期刊文献+

电网工控网络攻击场景中的层次关联分析方法 被引量:8

Hierarchical association analysis method in industrial control cyber attack scenario of power grid
在线阅读 下载PDF
导出
摘要 为提高对恶意攻击事件识别的精度和效率,该文提出了电网工控网络攻击场景中的层次化关联分析方法。首先,对电网中可能遭受的典型攻击场景进行分析,并对电网各层次采集的异常信息及产生的异常事件进行梳理。构建了电网层次化关联分析流程,提出了基于Apriori算法的层次化关联分析模型,精细化挖掘电网各层次频繁项集,并基于时空关联生成了电网各攻击场景下的关联规则。对贝叶斯模型进行了改进,提出了加权贝叶斯分类模型,实现在线事件按攻击场景的快速分类。提出了属性相似度的关联匹配方法,实现关联规则的高速匹配。最后,在源网荷仿真实验系统上验证了该文方法的有效性。该文方法充分挖掘电网各层次异常事件的频繁项集,并对频繁项进行时空关联,进一步提高了对网络攻击的辨识精度。 To improve the accuracy and efficiency of malicious attack event identification,a hierarchical correlation analysis method is proposed for industrial control cyber attack scenarios of power grids.Firstly,the typical attack scenarios in power grids are analyzed,and the abnormal information collected from all levels of power grids and the abnormal events generated are sorted out.Secondly,a hierarchical association analysis process of power grids is constructed,and a hierarchical association analysis model based on Apriori is proposed.Frequent itemsets at all levels of power grids are refined,and the association rules under each attack scenario of power grids are generated based on spatio-temporal association.Thirdly,the Bayesian model is improved,and a weighted Bayesian classification model is proposed to realize fast classification of online events according to attack scenarios.Fourthly,an association matching method based on attribute similarity is proposed to achieve high-speed matching of association rules.Finally,the effectiveness of the proposed method is verified on the source grid load simulation experiment system.This method fully excavates the frequent itemsets of abnormal events at all levels of power grids,and correlates the frequent items in time and space,which further improves the identification accuracy of cyber attacks.
作者 费稼轩 裴培 张明 孙佳炜 Fei Jiaxuan;Pei Pei;Zhang Ming;Sun Jiawei(State Grid Key Laboratory of Information and Network Security,Global Energy Interconnection Research Institute Co.,Ltd.,Nanjing 210003,China;State Grid Jiangsu Electric Power Co.,Ltd.,Nanjing 210003,China)
出处 《南京理工大学学报》 EI CAS CSCD 北大核心 2020年第6期715-723,共9页 Journal of Nanjing University of Science and Technology
基金 国家电网有限公司科技项目(SGGR0000XTJS1800089)。
关键词 电网 工控网络 攻击场景 层次关联 时空关联 贝叶斯分类 属性相似度 源网荷 power grid industrial control attack scenarios hierarchical correlation spatial-temporal correlation Bayesian classification attribute similarity source grid load
  • 相关文献

参考文献9

二级参考文献74

共引文献433

同被引文献104

引证文献8

二级引证文献43

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部