Power network sensitive data leakage prediction method and device based on ai model
Patent Information
- Application Number
- CN202610890602.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-18
- Publication Date
- 2026-09-22
AI Technical Summary
[0003]然而,现有电力网络针对敏感数据泄露的防护手段以被动检测为主,仅依靠单一流量参数或事后告警开展风险排查,未搭建多源异构数据联合分析体系,缺少多层级证据核验的研判流程,难以识别隐蔽信道传输行为,无法提前锁定泄露风险节点并区分风险严重程度
获取电力网络敏感数据传输时的传输异常信息和历史攻击模式;将所述传输异常信息和所述历史攻击模式输入数据传输信道上设定的静态信道敏感模型中,提取电力网络敏感数据在固定时间窗口内的局部波动指标,根据所述局部波动指标确定电力网络数据在数据传输信道上的动态参照锚点;采集实时传输状态下的电力网络敏感数据的敏感响应特征,根据所述动态参照锚点识别所述敏感响应特征中的对称传输偏差,进而由所述对称传输偏差确定电力网络敏感数据通过隐蔽信道向外传输时的流量置换行为;依据所述流量置换行为标记电力网络敏感数据传输时的泄露风险节点,并输出泄露风险等级。
Smart Images

Figure CN122802205A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power sensitive data transmission technology, and more specifically, to a method and apparatus for predicting leakage of power network sensitive data based on an AI model. Background Technology
[0002] Power-sensitive data transmission is a fundamental data interaction link in the power network operation system. It mainly completes the cross-node and cross-network segment flow of various confidential data such as power grid operation parameters, equipment ledger information, network topology data, business management and control data, and user permission information. This type of data is transmitted by relying on dedicated network links and communication protocols, covering all business scenarios such as power grid dispatching, equipment monitoring, operation and maintenance management, and database access. The transmission process runs through various hardware devices and software platforms of the power system. The data sources are multi-source and heterogeneous, and the transmission behavior shows regular fluctuations with changes in power grid load. It is a supporting link to ensure the normal operation of power business and real-time synchronization of system status.
[0003] However, existing power grid protection measures against sensitive data leaks are primarily based on passive detection, relying solely on single traffic parameters or post-event alarms for risk assessment. They lack a multi-source heterogeneous data joint analysis system and a multi-level evidence verification process, making it difficult to identify covert transmission channels and proactively pinpoint leak risk nodes and differentiate risk severity. Therefore, how to proactively locate leak risk nodes and classify risk levels to enhance the initiative in protecting sensitive data in power grids is a challenge facing the industry. Summary of the Invention
[0004] This application provides a method and apparatus for predicting the leakage of sensitive data in power networks based on an AI model. It can locate leakage risk nodes in advance and classify risk levels to improve the initiative in protecting the security of sensitive data in power networks.
[0005] Firstly, this application provides a method for predicting the leakage of sensitive data in power networks based on an AI model, the prediction method comprising the following steps: Acquire abnormal transmission information and historical attack patterns during sensitive data transmission in power grids; The abnormal transmission information and the historical attack patterns are input into the static channel sensitivity model set on the data transmission channel to extract the local fluctuation index of the power network sensitive data within a fixed time window, and the dynamic reference anchor point of the power network data on the data transmission channel is determined based on the local fluctuation index. The system collects sensitive response characteristics of sensitive power network data under real-time transmission status, identifies symmetrical transmission deviations in the sensitive response characteristics based on the dynamic reference anchor point, and then determines the flow displacement behavior of sensitive power network data when it is transmitted outward through a covert channel based on the symmetrical transmission deviations. Based on the described flow replacement behavior, nodes at risk of leakage during sensitive data transmission in the power network are marked, and the leakage risk level is output.
[0006] In this embodiment, inputting the transmission anomaly information and the historical attack pattern into a static channel sensitivity model set on the data transmission channel to extract local fluctuation indicators of power network sensitive data within a fixed time window specifically includes: The transmission anomaly information and the historical attack pattern are concatenated and aligned to obtain a multi-source joint input sequence; The joint input sequence is loaded into the past state encoder of the static channel-sensitive model, and the multivariate sequence within a fixed time window is scanned frame by frame. The hidden state output of the multivariate sequence within the fixed time window is determined, and the fluctuation of the hidden state output is aggregated to obtain the local fluctuation index of the power network sensitive data within the fixed time window.
[0007] In this embodiment, concatenating and aligning the transmission anomaly information with the historical attack pattern to obtain the multi-source joint input sequence specifically includes: Perform source cleaning on the transmission anomaly information and the historical attack patterns respectively to obtain aligned static covariates; By synchronously concatenating the window start timescale and the aligned static covariates, a multi-source joint input sequence is obtained.
[0008] In this embodiment, determining the dynamic reference anchor point of power network data on the data transmission channel based on the local fluctuation index specifically includes: The local fluctuation index is input into the interpretability attention module of the TFT model to calculate the similarity score between the current window sequence and each segment in the historical pattern library. Based on the similarity score and historical transmission pattern fragments, a set of candidate anchor points for power network data on the data transmission channel is determined; The candidate anchor point set is matched with the current fluctuation trend to output the dynamic reference anchor point of the power network data on the data transmission channel.
[0009] In this embodiment, the sensitive response features of collecting sensitive power network data in real-time transmission status specifically include: Extract the number of SELECT operations and the length of abnormal DNS queries from the execution depth of traffic in real-time transmission status for sensitive data tables of the power network; Based on the number of SELECT operations and the length of abnormal DNS queries, a pre-set sensitive data regular expression table is synchronously matched to obtain the sensitive response characteristics of power network sensitive data.
[0010] In this embodiment, identifying the symmetric transmission deviation in the sensitive response features based on the dynamic reference anchor point specifically includes: Based on the dynamic reference anchor point, locate the historical reference window, extract the amplitude direction of the data transmission rate within the historical reference window, and simultaneously extract the rate change sequence in the sensitive response features; Based on the amplitude change direction and the rate change sequence, a candidate set of symmetric transmission deviations for sensitive data transmission in the power network is determined. The symmetric transmission deviation is determined based on the candidate set of symmetric transmission deviations and the number of hits in the transmission content fingerprint during power network data transmission.
[0011] In this embodiment, determining the candidate set of symmetric transmission deviations for sensitive data transmission in the power network based on the amplitude change direction and the rate change sequence specifically includes: The reverse deviation sequence segment during sensitive data transmission in the power network is determined based on the reverse rate change sequence that is opposite to the screening direction of the amplitude change. Extract the candidate set of symmetric transmission deviations for sensitive data transmission in the power network from the reverse deviation sequence segment.
[0012] In this embodiment, determining the flow permutation behavior of sensitive power network data transmitted outward through a covert channel based on the symmetric transmission deviation specifically includes: Based on the symmetrical transmission deviation, determine the unconfirmed permutation events when sensitive power network data is transmitted outward through a covert channel; Simultaneously extract the number of outbound transmission attempts outside the insecure domain within the time window corresponding to the event to be confirmed, and detect the characteristics of covert channel transmission; By matching the number of outbound transmission attempts in the non-secure domain with the transmission characteristics of the covert channel, the traffic displacement behavior when sensitive power network data is transmitted outward through the covert channel is obtained.
[0013] In this embodiment, marking nodes at risk of leakage during sensitive data transmission in the power network based on the traffic displacement behavior and outputting the leakage risk level specifically includes: Based on the confidence score of the traffic replacement behavior, locate the corresponding storage area address and extract the sensitive data service level from the storage area address; Based on the sensitive data service level and traffic permutation confidence level, identify the nodes at risk of leakage during sensitive data transmission in the power network; The nodes at risk of leakage are assessed and the leakage risk level is output.
[0014] Secondly, this application provides an AI-based power grid sensitive data leakage prediction device for executing an AI-based power grid sensitive data leakage prediction method, the prediction device comprising: The acquisition module is used to acquire abnormal transmission information and historical attack patterns during sensitive data transmission in the power network. The processing module is used to input the transmission anomaly information and the historical attack pattern into a static channel sensitivity model set on the data transmission channel, extract the local fluctuation index of the power network sensitive data within a fixed time window, and determine the dynamic reference anchor point of the power network data on the data transmission channel based on the local fluctuation index. The processing module is also used to collect sensitive response characteristics of power network sensitive data in real-time transmission state, identify symmetrical transmission deviation in the sensitive response characteristics based on the dynamic reference anchor point, and then determine the flow displacement behavior when power network sensitive data is transmitted outward through the covert channel based on the symmetrical transmission deviation. The execution module is used to mark nodes at risk of leakage during sensitive data transmission in the power network based on the traffic substitution behavior, and output the leakage risk level.
[0015] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects: The system acquires transmission anomaly information and historical attack patterns during the transmission of sensitive data from the power network; inputs the transmission anomaly information and historical attack patterns into a static channel sensitivity model set on the data transmission channel; extracts local fluctuation indicators of the sensitive power network data within a fixed time window; determines the dynamic reference anchor point of the power network data on the data transmission channel based on the local fluctuation indicators; collects sensitive response characteristics of the sensitive power network data under real-time transmission conditions; identifies symmetrical transmission deviations in the sensitive response characteristics based on the dynamic reference anchor point; and determines the flow displacement behavior when the sensitive power network data is transmitted outward through a covert channel based on the symmetrical transmission deviations; marks leakage risk nodes during the transmission of sensitive power network data based on the flow displacement behavior and outputs the leakage risk level.
[0016] Therefore, this application marks the leakage risk nodes during sensitive data transmission in the power network based on the described flow replacement behavior and outputs the leakage risk level. By determining the dynamic reference anchor point, a standardized time-series transmission benchmark adapted to the real-time operating conditions of the power grid can be obtained, thereby eliminating the operating condition adaptation defects caused by fixed static comparison thresholds. The transmission behavior benchmark calibration is completed by relying on window time-series fluctuation characteristics and historical attack patterns. It can accurately capture the reverse symmetric transmission deviation that cannot be identified by conventional flow detection, distinguish in advance between normal load fluctuations and abnormal changes caused by attackers tampering with flow, and provide a quantitative judgment basis for the pre-identification of data theft behavior in concealed channels. It narrows the risk screening scope from the source of transmission characteristics, supports the security protection system to shift from post-event alarm to real-time monitoring, and improves the pre-emptiveness of sensitive data leakage risk identification. By identifying traffic substitution behavior, malicious covert transmission events can be obtained after cross-verification of multi-dimensional features. This completes the joint evidence loop of symmetrical transmission deviation, non-secure outbound behavior, and covert channel message characteristics, eliminating misjudgment samples caused by simple rate fluctuations, accurately locking down attack behaviors that disguise data transmission through legitimate communication links, and effectively identifying low-speed tunneling theft behaviors that are not easily detected. Simultaneously, the storage area and service level information corresponding to abnormal transmission links are bound, providing reliable judgment material for tracing and marking leakage risk nodes and quantifying the risk hazard level, thereby strengthening the predictive ability of power network sensitive data security protection.
[0017] In summary, the technical solution adopted in this application can proactively identify nodes at risk of leakage and classify risk levels, thereby enhancing the initiative in protecting sensitive data in power networks. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this embodiment of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is an exemplary flowchart of a method for predicting the leakage of sensitive data in power networks based on an AI model, as provided in this application. Figure 2 This is a flowchart illustrating the process for identifying symmetrical transmission deviations provided in this application; Figure 3 This is a module structure diagram of a power network sensitive data leakage prediction device based on an AI model, provided in this application. Detailed Implementation
[0020] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0021] This application provides a method and apparatus for predicting leakage of sensitive power network data based on an AI model. The core of this method is to acquire transmission anomaly information and historical attack patterns during the transmission of sensitive power network data; input the transmission anomaly information and historical attack patterns into a static channel sensitivity model set on the data transmission channel; extract local fluctuation indicators of the sensitive power network data within a fixed time window; determine the dynamic reference anchor point of the power network data on the data transmission channel based on the local fluctuation indicators; collect sensitive response characteristics of the sensitive power network data under real-time transmission conditions; identify symmetrical transmission deviations in the sensitive response characteristics based on the dynamic reference anchor point; and determine the flow displacement behavior when the sensitive power network data is transmitted outward through a covert channel based on the symmetrical transmission deviations; mark leakage risk nodes during the transmission of sensitive power network data based on the flow displacement behavior; and output the leakage risk level.
[0022] Example 1: To better understand the above technical solution, the following will provide a detailed description of the technical solution in conjunction with the accompanying drawings and specific implementation methods. (Refer to...) Figure 1 As shown in the figure, this is an exemplary flowchart of a power network sensitive data leakage prediction method based on an AI model according to this embodiment of the application. The prediction method includes the following steps: In step S1, abnormal transmission information and historical attack patterns during sensitive data transmission in the power network are obtained.
[0023] In practice, the system first connects to power monitoring devices, network sensors, firewalls, and intrusion detection systems to continuously collect full operational data, including line power flow, bus voltage, network logs, access records, and firewall alarms. Data cleaning removes invalid, duplicate, and fault-related data, which is then compared with the system's preset normal transmission baseline to identify abnormalities in transmission volume, rate, and access frequency. This information is then aggregated to obtain transmission anomaly information. Subsequently, the system retrieves local historical security event archives and connects to industrial control threat databases such as MITRE ATT&CK and CAPEC to extract various intrusion and data theft behaviors targeting the power grid. The system analyzes the corresponding traffic characteristics, access patterns, abnormal addresses, and behavioral sequences of these attacks, uniformly classifies and organizes similar malicious behavior characteristics, and constructs a standardized historical attack pattern database. This completes the acquisition of transmission anomaly information and historical attack patterns.
[0024] It should be noted that, in this application, sensitive power network data refers to data related to power system operation, equipment control, and business management; abnormal transmission information refers to various abnormal state data generated when operating parameters deviate from the normal baseline during power network data transmission; and historical attack patterns refer to a complete set of malicious behavior characteristics formed by past data theft and intrusion attacks against the power network.
[0025] In step S2, the transmission anomaly information and the historical attack pattern are input into the static channel sensitivity model set on the data transmission channel to extract the local fluctuation index of the power network sensitive data within a fixed time window, and the dynamic reference anchor point of the power network data on the data transmission channel is determined based on the local fluctuation index.
[0026] In this embodiment, the following steps can be used to extract local fluctuation indicators of power network sensitive data within a fixed time window by inputting the transmission anomaly information and the historical attack patterns into a static channel sensitivity model set on the data transmission channel: The transmission anomaly information and the historical attack pattern are concatenated and aligned to obtain a multi-source joint input sequence; The joint input sequence is loaded into the past state encoder of the static channel-sensitive model, and the multivariate sequence within a fixed time window is scanned frame by frame. The hidden state output of the multivariate sequence within the fixed time window is determined, and the fluctuation of the hidden state output is aggregated to obtain the local fluctuation index of the power network sensitive data within the fixed time window.
[0027] In practical implementation, firstly, the data format, precision, and timing of transmitted anomaly information and historical attack patterns are standardized. The time nodes of all data are calibrated using the globally unified clock of the power network as a reference. Anomaly information is transmitted in chronological order, and historical attack pattern data within the same time dimension are sequentially concatenated. For missing data periods, historical averages under the same operating conditions are used for completion. For data with temporal misalignment, temporal offset correction is performed. The two types of heterogeneous data are merged into a complete data stream with continuous timing and unified dimensions, which is the multi-source joint input sequence. Then, the generated multi-source joint input sequence is completely imported into the past state encoder. This unit operates based on a long short-term memory network, uniformly dividing the continuous sequence according to a preset fixed time window. Each segment of data is defined as a frame. The encoder reads each frame of data sequentially, traversing and parsing the multivariate sequence containing transmission parameters and attack features within each frame to obtain the multivariate sequence. Finally, relying on the weighting rules of the long short-term memory network, the past state encoder performs feature transformation and state transfer layer by layer on each frame of multivariate sequence, calculating the hidden state output corresponding to the fixed time window. A weighted summation operation is used to aggregate fluctuations. The weighting coefficients are assigned in combination with the weighting rules of the physical parameters set in the disclosure document. All hidden state values within the window are integrated, and the aggregated results are quantified to generate a local fluctuation index that can intuitively represent short-term changes in the data.
[0028] It should be noted that in this application, the data transmission channel refers to the network link and transmission channel in the power network that carries sensitive data, operational data, and log data; the static channel sensitivity model refers to the data transmission channel deployed in the power network, with the time-series fusion Transformer as the core architecture; the fixed time window refers to a uniform data statistical period defined by humans; splicing and alignment refers to unifying the time base, data dimension, and arrangement rules for multiple types of data with inconsistent sources, formats, and time series; the multi-source joint input sequence refers to the regularization of data from different sources into a continuous data sequence with a uniform format and corresponding time series; the past state encoder refers to the feature extraction unit built into the static channel sensitivity model; the multivariate sequence refers to the combined time series data containing multiple transmission parameters such as transmission volume, transmission rate, and access frequency; the hidden state output refers to the intermediate calculation result representing the deep operational characteristics of the data generated after the past state encoder completes feature parsing of the input sequence; fluctuation aggregation refers to the quantitative calculation process of integrating multiple hidden state data within a single time series segment according to a unified calculation rule and summarizing them to form the data fluctuation situation; and the local fluctuation index refers to the quantitative result reflecting the short-term change amplitude and change law of various transmission parameters of sensitive data within a fixed time window.
[0029] In addition, it should be noted that the static channel sensitivity model in this application is set up as follows: The static channel sensitivity model is built by relying on the time-series fusion Transformer to complete the overall architecture. First, according to the power network business partitioning and network segment division results, independent model instances are deployed in each independent transmission channel to realize single-channel dedicated monitoring and analysis. The static channel sensitivity model embeds a past state encoder composed of a long short-term memory network. At the same time, a static metadata encoder is configured to access background information such as equipment model and business attributes. A fixed time window is set as a data interception unit in combination with the power grid operation characteristics. The value range of core parameters such as volume weight and rate weight is preset according to the physical parameter calculation rules. It is equipped with supporting functional modules such as data cleaning, feature encoding, and fluctuation calculation. After completing the basic architecture and parameter configuration, offline training is carried out using the power network historical security event dataset. The network weight and attention mechanism parameters are repeatedly iterated and optimized. After the training reaches the target, the model structure and operation logic are solidified to form a static channel sensitivity model that can run stably and whose parameters no longer change dynamically.
[0030] In addition, in this embodiment, the concatenation and alignment of the transmission anomaly information with the historical attack pattern to obtain the multi-source joint input sequence can be achieved by the following steps: Perform source cleaning on the transmission anomaly information and the historical attack patterns respectively to obtain aligned static covariates; By synchronously concatenating the window start timescale and the aligned static covariates, a multi-source joint input sequence is obtained.
[0031] In practice, the process begins with the following steps: First, data is cleaned according to the general processing specifications for power network data. This involves removing null values, duplicate entries, and erroneous data caused by equipment failures from both types of data. The names, units of measurement, and data storage formats of data fields related to transmission anomalies and historical attack patterns are standardized. Then, the timestamps of each data entry are calibrated using the global standard clock of the power system. For short-term missing data, historical normal data from the same network segment under the same operating conditions is retrieved to complete the data. For data with time-series offsets, the time coordinates are corrected item by item. After all standardization processing is complete, the dimensions, time series, and formats of the two types of data are perfectly matched, forming aligned static covariates. Next, a fixed data statistics window is pre-defined, and a corresponding window start timescale is generated as the global time reference. Starting from the start timescale of a single window, static covariates related to transmission anomalies and historical attack patterns are sequentially extracted within the corresponding time range. The two types of data under the same timescale are then sequentially connected and arranged according to chronological order, maintaining the original arrangement logic of the variables within the data. Data extraction and connection operations are completed window by window, and all window data are continuously spliced together to generate a time-coherent, dimensionally complete multi-source joint input sequence.
[0032] It should be noted that in this application, "same-source cleaning" refers to the process of standardizing transmission anomaly information and historical attack patterns generated under the same power network system according to unified data specifications; "aligned static covariates" refers to two sets of basic data with unified format, unified time series benchmark, and mutually matched dimensions; "window start time index" refers to the time marker that marks the initial time of each set of data statistical windows; "synchronous splicing" refers to the data integration method that combines compliant data from different sources into an overall sequence according to the time series, using the window start time index as a unified time benchmark; and "multi-source joint input sequence" refers to the standard data stream formed after integrating transmission anomaly information and historical attack patterns.
[0033] In this embodiment, determining the dynamic reference anchor point of power network data on the data transmission channel based on the local fluctuation index can be achieved through the following steps: The local fluctuation index is input into the interpretability attention module of the TFT model to calculate the similarity score between the current window sequence and each segment in the historical pattern library. Based on the similarity score and historical transmission pattern fragments, a set of candidate anchor points for power network data on the data transmission channel is determined; The candidate anchor point set is matched with the current fluctuation trend to output the dynamic reference anchor point of the power network data on the data transmission channel.
[0034] In specific implementation, firstly, the extracted local fluctuation indicators are used to form a complete window sequence, which is then fed into the interpretable attention module of the time-series fusion Transformer model. The interpretable attention module first performs feature vectorization transformation on the current window sequence and each data segment in the historical pattern library, unifying the feature dimensions and expression forms. Relying on the attention weight allocation mechanism, it performs correlation calculations on the two sets of vectors one by one, and completes the numerical solution by referring to the vector similarity calculation logic commonly used in the field of power network security. It then traverses all segments in the historical pattern library one by one to obtain the corresponding similarity score. Then, a similarity judgment threshold is set in advance based on the long-term operation experiment results of the power grid. This similarity judgment threshold is determined by repeatedly verifying samples from normal transmission scenarios and abnormal transmission scenarios. All similarity scores are compared with the preset threshold one by one, and historical transmission pattern segments with scores that reach or exceed the threshold are selected. The selected historical transmission pattern segments are sorted in descending order of similarity score, and redundant segments with duplicate content and conflicting operating conditions are removed. The remaining valid historical transmission pattern segments are integrated and classified to form a complete candidate anchor set. Finally, by integrating all local fluctuation indicators, the continuous fluctuation trend of the current data transmission is identified, and the direction, magnitude, and duration of parameter changes are clarified. Each historical pattern segment in the candidate anchor point set is retrieved in turn, and the degree of fit between the fluctuation pattern of the segment itself and the current fluctuation trend is compared. Historical pattern segments that are highly consistent with the overall change rhythm and parameter characteristics and the current operating conditions are selected first. The standard data characteristics corresponding to the historical pattern segment are set as a unified benchmark, and the dynamic reference anchor point of the power network data on the data transmission channel is output.
[0035] It should be noted that, in this application, the TFT model refers to the temporal fusion Transformer model; the interpretable attention module refers to the built-in functional unit of the temporal fusion Transformer model, used to quantify the correlation between the current data sequence and historical data segments; the current window sequence refers to the set of local fluctuation indicators obtained by truncating a fixed time window; the historical pattern library refers to the set of complete data segments corresponding to various normal and abnormal transmission states of the power network; the similarity score refers to the numerical value of the matching degree between the current window data sequence and the historical data segments; the historical transmission pattern segment refers to a single time-series data sample separated from the historical pattern library, recording the data transmission rules under different operating conditions and different safety states; the candidate anchor set refers to a set of multiple sets of alternative benchmark data selected based on the similarity score; the current fluctuation trend refers to the continuous change pattern formed by the combination of local fluctuation indicators; and the dynamic reference anchor refers to a standardized data benchmark adapted to real-time transmission conditions.
[0036] In step S3, sensitive response characteristics of power network sensitive data under real-time transmission status are collected. Based on the dynamic reference anchor point, the symmetrical transmission deviation in the sensitive response characteristics is identified, and then the flow displacement behavior of power network sensitive data when it is transmitted outward through the covert channel is determined by the symmetrical transmission deviation.
[0037] In this embodiment, the sensitive response characteristics of power network sensitive data under real-time transmission status can be acquired through the following steps: Extract the number of SELECT operations and the length of abnormal DNS queries from the execution depth of traffic in real-time transmission status for sensitive data tables of the power network; Based on the number of SELECT operations and the length of abnormal DNS queries, a pre-set sensitive data regular expression table is synchronously matched to obtain the sensitive response characteristics of power network sensitive data.
[0038] In practice, the process begins by using deep packet inspection (DPI) technology to analyze real-time network traffic packet by packet. This involves dissecting the database interaction fields and domain name resolution fields within each packet, continuously monitoring all database access behaviors pointing to sensitive data tables, recording the triggering behavior of query commands, and accumulating the number of SELECT operations at fixed time intervals. Simultaneously, the data payload of each DNS message is analyzed, compared to the normal communication message length range of the power grid, and messages exceeding the normal range are filtered out and their corresponding data lengths are calculated. This completes the extraction of the number of SELECT operations and the length of abnormal DNS queries. Then, using the number of SELECT operations and the length of abnormal DNS queries as matching inputs, the system's built-in sensitive data regular expression table is invoked. The real-time traffic payload is traversed according to the preset character matching rules in the sensitive data regular expression table to identify sensitive content such as power grid topology and equipment parameters contained in the messages. Combining the query operation frequency, DNS message length, and regular expression matching results, the three types of information are correlated and integrated. The integrated information is then standardized according to unified feature encoding rules to form a sensitive response feature that comprehensively reflects the risk of sensitive data access and leakage.
[0039] It should be noted that, in this application, the execution depth of traffic in real-time transmission refers to the underlying data content obtained after full-dimensional parsing of real-time network data packets and communication messages of the power network; the power network sensitive data table refers to a data form in the power network database that specifically stores power grid operating parameters, equipment ledgers, network topology, and user permissions; the number of SELECT operations refers to the cumulative frequency of executing data query commands against the power network sensitive data table; the abnormal DNS query length refers to the length of domain name resolution message data that deviates from normal communication norms; the sensitive data regular expression table refers to a pre-compiled and stored set of rules that includes character matching rules corresponding to various sensitive data in the power industry; and the sensitive response features refer to a set of features formed by integrating data access behavior, abnormal communication behavior, and sensitive content matching results.
[0040] Preferably, in this embodiment, the symmetric transmission deviation in the sensitive response features is identified based on the dynamic reference anchor point, with reference to... Figure 2 As shown in the figure, this is a schematic flowchart of identifying symmetrical transmission deviation in some embodiments of this application. In this embodiment, identifying symmetrical transmission deviation can be achieved by the following steps: In step S31, the historical reference window is located based on the dynamic reference anchor point, the amplitude of the data transmission rate within the historical reference window is extracted, and the rate change sequence in the sensitive response feature is extracted simultaneously. In step S32, a candidate set of symmetric transmission deviations for sensitive data transmission in the power network is determined based on the amplitude change direction and the rate change sequence. In step S33, the symmetric transmission deviation is determined based on the candidate set of symmetric transmission deviations and the number of hits of the transmission content fingerprint during power network data transmission.
[0041] In practice, firstly, relying on the time and operating condition information bound to the dynamic reference anchor point, a historical reference window matching the range is locked in the historical pattern library. All transmission rate data within the historical reference window are read line by line, and the increase and decrease trends of the values are sorted out according to time sequence to clarify the direction of amplitude change throughout the process. At the same time, the collected sensitive response features are traversed, and real-time rate values are extracted according to a uniform time interval and arranged in chronological order to form a complete rate change sequence. Then, the amplitude change direction corresponding to the historical reference window is compared with the real-time rate change sequence item by item. First, it is determined whether the overall increase and decrease directions of the two are completely opposite. Then, the rate change amplitude at the corresponding time node is calculated segment by segment. Data groups with opposite change directions and amplitude differences within a preset reasonable range are selected. These data groups are uniformly collected, and invalid data combinations with chaotic trends and excessive amplitude differences are eliminated. The remaining content that meets the preliminary judgment conditions is integrated into a candidate set of symmetrical transmission deviation. Finally, real-time traffic data corresponding to each group of data in the candidate set of symmetrical transmission deviation is retrieved, and the preset sensitive content fingerprint rules are called to match the data stream one by one. The number of transmission content fingerprint hits in a single sample is counted. Combined with the long-term operation test of the power network, a threshold for the number of hits is set. When the number of fingerprint hits of a candidate sample reaches the threshold, it proves that the data stream contains sensitive content, and the data group can be officially determined to have symmetrical transmission deviation. Samples that do not reach the threshold are judged as normal fluctuations and are removed.
[0042] It should be noted that in this application, the historical reference window refers to the standard time interval defined by the dynamic reference anchor point; the data transmission rate refers to the volume of data packets transmitted per unit time in the power network; the amplitude change direction characterizes the trend and direction of increase or decrease of the data transmission rate within the corresponding time window; the rate change sequence refers to the set of real-time transmission rate values arranged in chronological order; the symmetric transmission deviation candidate set refers to the data combinations with reverse change characteristics initially screened, which is the set of candidate samples for the final determination of symmetric transmission deviation; the number of transmission content fingerprint hits refers to the statistical number of entries in the real-time data stream that match the preset sensitive content features; and the symmetric transmission deviation refers to the abnormal transmission state in which the real-time rate change trend is opposite to the historical benchmark trend and the change amplitude is similar.
[0043] Furthermore, in this embodiment, determining the candidate set of symmetric transmission deviations for sensitive data transmission in the power network based on the amplitude change direction and the rate change sequence can be achieved using the following steps: The reverse deviation sequence segment during sensitive data transmission in the power network is determined based on the reverse rate change sequence that is opposite to the screening direction of the amplitude change. Extract the candidate set of symmetric transmission deviations for sensitive data transmission in the power network from the reverse deviation sequence segment.
[0044] In practice, firstly, the time granularity of the historical reference window amplitude change direction and the real-time rate change sequence is unified. The change direction of the two is compared node by node, and the increasing or decreasing trend of each real-time sequence segment is determined. Continuous data regions that show the opposite trend to the historical amplitude change direction are extracted separately. A continuous effective duration standard is set based on the normal operation data of the power grid. Only the reverse data segments that meet the duration requirement are retained, and scattered data with instantaneous changes and no analytical value are eliminated. The resulting reverse deviation sequence segments are then obtained. Next, the change amplitude of all reverse deviation sequence segments is verified. The change difference between the real-time rate and the corresponding historical rate is calculated point by point. Based on the measured results of multiple scenarios in the power network, the allowable amplitude range is defined, and the sequence segments whose difference falls within the range are retained. At the same time, the continuity and stability of the data within the sequence are verified. Segments with drastic data jumps and those that do not conform to the characteristics of concealed transmission are eliminated. All verified sequence segments are integrated and classified, and the data format and time sequence arrangement are standardized to form a candidate set of symmetrical transmission deviations.
[0045] It should be noted that, in this application, the reverse rate change sequence refers to a real-time data transmission rate sequence whose overall increase or decrease trend is completely opposite to the amplitude change direction corresponding to the historical reference window under the same statistical granularity at the same time; the reverse deviation sequence segment refers to a continuous data segment in the real-time rate change sequence whose overall change direction is completely opposite to the amplitude change direction of the historical reference window.
[0046] In this embodiment, determining the flow permutation behavior of sensitive power network data transmitted outward through a covert channel based on the symmetrical transmission deviation can be achieved through the following steps: Based on the symmetrical transmission deviation, determine the unconfirmed permutation events when sensitive power network data is transmitted outward through a covert channel; Simultaneously extract the number of outbound transmission attempts outside the insecure domain within the time window corresponding to the event to be confirmed, and detect the characteristics of covert channel transmission; By matching the number of outbound transmission attempts in the non-secure domain with the transmission characteristics of the covert channel, the traffic displacement behavior when sensitive power network data is transmitted outward through the covert channel is obtained.
[0047] In practice, firstly, based on the determined symmetrical transmission deviation, the complete time interval, network node, and data flow link corresponding to the deviation are identified. Combined with power network business partitioning rules, the data type carried by the link is verified, confirming that the link transmission object contains sensitive power grid data. Network behaviors involving symmetrical transmission deviation and sensitive data transmission in this segment are separately marked and archived according to the event occurrence time, network address, and abnormal characteristics, forming independent pending replacement events, thus completing the initial identification of suspected risk events. Then, using the time window corresponding to the pending replacement event as the intercept range, the access logs and traffic logs of the boundary security devices are retrieved, and cross-regional transmission behaviors are identified one by one. The frequency of data flow to non-secure areas is statistically analyzed to obtain the number of outbound attempts from non-secure domains. Simultaneously, deep traffic analysis is enabled to analyze message encapsulation forms, communication intervals, and data payload patterns, comparing them item by item against the system's pre-stored hidden channel feature library to fully collect the various hidden channel transmission characteristics of the current data flow. Finally, based on the measured data accumulated from power grid safety operation and maintenance, a threshold for the number of outbound transmission attempts outside the security domain is set. First, the statistical values are compared with the threshold to confirm whether there are high-frequency illegal outbound transmission behaviors. Then, the detected transmission characteristics are matched with the covert channel standard feature library in all dimensions to determine the degree of overlap. When the number of attempts reaches the threshold and the feature matching is successful, the current event to be confirmed is determined to be a traffic replacement behavior. If neither of the two conditions is met at the same time, it is determined to be a normal traffic fluctuation and the risk is eliminated.
[0048] It should be noted that, in this application, a covert channel refers to an abnormal data transmission channel established by an attacker using conventional communication links and legitimate protocols of the power network; a pending confirmation substitution event refers to a transmission event in which abnormal traffic fluctuations are initially determined based on symmetrical transmission deviations; the number of attempts to transmit data outside the non-secure domain refers to the cumulative number of times sensitive data is sent to non-secure areas designated by the power network; covert channel transmission characteristics refer to the unique traffic characteristics formed by an attacker using conventional communication channels to disguise data transmission; and traffic substitution behavior refers to the malicious network behavior of an attacker tampering with the normal traffic of the power grid and stealing sensitive data from outside the network by using a covert channel.
[0049] In step S4, nodes at risk of leakage during sensitive data transmission in the power network are marked based on the flow replacement behavior, and the leakage risk level is output.
[0050] In this embodiment, marking nodes at risk of leakage during sensitive data transmission in the power network based on the traffic displacement behavior and outputting the leakage risk level can be achieved through the following steps: Based on the confidence score of the traffic replacement behavior, locate the corresponding storage area address and extract the sensitive data service level from the storage area address; Based on the sensitive data service level and traffic permutation confidence level, identify the nodes at risk of leakage during sensitive data transmission in the power network; The nodes at risk of leakage are assessed and the leakage risk level is output.
[0051] In practice, the process begins by retrieving the confidence score corresponding to the identified traffic substitution behavior. Combined with the network tracing logs associated with the confidence score, information such as the IP addresses and logical partition numbers traversed by the data flow is analyzed sequentially. Tracing back along the data transmission link, the storage area address generating the abnormal behavior is precisely located. The power network asset ledger and business classification table are then retrieved. Based on the located storage area address, the business type and data attributes carried by the located storage area are queried, and the pre-defined sensitive data business level is read, extracting the complete storage area address and sensitive data business level. Next, the sensitive data business level is divided into different tiers. Simultaneously, combined with long-term power network security operation and maintenance data, an effective judgment threshold for the confidence score is set. The current confidence score is compared with the preset threshold to confirm that the traffic substitution behavior is a genuine abnormal behavior. Finally, combined with the sensitive data business level of the corresponding storage area, the storage areas exhibiting compliant abnormal characteristics and associated transmission link nodes are uniformly marked. All marked objects are integrated to obtain all leakage risk nodes. Finally, for each identified leakage risk node, a multi-dimensional and hierarchical verification process was conducted. This included reviewing the duration of traffic replacement, the frequency of out-of-security domain transmissions, and the number of sensitive content matches corresponding to the leakage risk node. A comprehensive calculation was performed by combining the sensitive data service level and the confidence level of traffic replacement. Based on the power grid safety specifications, a multi-level risk classification standard was set. The comprehensive calculation results were then compared with the classification standard to complete the hierarchical classification. The information of each node and the corresponding hierarchical results were organized in a unified format to output complete leakage risk level information.
[0052] It should be noted that the confidence score is a numerical value that quantifies the credibility of traffic substitution behavior; the storage area address refers to the network node, logical partition, and corresponding network identifier in the power network that stores sensitive data; the sensitive data service level refers to the level standard divided according to the importance of the business and the level of data confidentiality; the traffic substitution confidence score is a quantitative determination of the credibility of the current network behavior as a traffic substitution attack; the leakage risk node refers to the network storage node and transmission node that have traffic substitution behavior and sensitive data that has the potential for leakage; the hierarchical verification refers to the process of conducting layered and item-by-item review and verification of the marked leakage risk nodes according to the established verification dimensions and judgment standards; the leakage risk level refers to the level of risk severity defined by integrating the level of data confidentiality, attack credibility, and abnormal behavior characteristics.
[0053] Therefore, this application marks the leakage risk nodes during sensitive data transmission in the power network based on the described flow replacement behavior and outputs the leakage risk level. By determining the dynamic reference anchor point, a standardized time-series transmission benchmark adapted to the real-time operating conditions of the power grid can be obtained, thereby eliminating the operating condition adaptation defects caused by fixed static comparison thresholds. The transmission behavior benchmark calibration is completed by relying on window time-series fluctuation characteristics and historical attack patterns. It can accurately capture the reverse symmetric transmission deviation that cannot be identified by conventional flow detection, distinguish in advance between normal load fluctuations and abnormal changes caused by attackers tampering with flow, and provide a quantitative judgment basis for the pre-identification of data theft behavior in concealed channels. It narrows the risk screening scope from the source of transmission characteristics, supports the security protection system to shift from post-event alarm to real-time monitoring, and improves the pre-emptiveness of sensitive data leakage risk identification. By identifying traffic substitution behavior, malicious covert transmission events can be obtained after cross-verification of multi-dimensional features. This completes the joint evidence loop of symmetrical transmission deviation, non-secure outbound behavior, and covert channel message characteristics, eliminating misjudgment samples caused by simple rate fluctuations, accurately locking down attack behaviors that disguise data transmission through legitimate communication links, and effectively identifying low-speed tunneling theft behaviors that are not easily detected. Simultaneously, the storage area and service level information corresponding to abnormal transmission links are bound, providing reliable judgment material for tracing and marking leakage risk nodes and quantifying the risk hazard level, thereby strengthening the predictive ability of power network sensitive data security protection.
[0054] In summary, the technical solution adopted in this application can proactively identify nodes at risk of leakage and classify risk levels, thereby enhancing the initiative in protecting sensitive data in power networks.
[0055] Example 2: This application provides a power grid sensitive data leakage prediction device based on an AI model, referencing... Figure 3 As shown in the figure, this is a module structure diagram of a power network sensitive data leakage prediction device based on an AI model according to this embodiment of the present application. The prediction device includes: The acquisition module 100 is used to acquire abnormal transmission information and historical attack patterns during sensitive data transmission in the power network. Processing module 200 is used to input the transmission anomaly information and the historical attack pattern into a static channel sensitivity model set on the data transmission channel, extract the local fluctuation index of power network sensitive data within a fixed time window, and determine the dynamic reference anchor point of power network data on the data transmission channel based on the local fluctuation index. The processing module 200 is also used to collect sensitive response characteristics of power network sensitive data in real-time transmission state, identify symmetrical transmission deviation in the sensitive response characteristics based on the dynamic reference anchor point, and then determine the flow displacement behavior when power network sensitive data is transmitted outward through the covert channel based on the symmetrical transmission deviation. The execution module 300 is used to mark nodes at risk of leakage during sensitive data transmission in the power network based on the traffic substitution behavior, and output the leakage risk level.
[0056] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0057] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compactdisc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.
[0058] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
Claims
1. A method for predicting the leakage of sensitive data in power networks based on an AI model, characterized in that, The prediction method includes the following steps: Acquire abnormal transmission information and historical attack patterns during sensitive data transmission in power grids; The abnormal transmission information and the historical attack patterns are input into the static channel sensitivity model set on the data transmission channel to extract the local fluctuation index of the power network sensitive data within a fixed time window, and the dynamic reference anchor point of the power network data on the data transmission channel is determined based on the local fluctuation index. The system collects sensitive response characteristics of sensitive power network data under real-time transmission status, identifies symmetrical transmission deviations in the sensitive response characteristics based on the dynamic reference anchor point, and then determines the flow displacement behavior of sensitive power network data when it is transmitted outward through a covert channel based on the symmetrical transmission deviations. Based on the described flow replacement behavior, nodes at risk of leakage during sensitive data transmission in the power network are marked, and the leakage risk level is output.
2. The method for predicting leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, The process of inputting the transmission anomaly information and the historical attack patterns into a static channel sensitivity model set on the data transmission channel to extract local fluctuation indicators of power network sensitive data within a fixed time window specifically includes: The transmission anomaly information and the historical attack pattern are concatenated and aligned to obtain a multi-source joint input sequence; The joint input sequence is loaded into the past state encoder of the static channel-sensitive model, and the multivariate sequence within a fixed time window is scanned frame by frame. The hidden state output of the multivariate sequence within the fixed time window is determined, and the fluctuation of the hidden state output is aggregated to obtain the local fluctuation index of the power network sensitive data within the fixed time window.
3. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 2, characterized in that, The process of concatenating and aligning the transmission anomaly information with the historical attack patterns to obtain the multi-source joint input sequence specifically includes: Perform source cleaning on the transmission anomaly information and the historical attack patterns respectively to obtain aligned static covariates; By synchronously concatenating the window start timescale and the aligned static covariates, a multi-source joint input sequence is obtained.
4. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, Determining the dynamic reference anchor point of power network data on the data transmission channel based on the local fluctuation index specifically includes: The local fluctuation index is input into the interpretability attention module of the TFT model to calculate the similarity score between the current window sequence and each segment in the historical pattern library. Based on the similarity score and historical transmission pattern fragments, a set of candidate anchor points for power network data on the data transmission channel is determined; The candidate anchor point set is matched with the current fluctuation trend to output the dynamic reference anchor point of the power network data on the data transmission channel.
5. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, The specific sensitive response characteristics of power network sensitive data collected in real-time transmission include: Extract the number of SELECT operations and the length of abnormal DNS queries from the execution depth of traffic in real-time transmission status for sensitive data tables of the power network; Based on the number of SELECT operations and the length of abnormal DNS queries, a pre-set sensitive data regular expression table is synchronously matched to obtain the sensitive response characteristics of power network sensitive data.
6. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, Identifying the symmetric transmission deviation in the sensitive response features based on the dynamic reference anchor point specifically includes: Based on the dynamic reference anchor point, locate the historical reference window, extract the amplitude direction of the data transmission rate within the historical reference window, and simultaneously extract the rate change sequence in the sensitive response features; Based on the amplitude change direction and the rate change sequence, a candidate set of symmetric transmission deviations for sensitive data transmission in the power network is determined. The symmetric transmission deviation is determined based on the candidate set of symmetric transmission deviations and the number of hits in the transmission content fingerprint during power network data transmission.
7. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 6, characterized in that, The candidate set for determining symmetric transmission deviations during sensitive data transmission in power networks based on the amplitude shift direction and the rate change sequence specifically includes: The reverse deviation sequence segment during sensitive data transmission in the power network is determined based on the reverse rate change sequence that is opposite to the screening direction of the amplitude change. Extract the candidate set of symmetric transmission deviations for sensitive data transmission in the power network from the reverse deviation sequence segment.
8. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, The flow permutation behavior of sensitive power network data transmitted outward through covert channels, determined by the aforementioned symmetrical transmission deviation, specifically includes: Based on the symmetrical transmission deviation, determine the unconfirmed permutation events when sensitive power network data is transmitted outward through a covert channel; Simultaneously extract the number of outbound transmission attempts outside the insecure domain within the time window corresponding to the event to be confirmed, and detect the characteristics of covert channel transmission; By matching the number of outbound transmission attempts in the non-secure domain with the transmission characteristics of the covert channel, the traffic displacement behavior when sensitive power network data is transmitted outward through the covert channel is obtained.
9. The method for predicting the leakage of sensitive power network data based on an AI model as described in claim 1, characterized in that, Based on the aforementioned flow permutation behavior, nodes at risk of leakage during sensitive data transmission in the power network are identified, and the leakage risk level is output, specifically including: Based on the confidence score of the traffic replacement behavior, locate the corresponding storage area address and extract the sensitive data service level from the storage area address; Based on the sensitive data service level and traffic permutation confidence level, identify the nodes at risk of leakage during sensitive data transmission in the power network; The nodes at risk of leakage are assessed and the leakage risk level is output.
10. An AI-based power grid sensitive data leakage prediction device, used to execute the AI-based power grid sensitive data leakage prediction method as described in any one of claims 1 to 9, characterized in that, The prediction device includes: The acquisition module is used to acquire abnormal transmission information and historical attack patterns during sensitive data transmission in the power network. The processing module is used to input the transmission anomaly information and the historical attack pattern into a static channel sensitivity model set on the data transmission channel, extract the local fluctuation index of the power network sensitive data within a fixed time window, and determine the dynamic reference anchor point of the power network data on the data transmission channel based on the local fluctuation index. The processing module is also used to collect sensitive response characteristics of power network sensitive data in real-time transmission state, identify symmetrical transmission deviation in the sensitive response characteristics based on the dynamic reference anchor point, and then determine the flow displacement behavior when power network sensitive data is transmitted outward through the covert channel based on the symmetrical transmission deviation. The execution module is used to mark nodes at risk of leakage during sensitive data transmission in the power network based on the traffic substitution behavior, and output the leakage risk level.