A security detection system and method based on a power network vertical large model
By using a security detection system based on a vertical large model of the power network, real-time collection and analysis of power network data is achieved. Knowledge triples are generated and deep semantic understanding is performed, which solves the problems of insufficient generalization ability and high false alarm rate of traditional methods in complex attack scenarios, and realizes high-precision security detection and decision support.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUANENG POWER INT INC
- Filing Date
- 2026-02-11
- Publication Date
- 2026-06-02
Smart Images

Figure CN122133766A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of power system network security and artificial intelligence technology, and relates to a security detection system and method based on a vertical large model of power networks. Background Technology
[0002] As a crucial component of the nation's critical infrastructure, the safe and stable operation of the power system has a vital impact on the national economy and people's livelihoods. It not only concerns the normal order of social production and daily life but is also a core support for national energy security. A failure in the power system will trigger a series of chain reactions, causing incalculable losses to the social economy and people's lives.
[0003] In today's era of rapid technological advancement, smart grids and the Internet of Things (IoT) have become widely adopted. Smart grids, through advanced sensing, measurement, communication, information, computer, and control technologies, enable intelligent management and operation of power systems. IoT technology connects various devices and systems, enabling real-time information interaction and sharing. However, while these advanced technologies improve the efficiency and management level of power systems, they also expose them to increasingly severe cyberattack threats. Power generation, as the source of electricity production, and transmission, as the critical path for power transmission, have become key targets for cyberattacks. Malicious code injection attacks can implant malicious programs into the power system, interfering with the normal operation of equipment and disrupting the system's control logic. Denial-of-service attacks can prevent critical services of the power system from operating normally, causing communication interruptions between devices and affecting the stable operation of the entire power system. If these cyberattacks succeed, they are highly likely to cause equipment failures or even large-scale power outages, bringing enormous disasters to society.
[0004] Faced with such a severe cyberattack situation, traditional security detection methods are proving inadequate. Traditional security detection primarily relies on rule bases and signature matching techniques, the basic principle of which is to identify abnormal behavior in the network through pre-defined rules and the characteristics of known attacks. However, this method has significant limitations. With the continuous evolution and innovation of cyberattack methods, new and unknown attacks are constantly emerging. These attacks often lack the typical characteristics defined in traditional rule and signature bases, making them difficult for traditional methods to detect effectively. Furthermore, traditional security detection methods have weak generalization capabilities, exhibiting significant differences in detection effectiveness for different scenarios and types of attacks. In addition, due to the limitations of rule and signature bases, traditional methods are prone to false alarms during detection, misclassifying normal network behavior as attack behavior. This not only increases the workload of security management personnel but may also affect the normal operation of the power system. Summary of the Invention
[0005] The purpose of this invention is to address the technical problems of traditional detection methods in the field of power network security, such as insufficient generalization ability in complex attack scenarios, difficulty in dealing with unknown threats, and lack of interactive decision support. This invention provides a security detection system and method based on a large vertical model of power networks.
[0006] To achieve the above objectives, the present invention employs the following technical solution: The first aspect of this invention provides a security detection system based on a large vertical model of a power network, comprising: The data processing and knowledge extraction module is used to collect power network operation data in real time; and to extract key entities and the relationships between key entities from the power network operation data through NER model and relation extraction model to form knowledge triples. The knowledge base management module is used to store knowledge triples, power network operation data and log text extracted from the data processing and knowledge extraction module, and provides a knowledge management API. The security detection and analysis module constructs analysis instructions based on knowledge triples; The vertical large model engine module performs security detection based on the analysis instructions constructed by the security detection and analysis module, and outputs a threat analysis report. The threat analysis report is then queried by the security detection and analysis module to obtain the context information from the knowledge base management module, generating the final detection result.
[0007] Furthermore, the data processing and knowledge extraction module has built-in multiple data interface adapters, which support real-time subscription and batch import of various data sources such as Kafka, MQTT, databases, Syslog, SNMP and NetFlow / sFlow.
[0008] Furthermore, the knowledge base management module stores knowledge triples in the Neo4j graph database to construct a knowledge graph that expresses complex relationships between entities such as devices, protocols, and vulnerabilities; and stores power network operation data text and log text in a vector database after vectorization using the Sentence-BERT model.
[0009] Furthermore, the vertical large model engine module performs security detection using a large language model based on the analysis instructions constructed by the security detection and analysis module.
[0010] Furthermore, the training method for the large language model is as follows: The generated task instruction templates, expert-written task instruction templates, and instruction datasets generated by the large language model based on expert-written task instruction templates and knowledge from the knowledge base management module were used as the fine-tuning training set. The large language model is trained once using the knowledge extraction instruction dataset from the knowledge base management module; Then, the large language model after one training session is fine-tuned using the fine-tuning training set.
[0011] Furthermore, it also includes: The intelligent question answering and decision support module, based on retrieval enhancement generation technology, performs semantic retrieval of user queries in the knowledge base management module and retrieves relevant knowledge fragments; the relevant knowledge fragments are combined into enhanced analysis instruction prompts and input into the vertical large model engine module to generate the final detection results.
[0012] A second aspect of this invention provides a security detection method based on a large vertical model of a power network, comprising the following steps: Acquire power network operation data, and extract key entities and entity relationships based on the power network operation data to generate knowledge triples; update the knowledge base based on the knowledge triples; Based on the aforementioned knowledge triples, construct analysis instructions; The analysis commands are input into a pre-trained large language model to generate a threat analysis report; The threat analysis report is queried and matched in the knowledge base to generate the final security detection result.
[0013] A third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the security detection method based on a vertical large model of a power network.
[0014] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the security detection method based on a vertical large model of a power network.
[0015] The fifth aspect of the present invention provides a computer program product, the computer program product including computer instructions, the computer instructions instructing a computer to execute the security detection method based on a vertical large model of a power network.
[0016] Compared with the prior art, the present invention has the following beneficial effects: This invention discloses a security detection system based on a large-scale vertical model of power networks. By constructing a knowledge base for the power network security domain and performing domain knowledge enhancement and supervised fine-tuning based on a pre-trained large-scale model, a large-scale vertical model for power network security with deep semantic understanding and domain reasoning capabilities is formed. This model can more accurately identify abnormal behaviors and malicious operations in power networks, making the judgment of security threats more accurate, significantly reducing the false alarm rate, and improving detection accuracy. For example, in actual detection, traditional methods may fail to identify some disguised or novel network intrusion behaviors, while the system of this invention can accurately discover potential threats thanks to its powerful semantic understanding and knowledge reasoning capabilities. The system constructs a structured domain knowledge system covering multimodal data such as industrial control protocol data, network traffic data, system logs, sensor data, security incident reports, vulnerability databases, emergency plans, and power industry standards and regulations. This knowledge-driven approach enables the system to comprehensively grasp the operating status and security posture of the power network, analyzing and judging security threats from multiple dimensions. Whether it is abnormal data caused by equipment failure or abnormal traffic caused by external network attacks, the system can make comprehensive judgments based on rich knowledge, providing comprehensive security protection. For example, when network traffic anomalies occur, the system can not only analyze the characteristics of the traffic itself, but also combine information such as the operating status of the device and historical security events to accurately determine the cause of the anomaly and take corresponding measures.
[0017] Furthermore, during security detection and analysis, the system can output structured security incident alerts and handling suggestions, and the detection results and decision-making process are highly interpretable. Through deep semantic analysis and contextual association of the vertical large model, as well as integration with a knowledge base, the system can clearly explain the basis for security threat judgments and the source of handling suggestions. This enables security operations personnel to better understand the system's decision-making process, enhances the credibility of detection results, and facilitates timely and accurate countermeasures. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of the overall system architecture provided in an embodiment of the present invention; Figure 2 This is the security detection and question-and-answer interaction process provided in the embodiments of the present invention. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0021] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0022] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0023] The present invention will now be described in further detail with reference to the accompanying drawings: like Figure 1 The diagram illustrates the overall architecture of a large-scale power network security vertical large-model system provided by an embodiment of the present invention. It includes five modules: a data processing and knowledge extraction module S1, a knowledge base management module S2, a vertical large-model engine module S3, a security detection and analysis module S4, and an intelligent question answering and decision support module S5. The entire system forms an integrated intelligent security hub, deployed using microservices based on Docker and Kubernetes. Each core module (S1-S5) is encapsulated as an independent container, and service discovery and traffic management are performed through Service Mesh (such as Istio).
[0024] The system has two deployment modes: online and offline. When using the online deployment mode, modules S1 and S4 are deployed as DaemonSets on each critical power monitoring node or network segment to achieve localized real-time detection. Modules S2, S3, and S5 can be centrally deployed in the regional cloud center for all nodes to access.
[0025] When deployed offline, the entire system can be deployed entirely on the power company's private cloud or physical server, meeting the security requirement that data does not leave the power plant.
[0026] The system provides a standard RESTful API for integration with third-party systems (such as SOC and SIEM), and provides a visual dashboard to display the overall security posture, knowledge graph topology, and question-and-answer interaction records.
[0027] One embodiment of the present invention provides a security detection system based on a large vertical model of power network security, comprising: Data Processing and Knowledge Extraction Module: This module is responsible for the real-time acquisition, cleaning, standardization, and feature extraction of multi-source heterogeneous data. It has built-in multiple data interface adapters, supporting real-time subscription and batch import of various data sources such as Kafka, MQTT, databases, Syslog, SNMP, and NetFlow / sFlow. Data cleaning includes deduplication, outlier handling, and format standardization (e.g., unifying timestamps to ISO 8601 format). Subsequently, this module utilizes pre-trained Named Entity Recognition (NER) models (such as BERT-BiLSTM-CRF) and relation extraction models to automatically extract entities and their relationships, such as device identifiers (IP, MAC, device name), protocol types, operation instructions, and alarm types, from unstructured text, i.e., power network operation data text (such as log messages and event reports), forming structured knowledge triples to provide raw materials for the construction and dynamic updating of the knowledge base.
[0028] Knowledge Base Management Module: This module adopts a dual-storage architecture of "graph database + vector database". Knowledge triples (entity-relationship-entity) extracted from the data processing and knowledge extraction modules are stored in the Neo4j graph database to represent complex relationships between devices, protocols, vulnerabilities, and events, supporting efficient relational queries and path analysis. Simultaneously, all unstructured documents (such as technical white papers, protocol specifications, and emergency response plans) and cleaned log texts are vectorized using the Sentence-BERT model and stored in vector databases such as Milvus or Chroma for semantic similarity-based retrieval. The knowledge base management module provides a complete set of knowledge management APIs, supporting CRUD operations, version control, consistency checks, and scheduled incremental updates to ensure the accuracy and timeliness of domain knowledge.
[0029] The vertical large model engine module is the intelligent core of the system. In this embodiment of the invention, the open-source large language model LLaMA3-8B or ChatGLM3-6B is used as the base model. Training is performed on an 8-GPU NVIDIA A100 (80G) server, employing the DeepSpeed ZeRO-3 optimization strategy to reduce GPU memory usage. Training is divided into three stages: (1) First, data construction is carried out. The instruction dataset is constructed through "expert writing + model generation + manual review". First, a large number of task instruction templates are generated. Then, experts write some high-quality samples. Then, the open-source large language model is used to expand and generate based on the task instruction templates and knowledge base content. Finally, the instruction dataset is reviewed and confirmed by the expert team to ensure data quality and security.
[0030] (2) Perform domain knowledge injection pre-training. Extract a large-scale domain corpus from the knowledge base module S2, including protocol specifications, equipment manuals, vulnerability descriptions, historical security event reports, compliance requirements, etc., to build a continuous pre-training dataset. Employ efficient parameter fine-tuning techniques such as LoRA (Low-Rank Adaptation) to train for 10-15 epochs on an 8*A100 (80G) GPU cluster, deeply embedding power safety knowledge into the model parameters.
[0031] (3) Supervised Instruction Fine-tuning (SFT): Using the instruction dataset constructed in step (1), the format is (Instruction Description IST, Event Input I, Result Output O). For example, the instruction description IST is "Analyze whether the following log fragments contain security threats", the event input I is an Apache log segment, and the result output O is the threat analysis report generated by the model. In this stage, the domain model trained above is further fine-tuned on the instruction dataset for 1-3 epochs, so that it can finally follow instructions and complete security analysis tasks. The final model is deployed using high-performance inference frameworks such as vLLM to provide high-concurrency, low-latency API services.
[0032] Security Detection and Analysis Module: This module is the main business logic execution unit. It receives standardized data streams processed by the data processing and knowledge extraction module in real time via a message queue (such as RabbitMQ). For each piece of data (such as a network traffic record or a system log), the security detection and analysis module calls the API of the vertical large model engine module and constructs a specific analysis instruction (Prompt), such as: "Please analyze the following network traffic record: [data content]. Determine if there is a security risk. If so, please indicate the risk type, confidence level, and basis." The model returns a structured JSON result, which the security detection and analysis module parses and combines with contextual information queried from the knowledge base management module (such as the historical behavior of the source IP and the importance level of the target device) to perform a comprehensive judgment, generate the final security event alarm, and send it to the event response pipeline.
[0033] Intelligent Question Answering and Decision Support Module: This module is user-facing, providing a web-based interactive interface and API. Its core technology is Retrieval Enhanced Generation (RAG). When a user poses a question (Query), such as "How to handle SQL injection attacks?", the module first vectorizes the user's query and performs a semantic search in the vector database of the knowledge base management module, retrieving the top-K most relevant knowledge fragments (such as the SQL injection handling section in the emergency response plan, and related vulnerability announcements). Then, these knowledge fragments are combined with the user's query to form enhanced analysis instructions, which are input into the vertical large-scale model engine module. Based on its own knowledge and provided reference knowledge, the model generates a professional, accurate answer with accompanying handling steps, which is then presented to the user through the interface. All question-and-answer records are logged for use in optimizing the model and knowledge base.
[0034] In this invention, the knowledge base is dynamically updated. During system initialization, existing historical data, technical documents, and vulnerability databases (CVE / CNVD) are imported into the knowledge base management module using a batch import tool. During system runtime, the data processing and knowledge extraction module continuously processes the real-time data stream. For example, from a Windows security log entry (EventID=4625, Source IP: 192.168.1.100, Status: Failed), the NER model extracts the entities "192.168.1.100" and "4625", and the relation extraction model determines the relation as "Login Attempt Failed". This triple (IP: 192.168.1.100, Behavior, Login Failed) is synchronized in real-time to the graph database of the knowledge base management module. Furthermore, the knowledge base has a scheduled task that automatically retrieves the latest power industry-related vulnerability information from authoritative vulnerability databases such as CNVD and NVD daily, parses it, and updates it to the database to ensure the timeliness of threat intelligence.
[0035] Figure 2 The above illustrates a security detection method based on a large vertical model for power network security, as provided in an embodiment of the present invention. Specifically: Real-time monitoring S11: A Modbus / TCP packet is captured by the collector and sent to Kafka.
[0036] Data processing S12: Module S1 consumes this data, parses the message header fields (function code, address field), and converts them into JSON format {"protocol": "Modbus", "func_code": 6, "address": 40001, "value": 1000}.
[0037] Knowledge Extraction S13: Module S1 calls the NER model and identifies 40001 as a "holding register" address.
[0038] Knowledge Update S14: Write the triple (Device A, Write Register, 40001) to the graph database.
[0039] Model Inference S15: Module S4 constructs a Prompt: "The following is a Modbus write operation record: [JSON data]. Register address 40001 is typically used to control the start / stop of device XX. This operation occurred at an unplanned time; is it suspicious?" and sends it to module S3.
[0040] Analysis and Response S16: Module S3 returns the following result: {"risk": "High risk", "reason": "Write operation performed on critical control register during non-maintenance time", "suggestion": "Immediately issue an alarm and investigate the source of the operation"}. Based on this, Module S4 generates a high-risk alarm and triggers the work order creation process of Module S5.
[0041] Intelligent Question Answering S17: After seeing the alarm, the user asks on the interface: "What is the normal operating time for register 40001?" Module S5 retrieves the "Device A Operating Procedures" from the vector database, finds the relevant paragraph as a reference, and sends it along with the question to module S3. The model generates the answer: "According to section 5.2 of the operating procedures, operations on register 40001 should be limited to 9:00-17:00, Monday to Friday. The current operating time is 22:30, which is abnormal behavior." One embodiment of the present invention provides a security detection method based on a large vertical model of a power network, comprising the following steps: Acquire power network operation data, and extract key entities and entity relationships based on the power network operation data to generate knowledge triples; update the knowledge base based on the knowledge triples; Based on the aforementioned knowledge triples, construct analysis instructions; The analysis commands are input into a pre-trained large language model to generate a threat analysis report; The threat analysis report is queried and matched in the knowledge base to generate the final security detection result.
[0042] One embodiment of the present invention provides a computer program product, the computer program product including computer instructions, the computer instructions instructing a computer to execute the security detection method based on a vertical large model of a power network.
[0043] In one embodiment of the present invention, an electronic device is provided, comprising a processor and a memory. The memory stores a computer program, which includes program instructions. The processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to achieve a corresponding method flow or corresponding function. The processor described in this embodiment of the present invention can be used for the operation of a security detection method based on a vertical large-scale power network model.
[0044] In one embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium (Memory), which is a memory device in a terminal device for storing programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and extended storage media supported by the terminal device; it can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for loading and execution by a processor, which can be one or more computer programs (including program code). It should be noted that more specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0045] Computer-readable storage media also include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable storage medium can also be any readable medium other than a readable storage medium that can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0046] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0047] One or more instructions stored in a computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the security detection method based on a vertical large model of a power network in the above embodiments.
[0048] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A security detection system based on a large vertical model of a power network, characterized in that, include: The data processing and knowledge extraction module is used to collect power network operation data in real time; and to extract key entities and the relationships between key entities from the power network operation data through NER model and relation extraction model to form knowledge triples. The knowledge base management module is used to store knowledge triples, power network operation data and log text extracted from the data processing and knowledge extraction module, and provides a knowledge management API. The security detection and analysis module constructs analysis instructions based on knowledge triples; The vertical large model engine module performs security detection based on the analysis instructions constructed by the security detection and analysis module, and outputs a threat analysis report. The threat analysis report is then queried by the security detection and analysis module to obtain the context information from the knowledge base management module, generating the final detection result.
2. The security detection system based on a large vertical model of a power network according to claim 1, characterized in that, The data processing and knowledge extraction module has multiple built-in data interface adapters, which support real-time subscription and batch import of various data sources such as Kafka, MQTT, databases, Syslog, SNMP and NetFlow / sFlow.
3. The security detection system based on a large vertical model of a power network according to claim 1, characterized in that, The knowledge base management module stores knowledge triples in the Neo4j graph database to construct a knowledge graph that expresses complex relationships between entities such as devices, protocols, and vulnerabilities; and stores power network operation data text and log text in a vector database after vectorization using the Sentence-BERT model.
4. A security detection system based on a large vertical model of a power network according to claim 1, characterized in that, The vertical large model engine module performs security detection using a large language model based on the analysis instructions constructed by the security detection and analysis module.
5. A security detection system based on a large vertical model of a power network according to claim 4, characterized in that, The training method for the large language model is as follows: The generated task instruction templates, expert-written task instruction templates, and instruction datasets generated by the large language model based on expert-written task instruction templates and knowledge from the knowledge base management module were used as the fine-tuning training set. The large language model is trained once using the knowledge extraction instruction dataset from the knowledge base management module; Then, the large language model after one training session is fine-tuned using the fine-tuning training set.
6. A security detection system based on a large vertical model of a power network according to claim 1, characterized in that, Also includes: The intelligent question answering and decision support module, based on retrieval enhancement generation technology, performs semantic retrieval of user queries in the knowledge base management module and retrieves relevant knowledge fragments; the relevant knowledge fragments are combined into enhanced analysis instruction prompts and input into the vertical large model engine module to generate the final detection results.
7. A security detection method based on a large vertical model of a power network, characterized in that, Includes the following steps: Acquire power network operation data, and extract key entities and entity relationships based on the power network operation data to generate knowledge triples; Update the knowledge base based on the knowledge triples; Based on the aforementioned knowledge triples, construct analysis instructions; The analysis commands are input into a pre-trained large language model to generate a threat analysis report; The threat analysis report is queried and matched in the knowledge base to generate the final security detection result.
8. An electronic device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the security detection method based on a vertical large model of a power network as described in any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the security detection method based on a vertical large model of a power network as described in any one of claims 1-7.
10. A computer program product, the computer program product comprising computer instructions, characterized in that, The computer instructions instruct the computer to execute the security detection method based on a vertical large model of a power network as described in any one of claims 1-7.