CN109066981B - Information safety monitoring method for medium-voltage distribution network - Google Patents

Information safety monitoring method for medium-voltage distribution network Download PDF

Info

Publication number
CN109066981B
CN109066981B CN201810962229.1A CN201810962229A CN109066981B CN 109066981 B CN109066981 B CN 109066981B CN 201810962229 A CN201810962229 A CN 201810962229A CN 109066981 B CN109066981 B CN 109066981B
Authority
CN
China
Prior art keywords
distribution network
medium
voltage distribution
information
information safety
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201810962229.1A
Other languages
Chinese (zh)
Other versions
CN109066981A (en
Inventor
李映雪
朱文广
杨为群
章小枫
周成
刘小春
郑富永
彭怀德
王敏
王丽
王伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
State Grid Corp of China SGCC
Economic and Technological Research Institute of State Grid Jiangxi Electric Power Co Ltd
Original Assignee
State Grid Corp of China SGCC
Economic and Technological Research Institute of State Grid Jiangxi Electric Power Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by State Grid Corp of China SGCC, Economic and Technological Research Institute of State Grid Jiangxi Electric Power Co Ltd filed Critical State Grid Corp of China SGCC
Priority to CN201810962229.1A priority Critical patent/CN109066981B/en
Publication of CN109066981A publication Critical patent/CN109066981A/en
Application granted granted Critical
Publication of CN109066981B publication Critical patent/CN109066981B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • H02J13/0006
    • HELECTRICITY
    • H02GENERATION; CONVERSION OR DISTRIBUTION OF ELECTRIC POWER
    • H02JCIRCUIT ARRANGEMENTS OR SYSTEMS FOR SUPPLYING OR DISTRIBUTING ELECTRIC POWER; SYSTEMS FOR STORING ELECTRIC ENERGY
    • H02J2203/00Indexing scheme relating to details of circuit arrangements for AC mains or AC distribution networks
    • H02J2203/20Simulating, e g planning, reliability check, modelling or computer assisted design [CAD]

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Remote Monitoring And Control Of Power-Distribution Networks (AREA)

Abstract

The invention discloses an information safety monitoring method for a medium voltage distribution network, which comprises the steps of collecting communication data information of a medium voltage distribution network terminal; constructing a situation awareness analysis probability model of a medium-voltage distribution network terminal and monitoring the information security state of the medium-voltage distribution network; and reporting the monitoring information to the master station and finishing information safety monitoring of the medium-voltage distribution network. According to the information safety monitoring method for the medium-voltage distribution network, provided by the invention, the data statistics and the access frequency characteristic of the communication flow of the distribution network terminal monitored by the distribution network main station are actively obtained and fully considered, and the data information of the monitoring distribution terminal of the distribution network main station is acquired and obtained, so that a sensing analysis model of the flow and the access frequency situation of the distribution network terminal is constructed, and the effectiveness of information safety monitoring of the medium-voltage distribution network terminal is improved.

Description

Information safety monitoring method for medium-voltage distribution network
Technical Field
The invention particularly relates to an information safety monitoring method for a medium-voltage distribution network.
Background
With the development of economic technology and the improvement of living standard of people, electric energy becomes essential secondary energy in production and life of people, and brings endless convenience to production and life of people.
The communication information safety of the medium-voltage distribution network is one of the preconditions for the normal operation of the distribution network. The information security attack incident to medium voltage distribution network is increasingly frequent, and the safety protection equipment is relatively isolated, and the phenomenon of safe isolated island is outstanding. The harm of malicious network attack to the power distribution network is serious, which may cause the data leakage of the power distribution network terminal, and even may cause social harm such as large-area power failure.
In the existing communication information security strategy of the medium-voltage distribution network, most of the strategies are focused on setting physical isolation or adopting an encryption authentication system and the like. However, at present, the communication information security strategy for the medium voltage distribution network is passive, that is, the external attack event to the medium voltage distribution network communication is invalidated through enhancing the confidentiality and the tolerance of the strategy. However, it is obvious that the current security policy is very passive, and the protection capability against unknown attack events is obviously insufficient, so that the communication information security of the medium-voltage distribution network still bears huge risks.
Disclosure of Invention
The invention aims to provide an information safety monitoring method for a medium-voltage distribution network, which realizes the active monitoring of the communication information safety of the medium-voltage distribution network by actively sensing the communication information data volume of the medium-voltage distribution network.
The invention provides an information safety monitoring method for a medium-voltage distribution network, which comprises the following steps:
s1, collecting communication data information of a medium-voltage distribution network terminal;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.
Step S1 is to collect communication data information of the medium voltage distribution network terminal, specifically to collect traffic and frequency data information of the medium voltage distribution network terminal.
The method comprises the steps of collecting flow and frequency data information of a medium-voltage distribution network terminal, specifically, collecting flow data and access frequency of each monitoring period in a counting period by taking the first N monitoring periods of the current monitoring period as the counting period, so as to obtain a flow sequence { x (i) } and a frequency sequence { y (i) } in the counting period; wherein x (i) is the flow data of the ith monitoring period in the counting period, and y (i) is the frequency data of the ith monitoring period in each stage in the counting period.
Step S2, constructing a situation awareness analysis probability model of the medium voltage distribution network terminal, specifically constructing the model by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the flow rate sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density with a Poisson parameter of λyThe poisson probability distribution model probability density.
Step S3, monitoring the information security state of the medium voltage distribution network, specifically, monitoring by using the following steps:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
Figure BDA0001774079170000031
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If the current monitoring period is less than gamma, the information safety state of the current monitoring period is judged to be abnormal.
According to the information safety monitoring method for the medium-voltage distribution network, provided by the invention, the data statistics and the access frequency characteristic of the communication flow of the distribution network terminal monitored by the distribution network main station are actively obtained and fully considered, and the data information of the monitoring distribution terminal of the distribution network main station is acquired and obtained, so that a sensing analysis model of the flow and the access frequency situation of the distribution network terminal is constructed, and the effectiveness of information safety monitoring of the medium-voltage distribution network terminal is improved.
Drawings
FIG. 1 is a process flow diagram of the process of the present invention.
Fig. 2 is a schematic diagram of a two-dimensional region S constructed by the method of the present invention.
Detailed Description
FIG. 1 shows a flow chart of the method of the present invention: the invention provides an information safety monitoring method for a medium-voltage distribution network, which comprises the following steps:
s1, collecting communication data information of a medium-voltage power distribution network terminal, specifically collecting flow and frequency data information of the medium-voltage power distribution network terminal; in the acquisition process, the first N (10-15 suggested values) monitoring periods of the current monitoring period are taken as statistical periods, and the flow data and the access frequency of each monitoring period in the statistical periods are acquired, so that a flow sequence { x (i) } and a frequency sequence { y (i) } in the statistical periods are obtained; wherein x (i) is the flow data of the ith monitoring period in the statistical period, and y (i) is the frequency data of the ith monitoring period in each stage in the statistical period;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1; specifically, the model is constructed by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the flow rate sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density with a Poisson parameter of λyThe probability density of the poisson probability distribution model;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2; the method specifically comprises the following steps of:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma, wherein the value range of the safety coefficient alpha is 0-1, the value range of the frequency safety coefficient beta is 0-1, and the value range of the proposed safety threshold gamma is 4% -8%;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area; the schematic diagram of the region S is shown in fig. 2;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
Figure BDA0001774079170000051
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If the current monitoring period is less than gamma, judging the information safety state of the current monitoring period to be abnormal;
the above calculation step is a calculation point (x)0,y0) The information safety probability corresponding to the shadow part in the region where the shadow part falls;
in the examples, α is 0.2, β is 0.2, γ is 8%, and λ is takenx=λyIf 100, the safety range S is S { (x, y) | x ∈ [80,120 { (x, y) | x ∈ { (x, y) |],y∈[80,120]When the judgment is carried out, two specific situations are adopted: in the monitoring period, if the monitored information security parameter flow time sequence x (i) of the distribution network terminal at the current time is 60, the monitored frequency time sequence y (i) is 80 times/S, and the terminal is not in the security region S, the terminal is identifiedThe information security is in an abnormal state; in the monitoring period, the monitored information security parameter flow time sequence x (i) of the distribution network terminal at the current time is 90bps, and the frequency time sequence y (i) is 90 times/S, and in the security region S, the information security reconfirmation state is entered, and the joint probability value P (x, y) of the joint probability density function P (x, y) of the flow and the frequency is calculated through a formula. If P (x, y) is not less than 0.08, the terminal information safety is identified to be in a normal state, otherwise, the terminal information safety is identified to be in an abnormal state;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.

Claims (2)

1. An information safety monitoring method for a medium-voltage distribution network comprises the following steps:
s1, collecting communication data information of a medium-voltage distribution network terminal; specifically, the method comprises the steps of collecting flow and frequency data information of a medium-voltage distribution network terminal; collecting flow data and access frequency of each monitoring period in the counting period by taking the first N monitoring periods of the current monitoring period as the counting period, thereby obtaining a flow sequence { x (i) } and a frequency sequence { y (i) } in the counting period; wherein x (i) is the flow data of the ith monitoring period in the statistical period, and y (i) is the frequency data of the ith monitoring period in each stage in the statistical period;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1; specifically, the model is constructed by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the frequency sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density,having a Poisson parameter of λyThe probability density of the poisson probability distribution model;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.
2. The information safety monitoring method for the medium voltage distribution network according to claim 1, wherein the step S3 of monitoring the information safety state of the medium voltage distribution network specifically comprises the following steps:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
Figure FDA0003076960440000021
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If < gamma, the current monitor is determinedAnd measuring the information safety state of the cycle as abnormal.
CN201810962229.1A 2018-08-22 2018-08-22 Information safety monitoring method for medium-voltage distribution network Active CN109066981B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201810962229.1A CN109066981B (en) 2018-08-22 2018-08-22 Information safety monitoring method for medium-voltage distribution network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201810962229.1A CN109066981B (en) 2018-08-22 2018-08-22 Information safety monitoring method for medium-voltage distribution network

Publications (2)

Publication Number Publication Date
CN109066981A CN109066981A (en) 2018-12-21
CN109066981B true CN109066981B (en) 2021-08-17

Family

ID=64687950

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201810962229.1A Active CN109066981B (en) 2018-08-22 2018-08-22 Information safety monitoring method for medium-voltage distribution network

Country Status (1)

Country Link
CN (1) CN109066981B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110765421B (en) * 2019-10-22 2023-05-23 南方电网科学研究院有限责任公司 Verification method, device, equipment and storage medium for operation parameters of power distribution network

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103501293A (en) * 2013-09-25 2014-01-08 国网重庆市电力公司 Authentication method of terminal credible access in smart power grid
CN106027288A (en) * 2016-05-10 2016-10-12 华北电力大学 Communication traffic prediction method for distribution line information monitoring service
CN107834703A (en) * 2017-11-21 2018-03-23 武汉精伦电气有限公司 A kind of intelligent grid power distribution room monitoring management system and method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103501293A (en) * 2013-09-25 2014-01-08 国网重庆市电力公司 Authentication method of terminal credible access in smart power grid
CN106027288A (en) * 2016-05-10 2016-10-12 华北电力大学 Communication traffic prediction method for distribution line information monitoring service
CN107834703A (en) * 2017-11-21 2018-03-23 武汉精伦电气有限公司 A kind of intelligent grid power distribution room monitoring management system and method

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
基于主动配电系统供电能力的安全态势感知方法;黄伟等;《电力自动化设备》;20170831;第37卷(第8期);74-79 *

Also Published As

Publication number Publication date
CN109066981A (en) 2018-12-21

Similar Documents

Publication Publication Date Title
Du et al. ADMM-based distributed state estimation of smart grid under data deception and denial of service attacks
CN107708173B (en) Selection method and device of fusion node
CN109767352B (en) Safety situation assessment method for electric power information physical fusion system
CN105868629B (en) Security threat situation assessment method suitable for electric power information physical system
CN109861825B (en) Internal attack detection method based on weighting rule and consistency in CPS system
Efstathopoulos et al. Operational data based intrusion detection system for smart grid
CN105279257A (en) Normal distribution-based internet big data mining method and system
CN108111348A (en) A kind of security policy manager method and system for enterprise&#39;s cloud application
CN115208604B (en) AMI network intrusion detection method, device and medium
CN117220416B (en) Smart power grid electric power information safety transmission system
CN109066981B (en) Information safety monitoring method for medium-voltage distribution network
CN115935415A (en) Data safety early warning system based on industrial internet multi-factor perception
Amin et al. Smart grid security enhancement by using belief propagation
CN110298170B (en) Power SCADA system security assessment method considering blind attack factors
Hu et al. Intrusion detection engine based on Dempster-Shafer's theory of evidence
CN103686737A (en) Wireless sensor network intrusion tolerance method and system based on tree topology
CN113159638A (en) Intelligent substation layered health degree index evaluation method and device
CN104601567B (en) A kind of indexing security measure method excavated based on information network security of power system event
CN112398693A (en) Assessment method for safety protection capability of power Internet of things sensing layer
CN107277070A (en) A kind of computer network instrument system of defense and intrusion prevention method
Liang et al. Anomaly detection based on edge computing framework for AMI
CN108924129A (en) One kind being based on computer network instrument system of defense and intrusion prevention method
CN111447168B (en) Multidimensional network security prediction method
Cui et al. Real-time early warning of network security threats based on improved ant colony algorithm
CN112672301B (en) Network data aggregation method for wireless sensor

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant