An intrusion detection method for smart substations based on Hidden Markov Models includes the following steps: S1: Segmenting network traffic according to time scale, extracting packet identifiers, packet measurement data, and packet
throughput to construct an intrusion detection dataset; S2: Calculating the difference between state variables and measurement values based on the unscented
Kalman filter method to establish a
state model capable of calculating the
attack detection index; S3: Establishing an ARIMA model, selecting the optimal
traffic model, determining the detection
confidence interval, and establishing a traffic
throughput detection model; S4: Establishing multiple protocol compliance detection rules and, based on the
Hamming distance calculation method, establishing a standardized detection model; S5: Real-time detection of network traffic in the
smart substation, calculating detection vectors based on the models established in S2, S3, and S4 respectively, and using them as input variables for the
Hidden Markov Model, comprehensively analyzing
system anomaly characteristics, and achieving final discrimination.