A new energy transformer area information physical attack propagation analysis and risk assessment method and system

By constructing a cyber-physical dual-layer coupling diagram, the communication and electrical connections of new energy power distribution areas are uniformly expressed, and the attack propagation path is described. This solves the problems of difficulty in characterizing attack propagation paths and quantifying risk impact in new energy power distribution areas, and realizes security risk assessment and protection for high-proportion access power distribution areas.

CN122640232APending Publication Date: 2026-08-25STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611011186.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-08
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

In areas where a high proportion of renewable energy is connected, the deep coupling between the information network and the physical power grid makes it difficult to characterize the attack propagation path, quantify the risk impact, locate the attack entry point and affected nodes, and distinguish between normal renewable energy fluctuations and malicious attacks using existing detection methods. Furthermore, fixed thresholds are prone to false alarms and false negatives.

Method used

A cyber-physical dual-layer coupling graph is constructed to uniformly express communication connections, electrical connections, and cross-layer control dependencies. Typical attack propagation paths are described through attack vectors, attack propagation weights and path risk values ​​are calculated, and node and system risks are dynamically assessed.

Benefits of technology

It enables correlation analysis between information-side attack behaviors and physical-side operational consequences, generates interpretable attack propagation paths, improves the rationality and accuracy of attack risk assessment, and can identify suspected attack entry points and key propagation paths, supporting the security protection and risk management of the distribution area.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640232A_ABST
    Figure CN122640232A_ABST
Patent Text Reader

Abstract

The application discloses a new energy transformer area information physical attack propagation analysis and risk assessment method and system. The method collects network security monitoring data, transformer area business operation data and asset allocation data, and after time alignment, space mapping and normalization processing, a double-layer coupling graph containing an information layer, a physical layer and a cross-layer coupling edge is constructed; attack vectors such as instruction tampering, measurement tampering, false data injection, replay attack and denial of service attack are mapped into the graph, attack propagation weights are calculated and candidate propagation paths are generated; further combined with path propagation probability, physical influence degree, asset importance, business importance and protection ability, path risk, node risk and system risk are calculated, and attack path sorting, key risk nodes and transformer area risk levels are output. The application can be used for information physical attack propagation analysis and security risk assessment of new energy high proportion access transformer area.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical fields of distribution network cyber-physical security, power Internet of Things security, and risk assessment of new energy access distribution areas, and particularly relates to a method and system for cyber-physical attack propagation analysis and risk assessment in new energy distribution areas. Background Technology

[0002] With the high proportion of distributed photovoltaic (PV) systems, user-side energy storage, charging piles, and adjustable loads being connected to low-voltage distribution transformer areas, traditional transformer areas are gradually transforming from a unidirectional power supply and passive power consumption mode to a multi-source access, bidirectional interaction, and dynamic adjustment mode. Frequent exchanges of telemetry, telesignaling, telecontrol, parameter configuration, and business strategy data between devices such as transformer area smart converged terminals, security access gateways, data acquisition terminals, smart meters, PV inverters, energy storage converters, and charging pile controllers mean that the operating status of the transformer area is simultaneously affected by factors such as electrical topology, load changes, communication links, terminal identity, control commands, and data quality.

[0003] Under this operating mode, abnormal behavior on the information side may be transmitted to the physical side through control commands, measurement data, parameter configurations, or communication disruptions, causing risks such as abnormal photovoltaic output, deviations in energy storage charging and discharging, abnormal switching of charging loads, low-voltage bus voltage exceeding limits, increased reverse power transmission from the distribution area, or overload of the distribution area transformer. This type of attack has obvious cyber-physical coupling characteristics, and its impact depends not only on the attack entry point and attack method, but also on communication relationships, service dependencies, electrical topology location, and real-time operating status.

[0004] Existing methods for detecting electrical anomalies in transformer substations typically separate network intrusion detection from electrical anomaly detection. Network-side detection can detect abnormal packets, abnormal logins, or unauthorized access, but it's difficult to determine whether these have caused physical consequences. Physical-side detection can detect voltage, current, and power deviations, but it struggles to distinguish between normal renewable energy fluctuations, sudden changes in charging load, and the impact of malicious attacks. A high proportion of renewable energy access also enhances the time-varying nature of power flow, voltage, and power exchange, making it easy for fixed thresholds or single anomaly criteria to generate false alarms and missed alarms.

[0005] Furthermore, existing risk assessment methods often focus on individual devices, single links, or single types of alarms, lacking a unified expression of the multi-level attack propagation relationships from "terminal to transformer area to master station." For typical attacks such as command tampering, measurement tampering, spoofed data injection, replay attacks, and denial-of-service attacks, the impact often propagates from information layer nodes to physical layer nodes through cross-layer coupling relationships and continues to spread along the electrical topology. Therefore, a unified method for modeling and assessing attack propagation paths that can describe communication connections, electrical connections, and control dependencies is needed to provide a basis for the safety protection and risk management of new energy transformer areas. Summary of the Invention

[0006] To address the shortcomings of existing technologies, this invention aims to solve the problems of difficulty in characterizing attack propagation paths, quantifying risk impact, and locating attack entry points and affected nodes in areas with a high proportion of renewable energy connected to power grids, where the information network and physical power grid are deeply coupled. By constructing a cyber-physical dual-layer coupling graph, it uniformly expresses communication connections, electrical connections, and cross-layer control dependencies, enabling dynamic assessment of typical attack propagation paths, node risks, and system risks.

[0007] The present invention adopts the following technical solution: This invention protects a method for analyzing and assessing the propagation and risks of cyber-physical attacks in new energy power distribution areas, comprising: Acquire operational data, cybersecurity monitoring data, and asset configuration data for the new energy distribution area; An information layer diagram is constructed based on the network security monitoring data, a physical layer diagram is constructed based on the business operation data, and a cross-layer coupling relationship between the information layer and the physical layer is established based on the control relationship and the measurement feedback relationship, forming an information-physical dual-layer coupling diagram. Construct an attack vector that includes the attack entry node, the attack target node, the attack method, and the attack affected objects, and determine the initial state of attack propagation in the cyber-physical dual-layer coupling graph based on the attack vector; The attack propagation weight is determined based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity. Candidate attack propagation paths are generated based on the attack propagation weights, and then filtered according to the physical impact of the candidate attack propagation paths to obtain a set of attack propagation paths that meet the physical impact constraints. For each attack propagation path in the attack propagation path set, determine the path propagation probability, path physical impact, path associated asset importance, and path protection capability, and determine the path risk value based on the path propagation probability, path physical impact, path associated asset importance, and path protection capability. Based on the path risk values, determine the node risk values, the attack path risk ranking results, and the system risk values ​​of the transformer area; Based on the node risk value, attack path risk ranking results, and area system risk value, the attack propagation path modeling results and dynamic security risk assessment results are output.

[0008] Furthermore, the operational data includes at least one of the following: transformer substation topology data, voltage data, current data, active power data, reactive power data, distributed photovoltaic output data, energy storage operation status data, charging pile load data, and distribution transformer operation data.

[0009] Furthermore, the network security monitoring data includes at least one of the following: terminal identity data, communication connection data, access behavior data, control command data, authentication log data, abnormal message data, and security alarm data.

[0010] Furthermore, the cross-layer coupling relationship includes at least one of the following: (1) Control coupling edge formed by control commands acting on physical devices; (2) Measurement coupling edge formed by uploading physical measurement data to the information system; (3) Access coupling edge formed by the terminal authentication result affecting the device access status; (4) The strategy coupling edge formed by the impact of business strategy on the operating status of new energy equipment.

[0011] Furthermore, the attack vector is represented as:

[0012] in, Indicates the first Attack vectors, This indicates an attack on the entry point node. Indicates the target node to be attacked. Indicates the attack method. Indicates the target of the attack. Indicates the duration of the attack or the attack time window.

[0013] Furthermore, the attack methods include at least one of instruction tampering, measurement tampering, spoofed data injection, replay attack, and denial-of-service attack.

[0014] Furthermore, determining the attack propagation weight based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity includes:

[0015] in, Indicates that by node Pointing to node The edge, Indicates time side attack propagation weight, Represents the normalized mapping function. Indicates the source node Vulnerability score, Represents the target node Vulnerability score, Represents a node With nodes The strength of the connection between them Indicates the strength of business dependency. Indicates attack on the border Sensitivity to the impact on the physical operating state after propagation Represents the target node The rating of protection capability These are the weighting coefficients.

[0016] Furthermore, the candidate attack propagation path is represented as follows:

[0017] in, Indicates the first Candidate attack propagation paths, This indicates an attack on the entry point node. Indicates the target node to be attacked, and any adjacent nodes. and There are information layer edges, physical layer edges, or cross-layer coupling edges between them. .

[0018] Furthermore, the candidate attack propagation path needs to satisfy the attack propagation weight threshold constraint, path length constraint, and physical impact constraint.

[0019] Furthermore, the path propagation probability of the candidate attack propagation path is determined based on the attack propagation weight corresponding to each propagation edge in the attack propagation path.

[0020] Furthermore, the path physical influence of the candidate attack propagation path Calculate using the following formula: in, Representing a path The degree of voltage deviation caused Indicates the degree of active power deviation. Indicates the degree of reactive power deviation. This indicates the degree of load loss or loss of new energy output. Indicates the degree to which the equipment has exceeded its limits. These are non-negative weighting coefficients. This represents the attack propagation path.

[0021] Furthermore, the degree of voltage deviation Active power deviation Degree of reactive power deviation The results were obtained by calculating the difference in the operating status of the transformer area before and after the attack disturbance:

[0022]

[0023]

[0024] in, , , These represent the attack propagation paths. The voltage, active power, and reactive power status after the action; , , These represent the voltage, active power, and reactive power states under unattacked or reference conditions, respectively. Represents the L2 norm; To prevent positive numbers with a denominator of zero.

[0025] Furthermore, the path risk value Calculate using the following formula:

[0026] in, Representing a path At any moment The risk value, Represents the path propagation probability. Indicates the physical impact of the path. Indicates the importance of path-related assets. Indicates the importance of path-related business operations. Indicates the path protection capability score. These are non-negative weighting coefficients.

[0027] Furthermore, the importance of the path-related assets. Calculate using the following formula:

[0028] in, Representing a path The Middle Asset importance score for each node, The number of nodes in the path is indicated; the asset importance score is determined based on at least one of the following: the type of equipment to which the node belongs, the power supply impact range, the new energy access capacity, the business function, and the impact of historical faults.

[0029] Furthermore, the path protection capability score Calculate using the following formula:

[0030] in, Representing a path The Middle The protection capability score of each node is determined based on at least one of the following: authentication strength, access control policy, communication encryption status, anomaly detection capability, security patch status, and security alarm response status.

[0031] Furthermore, the node risk value Calculate using the following formula:

[0032] in, Represents a node At any moment The risk value, Indicates passing through nodes The set of candidate attack propagation paths, Indicates the propagation path of candidate attacks The path risk value.

[0033] Furthermore, the system risk value of the transformer area Calculate using the following formula:

[0034] in, Indicates the time of the district system Overall risk value, Represents the set of candidate attack propagation paths. Indicates the number of candidate attack propagation paths. V represents the set of all nodes in the cyber-physical dual-layer coupling graph, where |V| represents the number of nodes. These are non-negative weighting coefficients.

[0035] Furthermore, the dynamic security risk assessment results include at least one of the following: high-risk attack entry nodes, high-risk physical impact nodes, high-risk cross-layer coupling edges, attack propagation path ranking results, attack type identification results, and the risk level of the transformer area system.

[0036] Furthermore, the risk level of the distribution area system is divided into low risk, medium risk, high risk, and severe risk based on the risk value of the distribution area system. When the risk value of the distribution area system exceeds a preset risk threshold, a corresponding risk alarm message is generated. The risk alarm message includes the attack entry point, attack target, attack propagation path, affected devices, affected services, and risk level.

[0037] In another aspect, this invention protects a cyber-physical attack propagation analysis and risk assessment system for new energy power distribution areas, comprising: The data acquisition module is used to acquire network security monitoring data, business operation data, and asset configuration data of the new energy distribution area; The cyber-physical coupling graph construction module is used to construct an information layer graph based on the network security monitoring data, construct a physical layer graph based on the business operation data, and establish cross-layer coupling relationships between the information layer and the physical layer based on control relationships and measurement feedback relationships, forming a cyber-physical dual-layer coupling graph; The attack vector construction module is used to construct an attack vector that includes the attack entry node, the attack target node, the attack method, and the attack affected objects, and to determine the initial state of attack propagation in the cyber-physical dual-layer coupling graph based on the attack vector. The propagation weight calculation module is used to determine the attack propagation weight based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity. The attack path generation module is used to generate candidate attack propagation paths based on the attack propagation weight, and to filter them according to the physical influence of the candidate attack propagation paths to obtain a set of attack propagation paths that meet the physical influence constraints. The risk assessment module is used to determine the path propagation probability, path physical impact, path-related asset importance, and path protection capability for each attack propagation path in the attack propagation path set, and to determine the path risk value based on the path propagation probability, path physical impact, path-related asset importance, and path protection capability. The results output module is used to determine the node risk value, attack path risk ranking result, and area system risk value based on the path risk value; and to output the attack propagation path modeling result and dynamic security risk assessment result based on the node risk value, attack path risk ranking result, and area system risk value.

[0038] Furthermore, the two-layer coupling graph construction module includes an information layer modeling unit, a physical layer modeling unit, and a cross-layer coupling modeling unit; The information layer modeling unit is used to establish communication connection relationships, access control relationships, and command transmission relationships; The physical layer modeling unit is used to establish the topology relationships of the transformer area, the power transmission relationships, and the equipment operation constraints. The cross-layer coupling modeling unit is used to establish the mapping relationship between control commands, measurement data, identity authentication results and business strategies and the operating status of physical equipment.

[0039] Furthermore, the risk assessment module is also used to sort candidate attack propagation paths and generate risk levels, risk alarms, and risk location results based on path risk values, node risk values, and system risk values ​​of the distribution area.

[0040] This invention also protects an electronic device, including a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements the above-described method for analyzing and assessing the propagation of cyber-physical attacks in new energy power distribution areas.

[0041] The present invention also protects a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described method for analyzing and assessing the propagation of cyber-physical attacks in new energy power distribution areas.

[0042] The beneficial effects of this invention are compared with those of the prior art: This invention uses a cyber-physical dual-layer coupling graph to uniformly express the communication connections, electrical connections, and cross-layer control dependencies in a new energy distribution area, enabling the correlation analysis of information-side attack behaviors and physical-side operational consequences within the same graph structure.

[0043] This invention uses attack vectors to describe typical attacks such as instruction tampering, measurement tampering, fake data injection, replay attacks, and denial-of-service attacks. It unifies the modeling of attack entry point, attack target, attack method, affected objects, and duration, making it easier to generate interpretable attack propagation paths.

[0044] This invention calculates attack propagation weights by considering node vulnerability, connection strength, business dependency strength, physical sensitivity, and protection capabilities, which can reflect the differences in attack propagation at the information layer, physical layer, and cross-layer coupling edges.

[0045] This invention incorporates path propagation probability, physical impact, asset importance, business importance, and protection capabilities into path risk calculation, which can avoid relying solely on a single network alarm or a single physical anomaly for judgment and improve the rationality of attack risk assessment results.

[0046] This invention can output path risk ranking, node risk intensity, and system risk level, enabling operations and maintenance personnel to identify suspected attack entry points, key propagation paths, affected physical nodes, and priority targets for handling, which helps to form a complete chain of evidence from attack modeling to risk assessment.

[0047] This invention can dynamically update the dual-layer coupling diagram and risk assessment results as the operating status of the transformer substation, the equipment access status, and the safety monitoring data change. It is applicable to the safety risk analysis of transformer substations under conditions of high proportion of distributed photovoltaic, energy storage, charging piles, and flexible load access. Attached Figure Description

[0048] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is the overall flowchart of the method for analyzing and assessing the propagation of cyber-physical attacks in new energy power distribution areas proposed in this invention; Figure 2 This is a schematic diagram of the cyber-physical dual-layer coupling diagram of the new energy distribution area proposed in this invention; Figure 3 This is a schematic diagram of the path risk ranking proposed in this invention; Figure 4 This is a schematic diagram of node risk heat proposed in this invention; Figure 5 This is a schematic diagram of the architecture of the cyber-physical attack propagation analysis and risk assessment system for new energy power distribution areas proposed in this invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this application are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, other embodiments obtained by those skilled in the art without creative effort are all within the protection scope of this invention.

[0050] To achieve the aforementioned objectives, this invention provides a method and system for analyzing and assessing the propagation and risks of cyber-physical attacks in new energy power distribution areas. The following will describe this solution in detail with reference to the accompanying drawings.

[0051] Example 1 The following example, using a typical renewable energy distribution area with a high proportion of low-voltage connections, illustrates the cyber-physical attack propagation analysis and risk assessment method for renewable energy distribution areas described in this invention. This embodiment is only used to explain the technical solution of this invention and does not limit the scope of protection of this invention.

[0052] This embodiment selects a 400 kVA low-voltage distribution transformer area as the object. This area includes one distribution transformer, one low-voltage busbar, six distributed photovoltaic (PV) access points, two sets of user-side energy storage devices, eight charging piles, one area integration terminal, one edge security gateway, and one main station business system. The peak load of the area is approximately 400 kW, the installed capacity of distributed PV is 260 kW, the rated power of energy storage is 100 kW, the energy storage capacity is 200 kWh, and the maximum total load of the charging piles is 160 kW. The installed capacity of new energy accounts for approximately 65% ​​of the peak load of the area, classifying it as a high-proportion new energy access area.

[0053] In this embodiment, the sampling period for network security monitoring data is 1 second, and the sampling period for transformer area operation data is 15 seconds. In order to achieve unified analysis of information-side data and physical-side data, the system uses 15 seconds as a unified time window to perform time alignment, spatial mapping, and standardization processing on data from different sources.

[0054] I. Overall Process The overall flow of the method of the present invention is as follows: Figure 1 As shown. In Figure 1 In the illustrated process, the system first collects multi-source data and then constructs a cyber-physical dual-layer coupling graph. Subsequently, attack vectors are mapped onto this dual-layer coupling graph, the propagation weight of the attack from the information layer to the physical layer is calculated, and candidate attack propagation paths are generated. Finally, the system calculates path risk, node risk, and regional system risk to obtain the attack propagation path ranking and risk level.

[0055] First, multi-source data is collected from areas with a high proportion of new energy connections. This multi-source data includes network security monitoring data, area operation data, and asset configuration data. Specifically, network security monitoring data includes terminal identity data, communication connection data, access behavior data, control command data, authentication log data, abnormal message data, and security alarm data; area operation data includes voltage, current, active power, reactive power, distributed photovoltaic output, energy storage operation status, charging pile load, and area transformer operation status; asset configuration data includes equipment type, equipment number, communication address, access location, service function, and equipment importance.

[0056] Subsequently, the multi-source data undergoes time alignment, spatial mapping, missing value completion, and normalization. Time alignment unifies network security monitoring data and transformer substation operation data from different sampling periods into the same time window; spatial mapping establishes the correspondence between information-side terminals and physical-side electrical nodes based on device number, communication address, measurement point number, and transformer substation topology location. Through these processes, standardized data samples suitable for attack propagation modeling are formed.

[0057] II. Construction of Cyber-Physical Two-Layer Coupling Graph In this embodiment, the information layer represents the relationships between communication, access, authentication, control commands, and data upload; the physical layer represents the electrical topology of the distribution area, power transmission relationships, and equipment operating status; and cross-layer coupling edges represent the impact of control commands, measurement data, or service policies on the operating status of physical equipment. The information-physical dual-layer coupling diagram is shown below. Figure 2 As shown.

[0058] The main objects and their node mapping relationships in this embodiment are shown in Table 1.

[0059] Table 1 Mapping Relationship between Transformer Area Objects and Two-Layer Graph Nodes

[0060] The information layer node set is as follows:

[0061] The physical layer node set is as follows:

[0062] Cross-layer coupling edges include:

[0063] in, This indicates the impact of control commands or measurement data in the photovoltaic communication unit on the state of the photovoltaic physical equipment. This indicates the impact of the energy storage communication unit on the energy storage charging and discharging state; This indicates the impact of the charging pile communication unit on the charging load status; This indicates the impact of bus measurement data uploaded by the integrated terminal of the distribution area on the main station's judgment of the operating status of the distribution area.

[0064] Then, construct the cyber-physical dual-layer coupling diagram of the new energy distribution area:

[0065] in, Indicates time Cyber-physical dual-layer coupling diagram; This represents a set of information layer nodes, including the main station business system, edge security gateway, photovoltaic communication unit, energy storage communication unit, charging pile communication unit, and distribution area convergence terminal; This represents the set of physical layer nodes, including upper-level distribution network connection points, transformer substations, low-voltage busbars, photovoltaic equipment, energy storage equipment, and charging pile loads; This represents the set of information layer edges, used to represent relationships between communication connections, access control, command issuance, and data transmission. This represents the set of physical layer edges, used to represent electrical connections, power transmission, and device operation constraints. This represents a set of cross-layer coupling edges, used to represent the impact of control commands, measurement data, and business strategies on the operating status of physical equipment; This represents the set of edge weights.

[0066] III. Attack Vector Construction This embodiment considers five typical cyber-physical attacks when new energy distribution areas participate in distribution network interaction, including command tampering, measurement tampering, spoofed data injection, replay attacks, and denial-of-service attacks. Based on the aforementioned two-layer coupling graph, attack vectors are constructed. Each type of attack is represented as an attack vector:

[0067] in, Represents the attack vector of type k; This indicates an attack on the entry point node; Indicates the target node to be attacked; Indicates the attack method; Indicates the target of the attack; Indicates the duration of the attack or the attack time window.

[0068] The attack vector settings in this embodiment are shown in Table 2.

[0069] Table 2 Attack Vector Settings

[0070] Taking attack A1 as an example, the attacker tampered with the active power control command of the photovoltaic inverter through the edge security gateway, causing the photovoltaic power limiting command issued by the master station to be changed into a command to maintain maximum output. Under the condition of high photovoltaic output and low load in the distribution area at noon, this attack may cause the low-voltage bus voltage to rise, and further cause the transformer in the distribution area to increase the back-feeding power.

[0071] IV. Attack Propagation Weight Calculation The system maps the attack vector to a cyber-physical dual-layer coupled graph, forming the initial state of attack propagation.

[0072] Furthermore, for any directed edge in the two-layer coupled graph Calculate the attack propagation weights:

[0073] in, Indicates that by node Pointing to node The edge; Indicates time Attack from node propagation to nodes The weights; Indicates the source node Vulnerability score; Represents the target node Vulnerability score; Represents a node With nodes The strength of the connection between them; Indicates the strength of business dependency; This indicates the sensitivity of the physical operating state after the attack propagates through this edge; Represents the target node The rating of protective capabilities; These are the weighting coefficients; This represents the normalization mapping function, used to map the propagation weights to the interval [0,1].

[0074] In this embodiment, all scores are normalized to the [0,1] interval. Let:

[0075] The attack propagation weights of some key edges are shown in Table 3 after calculation.

[0076] Table 3 Attack propagation weights for some critical edges

[0077] As can be seen from Table 3, the cross-layer coupling edge and physical layer edge The propagation weight is relatively high. This means that when a photovoltaic communication unit is attacked, the impact of the attack can be easily transmitted to the photovoltaic physical equipment through the control coupling relationship, and further affect the operating status of the low-voltage bus.

[0078] V. Generation of Candidate Attack Propagation Paths In this embodiment, the minimum propagation weight threshold is set as follows:

[0079] The maximum path length is:

[0080] The minimum physical impact threshold is:

[0081] For each attack entry point node, the system searches for candidate attack propagation paths that satisfy the constraints in the cyber-physical dual-layer coupling graph. The candidate paths are represented as follows:

[0082] in, Indicates the first Candidate attack propagation paths; This indicates an attack on the entry point node; This indicates the target node or the node with physical impact; adjacent nodes have information layer edges, physical layer edges, or cross-layer coupling edges. The path generation process satisfies propagation weight thresholds, maximum path length, and minimum physical impact constraints to prevent invalid paths or paths with weak physical impact from entering the risk ranking results.

[0083] After searching, the candidate attack propagation paths obtained in this embodiment are shown in Table 4.

[0084] Table 4 Candidate attack propagation paths

[0085] VI. Path Risk Calculation For each candidate attack propagation path, the path propagation probability is calculated according to the following formula:

[0086] in, Indicates an attack along the path The probability of propagation; Indicates adjacent nodes in the path and Attack propagation weights between them; This indicates the number of edges contained in the path.

[0087] Meanwhile, the physical impact of the path is calculated according to the following formula: in, Representing a path At any moment The degree of physical impact caused; Indicates the degree of voltage deviation; Indicates the degree of active power deviation; Indicates the degree of reactive power deviation; Indicates the degree of load loss or loss of new energy output; Indicates the degree to which the equipment has exceeded its limits; These are non-negative weighting coefficients.

[0088] In this embodiment, we take:

[0089] Based on this, the path risk value is calculated using the following formula:

[0090] in, Indicates the path risk value; Indicates the probability of path propagation; Indicates the physical impact of the path; Indicates the importance of path-related assets; Indicates the importance of path-related business; Indicates the path protection capability score; This is a non-negative weighting coefficient. The higher the path risk value, the higher the probability of propagation and the stronger the physical impact of the attack path, and it should be prioritized for inclusion in the protection scope.

[0091] In this embodiment, we take:

[0092] The calculation results for each candidate path are shown in Table 5.

[0093] Table 5. Results of Candidate Path Risk Calculation

[0094] As can be seen from Table 5, the path This path carries the highest risk because it has a high probability of propagation and the photovoltaic output has a significant impact on the low-voltage bus voltage and the reverse power transmission from the distribution area. Therefore, under the operating conditions of this distribution area, the command tampering path from the edge security gateway to the photovoltaic communication unit should be the priority for protection.

[0095] VII. Example of Physical Influence Calculation By path: For example, the key physical quantities before and after the attack are shown in Table 6.

[0096] Table 6 Changes in key physical quantities before and after the instruction tampering attack

[0097] Based on the operational status of the control area before and after the attack, the following calculations were performed:

[0098] Substitute into the physical influence calculation formula:

[0099] get:

[0100] Considering that five voltage over-limit measurement points appeared after the attack, this embodiment further introduces an over-limit correction coefficient:

[0101] in, Indicates the corrected physical impact level; This represents the correction factor for a single measurement point that exceeds the limit; This indicates the number of measurement points exceeding the limit. In this embodiment, we take:

[0102] but:

[0103] The corrected physical influence is approximately 0.62, which is consistent with the values ​​in Table 5. The physical impact is consistent. This result indicates that although changes in photovoltaic output may be caused by natural fluctuations, when they occur simultaneously with abnormal control commands, abnormal access behavior of edge gateways, and voltage over-limit states, this path should be identified as a high-risk propagation path.

[0104] VIII. Calculation of Node Risk and System Risk The node risk value is obtained by summing the risk values ​​of candidate paths passing through that node:

[0105] in, Represents a node At any moment The risk value; Indicates passing through nodes The set of candidate attack propagation paths; Indicates the propagation path of candidate attacks The path risk value. By using the node risk value, high-risk attack entry points and critical communication nodes in the information layer, as well as high-risk affected nodes in the physical layer, can be identified.

[0106] In this embodiment, the risk values ​​of key nodes are shown in Table 7.

[0107] Table 7 Risk Values ​​of Key Nodes

[0108] As shown in Table 7, the low-voltage bus P2 and the edge security gateway I2 have the highest node risk values. Low-voltage bus P2 is the convergence point of multiple physical impact paths, and edge security gateway I2 is a crucial communication forwarding node between the master station and terminal devices. Therefore, the system can mark I2 and P2 as key monitoring nodes at this moment.

[0109] Finally, the system risk value of the transformer area is calculated according to the following formula:

[0110] in, This indicates the overall risk value of the distribution area system; Represents the set of candidate attack propagation paths; Indicates the number of candidate paths; |V| represents the set of all nodes; |V| represents the number of nodes; These are non-negative weighting coefficients.

[0111] Based on the path risk value, node risk value, and system risk value of the distribution area, the system outputs the attack propagation path ranking results, key risk nodes, suspected attack entry points, affected physical devices, and system risk level. When the system risk value exceeds a preset threshold, a risk alarm is generated, providing a basis for subsequent access control tightening, terminal verification, device isolation, policy rollback, or manual handling.

[0112] In this embodiment, we take:

[0113] Based on the calculation results in Tables 5 and 7, we obtain:

[0114] The system risk level classification is shown in Table 8.

[0115] Table 8 System Risk Level Classification

[0116] In this embodiment, This corresponds to a high-risk level. The main alerts output by the system include: the suspected entry point for the attack is the edge security gateway I2, and the key propagation path is... The main affected components are photovoltaic equipment P3, low-voltage busbar P2, and transformer P1 in the distribution area.

[0117] IX. Risk Outcome Output To facilitate understanding of attack propagation relationships by operations and maintenance personnel, the system can output path risk ranking and node risk popularity results. The path risk and node risk rankings are as follows: Figure 3 and Figure 4 express.

[0118] Based on the above results, the system can generate the following risk assessment conclusion: Under the current operating status of the distribution area, the photovoltaic command tampering attack path poses the highest risk. This attack enters from the edge security gateway, acts on the photovoltaic equipment through the photovoltaic communication unit, and further affects the low-voltage bus and the distribution area transformer. The edge security gateway and the low-voltage bus are the key risk nodes on the information side and the physical side, respectively, and priority should be given to tightening access control, verifying control commands, verifying photovoltaic output, and monitoring bus voltage.

[0119] 10. Technical Effects of This Embodiment As can be seen from this embodiment, the present invention can uniformly map network security monitoring data, area business operation data and asset configuration data to a cyber-physical dual-layer coupling diagram, thereby expressing the path relationship of an attack propagating from the information layer to the physical layer.

[0120] This invention can generate corresponding candidate propagation paths for typical attack methods such as instruction tampering, measurement tampering, fake data injection, replay attacks, and denial-of-service attacks, and calculate the path risk value by considering path propagation probability, physical impact, asset importance, business importance, and protection capabilities.

[0121] This invention can further output node risk and system risk levels, enabling maintenance personnel not only to be aware of anomalies, but also to know where attacks might enter from, along which paths they might propagate, which physical devices might be affected, and which nodes require priority protection. This result can provide a basis for the cyber-physical security transformation, risk assessment, and protection strategy formulation for areas with a high proportion of new energy access.

[0122] Example 2 refer to Figure 5 The figure shows a cyber-physical attack propagation analysis and risk assessment system for new energy power distribution areas proposed in this invention, comprising: The data acquisition module is used to acquire network security monitoring data, business operation data, and asset configuration data of the new energy distribution area; The cyber-physical coupling graph construction module is used to construct an information layer graph based on the network security monitoring data, construct a physical layer graph based on the business operation data, and establish cross-layer coupling relationships between the information layer and the physical layer based on control relationships and measurement feedback relationships, forming a cyber-physical dual-layer coupling graph; The attack vector construction module is used to construct an attack vector that includes the attack entry node, the attack target node, the attack method, and the attack affected objects, and to determine the initial state of attack propagation in the cyber-physical dual-layer coupling graph based on the attack vector. The propagation weight calculation module is used to determine the attack propagation weight based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity. The attack path generation module is used to generate candidate attack propagation paths based on the attack propagation weight, and to filter them according to the physical influence of the candidate attack propagation paths to obtain a set of attack propagation paths that meet the physical influence constraints. The risk assessment module is used to determine the path propagation probability, path physical impact, path-related asset importance, and path protection capability for each attack propagation path in the attack propagation path set, and to determine the path risk value based on the path propagation probability, path physical impact, path-related asset importance, and path protection capability. The results output module is used to determine the node risk value, attack path risk ranking result, and area system risk value based on the path risk value; and to output the attack propagation path modeling result and dynamic security risk assessment result based on the node risk value, attack path risk ranking result, and area system risk value.

[0123] Furthermore, the two-layer coupling graph construction module includes an information layer modeling unit, a physical layer modeling unit, and a cross-layer coupling modeling unit; The information layer modeling unit is used to establish communication connection relationships, access control relationships, and command transmission relationships; The physical layer modeling unit is used to establish the topology relationships of the transformer area, the power transmission relationships, and the equipment operation constraints. The cross-layer coupling modeling unit is used to establish the mapping relationship between control commands, measurement data, identity authentication results and business strategies and the operating status of physical equipment.

[0124] Furthermore, the risk assessment module is also used to sort candidate attack propagation paths and generate risk levels, risk alarms, and risk location results based on path risk values, node risk values, and system risk values ​​of the distribution area.

[0125] Embodiment 3 of the present invention provides a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the method steps provided according to Embodiment 1.

[0126] Embodiment 4 of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method steps provided according to Embodiment 1.

[0127] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.

[0128] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0129] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.

[0130] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for analyzing and assessing the propagation and risks of cyber-physical attacks in new energy power distribution areas, characterized in that, include: Acquire operational data, cybersecurity monitoring data, and asset configuration data for the new energy distribution area; An information layer diagram is constructed based on the network security monitoring data, a physical layer diagram is constructed based on the business operation data, and a cross-layer coupling relationship between the information layer and the physical layer is established based on the control relationship and the measurement feedback relationship, forming an information-physical dual-layer coupling diagram. Construct an attack vector that includes the attack entry node, the attack target node, the attack method, and the attack affected objects, and determine the initial state of attack propagation in the cyber-physical dual-layer coupling graph based on the attack vector; The attack propagation weight is determined based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity. Candidate attack propagation paths are generated based on the attack propagation weights, and then filtered according to the physical impact of the candidate attack propagation paths to obtain a set of attack propagation paths that meet the physical impact constraints. For each attack propagation path in the attack propagation path set, determine the path propagation probability, path physical impact, path associated asset importance, and path protection capability, and determine the path risk value based on the path propagation probability, path physical impact, path associated asset importance, and path protection capability. Based on the path risk values, determine the node risk values, the attack path risk ranking results, and the system risk values ​​of the transformer area; Based on the node risk value, attack path risk ranking results, and area system risk value, the attack propagation path modeling results and dynamic security risk assessment results are output.

2. The method according to claim 1, characterized in that, The operational data includes at least one of the following: transformer substation topology data, voltage data, current data, active power data, reactive power data, distributed photovoltaic output data, energy storage operation status data, charging pile load data, and distribution transformer operation data.

3. The method according to claim 1, characterized in that, The network security monitoring data includes at least one of the following: terminal identity data, communication connection data, access behavior data, control command data, authentication log data, abnormal message data, and security alarm data.

4. The method according to claim 1, characterized in that, The cross-layer coupling relationship includes at least one of the following: (1) Control coupling edge formed by control commands acting on physical devices; (2) Measurement coupling edge formed by uploading physical measurement data to the information system; (3) Access coupling edge formed by the terminal authentication result affecting the device access status; (4) The strategy coupling edge formed by the impact of business strategy on the operating status of new energy equipment.

5. The method according to claim 1, characterized in that, The attack vector is represented as follows: in, Indicates the first Attack vectors, This indicates an attack on the entry point node. Indicates the target node to be attacked. Indicates the attack method. Indicates the target of the attack. Indicates the duration of the attack or the attack time window.

6. The method according to claim 5, characterized in that, The attack methods include at least one of the following: instruction tampering, measurement tampering, spoofed data injection, replay attack, and denial-of-service attack.

7. The method according to claim 1, characterized in that, The determination of attack propagation weights based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity includes: in, Indicates that by node Pointing to node The edge, Indicates time side attack propagation weight, Represents the normalized mapping function. Indicates the source node Vulnerability score, Represents the target node Vulnerability score, Represents a node With nodes The strength of the connection between them Indicates the strength of business dependency. Indicates attack on the border Sensitivity to the impact on the physical operating state after propagation Represents the target node The rating of protection capability These are the weighting coefficients.

8. The method according to claim 1, characterized in that, The candidate attack propagation path is represented as follows: in, Indicates the first Candidate attack propagation paths, This indicates an attack on the entry point node. Indicates the target node to be attacked, and any adjacent nodes. and There are information layer edges, physical layer edges, or cross-layer coupling edges between them. .

9. The method according to claim 8, characterized in that, The candidate attack propagation paths need to satisfy the attack propagation weight threshold constraint, path length constraint, and physical impact constraint.

10. The method according to claim 1, characterized in that, The path propagation probability of the candidate attack propagation path is determined based on the attack propagation weight corresponding to each propagation edge in the attack propagation path.

11. The method according to claim 1, characterized in that, The path physical influence of the candidate attack propagation path Calculate using the following formula: in, Representing a path The degree of voltage deviation caused Indicates the degree of active power deviation. Indicates the degree of reactive power deviation. This indicates the degree of load loss or loss of new energy output. Indicates the degree to which the equipment has exceeded its limits. These are non-negative weighting coefficients. This represents the attack propagation path.

12. The method according to claim 11, characterized in that, The degree of voltage deviation Active power deviation Degree of reactive power deviation The results were obtained by calculating the difference in the operating status of the transformer area before and after the attack disturbance: in, , , These represent the attack propagation paths. The voltage, active power, and reactive power status after the action; , , These represent the voltage, active power, and reactive power states under unattacked or reference conditions, respectively. Represents the L2 norm; To prevent positive numbers with a denominator of zero.

13. The method according to claim 1, characterized in that, The path risk value Calculate using the following formula: in, Representing a path At any moment The risk value, Represents the path propagation probability. Indicates the physical impact of the path. Indicates the importance of path-related assets. Indicates the importance of path-related business operations. Indicates the path protection capability score. These are non-negative weighting coefficients.

14. The method according to claim 13, characterized in that, The importance of the path-related assets Calculate using the following formula: in, Representing a path The Middle Asset importance score for each node, The number of nodes in the path is indicated; the asset importance score is determined based on at least one of the following: the type of equipment to which the node belongs, the power supply impact range, the new energy access capacity, the business function, and the impact of historical faults.

15. The method according to claim 14, characterized in that, The path protection capability score Calculate using the following formula: in, Representing a path The Middle The protection capability score of each node is determined based on at least one of the following: authentication strength, access control policy, communication encryption status, anomaly detection capability, security patch status, and security alarm response status.

16. The method according to claim 1, characterized in that, The node risk value Calculate using the following formula: in, Represents a node At any moment The risk value, Indicates passing through nodes The set of candidate attack propagation paths, Indicates the propagation path of candidate attacks The path risk value.

17. The method according to claim 1, characterized in that, The risk value of the transformer area system Calculate using the following formula: in, Indicates the time of the district system Overall risk value, Represents the set of candidate attack propagation paths. Indicates the number of candidate attack propagation paths. V represents the set of all nodes in the cyber-physical dual-layer coupling graph, where |V| represents the number of nodes. These are non-negative weighting coefficients.

18. The method according to claim 1, characterized in that, The dynamic security risk assessment results include at least one of the following: high-risk attack entry nodes, high-risk physical impact nodes, high-risk cross-layer coupling edges, attack propagation path ranking results, attack type identification results, and the risk level of the transformer area system.

19. The method according to claim 18, characterized in that, The risk level of the distribution area system is divided into low risk, medium risk, high risk and severe risk according to the risk value of the distribution area system. When the risk value of the distribution area system exceeds the preset risk threshold, the corresponding risk alarm information is generated. The risk alarm information includes the attack entry point, attack target, attack propagation path, affected devices, affected services and risk level.

20. A cyber-physical attack propagation analysis and risk assessment system for new energy power distribution areas, characterized in that, include: The data acquisition module is used to acquire network security monitoring data, business operation data, and asset configuration data of the new energy distribution area; The cyber-physical coupling graph construction module is used to construct an information layer graph based on the network security monitoring data, construct a physical layer graph based on the business operation data, and establish cross-layer coupling relationships between the information layer and the physical layer based on control relationships and measurement feedback relationships, forming a cyber-physical dual-layer coupling graph; The attack vector construction module is used to construct an attack vector that includes the attack entry node, the attack target node, the attack method, and the attack affected objects, and to determine the initial state of attack propagation in the cyber-physical dual-layer coupling graph based on the attack vector. The propagation weight calculation module is used to determine the attack propagation weight based on node vulnerability, inter-node connectivity, cross-layer coupling, and physical operational sensitivity. The attack path generation module is used to generate candidate attack propagation paths based on the attack propagation weight, and to filter them according to the physical influence of the candidate attack propagation paths to obtain a set of attack propagation paths that meet the physical influence constraints. The risk assessment module is used to determine the path propagation probability, path physical impact, path-related asset importance, and path protection capability for each attack propagation path in the attack propagation path set, and to determine the path risk value based on the path propagation probability, path physical impact, path-related asset importance, and path protection capability. The result output module is used to determine the node risk value, attack path risk ranking result and the area system risk value based on the path risk value. Based on the node risk value, attack path risk ranking results, and area system risk value, the system outputs attack propagation path modeling results and dynamic security risk assessment results.

21. The system according to claim 20, characterized in that, The two-layer coupling graph construction module includes an information layer modeling unit, a physical layer modeling unit, and a cross-layer coupling modeling unit. The information layer modeling unit is used to establish communication connection relationships, access control relationships, and command transmission relationships; The physical layer modeling unit is used to establish the topology relationships of the transformer area, the power transmission relationships, and the equipment operation constraints. The cross-layer coupling modeling unit is used to establish the mapping relationship between control commands, measurement data, identity authentication results and business strategies and the operating status of physical equipment.

22. The system according to claim 21, characterized in that, The risk assessment module is also used to sort candidate attack propagation paths and generate risk levels, risk alarms and risk location results based on path risk values, node risk values ​​and transformer area system risk values.

23. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements the method for analyzing and assessing the propagation of cyber-physical attacks in new energy power distribution areas as described in any one of claims 1 to 19.

24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the method for analyzing and assessing the propagation of cyber-physical attacks in new energy power distribution areas as described in any one of claims 1 to 19.