identified, and abnormal traffic data of the historical attack behavior is obtained. By comparing system log data, abnormal operations and abnormal processes of the historical attack behavior are identified, and abnormal log data of the historical attack behavior is obtained. By comparing user behavior data, abnormal sensitive operations and abnormal sensitive information of the historical attack behavior are identified, and abnormal user behavior data of the historical attack behavior is obtained. By combining the power grid intrusion detection results of the historical attack behaviors, the abnormal traffic identification data, abnormal log data, and abnormal user behavior data are correlated in multiple dimensions, and historical attack behaviors are identified based on the data correlation results.

5. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 1, characterized in that, The analysis involves establishing a baseline for each historical attack and calculating attack behavior similarity. Based on this similarity, similar attack behaviors in the current access behavior are evaluated to obtain the analysis results of similar attack behaviors in the power grid network. Specifically, this includes: Based on the attack behavior characteristics, predict the attack direction and attack intent of the historical attack behavior; based on the attack direction and attack intent, perform behavioral correlation on the historical attack behavior to obtain the attack behavior baseline. Based on the type of behavioral characteristics, the similarity of behavioral characteristics of adjacent attack behaviors on the baseline of the attack behavior is calculated to obtain the attack behavior similarity of the historical attack behaviors. The similarity of access behavior between adjacent access nodes of the current access behavior of the power grid network is calculated, and the similarity comparison results are used to evaluate the similar attack behavior in the current access behavior. The similar attack behaviors are compared with the historical attack behaviors in terms of behavioral feature similarity. Based on the comparison results, the hidden attack behavior features in the similar attack behaviors are labeled to obtain the similar attack behavior analysis results.

6. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 5, characterized in that, The process of calculating the similarity of access behaviors between adjacent access nodes in the power grid network and evaluating similar attack behaviors in the current access behavior based on the similarity comparison results specifically includes: Collaborative federated learning is used to perform collaborative learning on multiple similar attack behaviors of the same attack type. The similarity confidence of each similar attack behavior feature is calculated based on the similarity of the behavioral features, and the similarity confidence is sorted. Based on the confidence ranking results, high-confidence behavioral features are prioritized for clustering, and similar attack behavior threat intelligence for the current attack type is generated based on the clustering results of behavioral features. Based on the threat intelligence of similar attack behaviors, the current access behavior is compared with the characteristics of similar attack behaviors, and the similar attack behaviors that match the historical attack behaviors in the current access behavior are evaluated based on the comparison results.

7. The method for analyzing similar attack behaviors in power grid networks based on an AI model according to claim 5, characterized in that, After analyzing the baseline of each historical attack behavior and calculating the attack behavior similarity, and evaluating similar attack behaviors in the current access behavior based on the attack behavior similarity to obtain the analysis results of similar attack behaviors in the power grid network, the method further includes: Based on the hidden attack behavior characteristics, identify similar attack patterns of similar attack behaviors, and perform attack path tracking on the similar attack behaviors to obtain the hidden attack paths of the similar attack behaviors; Based on the hidden attack path, predict the attack intent of the similar attack behaviors and predict the next attack node; based on the similar attack patterns, pre-match the attack response mechanism for the next attack node and execute it. The effectiveness of the detection and response strategy for similar attack behaviors is evaluated based on the attack defense results of the next attack node, and the attack response mechanism for subsequent attack nodes is adjusted based on the effectiveness evaluation results.

8. A power grid network similar attack behavior analysis system based on an AI model, characterized in that, The system is applied to the AI-based power grid network similar attack behavior analysis method according to any one of claims 1-7, and the system comprises: The access data acquisition module is used to acquire network traffic data, system log data and user behavior data of the power grid network respectively, and perform data preprocessing. It uses the visitor IP of the power grid network as the association point to associate the data and obtain access association data. The model building module is used to analyze the user behavior baseline of the access-related data, and to train the relevant access-related data based on the user behavior baseline to build a behavior analysis AI model. The feature analysis module is used to acquire attack correlation data of historical attack behaviors, input it into the behavior analysis AI model for attack behavior analysis, and output the attack behavior features of each attack behavior. The similar behavior analysis module is used to analyze the baseline of each historical attack behavior and calculate the attack behavior similarity. Based on the attack behavior similarity, it evaluates the similar attack behaviors in the current access behavior and obtains the similar attack behavior analysis results of the power grid network.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the AI ​​model-based power grid network similar attack behavior analysis method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the AI ​​model-based power grid network similar attack behavior analysis method as described in any one of claims 1 to 7.