期刊文献+

基于业务逻辑的电力业务报文攻击识别方法 被引量:4

Identification method of power service packet attacks based on service logic
下载PDF
导出
摘要 针对电网测控终端的电力业务报文攻击极易造成电力一次设备误动,从而引发电力事故。电力业务报文攻击通常通过干扰正常业务逻辑达到攻击目的,已有攻击识别方法没有考虑业务逻辑,有效性比较差。因此,提出一种基于业务逻辑的电力业务报文攻击识别方法,该方法定义了电力业务逻辑状态链和黑白名单,将误用检测与异常检测方法相结合,基于业务逻辑黑白名单对业务的威胁度进行评估,并考虑电网时间风险与业务重要性,对威胁度进行修正,通过比较业务威胁度与安全阈值,实现对电力业务报文攻击的高效准确识别。给出了应用所提方法实现的一个攻击识别系统架构,并对实现后的系统进行了测试,验证了所提方法的有效性。 The PSPAs(Power Service Packet Attacks)of power grid measurement and control terminals are easy to cause misoperation of primary electric equipment,thus causing electric power accidents.PSPAs usually achieve the attack purpose by interfering the normal service logic.Existing attack identification methods do not take service logic into account and have poor effectiveness.Therefore,an identification method of PSPAs based on service logic is proposed.The state chain of power service logic,blacklist and whitelist are defined.The misuse detection method and anomaly detection method are combined to evaluate the threat degree of power service based on the service logic blacklist and whitelist.Considering the time risk and service importance of power grid,the threat degree is corrected,and the effective and accurate identification of PSPAs is realized by comparing the service threat degree and the security threshold.The architecture of an attack identification system based on the proposed method is presented,and the system is tested to verify the effectiveness of the proposed method.
作者 王海翔 朱朝阳 王宇 张锐文 李俊娥 李霁远 应欢 WANG Haixiang;ZHU Chaoyang;WANG Yu;ZHANG Ruiwen;LI Jun’e;LI Jiyuan;YING Huan(Information&Communication Department,China Electric Power Research Institute,Beijing 100192,China;Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,China;State Grid Zhejiang Electric Power Research Institute,Hangzhou 310014,China)
出处 《电力自动化设备》 EI CSCD 北大核心 2020年第8期217-224,共8页 Electric Power Automation Equipment
基金 国家电网有限公司总部科技项目(电网嵌入式终端漏洞挖掘与攻击检测关键技术研究)(52110418001K)。
关键词 电力业务报文攻击 攻击识别方法 业务逻辑 状态链 电网测控终端 power service packet attacks identification method of attacks service logic state chain power grid measurement and control terminals
  • 相关文献

参考文献4

二级参考文献115

  • 1陈壮奕.基于GPRS的电能远程抄表系统的设计与实现[J].广东电力,2006,19(1):71-74. 被引量:18
  • 2庞志勇,刘冬华,黄沫,陈弟虎.基于GPRS数据传输终端的实现[J].中山大学学报论丛,2006,26(2):129-133. 被引量:4
  • 3张晶,马国政.电力需求侧管理技术支持系统[J].电力需求侧管理,2006,8(5):56-57. 被引量:7
  • 4刘水,陶文娟.SqlServerCE在电力设备巡检系统中的开发应用[J].江西电力,2007,31(2):1-4. 被引量:1
  • 5Bari, A. 2014. "Challenges in the Smart Grid Applications: An Overview." International Journal of Distributed Server Networks 2014 (1): 1-11.
  • 6Wange, W. 2011. "A Survey on the Communication Architectures in Smart Grid." Computer Networks 55 (15): 3604-29.
  • 7Ye, Y., and Qian, Y. 2012. "A Survey on Smart Grid Communication Infrastructures: Motivations, Requireme.nts and Chal[enges." IEEE Communications Surveys and Tutorials 15 (1): 5-20.
  • 8Knapp, E. D. 2011. Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems. New York: Elsevier Inc.
  • 9Horowitz, S., and Phadke, A. 2008. Power System Relaying. New York: John Wiley & Sons, Ltd.
  • 10Depuru, S. 2011. "Smart Meters for Power Grid: Challenges, Issues, Advantages and Status." Renewable and Sustainable Energy Reviews 15 (6): 2736-42.

共引文献97

同被引文献68

引证文献4

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部