Active power distribution network malicious instruction attack risk assessment method considering behavior characteristics

By establishing a representation model and analyzing the behavioral characteristics of the active distribution network cyber-physical system, a risk assessment model for malicious command attacks is constructed. This solves the problem of insufficient risk assessment for active distribution networks when facing malicious command attacks, realizes dynamic risk assessment and accurate quantification of malicious command attacks, and improves the system's adaptability and stability.

CN121966932APending Publication Date: 2026-05-01STATE GRID LIAONING ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID LIAONING ELECTRIC POWER CO LTD
Filing Date
2025-12-22
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, active power distribution networks lack effective risk assessment models when facing malicious command attacks, resulting in the inability to accurately assess and prevent the risks of cascading power grid failures and catastrophic power outages.

Method used

A risk assessment method for malicious command attacks on active distribution networks that considers behavioral characteristics is adopted. By establishing a representation model of the cyber-physical network of a non-uniform power distribution network, a malicious command attack behavior model is constructed. Based on a numerical simulation model of historical event data analysis, a risk assessment model is constructed. Considering the influencing factors of information nodes being attacked, a risk assessment method for distribution networks under the threat of malicious command attacks is established.

Benefits of technology

It enables dynamic risk assessment of malicious command attacks on active power distribution networks, improves the system's adaptability and stability, provides accurate risk quantification assessment, supports the formulation of targeted defense strategies, and enhances the system's response speed and control accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966932A_ABST
    Figure CN121966932A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of risk assessment of malicious instruction attacks in the field of energy control, and particularly relates to an active power distribution network malicious instruction attack risk assessment method considering behavior characteristics. Comprising the steps of establishing a representation model of a non-uniform power distribution network information physical network; according to the representation model, constructing a malicious instruction attack behavior model so as to research the risk that the active power distribution network is attacked by malicious instructions, analyzing the invasion characteristics of the previous malicious instructions, and establishing a numerical simulation model based on historical event data analysis; and constructing a risk assessment model, considering influence factors that information nodes are attacked, and establishing a risk assessment method for the power distribution network under malicious instruction attack threats. According to the method, the evaluation is more comprehensive and accurate through a numerical simulation model of historical event data analysis, the risk value is directly quantified subsequently, the risk can be perceived and measured, the evaluation is more accurate compared with qualitative evaluation, and a targeted defense strategy can be formulated subsequently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of risk assessment of malicious command attacks in the energy control field, and particularly relates to a method for risk assessment of malicious command attacks on active distribution networks that considers behavioral characteristics, especially a method for risk assessment of malicious command attacks on active distribution networks that considers the behavioral characteristics of malicious commands. Background Technology

[0002] In recent years, with the improvement of information technology levels in distribution networks, the interaction between the information layer and the physical layer of the distribution network cyber-physical system (CPS) has become increasingly frequent. Attackers using attacks on power information systems to indirectly disrupt the physical power system has become a common tactic for grid attackers. When active distribution networks are affected by malicious commands, it can lead to a cascading failure across the entire grid, ultimately resulting in catastrophic power outages. Therefore, researching models of the cross-space propagation mechanism of malicious commands against active distribution network information systems is of great significance for the safe and stable operation of the power grid.

[0003] Active power distribution network cyber-physical systems (CPS) are mainly divided into two layers. The first is the information layer, composed of various information processing devices. This layer involves the collection and processing of a large amount of energy data, including energy supply, demand, and load data. Malicious commands attacking the information layer of the distribution network can lead to the loss or alteration of important power data, affecting the accuracy and real-time performance of the system's energy decisions. Malicious commands can not only cause data loss but may also cause malfunctions in the physical equipment of the distribution network. Protecting the active power distribution network CPS from malicious commands is crucial, but prior to this, research on the cross-space propagation mechanism of malicious commands against the active power distribution network information system is particularly important. The establishment of a propagation model will directly affect subsequent malicious command detection and system protection. Summary of the Invention

[0004] To address the shortcomings of existing risk assessment models for active distribution networks facing malicious command attacks, this invention provides a method for assessing the risk of malicious command attacks on active distribution networks that considers behavioral characteristics. The aim is to abstract the distribution network cyber-physical system (CPS) into a two-layer directed unweighted graph based on the topological correlation and the coupling logic between the information and physical layers. For simplified analysis, a station-level local area network (LAN) can be represented as a network node. Communication between the network node and the control center occurs through a communication network, typically employing a dual-star network or mesh network structure. In practice, a physical node in the power grid usually represents a bus, and a network node maps to one or more buses to monitor / control the physical components connected to its mapped buses. Subsequently, this invention considers the behavior of malicious command attacks, dividing it into two stages for evaluation, thus establishing the purpose of the risk assessment model that considers the behavioral characteristics of malicious commands.

[0005] The technical solution adopted by the present invention to achieve the above objectives is as follows:

[0006] Methods for assessing the risk of malicious command attacks on active power distribution networks that consider behavioral characteristics include:

[0007] Establish a representation model for cyber-physical networks of non-uniform power distribution networks;

[0008] Based on the aforementioned characterization model, a malicious command attack behavior model is constructed to study the risk of active power distribution networks being attacked by malicious commands, analyze the characteristics of past malicious command intrusions, and establish a numerical simulation model based on historical event data analysis.

[0009] Based on the numerical simulation model, a risk assessment model is constructed, taking into account the influencing factors of information node attacks, and a risk assessment method for distribution networks under the threat of malicious command attacks is established.

[0010] Furthermore, the establishment of a representation model for a non-uniform power distribution network cyber-physical network includes:

[0011] Assumptions are made about complex network theory;

[0012] Based on the assumptions, the physical layer representation and information layer representation of the active distribution network are abstracted.

[0013] Analysis of malicious command attack behavior at the information layer.

[0014] Furthermore, the assumptions made regarding complex network theory include:

[0015] 1) Taking the plant level as the research unit, the information network and physical site are regarded as equivalent information nodes and physical nodes, respectively;

[0016] 2) Communication lines between network sites are equivalent to the edge of the network, and transmission lines between physical sites are equivalent to the edge of the physical network;

[0017] 3) Consider the directionality and dependency between links in the physical network and the information network. Links between layers are undirected edges, while edges between different layers are directed edges.

[0018] Based on the above definitions and assumptions, and using complex network theory, the topology of the information network and physical network of the active distribution network is abstracted and represented as two unweighted partially directed graphs. and ,in For information networks, For physical networks;

[0019] The physical layer representation, wherein the physical layer model is abstracted as an unweighted graph of a complex network. ,in For nodes, As an edge, For the set of nodes in a physical network, It is the set of connection edges in the physical network. This is the adjacency matrix of the physical network;

[0020] The information layer representation, where information network nodes are the control and processing centers of the corresponding physical layer network nodes, assumes that all related functions are performed in abstract nodes within the network model; the network layer model is abstracted as a complex unweighted graph. ,in For nodes, For the edge, For a set of nodes in an information network, For the set of connection edges of an information network, This is the adjacency matrix of an information network;

[0021] The analysis of malicious command attack behavior at the information layer includes:

[0022] 1) An attack on the control center;

[0023] Attackers use advanced intrusion tools to bypass firewalls, scan hosts and services in the network, and after gaining access to application servers, send malicious commands directly to IEDs or RTUs.

[0024] 2) Attacks on substation networks;

[0025] Attackers used port scanning tools to identify the substation's IP address and then logged into the router via brute-force password attacks. After bypassing the firewall and gaining access to the substation's network, they performed IP scans on different user interfaces to execute unauthorized operations.

[0026] 3) Attacks on the communication link between the control center and the substation;

[0027] Attackers can gain access to communication networks, eavesdrop on messages, and analyze traffic to carry out attacks. After intercepting and decoding messages in the communication link, attackers can replace the actual measurement, status, or control data and replay the fabricated data into the network. When false measurement and status data are sent to the status estimation module, control decisions are misled, leading to incorrect tripping or load shedding. Another method to hide events and the status of active distribution networks is to delay / interrupt messages from reaching their intended destination through DoS attacks on the communication network. DoS attacks can prevent control centers from predicting or perceiving ongoing or impending faults, causing them to be unable to take timely measures, which in turn leads to a significant increase in the failure rate and maintenance time of active distribution networks.

[0028] To simplify the analysis, a station-level LAN is represented as a network node. The network node and the control center communicate with each other through a communication network, which is usually a dual-star network or a mesh network. In practice, a physical node in an active distribution network represents a bus. A network node maps one or more buses to monitor / control the physical components connected to its mapped bus. Therefore, attacking a communication network node is an effective way to compromise the physical network.

[0029] Furthermore, the numerical simulation model based on historical event data analysis includes:

[0030] The utility value of the target;

[0031] The selection of targets for malicious commands;

[0032] The number of targets attacked by malicious commands;

[0033] The probability of successful resource allocation and malicious command attacks.

[0034] Furthermore, the utility value of the attack target includes:

[0035] 1) Feature attributes:

[0036] The purposes of launching malicious command attacks on the power grid include: power disruption, political intimidation, and extreme aversion. Different purposes lead attackers to focus on different characteristics of candidate targets. Attackers weigh the characteristics of candidate targets, including attack complexity, topological relationships, and public opinion impact, and make decisions that are conducive to achieving their objectives.

[0037] The above attributes are divided into two categories based on their role in achieving the desired effect:

[0038] (1) The benefit attribute has a positive impact on the attack, and the higher the value, the more beneficial it is;

[0039] (2) Cost attribute, which has a negative impact on attacks; the higher the value, the lower the acceptance.

[0040] Attack complexity is a cost attribute that refers to the difficulty of successfully breaching a candidate target; the attribute value is quantified into defensive effectiveness using an exponential function.

[0041]

[0042] in, For attacking complexity attribute functions, For defense resource quantization function, Is Candidate targets The amount of defense resources allocated can be quantified; For defense conversion coefficient, where The elimination costs incurred by defenders to reduce vulnerability and increase defense strength , The defender's elimination score is defined as... The percentage of available cost elimination allocated above;

[0043] Topological relationship is a useful attribute that refers to the closeness of the relationship between a candidate objective and other candidate objectives; the attribute value is quantified as the first... The median degree of each node:

[0044]

[0045] in, This is a topological relation attribute function. For nodes and Through nodes The number of shortest paths between them. For nodes and The total number of shortest paths between them;

[0046] Public opinion impact is a beneficial attribute, referring to the degree of influence on political, economic, and social activities caused by attacks resulting in power outages or insufficient power supply in a specific area. The influence of public opinion is quantified using the economic or social value of load loss, and is determined as a function of load level and social impact coefficient.

[0047]

[0048] In the formula, For the attribute function of public opinion influence, To and The load of the corresponding physical node, for The social impact coefficient;

[0049] 2) Attack preferences:

[0050] Attackers can be categorized based on their objectives: terrorist attackers, high-performing attackers, and ordinary attackers.

[0051] When measuring the utility of candidate targets, feature attributes are converted into their natural unit values ​​based on their preference attitudes, which are then equated to attacker satisfaction. If an attribute is favored by the attacker, the score is higher or lower. Attack preference is used as the weight of attribute values ​​in the utility metric.

[0052] 3) Utility value calculation:

[0053] To construct an effective framework for modeling multi-factor behavior in network attacks, the following implementable and practical utility function is adopted:

[0054]

[0055]

[0056] in, for The utility value, The number of feature attributes for each candidate target. For utility weights, represents the weight of the first... The degree of preference for each feature attribute is calculated using the analytic hierarchy process (AHP). for The The quantized value of each feature attribute, for The normalized value, and They are the first The maximum and minimum values ​​of each feature attribute;

[0057] The selection of the target for the malicious instruction attack includes:

[0058] 1) Logit model and probabilistic response:

[0059] Determined based on utility value and Logit model The probability of being selected as a primary target of attack is denoted as the response probability:

[0060]

[0061] In the formula, For the response probability, This represents the attacker's utility value towards the candidate target. Let E be the t-th target being attacked, and E be the set of candidate targets. The attacker's response sensitivity to the utility value of candidate targets; The higher the value, the more significant the attacker's preference for the main target. In other words, the attacker has aggressive selection behavior, is more sensitive to the utility differences between candidate targets, and is more inclined to choose candidate targets with higher utility values. A lower value indicates an unclear bias in the selection of primary targets, suggesting that the attacker is very cautious in choosing their primary targets; when... When the value is zero, all candidate targets have the same response probability; given a target set The utility value and the historical records of the attack targets, where the records are approximately independent and have the same response probability, are used to determine the MLE based on the Maximum Likelihood Estimation. :

[0062]

[0063]

[0064]

[0065] In the formula, for The MLE function, Select the number of historical records for the primary attack target for the attacker. express In the Scenes selected as primary attack targets in historical records. for In the The probability of being selected as a primary attack target in a historical record;

[0066] set up for The number of cases selected as primary attack targets can be obtained as follows:

[0067] ;

[0068] 2) Utility decay model;

[0069] Once the primary target is locked, the attacker will proceed with a second selection process, where the utility value of each candidate target varies depending on its neighboring topology and its topological distance to the primary target.

[0070] When selecting the first The candidate targets are selected as the primary attack targets, denoted as... hour, The utility value from Become To make it easier to distinguish, The pre-utility value is named ,Will exist The post-utility value is named ;

[0071] The topological connection between two targets is the communication link between nodes in a communication network. The farther away from the primary target, the less attractive it is to attackers; this topological distance... ,from arrive Defined from arrive The number of links in the shortest topology path, utility value The calculation is as follows:

[0072]

[0073]

[0074] In the formula, This is the distance attenuation coefficient; when equal , =0, When the value is 1, the utility value of the primary objective remains unchanged during the second selection process;

[0075] When the attacker attempts to from Select from candidate targets When setting goals, once the main goals are determined... ,other Each candidate target will be in accordance with its Reorder the items and select the first ones. One goal;

[0076] The number of targets attacked by the malicious commands;

[0077] The number of targets that malicious commands can attack is limited by the attack capability and the total amount of resources. Typically, the number of targets is naturally random. It is also with Related random variables; and The probability distribution is obtained through historical event analysis and statistics; considering The probability distribution is not uniform; the inner probability of E is simulated based on the Poisson distribution model. The probability of a target being selected:

[0078]

[0079]

[0080] in, equal The expected value and its variance, The basic attack resources required to successfully attack the target, n max (1≤n max ≤T) represents the maximum expected number of attack targets. and Obtained through post-evaluation;

[0081] Assumption Follows a normal distribution ,in and These are parameters related to attacker characteristics. This represents the average attack resources required to execute the task; empirical evidence from the normal distribution indicates that 99% of the data will be distributed within the interval [range]. Within; to streamline the modeling process and simplify the analysis, the extended interval will be... Discretize into 7 subintervals, each represented by its median. , , , , , , The first resource quantity The possible values ​​are denoted as Its probability is ;

[0082] The probability of successful resource allocation and malicious command attacks;

[0083] When a candidate target is selected, the attacker allocates resources to ensure the attack's success; simultaneously, the defender also activates defensive resources in response to the attack. The resources invested by the two adversaries in this competition are used to model the probability of success; when the first candidate target is selected... One candidate When a target is identified as an attack target, the probability of success for this attack is calculated using an exponential function:

[0084]

[0085]

[0086]

[0087] In the formula, For attack The probability of success, for The amount of attack resources allocated above. for The amount of defense resources allocated above, and They are respectively The attack efficiency and defense efficiency of the attack. and These are the attack conversion coefficient and the defense conversion coefficient. Calculated as ,in It increases the probability of destruction. Minimum attack resources Is Attack resources allocated above The score;

[0088] Considering that attackers use utility values Allocate resources when the primary objective is... When locked, The calculation is as follows:

[0089]

[0090] in, This refers to the set of attack targets.

[0091] Furthermore, the risk assessment model includes:

[0092] Scenario probability;

[0093] Consequences of the attack;

[0094] Definition of risk index.

[0095] Furthermore, the scenario probabilities include:

[0096] Given an attack scenario Select the main target Total number of targets attacked Attack resources ,but The probability of occurrence is calculated as follows:

[0097]

[0098] There is a set of attack targets ; Assumption have A single successful attack scheme, the first A successful solution It means that, in The set containing successfully attacked targets is , ; The probability of its occurrence is:

[0099] ;

[0100] The consequences of the attack include:

[0101] Load loss directly caused by the attack Load reduction due to grid operation constraints Quantified by summation:

[0102]

[0103] in, The following calculations were performed using the optimal load reduction model:

[0104]

[0105] In the formula, For the power grid bus number, For the power flow vector of the transmission line, This refers to the active power vector injected into the bus. This is the load demand vector at the busbar. The load reduction vector at the busbar. Let A be the diagonal matrix of the transmission line admittance, A be the incidence matrix, and B be the admittance matrix.

[0106] The risk index is defined as follows:

[0107] Given the probability and consequences of an attack, the attack scenario... The risk calculation is as follows:

[0108]

[0109] in, yes The results show that the attack resources are discretized into 7 levels and scored, assuming a maximum number of attack targets. Then it has the main attack target. The The risk calculation for each target scenario is as follows:

[0110]

[0111] Accumulate the total risk to the power grid posed by malicious command behavior:

[0112] .

[0113] A risk assessment model for malicious command attacks on active power distribution networks that considers behavioral characteristics includes:

[0114] Characterization Model Building Module: Used to build a characterization model of a non-uniform power distribution network cyber-physical network;

[0115] Numerical simulation model building module: used to construct a malicious command attack behavior model based on the characterization model, thereby studying the risk of active power distribution networks being attacked by malicious commands, analyzing the characteristics of past malicious command intrusions, and establishing a numerical simulation model based on historical event data analysis;

[0116] Assessment Method Establishment Module: This module is used to construct a risk assessment model based on the numerical simulation model, consider the influencing factors of information node attacks, and establish a risk assessment method for the distribution network under the threat of malicious command attacks.

[0117] A computer device includes a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the active power distribution network malicious instruction attack risk assessment method considering behavioral characteristics as described in any one of the claims.

[0118] A computer storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of any of the methods for assessing the risk of malicious instruction attacks on active power distribution networks that consider behavioral characteristics.

[0119] The present invention has the following beneficial effects and advantages:

[0120] This invention proposes a cyber-physical system architecture for distribution networks, studies the intrusion mechanism of malicious commands, and conducts a risk assessment of malicious command attacks. After establishing the coupled network structure of the active distribution network cyber-physical system, this invention builds a behavioral model. Then, based on the analysis of historical event data, it uses probabilistic response and utility decay models to describe the behavior of attack target selection and attack resource allocation, respectively. It studies the process of malicious commands intruding into the coupled network and establishes a dynamic risk propagation model. Finally, it constructs a risk assessment model, providing an indicator for the safe and stable operation of active distribution networks from the perspectives of scenario probability, attack consequences, and the definition of risk indicators.

[0121] Compared with the existing cyber-physical system architecture of power distribution networks, this invention deeply integrates the power physical network and the information communication network to form a closely related comprehensive system. This helps to achieve more efficient information-physical interaction, improve system response speed and control accuracy, and realize the distribution of hybrid computing through the interaction of information flow and energy flow, enabling the system to respond in real time and adapt to various operating conditions, thereby improving the system's adaptability and stability.

[0122] Compared with existing methods, this invention proposes a novel behavioral model to study the risk of malicious command attacks on active power distribution networks. This model employs utility values ​​and a utility decay model to describe the different subjective attack attitudes and characteristics of candidate targets, thus fully considering the behavioral characteristics of malicious command attacks. Based on this model, this invention proposes a risk calculation method for malicious command intrusion, providing a reference for subsequent protection and detection. Numerical simulation models using historical event data analysis make the assessment more comprehensive and accurate, directly quantifying the risk value, making the risk not only perceptible but also measurable. This is more precise than qualitative assessments and is beneficial for developing targeted defense strategies.

[0123] Compared with existing methods, this invention proposes a behavioral model to study the risk of malicious command attacks on active power distribution networks. This model uses utility values ​​and a utility decay model to describe different subjective attack attitudes and characteristics of candidate targets, and employs a multi-attribute utility function to quantify the utility weights of different attack types, more realistically reflecting the attacker's subjective decision-making process. Furthermore, a risk calculation method for malicious command intrusion is proposed, which considers the randomness of the number of attack resources and the uncertainty of the number of attack targets, making the risk assessment results closer to reality and avoiding overly conservative estimates. Attached Figure Description

[0124] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0125] Figure 1 This is a schematic diagram of the cyber-physical system fusion architecture for power distribution networks according to the present invention;

[0126] Figure 2 This is a diagram illustrating the process of information network and physical network interaction and transmission in this invention.

[0127] Figure 3 This is an example of the information network node topology distance of the present invention;

[0128] Figure 4 This is a flowchart of the network risk assessment process for the cyber-physical system of the power distribution network according to the present invention;

[0129] Figure 5 This is the main execution structure diagram for risk assessment of this invention;

[0130] Figure 6 This is a flowchart of the risk assessment method for malicious command attacks on active power distribution networks that takes into account behavioral characteristics, as described in this invention. Detailed Implementation

[0131] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other.

[0132] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and therefore the scope of protection of the invention is not limited to the specific embodiments disclosed below.

[0133] The following reference Figures 1-6 The technical solutions of some embodiments of the present invention are described below.

[0134] Example 1

[0135] This invention provides an embodiment of a method for assessing the risk of malicious command attacks on active power distribution networks, taking into account behavioral characteristics, such as... Figure 1-6 As shown. This invention is applicable to the cyber-physical system of active power distribution networks. It establishes a coupled network for the active power distribution network cyber-physical system by physically connecting the electrical heating network using graph theory. A behavioral model is used to study the risk of malicious command attacks on active power distribution networks. Based on the methods of utility value and analysis of historical event data, probabilistic response and utility decay models are used to describe the behavior of attack target selection and attack resource allocation, respectively. A risk propagation threshold algorithm is also provided. Specifically, this is because the risk and vulnerable nodes of the power grid change with the characteristics of malicious command attack behavior and target attributes; therefore, the intrusion of malicious commands into the active power distribution network should be considered dynamically.

[0136] On the one hand, this invention establishes a representation model of the cyber-physical system network on the active distribution network side. The distribution network cyber-physical system consists of two layers, mainly divided into the physical network layer and the information network layer. The interaction process between the energy flow of the physical equipment layer and the information flow of the control center layer takes place in the information communication layer. The information layer collects and transmits information to the physical layer, thereby monitoring and controlling the distribution network.

[0137] On the other hand, this invention establishes a risk assessment model for malicious command attacks on active distribution networks that considers the behavioral characteristics of malicious commands. Specifically, it establishes a behavioral model to study the risk of malicious command attacks on active distribution networks. Currently, it is generally believed that physical node failures lead to coupled network node failures; however, network node failures can also lead to physical node failures. Therefore, this invention considers the risk assessment of information networks suffering from malicious command attacks. The utility value is first determined by the subjective attack attitude and the behavioral characteristics of the attack candidate targets; then, based on the analysis of historical event data, probabilistic response and utility decay models are used to describe the behavior of attack target selection and attack resource allocation. This is because the risk and vulnerable nodes of the power grid change with the characteristics of malicious command attack behavior and target attributes; therefore, the intrusion of malicious commands into the active distribution network should be considered dynamically.

[0138] Finally, this invention establishes a risk propagation assessment model for malicious commands occurring in active power distribution network cyber-physical systems.

[0139] In a distribution network cyber-physical system, the information layer and the physical layer often exhibit coupling effects. This coupling is primarily manifested in the frequent interactions between physical domain nodes and information domain nodes, and the need for coordination between information flow and energy flow. The main function of the information layer is to collect, transmit, and process power data from the distribution network, while the physical layer is the physical network comprising various types of power equipment. The composition of an active distribution network cyber-physical system is quite complex, mainly because both the information domain and the physical domain are vast systems containing massive amounts of power communication equipment and complex interconnected and mutually constraining rules.

[0140] This invention provides a method for assessing the risk of malicious command attacks on active power distribution networks that considers behavioral characteristics, specifically including the following steps:

[0141] S1. Establish a representation model of the cyber-physical network of a non-uniform power distribution network, establish physical layer representation and information layer representation, and based on this, establish a characteristic model of the cyber-physical coupled network and make reasonable assumptions.

[0142] This involves analyzing the overall architecture of the distribution network cyber-physical system, characterizing the physical equipment layer, the information communication layer, and the coupling relationships between them.

[0143] S2. Based on the representation model, construct a malicious command attack behavior model to study the risk of active power distribution networks being attacked by malicious commands. By analyzing the characteristics of past malicious command intrusions, establish a numerical simulation model based on historical event data analysis.

[0144] S3. Based on the numerical simulation model based on historical event data analysis, a risk assessment model was constructed, and considering the influencing factors of information node attacks, a risk assessment framework for the distribution network under the threat of malicious command attacks was established.

[0145] Example 2

[0146] The present invention provides another embodiment, which is a method for assessing the risk of malicious command attacks on active power distribution networks that takes into account behavioral characteristics.

[0147] like Figure 1 As shown, Figure 1 This is a schematic diagram of the cyber-physical system architecture of the power distribution network of the present invention, which mainly consists of two layers;

[0148] like Figure 2 As shown, Figure 2 This invention describes the process of interactive transmission between the information network and the physical network; that is, the coupling relationship between the power distribution network information network and the physical network, and the process of malicious commands propagating in the coupled network.

[0149] like Figure 3 As shown, Figure 3This is an example of the information network node topology distance of the present invention, namely, an example of the information network node topology distance of an active power distribution network;

[0150] like Figure 4 As shown, Figure 4 This is a flowchart of the network risk assessment process for the cyber-physical system of the distribution network of the present invention, namely, the risk assessment process for an active distribution network affected by malicious commands.

[0151] This invention provides a risk assessment method for malicious command attacks on active power distribution networks that considers the characteristics of malicious command behavior. Specifically, it employs the aforementioned quantitative risk assessment method for the propagation of malicious command attacks on active power distribution networks that considers the characteristics of malicious command behavior, and includes the following steps:

[0152] S1. A representation model of the cyber-physical network of a non-uniform power distribution network was established, and physical layer representation and information layer representation were established. Based on this, the locations where malicious commands are likely to occur were analyzed, and the situation was divided into three main cases.

[0153] S1.1: Assumptions are made regarding complex network theory, as follows:

[0154] 1) Taking the plant level as the research unit, the information network and physical site are regarded as equivalent information nodes and physical nodes, respectively.

[0155] The information network includes: the information systems and dispatch centers of each power station;

[0156] Physical sites include: power plants, substations, and converter stations.

[0157] Specifically, the connection between physical nodes and information nodes in an active power distribution network cyber-physical system is directional and interdependent. The failure of a physical node means that the information node cannot collect accurate physical data. Similarly, if an information node fails, the physical node is no longer reliable. Furthermore, a physical node can exchange information with several information nodes simultaneously. Therefore, the network model established in this invention can fully consider the risk assessment of information networks being attacked by malicious commands.

[0158] 2) Communication lines between network sites are equivalent to the edge of the network. Transmission lines between physical sites are equivalent to the edge of the physical network.

[0159] 3) Considering the directionality and dependency between links in physical networks and information networks, links between layers are undirected edges, while edges between different layers are directed edges.

[0160] Based on the above definitions and assumptions, the topological structure of the information network and physical network of the active distribution network is abstracted using complex network theory and represented as two unweighted partially directed graphs. and ,in Represents information networks, Represents a physical network.

[0161] S1.2: Physical layer characterization.

[0162] The physical layer model can be abstracted as a complex network unweighted graph. ,in For nodes (power plants, substations, converter stations). For the edge (transmission line). For the set of nodes in a physical network, It is the set of connection edges in the physical network. This is the adjacency matrix of the physical network. Edges between physical layer nodes are not considered in terms of direction or capacity. In the coupled model, if a physical node fails, the network nodes that depend on its energy will also fail.

[0163] S1.3: Information layer representation.

[0164] Information network nodes are the control and processing centers of their corresponding physical layer network nodes. In the network model, all related functions are considered to be performed in abstract nodes. Similar to the physical layer model, the network layer model is abstracted as a complex unweighted graph. ,in For nodes (servers, computing devices, data acquisition devices). For the edge (communication line). For a set of nodes in an information network, For the set of connection edges of an information network, This is the adjacency matrix of the information network. The direction of edges between nodes in the information layer is not considered.

[0165] S1.4: Analysis of malicious command attack behavior at the information layer.

[0166] A typical SCADA system consists of a control center local area network (LAN), multiple substation LANs, and communication links between the control center and the substations. Malicious attackers can compromise any available access point to the SCADA system, thereby impacting the physical network, including:

[0167] 1) Attacks on the control center. Attackers use advanced intrusion tools to bypass firewalls and scan hosts and services on the network. After gaining access to the application server, they can directly send malicious commands to the IED or RTU.

[0168] 2) Attacks on substation networks. Attackers use port scanning tools to identify the substation's IP addresses and then log in to the router via brute-force password attacks. After bypassing the firewall and gaining access to the substation network, they can perform IP scans on different user interfaces to perform unauthorized operations, such as reconfiguring field equipment parameters, manipulating measurement data and GPS time, and sending malicious commands to IEDs or RTUs.

[0169] 3) Attacks on the communication link between the control center and the substation. Attackers access the communication network, eavesdrop on messages, and analyze traffic to carry out attacks. After intercepting and decoding messages in the communication link, attackers can replace some actual measurement, status, or control data and replay the fabricated data into the network. When false measurement and status data are sent to the status estimation module, control decisions may be misled, leading to incorrect tripping or load shedding. Another method of concealing events and the status of the active distribution network is to delay / interrupt messages reaching their intended destination through a DoS attack on the communication network. DoS attacks prevent the control center from predicting or perceiving ongoing or impending faults, causing the control center to be unable to take timely measures, thus significantly increasing the failure rate and maintenance time of the active distribution network.

[0170] To simplify the analysis, a station-level LAN can be represented as a network node. Network nodes and the control center communicate with each other through a communication network, typically a satellite network or a mesh network. In practice, a physical node in an active distribution network usually represents a bus, and a network node maps one or more buses to monitor / control the physical components connected to its mapped bus. Therefore, it can be seen that attacking communication network nodes is an effective way to compromise the physical network.

[0171] S2. Construction of a malicious command attack behavior model.

[0172] A malicious command attack is a two-phase process, consisting of preparation and execution. In the preparation phase, the attacker selects a target to achieve their objective. In the execution phase, the attacker invests resources to breach the target and ensure the attack's success. The attack can be described as... Select from candidate targets The task involves identifying targets and allocating resources to ensure a successful attack on the selected targets. In this work, communication network nodes are candidate targets, and a candidate set can be used. Let T represent the total number of candidate nodes. For the first There are 10 candidate nodes, while the control center is negligible in the following analysis because the risk of it being directly breached by a network attack is extremely low.

[0173] Attackers, as agents with varying attitudes, often make decisions based on personal satisfaction or preferences. Measuring personal satisfaction or preferences is a key issue in research on attack behavior. According to utilitarianism and decision theory, the decision-making criteria among alternatives are numerical representations of the decision-maker's satisfaction or preferences; utility is a universally accepted concept for measuring satisfaction or preferences. Typically, each alternative is evaluated for desirability on several scoring criteria, and a utility function is used to convert the performance of alternatives, measured in natural units, into an equivalent value of the decision-maker's satisfaction or preferences. The utility value, incorporating the attacker's subjective attitudes, is then used to analyze target selection and resource allocation behavior on candidate targets.

[0174] S2.1: The utility value of the target.

[0175] Utility functions, as an effective method, have been widely applied in fields such as economics, finance, management, and artificial intelligence. Examples include modeling consumer preference ranking for a set of choices or investor satisfaction with different investment portfolios. In artificial intelligence, different utility functions are used to communicate the value of various outcomes to intelligent agents. However, expressing utility functions is a complex issue. It can be viewed as a cardinal number, an ordinal number, or a more precise representation can be obtained through big data analysis. Since the utility value of each alternative attack decision is evaluated based on multiple scoring criteria and subjective attitudes, the scoring criteria in this invention are defined as feature attributes, which can be used to reflect certain performances of the target candidate, while the attacker's attitude towards these feature attributes is defined as preference.

[0176] 1) Feature attributes:

[0177] Generally, the purposes of launching malicious command attacks on the power grid fall into three categories: power disruption, political intimidation, and strong aversion. These different purposes lead attackers to focus on different characteristics of candidate targets. Attackers weigh the characteristics of candidate targets, including attack complexity, topological relationships, and public opinion impact, and make decisions that are conducive to achieving their objectives.

[0178] The above attributes can be divided into two categories based on their role in achieving the desired effect:

[0179] (1) The benefit attribute has a positive impact on the attack, and the higher the value, the more beneficial it is.

[0180] (2) Cost attribute, which has a negative impact on attacks. The higher the value, the lower the acceptance.

[0181] Attack complexity is a cost attribute that refers to the difficulty of successfully breaching a candidate target. With limited attack resources, the stronger the defense, the greater the difficulty of the attack. From a difficulty aversion perspective, the easier the candidate target, the more attractive it is to the attacker. The attribute value can be quantified into defensive effectiveness using an exponential function:

[0182]

[0183] in, For attacking complexity attribute functions, For defense resource quantization function, Is Candidate targets The amount of defense resources allocated can be quantified. For defense conversion coefficient, where The elimination costs incurred by defenders to reduce vulnerability and increase defense strength , The defender's elimination score is defined as... The percentage of available cost elimination allocated above.

[0184] Topological relationships are a useful attribute, referring to the closeness of the relationship between a candidate target and other candidate targets. In node-based communication networks, the more associated nodes, the more critical the candidate target. From a power destruction perspective, the higher the topological criticality, the greater its attractiveness to attackers. Attribute values ​​can be quantified as follows: The median degree of each node:

[0185]

[0186] in, This is a topological relation attribute function. For nodes and Through nodes The number of shortest paths between them. For nodes and The total number of shortest paths between them.

[0187] Public opinion influence is a beneficial attribute, referring to the degree of impact on political, economic, and social activities caused by an attack resulting in a power outage or insufficient power supply in a specific area. From a political intimidation perspective, the greater the influence, the greater the attraction. The influence of public opinion can be quantified by the economic or social value of load loss, and can be determined as a function of load level and social impact coefficient.

[0188]

[0189] In the formula, For the attribute function of public opinion influence, To and The load of the corresponding physical node, for The social impact coefficient. Since the candidate target is part of the active distribution network cyber-physical system, the characteristic attributes can reflect the background information of the power system. In the short term, this background information can be considered constant, while in the long term, the characteristic attribute values ​​can also change.

[0190] 2) Attack preferences:

[0191] Typically, attackers prefer candidate targets with characteristics that better align with their attack objectives. This means that the same candidate target can have different utility for attackers depending on their preferences. Generally, attackers can be categorized into three types based on their objectives:

[0192] Terrorist attackers. Terrorists are organizations or individuals who use violence to disrupt social security and stability, with clear destructive intentions and political objectives. They may sometimes resort to any means necessary to carry out political intimidation in a particular region. Regarding preferences, the complexity of the attack is not a key attribute that attracts their attention. They are more concerned with topological relationships and the impact on public opinion.

[0193] Highly efficient attackers. These attackers aim to disrupt the power grid but have limited resources. They must target relatively important targets with weak network defenses to achieve high efficiency with limited resources. In terms of preferences, highly efficient attackers pay more attention to topology and attack complexity. In highly efficient attacks, targets in important positions but with poor or moderate defenses will be attacked.

[0194] Typical attackers. There are also attackers with less skill and resources. In typical attacks, attackers search for and exploit vulnerabilities in network systems without detailed information about the physical system. For their primary focus, attackers generally prioritize attack complexity.

[0195] When measuring the utility of candidate targets, feature attributes are converted from their natural unit values ​​to an equivalent of attacker satisfaction based on their preference attitudes. If an attribute is favored by the attacker, its score will be higher or lower. Therefore, attacker preference can be used as a weight for attribute values ​​in utility metrics.

[0196] 3) Utility value calculation:

[0197] Since utility is calculated based on multiple attributes, a multi-attribute utility function is needed. This is an extension of utility theory, designed to help decision-makers allocate utility values ​​while considering their decision preferences and combine these allocations to obtain an overall utility measure. Different multi-attribute utility functions are applicable to different decision problems, and their axioms and additivity independence have been proven in some studies. To construct an effective framework for modeling multi-factor behavior in cyberattacks, this invention employs an implementable and practical utility function that has been applied and proven effective in other research projects.

[0198]

[0199]

[0200] in, for The utility value, The number of feature attributes for each candidate target. For utility weights, represents the weight of the first... The degree of preference for each feature attribute can be calculated using the analytic hierarchy process (AHP). for The The quantized value of each feature attribute, for The normalized value. and They are the first The maximum and minimum values ​​of each feature attribute.

[0201] S2.2: Selection of targets for malicious commands.

[0202] Historical cases of cyberattacks show that multi-target attacks mostly target objects within a specific area, with relatively close connections between them. This means that targets outside this specific area are less attractive to attackers. However, even if attackers have a preference for targeting a specific area, the selection of targets within that area still has considerable uncertainty. This means that it is impossible to accurately model using mechanistic methods, and numerical simulation models based on historical event data analysis are more preferable. Therefore, considering that attackers select targets based on utility values ​​and launch multi-target attacks around a central point in the attack area, the multi-target selection behavior can be described as follows: first, selecting a primary target from the candidate target set E; second, selecting other related attack targets based on their connectivity. Based on utility values, a Logit model and a utility decay model are constructed to analyze the probability of a candidate target being selected as the primary target and the selection of other targets.

[0203] 1) Logit model and probabilistic response.

[0204] This invention establishes a probabilistic model for goal selection. The Logit model has a solid theoretical foundation in utility theory and is a commonly used probabilistic model for studying human decision-making behavior. Based on utility values ​​and the Logit model, [the model is] determined... The probability of being selected as a primary target of attack is denoted as the response probability:

[0205]

[0206] In the formula, For the response probability, This represents the attacker's utility value towards the candidate target. Let E be the t-th target being attacked, and E be the set of candidate targets. This represents the attacker's response sensitivity to the utility value of candidate targets. The higher the value, the more significant the attacker's preference for the main target. In other words, the attacker has aggressive selection behavior, is more sensitive to the utility differences between candidate targets, and is more inclined to choose candidate targets with higher utility values. A lower value indicates an unclear bias in the selection of primary targets, suggesting that the attacker is very cautious in choosing their primary target. When the value is zero, all candidate targets have the same response probability. Some articles have explored the application of the Logit model in behavioral research, among which... This can be obtained through statistical analysis of historical data. In this invention, given a target set... The utility value and the historical records of the attack targets, where the records are approximately independent and have the same response probability, can be determined using maximum likelihood estimation (MLE). :

[0207]

[0208]

[0209]

[0210] In the formula, for The MLE function, Select the number of historical records for the primary attack target for the attacker. express In the Scenes selected as primary attack targets in historical records. for In the The probability of being selected as a primary attack target in a historical record. Let... for The number of cases selected as primary attack targets. Therefore:

[0211]

[0212] Information security technologies, such as security information and incident management, honeypots, and big data mining, have made significant progress in the field of cybersecurity. Based on the widespread application of these technologies in the monitoring, tracking, and analysis of future network attacks, it will be easier and more accurate to perform relevant data analysis on historical records.

[0213] 2) Utility decay model.

[0214] Once the primary target is identified, the attacker will proceed with a second selection process, primarily choosing other attack targets based on the correlation between candidate objects. This correlation can be measured through adjacent topologies, where the attack range is represented by topological distance in cyberspace. Since targets outside this range are less attractive to the attacker, the change in satisfaction with increasing distance from the primary target is described as a decrease in the utility decay of candidate targets. In other words, the utility value of each candidate target varies with its adjacent topological relationships and its topological distance to the primary target.

[0215] When selecting the first The candidate targets are selected as the primary attack targets, denoted as... hour, The utility value from Become To make it easier to distinguish, we will The pre-utility value is named ,Will exist The post-utility value is named .

[0216] like Figure 3 As shown, Figure 3 This section presents an example of the topological relationships between candidate targets, i.e., communication network nodes, where the topological connection between two targets is a communication link between the network nodes. The greater the distance from the primary target, the less attractive it is to an attacker. (The text then abruptly shifts to discussing topological distance.) (from arrive ) is defined as from arrive The number of links in the shortest topology path, utility value The calculation is as follows:

[0217]

[0218]

[0219] In the formula, Let be the distance attenuation coefficient. Clearly, when... equal , =0, When the value is 1, the utility value of the primary objective remains unchanged during the second selection process. Although other factors may influence the second objective selection process, the following explains why topological relationships are considered a primary factor:

[0220] (1) Since numerical models based on historical event data analysis are more suitable for target selection simulation, the number of communication links caused by adjacent topology can be easily obtained by using statistical data of historical attacks to obtain a single-parameter model.

[0221] (2) Consider the number of communication links rather than their length. Since the distance in cyberspace is different from that in physical space, attackers can carry out remote attacks without geographical restrictions, so the cost is not significantly different. Attackers are more concerned with whether there is a network path to the target, rather than the cost caused by distance.

[0222] (3) The simplified representation can also reflect the characteristics of the attacker targeting a specific area, while paying less attention to targets far away from the main target.

[0223] When the attacker attempts to from Select from candidate targets When setting goals, once the main goals are determined... ,other Each candidate target will be in accordance with its Reorder the items and select the first ones. One goal.

[0224] S2.3: Number of targets attacked by malicious commands.

[0225] The number of targets a malicious command can attack is limited by the attack capability and is generally measured in attack resources, including the personnel or hackers involved in the attack, as well as technical resources such as advanced tools or malware. Due to the total amount of resources... It is usually naturally random, so the number of attack targets It is also with Related random variables. and The probability distribution can be obtained through historical event analysis and statistics. Considering The probability distribution is not uniform, and the probability within E can be simulated based on the Poisson distribution model. The probability of a target being selected:

[0226]

[0227]

[0228] in, equal The expected value and its variance, The basic attack resources required to successfully attack the target, n max (1≤n max ≤T) represents the maximum expected number of attack targets. and This can be obtained through post-evaluation.

[0229] Assumption Follows a normal distribution ,in and These are parameters related to attacker characteristics. This represents the average attack resources required to execute the task. Empirical evidence from the normal distribution indicates that 99% of the data will fall within the interval [range missing]. To streamline the modeling process and simplify analysis, the extended interval will be used. Discretize into 7 subintervals, each represented by its median. , , , , , , The first resource quantity The possible values ​​are denoted as Its probability is .

[0230] S2.4: Success rate of resource allocation and malicious command attacks.

[0231] When a candidate target is selected, the attacker allocates resources to ensure the attack's success. Simultaneously, the defender activates defensive resources, such as security personnel, firewalls, encryption devices, antivirus software, and intrusion detection systems. From an offensive-defensive competition perspective, the success probability of an attack is determined by the competition between the attacker and the defender; therefore, the resources invested by the two adversaries in this competition can be used to model the success probability. Thus, when the first... One candidate When an attack target is selected, the probability of success can be calculated using an exponential function:

[0232]

[0233]

[0234]

[0235] In the formula, For attack The probability of success, for The amount of attack resources allocated above. for The amount of defense resources allocated above, and They are respectively The attack efficiency and defense efficiency of the attack. and For attack conversion coefficient and defense conversion coefficient, It can be calculated as ,in It increases the probability of destruction. Minimum attack resources Is Attack resources allocated above The score.

[0236] Considering that attackers use utility values Allocate resources when the primary objective is... When locked, The calculation is as follows:

[0237]

[0238] in, This refers to the set of attack targets. Since attack targets are determined by attack capabilities and attack preferences, the allocation of attack resources and the probability of success will vary in different scenarios.

[0239] S3. Risk assessment model.

[0240] S3.1: Scenario probability.

[0241] Due to the uncertainty of attack resources and target selection, multiple attack scenarios may exist. Given an attack scenario... The main target was selected. Total number of targets attacked Attack resources ,but The probability of occurrence is calculated as follows:

[0242]

[0243] There is a set of attack targets Clearly, the success of an attack on the target is uncertain, as is the success of the proposed strategy. Assume... have A single successful attack scheme, the first A successful solution It means that, in The set containing successfully attacked targets is , . The probability of its occurrence is:

[0244] ;

[0245] S3.2: Consequences of the attack.

[0246] Once the target is accessible, attackers will execute their plan using one or more techniques, such as sending erroneous trip commands, injecting false data, or delaying or interrupting message transmission. The consequences of cyberattacks on power systems can be analyzed through power system simulation modeling, with optimal power flow models being widely used. The consequences can be directly assessed through load losses caused by the attack. Load reduction due to grid operation constraints Quantified by summation:

[0247]

[0248] in, The following can be calculated using the optimal load reduction model:

[0249]

[0250] In the formula, For the power grid bus number, For the power flow vector of the transmission line, This refers to the active power vector injected into the bus. This is the load demand vector at the busbar. The load reduction vector at the busbar. Let A be the diagonal matrix of the transmission line admittance, B be the correlation matrix, and C be the admittance matrix. These six equations represent the objective function, the DC model of the power flow equation, the capacity limits of the transmission line and generator, and the constraint ensuring that the load reduction is less than or equal to the load demand.

[0251] S3.3: Definition of risk index.

[0252] In risk assessment, the risk index of a scenario is typically expressed as the product of the scenario's probability and its consequences, while the risk of a system is the sum of the risks of all scenarios. Given the probability of an attack and its associated consequences, attack scenarios... The risk calculation is as follows:

[0253]

[0254] in, yes The results show that the attack resources are discretized into 7 levels and scored, assuming a maximum number of attack targets. Then it has the main attack target. The The risk of each target scenario can be calculated as follows:

[0255]

[0256] Accumulate the total risk to the power grid posed by malicious command behavior:

[0257] .

[0258] This invention, based on a deep understanding and analysis of the cyber-physical system of active power distribution networks, primarily focuses on the risk assessment mechanism of malicious command attacks under the coupling relationship between the information layer and the physical layer of active power distribution networks. In the era of smart grids, the power cyber-physical system is not merely a traditional power distribution network, but a product of the deep integration of information technology and physical infrastructure. The characteristics of this system determine that the security challenges it faces are fundamentally different from those of traditional power systems, requiring new security management methods and technologies to ensure its stable operation and information security.

[0259] First, this invention innovatively constructs a utility function to measure attacker satisfaction, which is related to the subjective attitudes and characteristics of information networks and physical systems. The utility value reflects the attacker's behavior, including target selection and resource allocation. Traditional malicious command risk assessments always focus on studying the implementation scheme rather than the attack decision-making strategy; therefore, the attacker's intent and other subjective factors are usually omitted. In contrast, the model proposed in this invention considers the influence of the attacker's intent and other subjective factors, enabling a more accurate description of the complex dynamic behavior of the system.

[0260] Secondly, this invention proposes a probabilistic response model and a utility decay model based on utility value and historical event data analysis, according to the regional characteristics of attacks, to analyze attack target selection behavior, and then analyze attack resource allocation behavior based on the selection results. This method enables the invention to predict security risks in coupled networks, thereby identifying potential risk outbreaks in advance and laying the foundation for subsequent responses, providing system administrators and security experts with strong decision-making support and response strategies.

[0261] It is particularly important to emphasize that this invention is not limited to the construction of a theoretical model, but also encompasses the wide applicability and practicality of this model in real-world applications. In modern power systems, smart grids have become an important means to improve energy efficiency and optimize power supply management; however, they face increasingly severe information security threats. The malicious command cross-space propagation model established in this invention not only reveals the propagation mechanism of malicious commands in active distribution networks, but also considers the coupling relationship between the information layer and the physical layer of the cyber-physical system, providing a model foundation for subsequent identification and protection against malicious commands. The security risk assessment method proposed in this invention can not only serve as a key indicator for predicting risk outbreaks, but also as a standard for evaluating network topology security, thus providing important guarantees for the safe operation and reliability of smart grids.

[0262] Finally, the application prospects and technological scalability of this invention are also noteworthy. The risk assessment model for malicious command attacks on active distribution networks, which considers the characteristics of malicious command behavior, is not only applicable to distribution networks but can also be extended to the security analysis of other complex systems, such as industrial control systems and intelligent transportation systems. In the future, with the continuous development and popularization of smart grid technology, the security management of power cyber-physical systems will face new challenges and opportunities. This invention provides an innovative methodology and technological foundation for addressing these challenges, injecting new vitality and possibilities into the future development of smart grid security.

[0263] In summary, this invention not only theoretically overcomes the limitations of traditional malicious instruction risk assessment models, but also demonstrates significant security management value and technical advantages in practical applications. Through in-depth analysis of the characteristics and security requirements of smart grids, this invention provides a novel perspective and solution for the security management of power cyber-physical systems, exhibiting significant innovation and practicality, and is expected to have a profound impact and application value in the field of smart grid security.

[0264] Example 3

[0265] This invention provides another embodiment, which is a risk assessment model for malicious command attacks on active power distribution networks that considers behavioral characteristics, including:

[0266] Characterization Model Building Module: Used to build a characterization model of a non-uniform power distribution network cyber-physical network;

[0267] Numerical simulation model building module: used to construct a malicious command attack behavior model based on the representation model, thereby studying the risk of active power distribution networks being attacked by malicious commands, analyzing the characteristics of past malicious command intrusions, and establishing a numerical simulation model based on historical event data analysis;

[0268] Assessment Method Establishment Module: This module is used to construct a risk assessment model based on a numerical simulation model derived from historical event data analysis, taking into account the impact factors of attacks on information nodes, and to establish a risk assessment method for the distribution network under the threat of malicious command attacks.

[0269] The active distribution network malicious command attack risk assessment model considering behavioral characteristics described in this embodiment is used to implement the steps of the active distribution network malicious command attack risk assessment method considering behavioral characteristics described in any of Embodiments 1-2.

[0270] Example 4

[0271] Based on the same inventive concept, embodiments of the present invention also provide a computer device, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the computer program, it implements the steps of any of the active power distribution network malicious command attack risk assessment methods considering behavioral characteristics described in Embodiment 1 or 2.

[0272] Example 5

[0273] Based on the same inventive concept, this embodiment of the invention also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the steps of any of the active power distribution network malicious instruction attack risk assessment methods considering behavioral characteristics described in Embodiment 1 or 2.

[0274] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0275] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0276] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0277] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0278] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A risk assessment method for malicious command attacks on active power distribution networks considering behavioral characteristics, characterized by: include: Establish a representation model for cyber-physical networks of non-uniform power distribution networks; Based on the aforementioned characterization model, a malicious command attack behavior model is constructed to study the risk of active power distribution networks being attacked by malicious commands, analyze the characteristics of past malicious command intrusions, and establish a numerical simulation model based on historical event data analysis. Based on the numerical simulation model, a risk assessment model is constructed, taking into account the influencing factors of information node attacks, and a risk assessment method for distribution networks under the threat of malicious command attacks is established.

2. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 1, characterized in that: The establishment of a representation model for a non-uniform power distribution network cyber-physical network includes: Assumptions are made about complex network theory; Based on the assumptions, the physical layer representation and information layer representation of the active distribution network are abstracted. Analysis of malicious command attack behavior at the information layer.

3. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 2, characterized in that: The assumptions made about complex network theory include: 1) Taking the plant level as the research unit, the information network and physical site are regarded as equivalent information nodes and physical nodes, respectively; 2) Communication lines between network sites are equivalent to the edge of the network, and transmission lines between physical sites are equivalent to the edge of the physical network; 3) Consider the directionality and dependency between links in the physical network and the information network. Links between layers are undirected edges, while edges between different layers are directed edges. Based on the above definitions and assumptions, and using complex network theory, the topology of the information network and physical network of the active distribution network is abstracted and represented as two unweighted partially directed graphs. and ,in For information networks, For physical networks; The physical layer representation, wherein the physical layer model is abstracted as an unweighted graph of a complex network. ,in For nodes, As an edge, For the set of nodes in a physical network, It is the set of connection edges in the physical network. This is the adjacency matrix of the physical network; The information layer representation, where information network nodes are the control and processing centers of the corresponding physical layer network nodes, assumes that all related functions are performed in abstract nodes within the network model; the network layer model is abstracted as a complex unweighted graph. ,in For nodes, For the edge, For a set of nodes in an information network, For the set of connection edges of an information network, This is the adjacency matrix of an information network; The analysis of malicious command attack behavior at the information layer includes: 1) An attack on the control center; 2) Attacks on substation networks; 3) Attacks on the communication link between the control center and the substation; To simplify the analysis, a station-level LAN is represented as a network node. The network node and the control center communicate with each other through a communication network, which is usually a dual-star network or a mesh network. In practice, a physical node in an active distribution network represents a bus. A network node maps one or more buses to monitor / control the physical components connected to its mapped bus.

4. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 1, characterized in that: The numerical simulation model based on historical event data analysis includes: The utility value of the target; The selection of targets for malicious commands; The number of targets attacked by malicious commands; The probability of successful resource allocation and malicious command attacks.

5. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 1, characterized in that: The utility value of the attack target includes: 1) Characteristic attributes: The purposes of launching malicious command attacks on the power grid include: power disruption, political intimidation, and strong aversion. Different purposes lead attackers to focus on different characteristic attributes of candidate targets. Attackers weigh the characteristic attributes of candidate targets, including attack complexity, topological relationships, and public opinion impact, and make decisions that are conducive to achieving their purposes. The above attributes are divided into two categories based on their role in achieving the desired effect: (1) The benefit attribute has a positive impact on the attack, and the higher the value, the more beneficial it is; (2) Cost attribute, which has a negative impact on attacks; the higher the value, the lower the acceptance. Attack complexity is a cost attribute that refers to the difficulty of successfully breaching a candidate target; the attribute value is quantified into defensive effectiveness using an exponential function. ; in, For attacking complexity attribute functions, For defense resource quantization function, Is Candidate targets The amount of defense resources allocated can be quantified; For defense conversion coefficient, where The elimination costs incurred by defenders to reduce vulnerability and increase defense strength , The defender's elimination score is defined as... The percentage of available cost elimination allocated above; Topological relationship is a useful attribute that refers to the closeness of the relationship between a candidate objective and other candidate objectives; the attribute value is quantified as the first... The median degree of each node: ; in, This is a topological relation attribute function. For nodes and Through nodes The number of shortest paths between them. For nodes and The total number of shortest paths between them; Public opinion impact is a beneficial attribute, referring to the degree of influence on political, economic, and social activities caused by attacks resulting in power outages or insufficient power supply in a specific area. The influence of public opinion is quantified using the economic or social value of load loss, and is determined as a function of load level and social impact coefficient. ; In the formula, For the attribute function of public opinion influence, To and The load of the corresponding physical node, for The social impact coefficient; 2) Attack preferences: Attackers can be categorized based on their objectives: terrorist attackers, high-performing attackers, and ordinary attackers. When measuring the utility of candidate targets, feature attributes are converted into their natural unit values ​​based on their preference attitudes, which are then equated to attacker satisfaction. If an attribute is favored by the attacker, the score is higher or lower. Attack preference is used as the weight of attribute values ​​in the utility metric. 3) Utility value calculation: To construct an effective framework for modeling multi-factor behavior in network attacks, the following implementable and practical utility function is adopted: ; ; in, for The utility value, The number of feature attributes for each candidate target. For utility weights, represents the weight of the first... The degree of preference for each feature attribute is calculated using the analytic hierarchy process (AHP). for The The quantized value of each feature attribute, for The normalized value, and They are the first The maximum and minimum values ​​of each feature attribute; The selection of the target for the malicious instruction attack includes: 1) Logit model and probabilistic response: Determined based on utility value and Logit model The probability of being selected as a primary target of attack is denoted as the response probability: ; In the formula, For the response probability, This represents the attacker's utility value towards the candidate target. Let E be the t-th target being attacked, and E be the set of candidate targets. The attacker's response sensitivity to the utility value of candidate targets; The higher the value, the more significant the attacker's preference for the main target. In other words, the attacker has aggressive selection behavior, is more sensitive to the utility differences between candidate targets, and is more inclined to choose candidate targets with higher utility values. A lower value indicates an unclear bias in the selection of primary targets, suggesting that attackers are very cautious in choosing their primary targets; when... When the value is zero, all candidate targets have the same response probability; given a target set The utility value and the historical records of the attack targets, where the records are approximately independent and have the same response probability, are used to determine the MLE based on the Maximum Likelihood Estimation. : ; ; ; In the formula, for The MLE function, Select the number of historical records for the primary attack target for the attacker. express In the Scenes selected as primary attack targets in historical records. for In the The probability of being selected as a primary attack target in a historical record; set up for The number of cases selected as primary attack targets can be obtained as follows: ; 2) Utility decay model; Once the primary target is locked, the attacker will proceed with a second selection process, where the utility value of each candidate target varies depending on its neighboring topology and its topological distance to the primary target. When selecting the first The candidate targets are selected as the primary attack targets, denoted as... hour, The utility value from Become To make it easier to distinguish, The pre-utility value is named ,Will exist The post-utility value is named ; The topological connection between two targets is the communication link between nodes in a communication network. The farther away from the primary target, the less attractive it is to attackers; this topological distance... ,from arrive Defined from arrive The number of links in the shortest topology path, utility value The calculation is as follows: ; ; In the formula, This is the distance attenuation coefficient; when equal , =0, When the value is 1, the utility value of the primary objective remains unchanged during the second selection process; When the attacker attempts to from Select from candidate targets When setting goals, once the main goals are determined... ,other Each candidate target will be in accordance with its Reorder the items and select the first ones. One goal; The number of targets attacked by the malicious commands; The number of targets that malicious commands can attack is limited by the attack capability and the total amount of resources. Typically, the number of targets is naturally random. It is also with Related random variables; and The probability distribution is obtained through historical event analysis and statistics; considering The probability distribution is not uniform; the inner probability of E is simulated based on the Poisson distribution model. The probability of a target being selected: ; ; in, equal The expected value and its variance, The basic attack resources required to successfully attack the target, n max (1≤n max ≤T) represents the maximum expected number of attack targets. and Obtained through post-evaluation; Assumption Follows a normal distribution ,in and These are parameters related to attacker characteristics. This represents the average attack resources required to execute the task; empirical evidence from the normal distribution indicates that 99% of the data will be distributed within the interval [range]. Within; to streamline the modeling process and simplify the analysis, the extended interval will be... Discretize into 7 subintervals, each represented by its median. , , , , , , The first resource quantity The possible values ​​are denoted as Its probability is ; The probability of successful resource allocation and malicious command attacks; When a candidate target is selected, the attacker allocates resources to ensure the attack's success; simultaneously, the defender also activates defensive resources in response to the attack. The resources invested by the two adversaries in this competition are used to model the probability of success; when the first candidate target is selected... One candidate When a target is identified as an attack target, the probability of success for this attack is calculated using an exponential function: ; ; ; In the formula, For attack The probability of success, for The amount of attack resources allocated above. for The amount of defense resources allocated above, and They are respectively The attack efficiency and defense efficiency of the attack. and These are the attack conversion coefficient and the defense conversion coefficient. Calculated as ,in It increases the probability of destruction. Minimum attack resources Is Attack resources allocated above The score; Considering that attackers use utility values Allocate resources when the primary objective is... When locked, The calculation is as follows: ; in, This refers to the set of attack targets.

6. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 1, characterized in that: The risk assessment model includes: Scenario probability; Consequences of the attack; Definition of risk index.

7. The method for assessing the risk of malicious command attacks on active distribution networks considering behavioral characteristics as described in claim 6, characterized in that: The scenario probabilities include: Given an attack scenario Select the main target Total number of targets attacked Attack resources ,but The probability of occurrence is calculated as follows: ; There is a set of attack targets ; Assumption have A single successful attack scheme, the first A successful solution It means that, in The set containing successfully attacked targets is , ; The probability of its occurrence is: ; The consequences of the attack include: Load loss directly caused by the attack Load reduction due to grid operation constraints Quantified by summation: ; in, The following calculations were performed using the optimal load reduction model: ; In the formula, For the power grid bus number, For the power flow vector of the transmission line, This refers to the active power vector injected into the bus. This is the load demand vector at the busbar. The load reduction vector at the busbar. Let A be the diagonal matrix of the transmission line admittance, A be the incidence matrix, and B be the admittance matrix. The risk index is defined as follows: Given the probability and consequences of an attack, the attack scenario... The risk calculation is as follows: ; in, yes The results show that the attack resources are discretized into 7 levels and scored, assuming a maximum number of attack targets. Then it has the main attack target. The The risk calculation for each target scenario is as follows: ; Accumulate the total risk to the power grid posed by malicious command behavior: 。 8. A risk assessment model for malicious command attacks on active power distribution networks that considers behavioral characteristics, characterized by: include: Characterization Model Building Module: Used to build a characterization model of a non-uniform power distribution network cyber-physical network; Numerical simulation model building module: used to construct a malicious command attack behavior model based on the characterization model, thereby studying the risk of active power distribution networks being attacked by malicious commands, analyzing the characteristics of past malicious command intrusions, and establishing a numerical simulation model based on historical event data analysis; Assessment Method Establishment Module: This module is used to construct a risk assessment model based on the numerical simulation model, consider the influencing factors of information node attacks, and establish a risk assessment method for the distribution network under the threat of malicious command attacks.

9. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method for assessing the risk of malicious command attacks on active power distribution networks that considers behavioral characteristics, as described in any one of claims 1-7.

10. A computer storage medium, characterized in that: The computer storage medium contains a computer program, which, when executed by a processor, implements the steps of the active power distribution network malicious command attack risk assessment method considering behavioral characteristics as described in any one of claims 1-7.