CN109066981B - Information safety monitoring method for medium-voltage distribution network - Google Patents
Information safety monitoring method for medium-voltage distribution network Download PDFInfo
- Publication number
- CN109066981B CN109066981B CN201810962229.1A CN201810962229A CN109066981B CN 109066981 B CN109066981 B CN 109066981B CN 201810962229 A CN201810962229 A CN 201810962229A CN 109066981 B CN109066981 B CN 109066981B
- Authority
- CN
- China
- Prior art keywords
- distribution network
- medium
- voltage distribution
- information
- information safety
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000012544 monitoring process Methods 0.000 title claims abstract description 73
- 238000000034 method Methods 0.000 title claims abstract description 19
- 238000004891 communication Methods 0.000 claims abstract description 17
- 238000004458 analytical method Methods 0.000 claims abstract description 16
- 230000008447 perception Effects 0.000 claims description 9
- 230000002159 abnormal effect Effects 0.000 claims description 8
- 238000010586 diagram Methods 0.000 description 3
- 238000004364 calculation method Methods 0.000 description 2
- 238000004519 manufacturing process Methods 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 1
- 230000002708 enhancing effect Effects 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000002955 isolation Methods 0.000 description 1
Images
Classifications
-
- H02J13/0006—
-
- H—ELECTRICITY
- H02—GENERATION; CONVERSION OR DISTRIBUTION OF ELECTRIC POWER
- H02J—CIRCUIT ARRANGEMENTS OR SYSTEMS FOR SUPPLYING OR DISTRIBUTING ELECTRIC POWER; SYSTEMS FOR STORING ELECTRIC ENERGY
- H02J2203/00—Indexing scheme relating to details of circuit arrangements for AC mains or AC distribution networks
- H02J2203/20—Simulating, e g planning, reliability check, modelling or computer assisted design [CAD]
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
- Remote Monitoring And Control Of Power-Distribution Networks (AREA)
Abstract
The invention discloses an information safety monitoring method for a medium voltage distribution network, which comprises the steps of collecting communication data information of a medium voltage distribution network terminal; constructing a situation awareness analysis probability model of a medium-voltage distribution network terminal and monitoring the information security state of the medium-voltage distribution network; and reporting the monitoring information to the master station and finishing information safety monitoring of the medium-voltage distribution network. According to the information safety monitoring method for the medium-voltage distribution network, provided by the invention, the data statistics and the access frequency characteristic of the communication flow of the distribution network terminal monitored by the distribution network main station are actively obtained and fully considered, and the data information of the monitoring distribution terminal of the distribution network main station is acquired and obtained, so that a sensing analysis model of the flow and the access frequency situation of the distribution network terminal is constructed, and the effectiveness of information safety monitoring of the medium-voltage distribution network terminal is improved.
Description
Technical Field
The invention particularly relates to an information safety monitoring method for a medium-voltage distribution network.
Background
With the development of economic technology and the improvement of living standard of people, electric energy becomes essential secondary energy in production and life of people, and brings endless convenience to production and life of people.
The communication information safety of the medium-voltage distribution network is one of the preconditions for the normal operation of the distribution network. The information security attack incident to medium voltage distribution network is increasingly frequent, and the safety protection equipment is relatively isolated, and the phenomenon of safe isolated island is outstanding. The harm of malicious network attack to the power distribution network is serious, which may cause the data leakage of the power distribution network terminal, and even may cause social harm such as large-area power failure.
In the existing communication information security strategy of the medium-voltage distribution network, most of the strategies are focused on setting physical isolation or adopting an encryption authentication system and the like. However, at present, the communication information security strategy for the medium voltage distribution network is passive, that is, the external attack event to the medium voltage distribution network communication is invalidated through enhancing the confidentiality and the tolerance of the strategy. However, it is obvious that the current security policy is very passive, and the protection capability against unknown attack events is obviously insufficient, so that the communication information security of the medium-voltage distribution network still bears huge risks.
Disclosure of Invention
The invention aims to provide an information safety monitoring method for a medium-voltage distribution network, which realizes the active monitoring of the communication information safety of the medium-voltage distribution network by actively sensing the communication information data volume of the medium-voltage distribution network.
The invention provides an information safety monitoring method for a medium-voltage distribution network, which comprises the following steps:
s1, collecting communication data information of a medium-voltage distribution network terminal;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.
Step S1 is to collect communication data information of the medium voltage distribution network terminal, specifically to collect traffic and frequency data information of the medium voltage distribution network terminal.
The method comprises the steps of collecting flow and frequency data information of a medium-voltage distribution network terminal, specifically, collecting flow data and access frequency of each monitoring period in a counting period by taking the first N monitoring periods of the current monitoring period as the counting period, so as to obtain a flow sequence { x (i) } and a frequency sequence { y (i) } in the counting period; wherein x (i) is the flow data of the ith monitoring period in the counting period, and y (i) is the frequency data of the ith monitoring period in each stage in the counting period.
Step S2, constructing a situation awareness analysis probability model of the medium voltage distribution network terminal, specifically constructing the model by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the flow rate sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density with a Poisson parameter of λyThe poisson probability distribution model probability density.
Step S3, monitoring the information security state of the medium voltage distribution network, specifically, monitoring by using the following steps:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0;
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If the current monitoring period is less than gamma, the information safety state of the current monitoring period is judged to be abnormal.
According to the information safety monitoring method for the medium-voltage distribution network, provided by the invention, the data statistics and the access frequency characteristic of the communication flow of the distribution network terminal monitored by the distribution network main station are actively obtained and fully considered, and the data information of the monitoring distribution terminal of the distribution network main station is acquired and obtained, so that a sensing analysis model of the flow and the access frequency situation of the distribution network terminal is constructed, and the effectiveness of information safety monitoring of the medium-voltage distribution network terminal is improved.
Drawings
FIG. 1 is a process flow diagram of the process of the present invention.
Fig. 2 is a schematic diagram of a two-dimensional region S constructed by the method of the present invention.
Detailed Description
FIG. 1 shows a flow chart of the method of the present invention: the invention provides an information safety monitoring method for a medium-voltage distribution network, which comprises the following steps:
s1, collecting communication data information of a medium-voltage power distribution network terminal, specifically collecting flow and frequency data information of the medium-voltage power distribution network terminal; in the acquisition process, the first N (10-15 suggested values) monitoring periods of the current monitoring period are taken as statistical periods, and the flow data and the access frequency of each monitoring period in the statistical periods are acquired, so that a flow sequence { x (i) } and a frequency sequence { y (i) } in the statistical periods are obtained; wherein x (i) is the flow data of the ith monitoring period in the statistical period, and y (i) is the frequency data of the ith monitoring period in each stage in the statistical period;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1; specifically, the model is constructed by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the flow rate sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density with a Poisson parameter of λyThe probability density of the poisson probability distribution model;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2; the method specifically comprises the following steps of:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma, wherein the value range of the safety coefficient alpha is 0-1, the value range of the frequency safety coefficient beta is 0-1, and the value range of the proposed safety threshold gamma is 4% -8%;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area; the schematic diagram of the region S is shown in fig. 2;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0;
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If the current monitoring period is less than gamma, judging the information safety state of the current monitoring period to be abnormal;
the above calculation step is a calculation point (x)0,y0) The information safety probability corresponding to the shadow part in the region where the shadow part falls;
in the examples, α is 0.2, β is 0.2, γ is 8%, and λ is takenx=λyIf 100, the safety range S is S { (x, y) | x ∈ [80,120 { (x, y) | x ∈ { (x, y) |],y∈[80,120]When the judgment is carried out, two specific situations are adopted: in the monitoring period, if the monitored information security parameter flow time sequence x (i) of the distribution network terminal at the current time is 60, the monitored frequency time sequence y (i) is 80 times/S, and the terminal is not in the security region S, the terminal is identifiedThe information security is in an abnormal state; in the monitoring period, the monitored information security parameter flow time sequence x (i) of the distribution network terminal at the current time is 90bps, and the frequency time sequence y (i) is 90 times/S, and in the security region S, the information security reconfirmation state is entered, and the joint probability value P (x, y) of the joint probability density function P (x, y) of the flow and the frequency is calculated through a formula. If P (x, y) is not less than 0.08, the terminal information safety is identified to be in a normal state, otherwise, the terminal information safety is identified to be in an abnormal state;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.
Claims (2)
1. An information safety monitoring method for a medium-voltage distribution network comprises the following steps:
s1, collecting communication data information of a medium-voltage distribution network terminal; specifically, the method comprises the steps of collecting flow and frequency data information of a medium-voltage distribution network terminal; collecting flow data and access frequency of each monitoring period in the counting period by taking the first N monitoring periods of the current monitoring period as the counting period, thereby obtaining a flow sequence { x (i) } and a frequency sequence { y (i) } in the counting period; wherein x (i) is the flow data of the ith monitoring period in the statistical period, and y (i) is the frequency data of the ith monitoring period in each stage in the statistical period;
s2, constructing a situation awareness analysis probability model of the medium-voltage power distribution network terminal according to the communication data information collected in the step S1; specifically, the model is constructed by adopting the following steps:
a. the mathematical expectation λ of the flow rate sequence { x (i) } obtained in step S1 is calculatedxAnd constructing a Poisson parameter of λxA poisson probability distribution model of (a);
b. calculating the mathematical expectation λ of the frequency sequence { y (i) } obtained in step S1yAnd constructing a Poisson parameter of λyA poisson probability distribution model of (a);
c. constructing a situation perception analysis probability model p (x, y) ═ p (x) × p (y) of the medium-voltage distribution network terminal, wherein p (x) is flow probability density, and the value of p (x) is Poisson parameter lambdaxThe probability density of the poisson probability distribution model of (1); p (y) is the frequency probability density,having a Poisson parameter of λyThe probability density of the poisson probability distribution model;
s3, monitoring the information safety state of the medium-voltage distribution network by adopting the situation perception analysis probability model obtained in the step S2;
and S4, reporting the monitoring information obtained in the step S3 to the main station, thereby completing the information safety monitoring of the medium voltage distribution network.
2. The information safety monitoring method for the medium voltage distribution network according to claim 1, wherein the step S3 of monitoring the information safety state of the medium voltage distribution network specifically comprises the following steps:
(1) setting a flow safety coefficient alpha, a frequency safety coefficient beta and a safety threshold gamma;
(2) in the space of a situation perception analysis probability model of a medium-voltage distribution network terminal, a two-dimensional area S is defined by taking a flow variable as an x axis and a frequency variable as a y axis, wherein the range of the area S is defined by a straight line x ═ 1-alpha lambdax、x=(1+α)λx、y=(1-β)λyAnd y ═ 1+ β) λyThe enclosed area;
(3) acquiring flow data x of medium-voltage distribution network terminal in current monitoring period0Sum frequency data y0;
(4) And (3) judging the information safety state of the current monitoring period by adopting the following rules:
r1. if point (x)0,y0) If the current monitoring period is not in the region S, judging that the information safety state of the current monitoring period is abnormal;
r2. if point (x)0,y0) In the region S, the information security probability of the current monitoring period is calculated according to the following formula:
and if P (x)0,y0) If the current monitoring period is more than or equal to gamma, judging the information safety of the current monitoring period to be normal; if P (x)0,y0) If < gamma, the current monitor is determinedAnd measuring the information safety state of the cycle as abnormal.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810962229.1A CN109066981B (en) | 2018-08-22 | 2018-08-22 | Information safety monitoring method for medium-voltage distribution network |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810962229.1A CN109066981B (en) | 2018-08-22 | 2018-08-22 | Information safety monitoring method for medium-voltage distribution network |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109066981A CN109066981A (en) | 2018-12-21 |
CN109066981B true CN109066981B (en) | 2021-08-17 |
Family
ID=64687950
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810962229.1A Active CN109066981B (en) | 2018-08-22 | 2018-08-22 | Information safety monitoring method for medium-voltage distribution network |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN109066981B (en) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110765421B (en) * | 2019-10-22 | 2023-05-23 | 南方电网科学研究院有限责任公司 | Verification method, device, equipment and storage medium for operation parameters of power distribution network |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103501293A (en) * | 2013-09-25 | 2014-01-08 | 国网重庆市电力公司 | Authentication method of terminal credible access in smart power grid |
CN106027288A (en) * | 2016-05-10 | 2016-10-12 | 华北电力大学 | Communication traffic prediction method for distribution line information monitoring service |
CN107834703A (en) * | 2017-11-21 | 2018-03-23 | 武汉精伦电气有限公司 | A kind of intelligent grid power distribution room monitoring management system and method |
-
2018
- 2018-08-22 CN CN201810962229.1A patent/CN109066981B/en active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103501293A (en) * | 2013-09-25 | 2014-01-08 | 国网重庆市电力公司 | Authentication method of terminal credible access in smart power grid |
CN106027288A (en) * | 2016-05-10 | 2016-10-12 | 华北电力大学 | Communication traffic prediction method for distribution line information monitoring service |
CN107834703A (en) * | 2017-11-21 | 2018-03-23 | 武汉精伦电气有限公司 | A kind of intelligent grid power distribution room monitoring management system and method |
Non-Patent Citations (1)
Title |
---|
基于主动配电系统供电能力的安全态势感知方法;黄伟等;《电力自动化设备》;20170831;第37卷(第8期);74-79 * |
Also Published As
Publication number | Publication date |
---|---|
CN109066981A (en) | 2018-12-21 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
Du et al. | ADMM-based distributed state estimation of smart grid under data deception and denial of service attacks | |
CN107708173B (en) | Selection method and device of fusion node | |
CN109767352B (en) | Safety situation assessment method for electric power information physical fusion system | |
CN105868629B (en) | Security threat situation assessment method suitable for electric power information physical system | |
CN109861825B (en) | Internal attack detection method based on weighting rule and consistency in CPS system | |
Efstathopoulos et al. | Operational data based intrusion detection system for smart grid | |
CN105279257A (en) | Normal distribution-based internet big data mining method and system | |
CN108111348A (en) | A kind of security policy manager method and system for enterprise's cloud application | |
CN115208604B (en) | AMI network intrusion detection method, device and medium | |
CN117220416B (en) | Smart power grid electric power information safety transmission system | |
CN109066981B (en) | Information safety monitoring method for medium-voltage distribution network | |
CN115935415A (en) | Data safety early warning system based on industrial internet multi-factor perception | |
Amin et al. | Smart grid security enhancement by using belief propagation | |
CN110298170B (en) | Power SCADA system security assessment method considering blind attack factors | |
Hu et al. | Intrusion detection engine based on Dempster-Shafer's theory of evidence | |
CN103686737A (en) | Wireless sensor network intrusion tolerance method and system based on tree topology | |
CN113159638A (en) | Intelligent substation layered health degree index evaluation method and device | |
CN104601567B (en) | A kind of indexing security measure method excavated based on information network security of power system event | |
CN112398693A (en) | Assessment method for safety protection capability of power Internet of things sensing layer | |
CN107277070A (en) | A kind of computer network instrument system of defense and intrusion prevention method | |
Liang et al. | Anomaly detection based on edge computing framework for AMI | |
CN108924129A (en) | One kind being based on computer network instrument system of defense and intrusion prevention method | |
CN111447168B (en) | Multidimensional network security prediction method | |
Cui et al. | Real-time early warning of network security threats based on improved ant colony algorithm | |
CN112672301B (en) | Network data aggregation method for wireless sensor |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant |