This invention proposes a method and
system for causal
verification and
attack tracing in power systems, belonging to the field of power
system network security technology. The method includes: collecting multi-
source data from the power
system; standardizing the multi-
source data; extracting entity-relationship-attribute triples; cleaning the triples to generate a triple dataset; constructing a
power attack tracing
knowledge graph based on the triple dataset and combining entities and their inter-entity business relationships; selecting candidate event sets from the
power attack tracing
knowledge graph based on abnormal equipment events; constructing an
attack causal
graph based on the candidate event sets; verifying the causal relationships between events; and reconstructing the
attack chain to locate the attack source. This invention improves the physical credibility of attack paths, the ability to identify attacks specific to power scenarios, and the supporting value and practicality of tracing results for defense decisions; it reduces the
false positive rate caused by accidental correlations and improves the accuracy of attack chain and source location.