The application provides a power
system causal
verification attack tracing method and
system, and belongs to the technical field of power
system network security. The method comprises the following steps: collecting power system multi-
source data, standardizing the power system multi-
source data, extracting entity-relation-attribute triples, performing data cleaning on the triples, and generating a triple
data set; based on the triple
data set, combining entities and business relationships between entities, constructing a
power attack tracing
knowledge graph; according to the device abnormal event, screening a candidate event set from the
power attack tracing
knowledge graph, constructing an
attack causal
graph based on the candidate event set, verifying the causal relationship between events, restoring the
attack chain to locate the attack source. The application improves the physical credibility of the attack path, the recognition ability of the power scene special attack, the support value and practicality of the tracing result for the defense decision, reduces the misjudgment rate caused by accidental association, and improves the accuracy of attack chain and source location.