Outline

Ingegneria Sismica

Ingegneria Sismica

Real-Time Anomaly Detection and Proactive Defense Response Mechanism for the Power Industry Based on Bagging-LSTM Algorithm and Security Knowledge Graph

Author(s): Zhenyu Luo1, Bangrong Chen1, Peng Xiao1, Zhenhong Zhang1
1Information Center of China Southern Power Grid Yunnan Power Grid Co., Ltd., Kunming, 650000, China
Luo, Zhenyu. et al “Real-Time Anomaly Detection and Proactive Defense Response Mechanism for the Power Industry Based on Bagging-LSTM Algorithm and Security Knowledge Graph.” Ingegneria Sismica Volume 43 Issue 2: 1-17, doi:10.65102/is2026877.

Abstract

Aiming at the more and more serious network safety condition inside the electric power domain, this paper puts forward a power system network safety defense scheme that is based on real-time abnormal checking and initiative defense reaction. Through the simulation of network attacks inside the power system, it utilizes Extended Berkeley Packet Filter (EBPF) for the acquisition of kernel data and thus applies the adaptive weighted Bagging-Long Short-Term Memory (Bagging-LSTM) algorithm to carry out anomaly detection with high precision. The adaptive Bagging-LSTM puts together different kinds of network data together with past information, therefore it can carry out adjustment and elevate its performance in accordance with need. This characteristic assists it to give accurate and rapid outcomes when it is carrying out detection work tasks. In the aspect of defense, it uses proactive defense of adaptive attack graph which is based on security knowledge graph (SKG). This method has an integration of an adaptive attack graph reasoning algorithm, which can at once change defense strategies according to historical attack information and future attack threats for the handling of complex and diverse attacks. Through experiments we can get that the model is able to reach a 96.8 percent accuracy, a 80 millisecond response time, and a 2.9 percent false alarm rate; they also have the proof that proactive defense can make protection for the power system defense capability, thus reaching a defense success rate which is 93.5%. In the end, the utilization of the adaptive Bagging algorithm that is combined with SKG has a major function in promoting the security measures of power system defense works, therefore helping to raise the overall network protection degree.

Keywords
Real-time anomaly detection, proactive defense, security knowledge graph, intelligent power system

Related Articles

Junhua Li1, Xiaojie He1, Hua Liu2
1School of Mathematics and Computer Science, Hanjiang Normal University, Shiyan, 442000, Hubei, China
2School of Mathematics and Physics, Jingchu University of Technology, Jingmen 448000, Hubei, China
Wei Guo1, Peng Tao1, Bo Ling1, Shen Hao1, Nan Kai1
1State Grid Hebei Marketing Service Center, Shijiazhuang 050000, Hebei, China
Tianzi Zheng1, Genlang Chen2, Binhua He1
1School of Computer Science and Technology (School of Artificial Intelligence), Zhejiang Sci-Tech University, Hangzhou 310018, China
2School of Computer and Data Engineering, Ningbo Tech University, Ningbo 315199, China
Jingwen Wu1
1School of Business, Minnan Normal University, Zhangzhou 363000, Fujian, China
Zijie Peng1, Qianhua Xiao2
1JiLuan College, Nanchang University, Jiangxi 330031, Nanchang, China
2College of Information Engineering, Nanchang University, Jiangxi 330031, Nanchang, China