Power distribution network attack scene simulation and security protection capability verification method, system and device, and medium

By constructing a digital twin simulation environment that integrates cyber-physical systems in the power distribution network, the adaptability and quantitative evaluation issues of network security testing in the power distribution network in existing technologies have been solved. This has enabled realistic simulation of the impact of attacks and optimization of protection strategies, thereby improving the security protection capabilities of the power distribution network.

CN122053115APending Publication Date: 2026-05-15GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUIZHOU POWER GRID CO LTD
Filing Date
2025-12-31
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing network security testing methods for power distribution networks cannot fully adapt to the business characteristics and dedicated communication protocols of industrial control systems. This leads to discrepancies between simulated attack scenarios and real threats, a lack of quantitative assessment of the impact of attacks and dynamic countermeasure verification, and difficulty in accurately measuring the consequences of security incidents and evaluating the effectiveness of protective measures.

Method used

Construct a digital twin simulation environment for the cyber-physical integration of power distribution networks, build an attack scenario library based on historical security events and threat intelligence, simulate attack chains and record execution status and success rate, monitor the state changes of physical and information systems, evaluate the detection accuracy and response time of the protection system, and generate quantitative evaluation results.

Benefits of technology

It enables realistic reproduction and quantitative assessment of the impact of attacks on power distribution networks, quickly identifies weaknesses and configuration defects in the protection system, provides quantitative evidence to optimize protection strategies, and improves the collaborative defense capabilities of the protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053115A_ABST
    Figure CN122053115A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of power distribution network security verification, and discloses a power distribution network attack scene simulation and security protection capability verification method, system and device, and a medium, and the method comprises the steps: constructing an attack scene library of power distribution network services based on historical data; establishing a digital twinborn simulation environment of power distribution network information physical fusion; based on the selected attack script, injecting an attack behavior into a simulation environment, simulating a process and recording an attack execution state and a success rate; calculating the influence degree of the network attack on power grid operation, and generating an evaluation result; simulating detection, alarm and blocking response of the deployed protection system to the attack behavior in the simulation environment, and evaluating the detection accuracy, response time and comprehensive defense success rate of the protection system; and calculating an overall safety protection comprehensive score, and identifying a protection weak link. According to the method, a quantitative basis can be provided for final decision making, weak links and configuration defects in the protection system can be quickly found, and the cooperative defense capability of the whole protection system can be evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power distribution network security verification technology, and in particular to a method, system, device and medium for simulating power distribution network attack scenarios and verifying security protection capabilities. Background Technology

[0002] With the increasing automation and intelligence of power distribution networks, information systems such as distribution automation systems, energy management systems, and distributed energy access systems have been deeply integrated into the power grid operation and control process. These systems are interconnected primarily through industrial Ethernet, wireless communication, and other methods, significantly improving operational efficiency. However, this also exposes the power distribution network to cybersecurity vulnerabilities. Therefore, the industry has developed numerous cybersecurity testing and protection verification methods for power distribution networks, such as using general vulnerability scanning tools, penetration testing techniques, and static policy checks to identify system vulnerabilities and assess the effectiveness of protective measures.

[0003] However, in practical applications, the aforementioned methods often suffer from limitations. Most testing tools originate from traditional IT fields and are not fully adapted to the business characteristics and specialized communication protocols of power distribution network industrial control systems. This leads to discrepancies between simulated attack scenarios and real threats, making it difficult to reproduce targeted attacks exploiting vulnerabilities in industrial protocols or flaws in business logic. Developing entirely new methods is time-consuming and labor-intensive. Furthermore, these methods typically focus on vulnerability identification and risk grading, lacking quantitative assessment of the actual operational impact after a successful attack. This makes it difficult for power companies to accurately measure potential load losses, equipment damage, or power outages caused by security incidents, resulting in a lack of basis for security investment decisions. Most protection verifications are also based on static configuration checks, failing to effectively test the real-time response and collaborative blocking capabilities of security devices and strategies in dynamic adversarial environments, and failing to demonstrate the shortcomings of the protection system under sustained attacks. Therefore, constructing a solution that integrates the physical characteristics of the power grid, supports quantitative assessment, and enables dynamic adversarial verification is crucial for power distribution network security. Summary of the Invention

[0004] In view of the aforementioned existing problems, the present invention is proposed.

[0005] Therefore, this invention provides a method and system for simulating power distribution network attack scenarios and verifying security protection capabilities to solve the problems of insufficient realism in existing power distribution network attack scenario simulations, difficulty in reflecting actual threats, lack of attack impact assessment mechanisms, inability to quantify security risks, incomplete verification of protection measures, and lack of dynamic adversarial testing.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: In a first aspect, the present invention provides a method for simulating power distribution network attack scenarios and verifying security protection capabilities, including: Based on historical security incidents and threat intelligence, an attack scenario library for power distribution network services is constructed. The attack scenario library contains multi-stage attack scripts described based on an attack chain model, and an attack complexity metric is defined for each attack script. Establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation; Based on the selected attack script, attack behaviors are sequentially injected into the digital twin simulation environment to simulate the execution process of each step in the attack chain, and the attack execution status and success rate are recorded. Monitor the state changes of the physical and information systems of the power distribution network during the execution of the attack, calculate the degree of impact of the network attack on the operation of the power grid, and generate assessment results; The simulation environment simulates the deployment of a protection system in response to attacks, including detection, alerting, and blocking. The system's detection accuracy, response time, and overall defense success rate are then evaluated. Based on the aforementioned attack complexity metrics, evaluation results, and detection accuracy, an overall security protection score is calculated, weak points in the protection are identified, and suggestions for optimizing the protection strategy are generated.

[0007] As a preferred embodiment of the method for simulating power distribution network attack scenarios and verifying security protection capabilities according to the present invention, the method includes: constructing an attack scenario library for power distribution network services based on historical security events and threat intelligence, including: Based on real historical cybersecurity incidents and threat intelligence, each attack scenario is defined as a multi-stage attack chain. An attack tree model is used to describe the attack chain, with the root node being the attack target and the leaf nodes being the specific attack actions. Each attack stage is defined as an attack step, and preconditions and poststates are defined for each attack step. Based on the technical difficulty and detectability of the attack steps, an attack chain complexity index is calculated to quantify the difficulty of implementing an attack script.

[0008] As a preferred embodiment of the method for simulating power distribution network attack scenarios and verifying security protection capabilities according to the present invention, the method includes: establishing a digital twin simulation environment for the integration of cyber-physical systems in the power distribution network, including physical power grid simulation and information system simulation, comprising: The physical power grid simulation layer collects actual distribution network operation data and establishes an equivalent model. Construct a virtual mirror of the power distribution automation master station, terminals, protection devices, and communication network. The mirror supports the industrial communication protocol stack and is configured with a network structure and security policy consistent with the actual system. The interface module enables bidirectional command and data interaction between the physical simulation layer and the information system simulation layer. By comparing the simulation results with the actual measurement data, the simulation error is calculated. When the error is lower than the set threshold, the simulation environment is determined to meet the fidelity requirements.

[0009] As a preferred embodiment of the method for simulating power distribution network attack scenarios and verifying security protection capabilities according to the present invention, the method includes: recording the attack execution status and success rate, including: The attack execution process is controlled by a state machine, which determines whether to execute a step based on the preconditions of each attack step. The overall success rate of an attack chain is determined by the cumulative success probability of all attack steps in the chain; among them, the success probability of each step is affected by factors including the technical success rate of the attack step itself and the probability that the corresponding step is blocked by the protection system.

[0010] As a preferred embodiment of the method for simulating distribution network attack scenarios and verifying security protection capabilities according to the present invention, the method includes: monitoring the state changes of the distribution network physical system and information system during the attack execution process, calculating the degree of impact of the network attack on the power grid operation, and generating evaluation results, including: Calculate the voltage impact index to reflect the degree of deviation of the bus voltage from the reference value after the attack, and identify the voltage over-limit nodes and their duration; Statistical analysis of the number of equipment malfunctions caused by attacks, calculation of equipment impact index, and assessment of the direct and cascading impacts of attacks on critical equipment; The load loss index is calculated by summing the power loss and duration caused by the attack, and the impact of the attack on power supply reliability is quantified. The information security impact index is calculated based on the amount of stolen data, the number of configurations tampered with, and the number of hosts implanted with backdoors.

[0011] As a preferred embodiment of the method for simulating power distribution network attack scenarios and verifying security protection capabilities according to the present invention, the evaluation of the detection accuracy, response time, and overall defense success rate of the protection system includes: Simulate the firewall's process of matching and blocking attack traffic according to access control rules, and count the number of successfully blocked and unblocked attack steps; The simulated intrusion detection system performs in-depth network traffic detection and alarm generation based on an attack signature database, and calculates the detection accuracy. Simulates industrial control security protection equipment to parse and whitelist industrial protocol messages, blocking unauthorized control commands and abnormal parameter settings; Simulate the linkage response mechanism between multiple protection systems, calculate the average time from the occurrence of an attack to the generation of a response by the protection system, and evaluate the protection response speed. The overall defense success rate of the protection system is calculated as the proportion of the number of attack steps that are successfully blocked to the total number of attack steps.

[0012] As a preferred embodiment of the method for simulating power distribution network attack scenarios and verifying security protection capabilities according to the present invention, the method further includes: applying the optimization suggestions to the simulation environment, re-executing the attack simulation and protection verification, evaluating the effectiveness of the optimization measures, and iteratively updating the protection strategy until the preset security level is met.

[0013] Secondly, the present invention provides a system for simulating power distribution network attack scenarios and verifying security protection capabilities, comprising: The attack scenario library construction module is used to build an attack scenario library for power distribution network services based on historical security events and threat intelligence. The attack scenario library contains multi-stage attack scripts described based on the attack chain model, and defines attack complexity quantification indicators for each attack script. The power distribution network simulation environment module is used to establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation. The attack behavior injection module is used to inject attack behaviors sequentially into the digital twin simulation environment based on the selected attack script, simulate the execution process of each step in the attack chain, and record the attack execution status and success rate. The impact assessment module is used to monitor the state changes of the physical and information systems of the power distribution network during the attack execution process, calculate the degree of impact of the network attack on the power grid operation, and generate assessment results. The protection response simulation module is used to simulate the detection, alarm and blocking response of the deployed protection system to attack behaviors in the simulation environment, and to evaluate the detection accuracy, response time and overall defense success rate of the protection system. The comprehensive verification module is used to calculate the overall security protection score based on the attack complexity quantification indicators, evaluation results, and detection accuracy, identify weak links in the protection, and generate suggestions for optimizing the protection strategy.

[0014] Thirdly, the present invention provides a computer device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement the steps of a method for simulating a power distribution network attack scenario and verifying security protection capabilities.

[0015] Fourthly, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method for simulating a power distribution network attack scenario and verifying security protection capabilities.

[0016] Compared with existing technologies, the beneficial effects of this invention are as follows: By constructing a cyber-physical simulation environment for power distribution networks, this invention combines network attack simulation with power distribution network physical operation simulation, enabling the reproduction of the complete process by which attackers exploit vulnerabilities in industrial protocols and defects in business logic to launch attacks; by monitoring the response of the power distribution network physical system during the attack process, it quantifies and assesses the actual impact of network attacks on the safe and stable operation of the power grid, transforming network security risks into specific numerical values ​​of power grid operation risks, providing a quantitative basis for final decision-making; and by conducting attack and defense simulations, it verifies the detection capabilities, response speed, and blocking effects of firewalls and other protective measures when facing attacks, simulating the dynamic process by which attackers adjust their attack strategies based on the response of the protection system, enabling the rapid discovery of weak links and configuration defects in the protection system, and evaluating the overall collaborative defense capabilities of the protection system. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a schematic diagram of the overall process of a method for simulating power distribution network attack scenarios and verifying security protection capabilities according to an embodiment of the present invention. Detailed Implementation

[0019] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0020] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for simulating power distribution network attack scenarios and verifying security protection capabilities is provided, comprising: S100: Based on historical security events and threat intelligence, construct an attack scenario library for power distribution network services. The attack scenario library contains multi-stage attack scripts described based on an attack chain model, and defines attack complexity metrics for each attack script. S200: Establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation; S300: Based on the selected attack script, inject attack behaviors sequentially into the digital twin simulation environment to simulate the execution process of each step in the attack chain, and record the attack execution status and success rate. S400: Monitors the state changes of the physical and information systems of the power distribution network during the execution of an attack, calculates the impact of the network attack on the operation of the power grid, and generates assessment results; S500: Simulate the detection, alarm, and blocking response of the protection system deployed in the simulation environment to attack behaviors, and evaluate the detection accuracy, response time, and overall defense success rate of the protection system; S600: Based on the aforementioned attack complexity metrics, evaluation results, and detection accuracy, calculate the overall security protection comprehensive score, identify weak points in protection, and generate suggestions for optimizing protection strategies.

[0021] Specifically, distribution network systems employ industrial communication protocols such as IEC 61850, Modbus, and DNP3. Attackers can exploit the characteristics of these protocols to launch targeted attacks, such as modifying protection settings, forging remote control commands, and tampering with measurement data. Existing testing methods cannot effectively simulate these deep attacks targeting distribution network business processes, resulting in significant discrepancies between test results and actual attack scenarios. The potential impact of a successful intrusion into the distribution automation system includes multiple aspects, such as load losses and voltage exceedances. However, the extent of the damage if the attack is successful cannot be quantified, making it difficult for power companies to accurately assess the necessity of cybersecurity investments. Furthermore, cyberattacks are a dynamic adversarial process; attackers adjust their attack strategies based on the response of the protection system, making it impossible to develop targeted protection strategies. Therefore, the S100-S600 steps first establish a digital twin simulation environment based on the actual distribution network topology and operational data. Then, according to preset attack scenarios, network attack behaviors are injected into the simulation environment. By monitoring the state changes of the distribution network's physical and information systems during the attack, the impact of the attack is assessed and the effectiveness of the protection measures is verified. The entire verification process is conducted in an isolated simulation environment, without affecting the actual power grid operation, and the combined effects of different attack scenarios and protection strategies can be tested repeatedly.

[0022] Example 2, refer to Figure 1 As an embodiment of the present invention, based on the above embodiment, a method for simulating power distribution network attack scenarios and verifying security protection capabilities is provided. The method includes: S100: Based on historical security events and threat intelligence, construct an attack scenario library for power distribution network services. The attack scenario library contains multi-stage attack scripts described based on an attack chain model, and defines attack complexity metrics for each attack script. In this embodiment of the application, step S100 involves constructing an attack scenario library for power distribution network services based on historical security events and threat intelligence, including the following steps A1-A3: A1: Based on real historical cybersecurity incidents and threat intelligence, each attack scenario is defined as a multi-stage attack chain; Specifically, each attack scenario is defined as a multi-stage attack chain, which may include the attack target, attack path, attack method, and expected effect.

[0023] A2: The attack chain is described using an attack tree model, with the root node being the attack target and the leaf nodes being the specific attack actions. Each attack stage is defined as an attack step, and the preconditions and poststates are defined for each attack step. Specifically, the attack steps may include attributes such as attack type, target system, exploit vulnerability, attack payload, and success conditions.

[0024] For example, the root node of the attack tree is the attack target, such as "causing the 10kV busbar to lose voltage"; the leaf nodes are the specific attack actions, such as "scanning the IP address of the power distribution terminal", "brute-forcing the login password", "sending illegal remote control commands", etc.

[0025] In one alternative implementation, the prerequisites in A2 can be defined as the permissions, information, or system state required to perform the step. In one alternative implementation, based on the above implementation, the post-state in A2 can be defined as the new privileges obtained by the attacker or the changes that occur in the system after the step is successful.

[0026] A3: Calculate the attack chain complexity index based on the technical difficulty and detection concealment of the attack steps, which is used to quantify the difficulty of implementing the attack script. Specifically, to quantify the complexity of an attack chain, the attack chain complexity exponent can be expressed as: (1) In the formula, The attack chain complexity index; The total number of steps in the attack chain; For the first The weight coefficient of each attack step is determined according to the technical difficulty of the corresponding step. For example, the weight coefficient of advanced persistent threat steps is 0.8 to 1.0, and the weight coefficient of conventional attack steps is 0.3 to 0.5. For the first The detection difficulty coefficient for each attack step is exemplified by the following values: for highly concealed attacks, the value is 1.5 to 2.0, and for easily detectable attacks, the value is 0.5 to 1.0.

[0027] It should be noted that the attack chain complexity index is mainly used in subsequent S600 tests to evaluate the differences in the ability of the protection system to cope with attacks of varying difficulty.

[0028] It should also be noted that adjacent steps in the attack chain of S100 are linked together through the matching relationship between preconditions and postconditions to form a complete attack path. For example, the system's built-in typical attack scenarios include: data theft attacks against distribution automation master stations, with an attack chain of "external network reconnaissance - phishing emails - lateral movement within the master station's internal network - database access - data transmission"; control tampering attacks against distribution terminals, with an attack chain of "wireless network eavesdropping - terminal identity spoofing - forged remote control commands - circuit breaker malfunction"; and setting modification attacks against protection devices, with an attack chain of "internal network access - protection device login - setting zone switching - protection failure," etc. Each scenario contains 5 to 8 attack steps, covering the complete process from initial intrusion to final destruction. The completed attack scenarios and their complexity index are also described. Stored in the scenario library as input for subsequent attack simulations.

[0029] S200: Establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation; In this embodiment of the application, step S200 establishes a digital twin simulation environment for the cyber-physical integration of the distribution network, including physical power grid simulation and information system simulation, comprising the following steps B1-B4: B1: The physical power grid simulation layer collects actual distribution network operation data and establishes an equivalent model; Specifically, in B2, the physical power grid simulation layer collects data such as the topology, equipment parameters, load curves, and distributed power output of the actual distribution network, and establishes an equivalent model in the simulation platform.

[0030] In one optional implementation, the simulation environment may include electrical models of equipment such as substations, distribution lines, sectionalizing switches, distribution transformers, and distributed photovoltaic systems, which can simulate physical processes such as power flow calculation, short-circuit calculation, and voltage regulation; the simulation time step is set to 100 milliseconds to meet the simulation accuracy requirements of transient processes in the distribution network.

[0031] B2: Construct a virtual mirror of the power distribution automation master station, terminals, protection devices, and communication network. The mirror supports the industrial communication protocol stack and is configured with a network structure and security policy consistent with the actual system. Specifically, in B2, the information system simulation layer establishes virtual mirrors of the power distribution automation master station system, power distribution terminals, protection devices, and communication networks.

[0032] In another optional implementation, based on the above-described implementation B1, the master station system of B may include components such as a SCADA platform, database server, and application server, configured with the same operating system, application software, and communication protocol stack as the actual system. The power distribution terminal and protection devices are implemented using software simulation, supporting industrial protocols such as IEC 61850 MMS, Modbus TCP, and DNP3, and capable of responding to telemetry, remote signaling, remote control, and remote adjustment commands. The communication network is built using virtual network technology, including multiple network domains such as the master station intranet, station communication network, and wireless private network, configured with the same IP address ranges, VLAN divisions, routing configurations, and firewall rules as the actual network.

[0033] B3: Enables bidirectional command and data interaction between the physical simulation layer and the information system simulation layer through the interface module; Specifically, the physical power grid simulation and the information system simulation are connected through an interface module. When a remote control command is issued from the information system, the interface module parses the command into action instructions for the physical devices.

[0034] For example, the "circuit breaker K3" can be passed to the physical simulation layer for execution. The physical simulation layer calculates the changes in the power grid state after the circuit breaker is tripped and feeds back the new voltage, current, power, and other measured values ​​to the telemetry acquisition module of the information system. This two-way interactive mechanism ensures that the operation of the information system can realistically affect the physical power grid state, and the changes in the physical power grid can be reflected in the monitoring interface of the information system in a timely manner, realizing closed-loop simulation.

[0035] B4: By comparing the simulation results with the actual measurement data, the simulation error is calculated. When the error is lower than the set threshold, the simulation environment is determined to meet the fidelity requirements.

[0036] Specifically, to ensure the fidelity of the simulation environment, the simulation error evaluation index can be expressed as: (2) In the formula, The root mean square error of the simulation environment. This represents the total number of busbar nodes in the distribution network. For the first Simulated voltage values ​​of each bus node. For the first The actual measured voltage values ​​of each busbar node.

[0037] For example, when When the simulation error is less than 3%, the simulation environment is deemed to meet the fidelity requirements and can be used for subsequent attack simulation testing.

[0038] It should be noted that during the establishment of the simulation environment in S200, the system automatically verifies the consistency between the simulation model and the actual system. For the physical power grid, by comparing the simulated power flow calculation results with actual measurement data, it ensures that the voltage deviation of key nodes is less than 2% of the rated voltage and the line current deviation is less than 5% of the rated current. For the information system, by sending standard test messages, the correctness of the protocol stack implementation is verified, ensuring that characteristics such as the telemetry data refresh cycle and remote control command response time are consistent with the actual system. The simulation environment and its error indicators after successful verification are shown below. As the foundational platform for attack simulation and protection verification, all subsequent tests are conducted in this environment, and the fidelity of the simulation environment directly affects the credibility of the verification results.

[0039] S300: Based on the selected attack script, inject attack behaviors sequentially into the digital twin simulation environment to simulate the execution process of each step in the attack chain, and record the attack execution status and success rate. Specifically, attack scenarios to be verified are selected from the attack scenario library built in S100, and attack behaviors are injected into the simulation environment built in S200 according to the steps of the attack chain.

[0040] For example, attack injection can generate corresponding network packets or operation commands based on the defined attack steps. For network layer attacks, such as port scanning and vulnerability exploitation, the system calls attack tools to generate raw network traffic and injects it into the virtual network of the simulation environment. For application layer attacks, such as SQL injection and command execution, the system constructs malicious request messages and sends them to the target application server. For industrial protocol attacks, such as unauthorized control of IEC 61850 and Modbus function code abuse, the system encodes the attack payload according to the protocol specifications and sends it to the target device through the communication interface.

[0041] In this embodiment of the application, step S300 records the attack execution status and success rate, including: The attack execution process is controlled by a state machine, which determines whether to execute a step based on the preconditions of each attack step. The overall success rate of an attack chain is determined by the cumulative success probability of all attack steps in the chain; among them, the success probability of each step is affected by factors including the technical success rate of the attack step itself and the probability that the corresponding step is blocked by the protection system.

[0042] Specifically, based on the above scheme, the success rate of the attack steps can be expressed as: (3) In the formula, The success rate of the entire attack chain; This represents the total number of attack steps. For the first The inherent success probability of each attack step under unprotected conditions is determined by the maturity of the attack technique. For the first The probability that an attack step is blocked by the protection system can be calculated by the subsequent protection response simulation of the S500.

[0043] In one optional implementation, in step S300, when the current step is successfully completed and the subsequent state meets the preconditions for the next step, the state machine automatically transitions to the execution of the next step. If a step fails, such as due to incorrect login credentials or unsuccessful vulnerability exploitation, the state machine suspends the execution of the attack chain, records the reason for the failure, and waits for manual intervention or automatic retry.

[0044] In another optional implementation, the S300 can record the start time, end time, execution result, and system response of each step in real time during attack execution. The log data can be used for subsequent attack impact assessment and protection effectiveness verification, ensuring the complete traceability of the attack simulation process. It supports concurrent execution of multiple attack scenarios, simulating collaborative or distributed attacks, and testing the performance of the protection system under high load conditions. The success rate of attack step execution is also assessed. It can be used as an intermediate variable in subsequent comprehensive analysis.

[0045] S400: Monitors the state changes of the physical and information systems of the power distribution network during the execution of an attack, calculates the impact of the network attack on the operation of the power grid, and generates assessment results; In this embodiment of the application, step S400 involves monitoring the state changes of the distribution network's physical and information systems during the attack execution process, calculating the degree of impact of the network attack on the power grid operation, and generating an evaluation result, including the following steps C1-C4: C1: Calculates the voltage impact index, which reflects the degree of deviation of the bus voltage from the reference value after the attack, and identifies the voltage over-limit node and duration. Specifically, regarding the impact on the physical system, the system collects electrical quantities such as bus voltage, line current, active power, and reactive power in the simulation environment, compares them with the baseline values ​​before the attack, calculates the degree of deviation, and the voltage impact index can be expressed as: (4) In the formula, Voltage influence index; This represents the total number of busbars in the distribution network. For the attack Actual voltage values ​​of each busbar; For the attack before the The voltage reference value for each bus. For example, when the voltage deviation of a bus exceeds 7% of the rated voltage, it is determined to be a voltage over-limit, and the bus number and duration of the over-limit bus are recorded.

[0046] C2: Count the number of device malfunctions caused by the attack, calculate the device impact index, and assess the direct and cascading impact of the attack on critical equipment; Specifically, the attack resulted in a number of equipment malfunctions, including circuit breaker tripping, protection device malfunctions, and automatic device failures. The equipment impact index is defined as: (5) In the formula, Equipment Impact Index; The number of devices that malfunctioned; This represents the total number of key equipment in the power distribution network.

[0047] It should be noted that equipment malfunctions can trigger a chain reaction. For example, a circuit breaker tripping malfunction may cause load transfer and overload other lines. The system automatically tracks these chain effects through the simulation environment and includes indirectly affected equipment in the statistics.

[0048] C3: Accumulate the power loss load and outage duration caused by the attack, calculate the load loss index, and quantify the impact of the attack on power supply reliability; Specifically, to calculate the load loss caused by the attack, for load nodes that lose power due to circuit breaker tripping or voltage collapse, the load power and outage duration are summed, and the load loss index can be expressed as: (6) In the formula, This represents the total electricity loss due to load, expressed in kilowatt-hours. This represents the number of power-loss load nodes. For the first The load power of each power failure node is expressed in kilowatts. This represents the power outage duration for that node, in hours. It should be noted that the load loss index directly reflects the impact of the attack on power supply reliability and is an important indicator for assessing the severity of the attack.

[0049] C4: Calculate the information security impact index based on the amount of stolen data, the number of configurations tampered with, and the number of hosts with implanted backdoors; Specifically, regarding the impact on information systems, the impact includes the amount of sensitive data stolen, the number of configuration parameters tampered with, and the number of backdoor programs implanted during the system's statistical attack; the information security impact index can be expressed as: (7) In the formula, Information security impact index; The number of data files stolen; This represents the total number of sensitive data files in the system. The number of configuration parameters that were tampered with; This represents the total number of key configuration parameters. The number of hosts that have been implanted with a backdoor; The total number of hosts in the information system; The weighting coefficients can be 0.4, 0.35, and 0.25, respectively, and can be determined based on the relative importance of data confidentiality, integrity, and availability. When an attack causes the master station SCADA system to lose its ability to monitor power distribution terminals, the number of out-of-control devices and the duration of the out-of-control period are recorded to assess the risk to the dispatching operation.

[0050] It should be noted that the S400 summarizes the above-mentioned impact indicators and generates an attack impact assessment report, which may include an attack timeline, marking the execution time of each attack step and the corresponding system state changes; and may also include a summary table of quantitative indicators, listing the voltage impact index. Equipment Impact Index Load loss index Information security impact index These are key numerical values. The above assessment results provide a basis for quantifying security risks, helping managers understand the severity of different attack scenarios, determine protection priorities and resource allocation priorities; the assessment results can be transmitted to the S600 as input for optimizing protection strategies.

[0051] S500: Simulate the detection, alarm, and blocking response of the protection system deployed in the simulation environment to attack behaviors, and evaluate the detection accuracy, response time, and overall defense success rate of the protection system; Specifically, the S500 deploys firewalls, intrusion detection systems, host protection software, security audit platforms, and other protective measures in a simulated environment, simulating these protective systems' response to network attacks in terms of detection, alerting, and blocking.

[0052] In this embodiment of the application, the evaluation of the detection accuracy, response time, and overall defense success rate of the protection system in step S500 includes the following D1-D5: D1: Simulate the process of a firewall matching and blocking attack traffic according to access control rules, and count the number of attack steps that are successfully blocked and those that are missed. Specifically, in D1, the firewall simulator can load the actual configured access control lists and perform rule matching on data packets entering and leaving each network domain. When attack traffic injected by the S300 passes through the firewall, the simulator determines whether the traffic violates the access control policy. If it matches the deny rule, the data packet is dropped, blocking the attack; if it matches the allow rule, the data packet is allowed, and the attack continues. The system records each rule matching result of the firewall and counts the number of successfully blocked attack steps and the number of missed attack steps.

[0053] D2: The simulated intrusion detection system performs in-depth detection and alarm generation of network traffic based on the attack feature library, and calculates the detection accuracy rate. Specifically, in D2, the attack feature library can be loaded by the intrusion detection system simulator to perform deep packet detection on the traffic in the simulated network. The feature library can include thousands of rules such as port scanning features, vulnerability exploitation features, malicious payload features, etc.

[0054] When traffic matching the features is detected, the simulator generates an alarm event, records information such as the source IP, target IP, attack type, threat level of the attack, etc.; the intrusion detection accuracy rate can be expressed as: (8) In the formula, is the detection accuracy rate of the intrusion detection system; is the number of real attacks correctly identified; is the number of false alarms that misjudge normal traffic as an attack. It should be noted that a higher detection accuracy rate means that the intrusion detection system can effectively detect attacks and will not generate too many false alarm messages that interfere with the operation and maintenance personnel.

[0055] D3: Simulate the parsing and whitelist verification of industrial protocol messages by industrial control security protection devices, and block illegal control commands and abnormal parameter settings; Specifically, in D3, for industrial protocol attacks, a dedicated industrial control security protection device simulator can be deployed. This device can parse protocols such as IEC 61850 and Modbus, and identify attack behaviors such as illegal control commands and abnormal parameter settings. When the forged remote control command injected in S300 passes through the industrial control protection device, the device analyzes fields such as the operation object, operation type, timestamp of the command, etc., and compares them with the whitelist rules to determine whether the command is legal. If it is determined to be illegal, the command transmission is blocked to protect the distribution terminal and physical devices from attacks.

[0056] D4: Simulate the linkage response mechanism between multiple protection systems, calculate the average time from the occurrence of an attack to the response of the protection system, and evaluate the protection response speed; Specifically, in D4, the linkage response mechanism of the protection system can be simulated. When the intrusion detection system discovers an attack behavior and generates an alarm, it automatically triggers the update of the firewall rules to block the source IP address of the attack and prevent the attacker from further penetration. When the host protection software detects an abnormal process or file modification, it automatically isolates the infected host and cuts off its network connection to prevent lateral movement. The effect of the linkage response is verified through simulation to observe whether the attack chain execution can be interrupted in time and the impact of the attack can be controlled within the minimum range.

[0057] Among these, assessing the response speed of protective measures involves measuring the time interval from the occurrence of an attack to the generation of a response by the protective system. The average response time can be expressed as: (9) In the formula, The average response time is in seconds. This represents the total number of attack steps detected. For the first The moment when the attack was blocked by the protection system; For the first The moment when the attack begins. It should be noted that the shorter the response time, the more promptly the protection system can block the attack and reduce losses.

[0058] D5: Calculate the overall defense success rate of the protection system, defined as the proportion of the number of attack steps that are successfully blocked to the total number of attack steps; Specifically, in D5, for multi-layered protection systems, the blocking contribution of each layer of protection is statistically analyzed to identify weak links in the protection chain.

[0059] In another optional implementation, if an attack scenario can still be successfully completed under the existing protection configuration, the S500 analyzes the path and reasons for the attack to bypass the protection and proposes protection hardening suggestions, such as adding detection rules, adjusting firewall policies, and deploying new security devices.

[0060] It should be noted that the results of the protective effect verification include the detection accuracy rate. Average response time And through actual testing, in The blocking probability is calculated from the statistical results of how many times this step was successfully blocked in a given attack. The attack impact of S400 was combined to comprehensively evaluate the network security protection capabilities of the power distribution network.

[0061] S600: Based on the aforementioned attack complexity metrics, evaluation results, and detection accuracy, calculate the overall security protection comprehensive score, identify weak points in protection, and generate suggestions for optimizing protection strategies.

[0062] Specifically, the S600 system analyzes test results from multiple attack scenarios to establish a correlation between attack success rate and protection configuration. For each attack scenario, it records information such as whether the attack was successful under the current protection configuration, the extent of the attack's impact, and the protection system's response. By comparing the test results of different scenarios, high-risk points and protection blind spots in the power distribution network information system are identified.

[0063] The overall security protection score is calculated by comprehensively considering three dimensions: attack detection capability, attack blocking capability, and impact control capability. The overall security score can be expressed as follows: (10) In the formula, The overall safety score is out of 100. The intrusion detection accuracy is derived from formula (8); This represents the number of attack steps that were successfully blocked. This represents the total number of steps in the attack chain. The voltage influence index is derived from formula (4); The equipment impact index is derived from formula (5); These are the weighting coefficients for the corresponding indicators. The weights of the three indicators are determined according to the requirements of distribution network safety management, and the weight of detection capability is usually included. Set to 0.3, for blocking capability weight. A value of 0.4 is used to influence the weight of control capability. The score is set to 0.3. A higher overall score indicates a more comprehensive protection system, capable of effectively detecting and blocking attacks and minimizing their impact.

[0064] Finally, a defense capability assessment report can be generated based on all the above data. The report may include the following: a summary table of attack scenario tests, listing the attack chain complexity for each scenario. Execution success rate Influencing indicators , , , The performance evaluation table for the protection system lists the detection accuracy rate of each protective device. Average response time Blocking probability By identifying critical nodes and systems in the distribution network that are vulnerable to attack and have weak protection, suggestions for optimizing protection strategies are proposed, and specific improvement measures are put forward for the identified protection deficiencies.

[0065] Furthermore, for any vulnerabilities identified during testing, optimization solutions are provided and their effectiveness verified. These optimization solutions include measures such as adding intrusion detection rules, adjusting firewall access control policies, deploying industrial control system security equipment, and strengthening authentication mechanisms.

[0066] In this embodiment of the application, the method further includes step S700: applying the optimization suggestions to the simulation environment, re-performing the attack simulation and protection verification, evaluating the effectiveness of the optimization measures, and iteratively updating the protection strategy until the preset security level is met.

[0067] Specifically, in the S700, the optimized solution is applied to a simulation environment, and the same attack scenario is re-executed. The protection effect before and after optimization is compared to verify the effectiveness of the improvement measures. The overall security score before and after optimization is compared. The changes are used to quantitatively evaluate the actual effectiveness of the optimization measures. If the attack is still successful after optimization, the path the attack takes to bypass the new protection is analyzed, and the protection scheme is iteratively improved until the expected level of security protection is achieved.

[0068] In summary, this invention, by constructing a cyber-physical fusion digital twin simulation environment, can realistically reproduce the actual impact of cyberattacks on the physical system of the distribution network. The attack scenario design is based on distribution network industrial protocols and business processes, and utilizes quantified attack chain complexity. The simulation results are highly consistent with actual threats, solving the problem that general security testing tools cannot reflect the special characteristics of the distribution network. By combining quantitative indicators such as voltage impact index, equipment impact index, load loss index, and information security impact index, abstract cybersecurity risks are transformed into specific power grid operation impact values, providing a data foundation for security investment. Compared with only providing qualitative risk levels, the data provided by this solution is more comprehensive and referential. Furthermore, because the entire process of attack and defense is simulated in the simulation environment, the detection accuracy and response speed of the protection system are quantitatively evaluated, verifying the actual effectiveness of the protection system in the face of real attacks. It can discover protection blind spots and configuration defects that cannot be found by static inspection, calculate a comprehensive security score to clarify the direction of optimization, and ensure that the protection measures are truly effective in responding to actual threats.

[0069] Example 3, referring to Tables 1 and 2, provides an application scheme for a method to simulate power distribution network attack scenarios and verify security protection capabilities, in order to verify the feasibility and effectiveness of the present invention.

[0070] This case study is based on a 10kV distribution network under a 110kV substation in the core area of ​​a provincial capital city. This distribution network comprises eight 10kV outgoing lines, serving a commercial center, government office area, and residential communities, with a total load capacity of approximately 45 MW and 12 MW of distributed photovoltaic power. The distribution automation system achieves 100% coverage, including one master station, 36 distribution terminals, and eight line protection devices. A digital twin model of this distribution network was built on a simulation platform, with a simulation duration of 24 hours, simulating typical daily load curves and photovoltaic output curves.

[0071] The system was tested with five preset typical attack scenarios: Scenario 1 is a data theft attack against the distribution master station, with the attack chain including four steps: phishing email, privilege escalation, database access, and data transmission; Scenario 2 is a denial-of-service attack against the distribution terminal, which causes terminal communication interruption through a large-scale DDoS attack; Scenario 3 is a setting tampering attack against the protection device, which modifies the protection setting value by cracking the login password; Scenario 4 is a fake remote control attack against the SCADA system, which sends false tripping commands to cause the circuit breaker to trip falsely; Scenario 5 is a multi-stage combined attack, which first steals the distribution network topology information and then carries out a precise coordinated attack to cause the critical busbar to lose pressure.

[0072] Table 1: Summary of Attack Scenario Test Results

[0073] The test results show that, under the existing protection configuration, four out of the five attack scenarios were successfully completed, with only scenario 3 failing partially due to strict access control of the protection device. Scenario 5, the coordinated attack, caused the most severe impact, resulting in voltage over-limit on two busbars, loss of voltage on three distribution transformers, and a cumulative load loss of 6,800 kWh, equivalent to a power outage for 1,700 households for four hours.

[0074] Table 2: Performance Evaluation of the Protection System

[0075] The test results of the protection systems showed that the industrial control security gateway had the strongest comprehensive protection capability, with a detection accuracy rate of 78.9% and a blocking success rate of 42.1%. Although the intrusion detection system detected some attack behaviors, it had no blocking capability and a high false alarm rate of 28%. The perimeter firewall had the fastest response time of 50 milliseconds, but its detection accuracy rate was only 61.5%, indicating insufficient capability to detect application layer attacks.

[0076] The system proposes optimization suggestions based on the protection flaws discovered during testing: It adds an industrial protocol attack signature database to the intrusion detection system, including 50 new detection rules such as IEC 61850 illegal control and Modbus function code abuse; it adjusts the boundary firewall policy to prohibit direct external access to the power distribution terminal management port, allowing only access via bastion host redirection; it deploys a database auditing system on the SCADA server to record all SQL query operations and promptly detect abnormal access; and it enables two-factor authentication for protection devices to prevent weak password cracking.

[0077] After applying the optimized solution to the simulation environment, the same attack scenarios were re-executed. The test results showed that: in Scenario 3, the fixed value tampering attack failed completely due to the two-factor authentication mechanism, and the success rate dropped from 60% to 0%; in Scenario 4, the forged remote control attack was blocked by the enhanced detection rules of the industrial control security gateway, and the success rate dropped from 83.3% to 16.7%; in Scenario 5, some steps of the coordinated attack were blocked by the new firewall policy, and the load loss decreased from 6800 kWh to 1200 kWh. After optimization, the overall security protection index improved from 42 points to 78 points, reaching a good level.

[0078] Example 4 illustrates a schematic scheme for a method of simulating a power distribution network attack scenario and verifying its security protection capabilities. It should be noted that the technical solution of this system for simulating a power distribution network attack scenario and verifying its security protection capabilities is based on the same concept as the technical solution of the method described above. Details not described in detail in this example can be found in the description of the method described above.

[0079] This embodiment also provides a system for simulating power distribution network attack scenarios and verifying security protection capabilities, including: The attack scenario library construction module is used to build an attack scenario library for power distribution network services based on historical security events and threat intelligence. The attack scenario library contains multi-stage attack scripts described based on the attack chain model, and defines attack complexity quantification indicators for each attack script. The power distribution network simulation environment module is used to establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation. The attack behavior injection module is used to inject attack behaviors sequentially into the digital twin simulation environment based on the selected attack script, simulate the execution process of each step in the attack chain, and record the attack execution status and success rate. The impact assessment module is used to monitor the state changes of the physical and information systems of the power distribution network during the attack execution process, calculate the degree of impact of the network attack on the power grid operation, and generate assessment results. The protection response simulation module is used to simulate the detection, alarm and blocking response of the deployed protection system to attack behaviors in the simulation environment, and to evaluate the detection accuracy, response time and overall defense success rate of the protection system. The comprehensive verification module is used to calculate the overall security protection score based on the attack complexity quantification indicators, evaluation results, and detection accuracy, identify weak links in the protection, and generate suggestions for optimizing the protection strategy.

[0080] This embodiment also provides a computer device applicable to a scenario of simulating a power distribution network attack and verifying its security protection capabilities, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for simulating a power distribution network attack scenario and verifying its security protection capabilities as proposed in the above embodiment.

[0081] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the method for simulating a power distribution network attack scenario and verifying security protection capabilities as proposed in the above embodiments.

[0082] The storage medium proposed in this embodiment belongs to the same inventive concept as the method for simulating a power distribution network attack scenario and verifying security protection capabilities proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0083] From the above description of the implementation methods, those skilled in the art will clearly understand that the present invention can be implemented using software and necessary general-purpose hardware. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0084] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for simulating power distribution network attack scenarios and verifying security protection capabilities, characterized in that, include: Based on historical security incidents and threat intelligence, an attack scenario library for power distribution network services is constructed. The attack scenario library contains multi-stage attack scripts described based on an attack chain model, and an attack complexity metric is defined for each attack script. Establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation; Based on the selected attack script, attack behaviors are sequentially injected into the digital twin simulation environment to simulate the execution process of each step in the attack chain, and the attack execution status and success rate are recorded. Monitor the state changes of the physical and information systems of the power distribution network during the execution of the attack, calculate the degree of impact of the network attack on the operation of the power grid, and generate assessment results; The simulation environment simulates the deployment of a protection system in response to attacks, including detection, alerting, and blocking. The system's detection accuracy, response time, and overall defense success rate are then evaluated. Based on the aforementioned attack complexity metrics, evaluation results, and detection accuracy, an overall security protection score is calculated, weak points in the protection are identified, and suggestions for optimizing the protection strategy are generated.

2. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 1, characterized in that, Based on historical security incidents and threat intelligence, an attack scenario library for power distribution network operations is constructed, including: Based on real historical cybersecurity incidents and threat intelligence, each attack scenario is defined as a multi-stage attack chain. An attack tree model is used to describe the attack chain, with the root node being the attack target and the leaf nodes being the specific attack actions. Each attack stage is defined as an attack step, and preconditions and poststates are defined for each attack step. Based on the technical difficulty and detectability of the attack steps, an attack chain complexity index is calculated to quantify the difficulty of implementing an attack script.

3. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 2, characterized in that, Establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation, including: The physical power grid simulation layer collects actual distribution network operation data and establishes an equivalent model. Construct a virtual mirror of the power distribution automation master station, terminals, protection devices, and communication network. The mirror supports the industrial communication protocol stack and is configured with a network structure and security policy consistent with the actual system. The interface module enables bidirectional command and data interaction between the physical simulation layer and the information system simulation layer. By comparing the simulation results with the actual measurement data, the simulation error is calculated. When the error is lower than the set threshold, the simulation environment is determined to meet the fidelity requirements.

4. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 3, characterized in that, Record the attack execution status and success rate, including: The attack execution process is controlled by a state machine, which determines whether to execute a step based on the preconditions of each attack step. The overall success rate of an attack chain is determined by the cumulative success probability of all attack steps in the chain; among them, the success probability of each step is affected by factors including the technical success rate of the attack step itself and the probability that the corresponding step is blocked by the protection system.

5. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 4, characterized in that, Monitor the state changes of the distribution network's physical and information systems during the attack execution process, calculate the impact of the network attack on the power grid operation, and generate assessment results, including: Calculate the voltage impact index to reflect the degree of deviation of the bus voltage from the reference value after the attack, and identify the voltage over-limit nodes and their duration; Statistical analysis of the number of equipment malfunctions caused by attacks, calculation of equipment impact index, and assessment of the direct and cascading impacts of attacks on critical equipment; The load loss index is calculated by summing the power loss and duration caused by the attack, and the impact of the attack on power supply reliability is quantified. The information security impact index is calculated based on the amount of stolen data, the number of configurations tampered with, and the number of hosts implanted with backdoors.

6. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 5, characterized in that, The evaluation of the protection system's detection accuracy, response time, and overall defense success rate includes: Simulate the firewall's process of matching and blocking attack traffic according to access control rules, and count the number of successfully blocked and unblocked attack steps; The simulated intrusion detection system performs in-depth network traffic detection and alarm generation based on an attack signature database, and calculates the detection accuracy. Simulates industrial control security protection equipment to parse and whitelist industrial protocol messages, blocking unauthorized control commands and abnormal parameter settings; Simulate the linkage response mechanism between multiple protection systems, calculate the average time from the occurrence of an attack to the generation of a response by the protection system, and evaluate the protection response speed. The overall defense success rate of the protection system is calculated as the proportion of the number of attack steps that are successfully blocked to the total number of attack steps.

7. The method for simulating power distribution network attack scenarios and verifying security protection capabilities as described in claim 6, characterized in that, Also includes: The optimization suggestions are applied to the simulation environment, and the attack simulation and protection verification are re-executed to evaluate the effectiveness of the optimization measures. The protection strategy is then iteratively updated until the preset security level is met.

8. A system for simulating power distribution network attack scenarios and verifying security protection capabilities, using the method described in any one of claims 1-7, characterized in that, include: The attack scenario library construction module is used to build an attack scenario library for power distribution network services based on historical security events and threat intelligence. The attack scenario library contains multi-stage attack scripts described based on the attack chain model, and defines attack complexity quantification indicators for each attack script. The power distribution network simulation environment module is used to establish a digital twin simulation environment for the cyber-physical integration of the power distribution network, including physical power grid simulation and information system simulation. The attack behavior injection module is used to inject attack behaviors sequentially into the digital twin simulation environment based on the selected attack script, simulate the execution process of each step in the attack chain, and record the attack execution status and success rate. The impact assessment module is used to monitor the state changes of the physical and information systems of the power distribution network during the attack execution process, calculate the degree of impact of the network attack on the power grid operation, and generate assessment results. The protection response simulation module is used to simulate the detection, alarm and blocking response of the deployed protection system to attack behaviors in the simulation environment, and to evaluate the detection accuracy, response time and overall defense success rate of the protection system. The comprehensive verification module is used to calculate the overall security protection score based on the attack complexity quantification indicators, evaluation results, and detection accuracy, identify weak links in the protection, and generate suggestions for optimizing the protection strategy.

9. A computer device, characterized in that, include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement the steps of the method for simulating and verifying the security protection capabilities of a power distribution network attack scenario as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, It stores computer-executable instructions, which, when executed by a processor, implement the steps of the method for simulating a power distribution network attack scenario and verifying security protection capabilities as described in any one of claims 1 to 7.