With the vigorous development of computer information technology and the advent of the big data era,power grid system is also following the tide of information age construction closely and carriying out the construction of enterprise informatization step by step.With the continuous improvement of the electric power service system,its scale,quantity and type are also continuously expanded.Network intrusions occur constantly,it plays an indelible role in the safe operation of the whole power grid service system to find the attacks on services and evaluate the network security status of all service systems in time.However,for so many service systems,it takes a lot of time and energy to check and analyze them one by one.The risk value of each service system can reflect whether the current service system is in a safe state directly,and then conducting a comprehensive analysis of the attacked service system,which can quickly locate the attacked source,so as to improve the operation and maintenance efficiency of power grid operation and maintenance personnel and save the time and energy cost of operation and maintenance.In view of this,based on the study of common network intrusion detection algorithms and service risk value evaluation strategies,this study designs and establishes a service risk value evaluation system integrating network incluing attack detection,historical alarm association mining and hierarchical service risk value evaluation,it realizes the attack intrusion detection of power grid data flow and the real-time display of service risk value in various operations.By comparing with the existing detection algorithms,the intrusion detection quality is improved,the service status is displayed in real time,and the operation and maintenance cost is reduced.The main research focus of this study includes the following three aspects:Research on attack detection based on real network flow.According to the characteristics of noise in real data,this study designs and implements a trestle noise reduction automatic encoder based on neural network to extract the high representation of the data.By integrating the attention mechanism and using BP neural network to realize supervised learning attack detection,the capability of attack detection against noise data is improved,so as to provide historical attack data support for subsequent risk value evaluation.Research hierarchical service risk value evaluation model based on attack stage and associated alarm.Through the analysis of the network attack stage,a correlation attack method based on the attack stage is proposed to mine the strong correlation alarm effectively in the historical data.Finally,by establishing a hierarchical risk value evaluation strategy and using the optimized index weight to calculate the risk value,the evaluation of service risk value is more accurate and solves the disadvantage of strong dependence on subjective experience.Research service value at risk display platform.Aiming at many services of power grid,the integrated platform of service risk value visualization is designed and implemented,which provides the risk value display function for all service systems.Based on this,the risk value display and detailed alarm display of service impact factors are designed to complete the design and implementation of attack tracing,historical service risk query and other functions. |