A substation resilience improvement system and method capable of empowering attack and defense confrontation of a large model
Patent Information
- Application Number
- CN202610897904.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-22
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]但当下电力网络攻击逐步呈现未知性、跨域性、时空耦合性特征,传统静态被动防御存在明显短板:一是防御存在滞后性,无法提前推演未知攻击的动态时空传播路径,仅能事后处置已知攻击;二是风险评估与现场运行脱节,离线仿真评估结果无法适配电网实时工况,不能快速输出可直接执行的最优防御与恢复策略,运维人员难以评估攻击全局影响;三是未实现信息域攻击时序渗透与物理域故障空间传播的耦合建模,无法应对跨信息、物理双域的协同网络攻击,防御方案存在片面性
本发明通过明确定义信息空间事件到物理系统状态变化的映射函数,实现网络攻击步骤与电力设备故障后果的精准关联与量化传导;大模型基于持续接收的实时运行数据、威胁情报等多源信息,动态更新虚拟映像拓扑、状态与参数,解析各类工况、事件在信息域物理域中的不同表征与连锁影响,确保虚拟映像与真实系统时空演化一致性,为后续精准推演提供可靠模型基础。
Smart Images

Figure CN122845183A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of power network security protection and cyber-physical system defense technology for smart substations. Specifically, it relates to a substation resilience enhancement system and method that enables large-scale model-based offensive and defensive countermeasures. Background Technology
[0002] With the continuous increase in electricity demand, the requirements for power grid stability are constantly rising. As a core hub of the power system, the safe operation of substations directly affects the reliability of the entire power grid. Currently, the digital transformation of the power system is progressing steadily, with primary power equipment and secondary information and communication systems deeply integrated to form a power information-physical coupling system. Power grid operation is highly dependent on information and communication networks. Once a substation's secondary system suffers a cyberattack, it will directly lose its power grid monitoring, control, and dispatch capabilities, easily triggering power grid failures or even large-scale power outages. Therefore, the cybersecurity risks of power industrial control systems are becoming increasingly prominent.
[0003] Currently, substation security protection is divided into two categories: physical electrical protection and network security protection. The existing solution closest to this invention is the traditional boundary network security protection system. Electrical protection relies on relay protection devices to resist physical electrical faults such as overvoltage and overcurrent; network security protection is based on firewalls and intrusion detection systems, relying on static security rules to passively intercept known network attacks matched by a signature database, and can deal with conventional single network threats.
[0004] However, current power grid attacks are increasingly exhibiting characteristics of being unknown, cross-domain, and spatiotemporally coupled. Traditional static passive defense has significant shortcomings: First, defense is lagging behind, unable to predict the dynamic spatiotemporal propagation path of unknown attacks in advance, and can only deal with known attacks after the fact; second, risk assessment is disconnected from on-site operation, offline simulation assessment results cannot be adapted to the real-time operating conditions of the power grid, and cannot quickly output the optimal defense and recovery strategies that can be directly executed, making it difficult for operation and maintenance personnel to assess the overall impact of attacks; third, it has not achieved coupled modeling of the temporal penetration of information domain attacks and the spatial propagation of physical domain faults, and cannot cope with collaborative network attacks across both information and physical domains, resulting in a one-sided defense solution.
[0005] In summary, existing substation network defenses remain static, passive, and offline, failing to anticipate unknown network attack paths, predict physical hazards, or make dynamic defense decisions, resulting in weak grid resilience against network attacks. To address these industry pain points, a closed-loop proactive defense solution is urgently needed to enhance the proactive protection capabilities and operational resilience of smart substations against complex network attacks. Summary of the Invention
[0006] To address the aforementioned issues, the present invention aims to provide a substation resilience enhancement system and method empowered by a large-scale model for offensive and defensive countermeasures. This system aims to revolutionize existing defense models by utilizing the spatiotemporal coupling characteristics of attacks to achieve a closed loop of security assessment and defense decision-making, thereby enhancing the resilience of smart substations in the face of unknown and complex network attacks.
[0007] To achieve the above technical objectives, this application provides a substation resilience enhancement system with large-scale model-enabled offensive and defensive capabilities, comprising: The modeling module is used to construct a cyber-physical coupling model of a substation that incorporates domain knowledge, in order to characterize the substation's network topology, equipment operation logic, and cross-domain impact relationships. The inference module is used to carry out attack planning based on the substation cyber-physical coupling model and a large language model enhanced with domain knowledge, and to obtain the time-series attack path. At the same time, it quantifies the physical consequences of the attack event and the system-level risk indicators. The decision-making module is used to construct a set of candidate defense strategies covering prevention, detection, response, and recovery based on the quantitative results and the identified attack path weaknesses. The execution module is used to construct a target optimization model based on the set of candidate defense strategies, output the current optimal targeted active defense strategy group, convert the strategy into executable instructions, and optimize the strategy based on the execution effect of the executable instructions.
[0008] Preferably, the modeling module is used to construct a substation information-physical coupling model based on the physical model, information model, cross-domain coupling interface model, and data and model access layer.
[0009] Preferably, the physical model includes a physical network topology, a steady-state model, a physical device model, and a protection model; The physical network topology is a directed graph. ,in: For physical nodes, It is a branch road; The steady-state model is: , In the formula: Net power vector injected into the node; Here is the nodal admittance matrix; The node voltage phase angle vector; branch road The trend; For branch circuit reactance; The physical device model is represented as follows: , In the formula: , , These are the generator's active power output, lower limit of active power output, and upper limit of active power output, respectively. For load shedding power, This represents the total load power.
[0010] Preferably, the information model includes an information network topology, an attack behavior database, and an attacker target model, wherein, The topology of an information network is represented as a directed graph. ,in: For information nodes, For logical communication links; The attack behavior library is used to build tuples (A ID , N, C pre E post , P s , T c ), where A ID N is the unique identifier for the attack step, and C is the information space entity targeted by this attack step. pre The state conditions that must be met before this attack step can be successfully executed; E post The changes to the system state that occur after successfully executing this attack step; P s The success rate of an attacker attempting to perform this action assuming all preconditions are met; T c The estimated time required for the attacker to perform the above steps and achieve the desired effect; Attacker target model is used to define the attacker's initial set of penetration points, privilege escalation path, and ultimate operational target on physical devices.
[0011] Preferably, the cross-domain coupling interface model is used to define a deterministic or probabilistic mapping function from information space events to physical space state changes, expressed as follows: In the formula: For coupling mapping functions; Let be a set of events in the information space, where any event This corresponds to a malicious action successfully completed by the attacker in the information space. Let be the set of state changes of a physical system, where any state This describes changes in the status or operating parameters of equipment in a primary power system. As a mapping relationship, when a specific information space event occurs... When it occurs, through the function Deterministically or probabilistically induce one or more changes in physical state. .
[0012] Preferably, a data and model access layer is built, including external threat intelligence sources and endogenous security data sources.
[0013] Preferably, the inference module is used to assemble a context structure based on multi-source heterogeneous information. The multi-source heterogeneous information is organized according to a logic that is easy for the large model to understand, and a multi-stage prompt context is constructed. The process involves intelligence analysis and attack surface mapping, initial access vector selection, lateral movement and privilege escalation path planning, and target achievement action design. After the model inference is executed, the path is filtered through automated rules and quantitative scoring to obtain the temporal attack path. During the large model inference, historical attack and defense cases, power equipment characteristics, causal and temporal dependencies between attack steps, and the entities and relationships most relevant to the current query are retrieved in real time to supplement the context input.
[0014] Preferably, the simulation module is also used to perform multi-path simulation and consequence assessment based on the time-series attack path, wherein the power outage probability and expected power outage amount are used as system-level risk indicators for consequence assessment.
[0015] Preferably, the decision module is used to dynamically assemble a defense decision context by designing decision event triggers and inferring consequences based on attack paths, so as to trigger decision events and construct a structured defense instruction context. The execution module is used to obtain the current optimal targeted proactive defense strategy group by sequentially passing through regularized feasibility filtering, quantitative scoring and sorting based on the output results of the decision module.
[0016] Based on the same inventive concept, this invention also discloses a method for improving the resilience of substations through large-scale model-enabled offensive and defensive countermeasures, comprising the following steps: Construct a cyber-physical coupling model of a substation that incorporates domain knowledge to characterize the substation's network topology, equipment operation logic, and cross-domain impact relationships; Based on the cyber-physical coupling model of substations, attack planning is carried out using a large language model enhanced with domain knowledge, and the temporal attack path is obtained. At the same time, the physical consequences of the attack events and system-level risk indicators are quantified. Based on the quantitative results, a set of candidate defense strategies covering prevention, detection, response, and recovery is constructed for the identified attack path weaknesses. Based on the candidate set of defense strategies, a target optimization model is constructed to output the current optimal set of targeted proactive defense strategies, and the strategies are transformed into executable instructions. At the same time, the strategies are optimized based on the execution effect of the executable instructions.
[0017] The present invention discloses the following technical effects: This invention achieves precise correlation and quantitative transmission between network attack steps and the consequences of power equipment failures by clearly defining the mapping function from information space events to physical system state changes. The large model dynamically updates the topology, state, and parameters of the virtual image based on continuously received real-time operational data, threat intelligence, and other multi-source information, and analyzes the different representations and chain effects of various operating conditions and events in the information and physical domains, ensuring the consistency of the spatiotemporal evolution of the virtual image and the real system, and providing a reliable model foundation for subsequent accurate inferences.
[0018] This invention introduces a domain-knowledge-enhanced large language model to conduct precise attack planning based on real-time system status and threat intelligence. It automatically infers and generates multiple logical, technically feasible, and probabilistic and temporal attack paths. Simultaneously, based on the large language model, it conducts defense planning for assessed high-risk attack paths and automatically devises a diverse and operable set of defense strategies covering protection, detection, response, and recovery, achieving a paradigm shift from relying on expert experience to artificial intelligence generation.
[0019] This invention drives decision generation through precise physical consequence quantification data, introduces an adversarial re-inference mode, verifies the actual effect of candidate defense strategies, and globally optimizes to output the defense strategy package with the best overall cost-effectiveness ratio. This elevates defense decision-making from discrete, static response to a verified, globally optimized, result-oriented proactive planning. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the system architecture and execution logic described in this invention.
[0022] Figure 2 This is a schematic diagram of the context-structured assembly described in this invention.
[0023] Figure 3 This is a schematic diagram of the context-structured dynamic assembly described in this invention. Detailed Implementation
[0024] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0025] Example 1: As Figure 1 As shown, this invention provides a large-scale model-enabled substation resilience enhancement system. This system is a complete system consisting of modeling, deduction, decision-making, execution, and learning, designed for large power grids facing cross-temporal and spatial composite attacks, including physical damage to substations, information network penetration, and malicious manipulation of control systems.
[0026] In one embodiment, the substation resilience enhancement system includes a modeling module, a deduction module, a decision-making module, and an execution module.
[0027] For example, the modeling module is used to establish a cyber-physical coupling model of the substation with access domain knowledge, so as to accurately depict the substation's network topology, equipment operation logic, and cross-domain impact correlation.
[0028] For example, the inference module is used to carry out attack planning using a large language model enhanced with domain knowledge. Based on real-time threat intelligence and system status, it automatically generates highly realistic time-series attack paths, accurately quantifies the physical consequences of attack events such as load shedding and power outage time, and quantifies risk indicators such as system-level power outage probability and expected power shortage.
[0029] For example, when faced with quantified risks, the decision module is used to automatically devise a diverse set of defense strategy candidates covering prevention, detection, response, and recovery for identified attack path weaknesses by activating a large language model based on defense planning.
[0030] For example, the execution module is used to optimize the target model, weigh the cost, complexity and effectiveness from multiple dimensions, output the current optimal targeted active defense strategy group, convert the strategy into executable instructions and send them to the actual system, the execution effect is continuously monitored and fed back, and based on the execution effect, the large model and optimization algorithm are continuously evolved and learned.
[0031] Example 2: Based on the same inventive concept, such as Figure 2As shown, this invention discloses a method for enhancing the resilience of substations through large-scale model-enabled attack and defense. First, a cyber-physical coupling model of the substation with access to domain knowledge is established to accurately characterize the substation's network topology, equipment operating logic, and cross-domain impact relationships. Second, an attack planning process is conducted using a domain-knowledge-enhanced large-scale language model. Based on real-time threat intelligence and system status, highly realistic temporal attack paths are automatically generated and simulated, accurately quantifying the physical consequences of attack events, such as load shedding and power outage time, and quantifying risk indicators such as system-level power outage probability and expected power shortage. Subsequently, facing the quantified risks, the system activates a large-scale language model based on defense planning. For identified attack path weaknesses, a diverse set of candidate defense strategies covering prevention, detection, response, and recovery is automatically conceived. Further, based on a target optimization model, the optimal targeted proactive defense strategy group is output by weighing multiple dimensions such as cost, complexity, and effectiveness. Finally, the strategy is transformed into executable instructions and issued to the actual system. The execution effect is continuously monitored and fed back, driving the continuous evolution of the large-scale model and optimization algorithm.
[0032] For example, through the above process, the present invention elevates the security defense of substations from a decentralized approach targeting single-point problems to a systematic, proactive decision support based on risk prediction, thereby enhancing the overall resilience of the system in the face of complex and uncertain attacks.
[0033] Step S100: Construction of the substation cross-domain coupled network mapping model in the access data model layer.
[0034] In step S100 of one implementation, the physical model is built, including the physical network topology, steady-state model, physical device model and protection model.
[0035] For example, the physical network topology can be represented as a directed graph. ,in: These are physical nodes, including busbars, circuit breakers, generators, loads, etc. Branch lines include power lines, transformers, etc.
[0036] For example, the steady-state model employs rapid DC power flow analysis and can be expressed as follows: In the formula: Net power vector injected into the node; Here is the nodal admittance matrix; The node voltage phase angle vector; branch road The trend; For branch circuit reactors.
[0037] For example, the physical equipment model includes constructed generator output and load reduction models, respectively represented as follows: In the formula: , , These are the generator's active power output, lower limit of active power output, and upper limit of active power output, respectively. To cut off the load power, This represents the total load power.
[0038] For example, overload protection action logic is defined through a protection model when the branch power flow... At that time, after a delay td, the current path is disconnected, where: This refers to the rated transmission capacity of the branch line.
[0039] In step S100 of one implementation, building the information model includes an information network topology, an attack behavior database, and an attacker target model.
[0040] For example, the topology of an information network can be represented as a directed graph. ,in: These are information nodes, including monitoring hosts, engineering workstations, smart terminals, merging units, etc. This is a logical communication link.
[0041] For example, the attack behavior library is used to build tuples (A ID , N, C pre E post , P s , T c ), where: A ID N is a unique identifier for the attack step, used to uniquely index and reference this attack action within the system; C is the information space entity targeted by this attack step. pre The system must meet certain state conditions before this attack step can be successfully executed; E post The changes to the system state that occur after successfully executing this attack step; P s The success rate of an attacker attempting to perform this action assuming all preconditions are met; T c The estimated time required for the attacker to perform the above steps and achieve the desired effect.
[0042] For example, the attacker's target model defines the attacker's initial set of penetration points, privilege escalation path, and ultimate operational target on the physical device.
[0043] In step S100 of one implementation, a cross-domain coupling interface model is built.
[0044] For example, a deterministic or probabilistic mapping function from information space events to changes in physical space states can be defined as follows: In the formula: For coupling mapping functions; Let be a set of events in the information space, where any event This corresponds to a malicious action successfully completed by the attacker in the information space. Let be the set of state changes of a physical system, where any state This describes changes in the status or operating parameters of equipment in a primary power system. As a mapping relationship, when a specific information space event occurs... When it occurs, through the function Deterministically or probabilistically induce one or more changes in physical state. .
[0045] In step S100 of one implementation, a data and model access layer is built, including external threat intelligence sources and endogenous security data sources.
[0046] For example, external threat intelligence sources automatically subscribe to and index intelligence information released by authoritative global or national cybersecurity agencies, equipment suppliers, open-source intelligence communities, etc., through standardized interfaces and protocols. This includes: the latest vulnerability details, severity levels, and affected product lists provided by CNVD (China National Vulnerability Database) and NVD (US National Vulnerability Database); threat alerts and attack incident analysis reports for industrial control systems released by ICS-CERT (Industrial Control System Network Emergency Response Team); and security patches and vulnerability notifications released by manufacturers of various equipment in substations, such as protection devices, switches, and servers.
[0047] For example, the intrinsic security data source is the output of other security components within the system, including: logs and alarms from the substation network security management platform, host antivirus detection, local threat discovery from the endpoint detection and response system; and verified high-risk attack pattern cases accumulated and marked by the system itself during historical operation.
[0048] Step S200 constructs an attack path based on a large language model.
[0049] In step S200 of one implementation, multi-data source event triggering and collection are performed.
[0050] For example, the system automatically triggers events based on a preset period T. When the threat intelligence stream captures a highly correlated attack pattern or detects abnormal network traffic during real-time operation, a threat event report is immediately triggered.
[0051] For example, the data collection process first extracts the complete equipment list, network topology connections, and key asset details of the target substation from step S100; then, it obtains a snapshot of the current system status, including the online / offline status of equipment, the open / closed status of major circuit breakers, the current rule summary of the network firewall, and the recent alarm types of the intrusion detection system (IDS); finally, it obtains detailed information on vulnerability exploitation related to the substation's equipment and software, as well as the techniques, tactics, and procedures commonly used by threat organizations.
[0052] In step S200 of one embodiment, the context structure based on multi-source heterogeneous information is assembled. This multi-source heterogeneous information is organized according to a logic easily understood by the larger model to construct a multi-stage prompt context, as shown in the structure below. Figure 1 As shown.
[0053] Step S300 generates a structured attack path based on large language model reasoning.
[0054] In step S300 of one embodiment, a large model of the domain is prepared.
[0055] For example, an open-source or commercial large language model with powerful code and logical reasoning capabilities can be selected. During model reasoning, historical attack and defense cases, power equipment characteristics, causal and temporal dependencies between attack steps, as well as the entities and relationships most relevant to the current query can be retrieved in real time as supplementary context input to ensure the accuracy and timeliness of information.
[0056] In step S300 of one embodiment, model inference is performed.
[0057] For example, after receiving the context assembled in step S200, the model performs internal reasoning and is guided by prompts to follow the following logic: ① Intelligence analysis and attack surface mapping: identify the most vulnerable boundaries; ② Initial access vector selection: assess the feasibility of using phishing emails, vulnerability exploits, or supply chain attacks; ③ Lateral movement and privilege escalation path planning: based on the initial foothold, cross security partitions and approach key nodes of controllable physical devices; ④ Goal achievement action design: determine the way to ultimately cause physical impact.
[0058] In step S300 of one implementation, structured output is performed, which forces the model to generate data that can be directly parsed by downstream systems through strict output format instructions.
[0059] Step S400 quickly simplifies the critical attack path.
[0060] In one implementation, since the initial generation of a large model generates a large number of paths with significant differences in quality, a subset of strong threat paths is quickly selected through automated rules and quantitative scoring.
[0061] In step S400 of one implementation, rule-based feasibility filtering is performed to quickly verify any link of each attack path, i.e.: if the target node of a certain step is currently offline, the path is marked as an infeasible link.
[0062] In step S400 of one implementation, quantitative scoring and ranking are performed. For paths that pass the feasibility filter, a comprehensive threat score is calculated and used to rank high-risk attack paths, quantified as follows: In the formula: This represents the probability of a successful attack path. The shorter the attack time, the greater the threat; To assess the potential impact, a preliminary estimate is made based on the target node of the final attack step. For example, the impact of causing the main transformer to shut down is greater than the impact of causing a single line to shut down. For technical complexity; , , , These are the weighting coefficients for the corresponding quantification terms.
[0063] In step S400 of one embodiment, critical attack path generation is performed. After filtering and sorting, the system outputs based on... k complete attack paths arranged in descending order k Each path represents a sequence of events, that is, Path k =[(t1, a1, s1), (t2, a2, s2), ..., (t m , a m , s m )] In the formula: t m a m s m These are the absolute time of the event, the attack action, and the system state after the action.
[0064] Step S500 critical attack path risk and consequences assessment.
[0065] In step S500 of one implementation, multipath deduction and consequence assessment are performed.
[0066] For example, a simulated attack is performed at time t. m To carry out an attack m Update system status s m ; For example, simulating a physical chain reaction, the optimal load shearing model is invoked, i.e. st The above equations represent the power balance constraint, generator output upper and lower limit constraint, load reduction upper and lower limit constraint, and branch power transmission limit constraint, respectively. Let i be the load reduction amount for node i. The active power output of generator set i; , These are the upper and lower limits of the active power of the generator set, respectively. The original load demand for node i; The active power of the branch circuit; This represents the active power transmission limit of the branch. For line reactance; The node voltage phase angle; Relax the node voltage phase angle of the system; , Let the system node set and the generator node set be the sets of nodes, respectively. Solving the above model yields the amount of load that must be cut off under this event and the reduction amount at each load point.
[0067] For example, the system records the load shedding caused by the current path and the system recovery time from the attack, generating and outputting a structured consequence record for subsequent risk assessment calculations.
[0068] In step S500 of one implementation, risk index calculation is performed, the consequences of all paths are collected, and system-level risk indices are calculated: Loss of Load Probability (LOLP) and Expected Energy Not Supplied (EENS), which can be expressed as follows: In the formula: This is an indicator function that indicates whether node i has indeed experienced load reduction in the k-th sampling. The function returns 1 if the load reduction does not occur, and 0 otherwise. The duration of the k-th sampling; Total duration; This represents the total number of samplings.
[0069] Step S600 constructs an active defense decision based on a large language model.
[0070] In one embodiment, a decision event is designed to trigger a risk indicator threshold, which is then compared with the quantified risk indicator value under the multi-attack path deduction completed in step S500. If the threshold is exceeded, a decision event is immediately triggered.
[0071] In one embodiment, the defense decision context based on the attack path deduction consequences is dynamically assembled. The attack path details and deduction consequences generated in steps S400-S500 are integrated with the current system hardening status and available resources to construct a structured defense instruction context.
[0072] Step S700 generates an active defense decision based on reasoning from a large language model.
[0073] In one implementation, a large domain model is prepared, selecting an open-source or commercial large language model with strong code and logical reasoning capabilities. During model inference, real-time training data focuses on security hardening solutions, operation and maintenance manuals, fault handling plans, cost-benefit analyses, etc. Historical security hardening cases, emergency plans, vulnerability repair reports, and attack and defense exercise debriefing datasets are used as supplementary context inputs to internalize knowledge such as security resource configuration, change risk assessment, and trade-offs of measure effectiveness, ensuring the accuracy and timeliness of information.
[0074] In one embodiment, the model reasoning process involves receiving the context assembled in step S600 and, in accordance with the principle of defense in depth for network security, devising layer-by-layer hardening measures from the boundary, network, host, application to the underlying physical logic. This includes balancing combinations of preventative measures, detection measures, responsive measures, and recovery measures. Based on the provided resource information and domain knowledge, the model assesses the time consumption and human and material resource costs of each executable measure, as well as the potential risks to business continuity.
[0075] In one implementation, structured output, through strict output format instructions, forces the model to generate data that can be directly optimized and processed later.
[0076] Step S800: Quickly assess the defense strategy.
[0077] In step S800 of one implementation, since the large number of strategy combinations initially generated by the large model is large, targeted high-value defense strategies are quickly screened and sorted through rule and quantification models.
[0078] In one implementation, rule-based feasibility filtering is performed to check whether the resources required for each measure in the strategy are within the range of currently available system resources. That is, if a measure requires immediate replacement of system components but there are no flexible backup resources, it is marked as an infeasible strategy.
[0079] In one implementation, quantitative scoring and ranking are performed. For strategies that pass the feasibility filter, a comprehensive value score for strategy effectiveness is calculated for preliminary ranking, and quantified as follows: In the formula: For the anticipated attack risk utility; Total cost of defense; To increase the complexity of defense implementation; To assess the degree of impact on business operations within the system; , , , These are the weighting coefficients for the corresponding quantification terms.
[0080] In one implementation, a targeted proactive defense strategy is generated, and after filtering and sorting, the system outputs a list based on... A descending list of candidate active defense strategies, where each strategy represents a sequence of defensive measures, can be represented as follows: Strategy i =[(d1, m1, s1), (d2, m2, s2), ..., (d n , m n , s n )] In the formula: d n m n s n These are the defense text description, defense measures, and system status after the action.
[0081] In summary, this invention innovatively constructs a substation cyber-physical coupling model that integrates a large language model, concretely representing the mixed risk scenarios faced by substations, including network penetration, physical damage, and cross-domain collaborative attacks. Based on real-time threat intelligence and system status, it automatically and proactively generates a large number of highly realistic potential attack paths, effectively simulating the attack methods and paths that attackers might take before an actual system attack occurs. Faced with massive and complex potential threats, it identifies high-risk attack paths based on the large language model and automatically generates diverse and operable defense strategies covering prevention, detection, response, and recovery, providing operators with scientific and accurate decision-making suggestions. This greatly improves the efficiency and scientific nature of the precise quantification of defense resource allocation and proactive defense optimal planning.
[0082] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0083] In the description of this invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0084] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A substation resilience enhancement system with large-scale model-enabled offensive and defensive capabilities, characterized in that, include: The modeling module is used to construct a cyber-physical coupling model of a substation that incorporates domain knowledge, in order to characterize the substation's network topology, equipment operation logic, and cross-domain impact relationships. The inference module is used to carry out attack planning based on the substation cyber-physical coupling model, using a large language model enhanced with domain knowledge, and to obtain the time-series attack path. At the same time, it quantifies the physical consequences of the attack event and the system-level risk indicators. The decision-making module is used to construct a set of candidate defense strategies covering prevention, detection, response, and recovery based on the quantitative results and the identified attack path weaknesses. The execution module is used to construct a target optimization model based on the set of defense strategy candidates to output the current optimal targeted active defense strategy group, and to convert the strategy into executable instructions. At the same time, the module optimizes the strategy based on the execution effect of the executable instructions.
2. The substation resilience enhancement system for large-scale model-enabled offensive and defensive confrontation as described in claim 1, characterized in that: The modeling module is used to construct the substation information-physical coupling model based on the physical model, information model, cross-domain coupling interface model, and data and model access layer.
3. The substation resilience enhancement system for large-scale model-enabled offensive and defensive countermeasures as described in claim 2, characterized in that: The physical model includes physical network topology, steady-state model, physical device model, and protection model; The physical network topology is a directed graph. ,in: For physical nodes, It is a branch road; The steady-state model is: , In the formula: Net power vector injected into the node; The nodal admittance matrix; The node voltage phase angle vector; branch road The trend; For branch circuit reactance; The physical device model is represented as follows: , In the formula: , , These are the generator's active power output, lower limit of active power output, and upper limit of active power output, respectively. To cut off the load power, This represents the total load power.
4. The substation resilience enhancement system for large-scale model-enabled offensive and defensive confrontation as described in claim 2, characterized in that: The information model includes an information network topology, an attack behavior database, and an attacker target model, wherein, The information network topology is represented as a directed graph. ,in: For information nodes, For logical communication links; The attack behavior database is used to establish tuples (A ID , N, C pre E post , P s , T c ), where A ID N is the unique identifier for the attack step, and C is the information space entity targeted by this attack step. pre The state conditions that must be met before this attack step can be successfully executed; E post The changes to the system state that occur after successfully executing this attack step; P s The success rate of an attacker attempting to perform this action assuming all preconditions are met; T c The estimated time required for the attacker to perform the above steps and achieve the desired effect; The attacker target model is used to define the attacker's initial set of penetration points, privilege escalation path, and final operational target on the physical device.
5. The substation resilience enhancement system for large-scale model-enabled offensive and defensive confrontation as described in claim 2, characterized in that: The cross-domain coupling interface model is used to define a deterministic or probabilistic mapping function from information space events to physical space state changes, expressed as follows: In the formula: For coupling mapping functions; Let be a set of events in the information space, where any event This corresponds to a malicious action successfully completed by the attacker in the information space. Let be the set of state changes of a physical system, where any state This describes changes in the status or operating parameters of equipment in a primary power system. As a mapping relationship, when a specific information space event occurs... When it occurs, through the function Deterministically or probabilistically induce one or more changes in physical state. .
6. The substation resilience enhancement system for large-scale offensive and defensive countermeasures according to claim 2, characterized in that: The data and model access layer includes external threat intelligence sources and internal security data sources.
7. The substation resilience enhancement system for large-scale model-enabled offensive and defensive confrontation as described in claim 1, characterized in that: The inference module is used to assemble a context structure based on multi-source heterogeneous information. It organizes the multi-source heterogeneous information according to a logic that is easy for the large model to understand, constructs a multi-stage prompt context, and sequentially performs intelligence analysis and attack surface mapping, initial access vector selection, lateral movement and privilege escalation path planning, and target achievement action design. After executing model inference, it performs path filtering through automated rules and quantitative scoring to obtain the temporal attack path. During the large model inference, it retrieves historical attack and defense cases, power equipment characteristics, causal and temporal dependencies between attack steps, and the entities and relationships most relevant to the current query in real time to supplement the context input.
8. The substation resilience enhancement system for large-scale model-enabled offensive and defensive countermeasures as described in claim 7, characterized in that: The simulation module is also used to perform multi-path simulation and consequence assessment based on the time-series attack path, wherein the power outage probability and expected power outage amount are used as system-level risk indicators for consequence assessment.
9. The substation resilience enhancement system for large-scale model-enabled offensive and defensive confrontation as described in claim 1, characterized in that: The decision module is used to dynamically assemble a defense decision context by designing decision event triggers and deducing the consequences based on the attack path, so as to trigger decision events and construct a structured defense instruction context. The execution module is used to obtain the current optimal targeted proactive defense strategy group by sequentially passing through regularized feasibility filtering, quantitative scoring and sorting based on the output results of the decision module.
10. A method for enhancing the resilience of substations through large-scale model-enabled offensive and defensive countermeasures, implemented using a large-scale model-enabled substation resilience enhancement system as described in claim 1, characterized in that: Includes the following steps: Construct a cyber-physical coupling model of a substation that incorporates domain knowledge to characterize the substation's network topology, equipment operation logic, and cross-domain impact relationships; Based on the substation cyber-physical coupling model, an attack planning process is carried out using a domain knowledge-enhanced large language model, and a time-series attack path is obtained. At the same time, the physical consequences of the attack events and system-level risk indicators are quantified. Based on the quantitative results, a set of candidate defense strategies covering prevention, detection, response, and recovery is constructed for the identified attack path weaknesses. Based on the set of defense strategy candidates, a target optimization model is constructed to output the current optimal targeted active defense strategy group, and the strategy is transformed into executable instructions. At the same time, the strategy is optimized based on the execution effect of the executable instructions.