节点文献
数据-模型驱动的智能变配电系统信息安全防护方法研究
Research on the Methodology of Cyber Security Defense for Smart Substation and Distribution Systems Driven by Data and Model
【作者】 杨杰;
【导师】 郭创新;
【作者基本信息】 浙江大学 , 电气工程, 2022, 博士
【摘要】 现代电力系统不仅在一次侧的能源结构上与传统电力系统有明显差异,而且在二次侧的测控体系中也发生了深刻的变革。信息技术的革新与进步使得电力系统在可观性与可控性上都有极大提升,进而将发展成为一个绿色低碳、广泛互联、智能互动的智能电网。IEC 61850标准具备高度开放性、扩展性和自描述能力,提供了互换互操作的标准化范式,高度契合了智能电网的建设愿景。因此,该系列标准在智能电网变配电系统中得到了广泛应用,已经成为电力自动化系统中最重要的通信标准之一。但是,该系列标准的开放性与信息物理的深度交互导致电网安全边界日趋模糊、高级安全威胁不断增多,安全事故频频发生。基于上述背景,本文从“节点级”、“功能级”与“系统级”三个角度对智能变配电系统的信息安全防护方法开展研究,采用了模型与数据双重驱动下的闭环控制思想,旨在提高系统应对先进网络攻击的韧性,洞悉系统安全态势,优化防御资源部署,实现安全、可靠运行。主要总结如下:(1)在节点重要度量化方面,对61850化变电站自动化系统(Substation Automation System,SAS)建立加权有向静态复杂网络动力学模型,提出了一种通过引入一阶线性反馈控制器来量化逻辑节点拓扑价值和信息附加价值的方法。在此基础上,提出等价域的定义及转换方法,显著降低原始网络拓扑的复杂度。同时,引入绝对价值和相对价值分别从节点的必要性和影响力两个角度来量化逻辑节点的重要度。算例分析表明,该方法可以准确评估逻辑节点重要度。(2)在入侵检测方面,提出了一种类PWM波流量指纹模型来捕捉SAS网络流量的特征。此外,建立了一个基于Bernstein多项式的非参数R-vine Copula模型来进行训练数据集采样以实现数据均衡。为了保留原始特征的关键信息并避免将异常流量误判为正常流量,提出了同时面向过程和目标的损失函数来构建改进后的深度自编码高斯混合模型(Modified Deep Autoencoding Gaussian Mixture Model,MDAGMM)进行入侵检测。算例分析表明,所提检测框架对已知攻击和未知攻击都具备良好检测性能。(3)在风险评估方面,面向61850化配电信息物理系统,在通用状态估计模型的基础上建立了具有有限攻击知识的协同攻击模型。提出基于模糊贝叶斯网络(Bayesian Network,BN)的风险概率区间计算方法。在此基础上,提出以网络攻击下系统状态向量与量测向量产生的综合偏差作为物理后果度量指标,实现从信息侧到物理侧的跨空间风险评估。算例分析表明,所提方法可以充分揭示系统风险与相关攻击要素间的非线性关系。(4)在防御决策方面,为充分利用主动配电网中的资源,提出了计及多重不确定性的主动配电网孤岛鲁棒防御策略。针对风光出力和攻击策略不确定性,建立了防御者-攻击者-防御者(Defender-Attacker-Defender,DAD)三层两阶段鲁棒数学模型,第一阶段进行防御资源预分配,第二阶段在最恶劣运行场景下,调度紧急防御资源,使切负荷量最小。对模型采用列和约束生成算法(Column and Constraint Generation,C&CG)进行求解。算例分析表明,所提防御策略能够有效分配防御资源,减少负荷损失。
【Abstract】 The modern power system is not only significantly different from the traditional power system in the energy structure of the primary side,but also has a profound change in the measurement and control system on the secondary side.The innovation and progress of information technology have greatly improved the observability and controllability of the power system,which will develop into a green,low-carbon,widely interconnected,intelligent and interactive smart grid.The IEC 61850 standards possess high degree of openness,scalability,and self-describing capabilities.And they provide a standardized paradigm for interchange and interoperability that highly meet the vision of smart grid construction.Therefore,this series of standards has been widely used in smart substation and distribution systems,and has become one of the most important communication standards in power automation systems.However,the openness of the standards and the deep interaction of cyber-physics have led to blurred security boundaries,advanced security threats,and frequent security incidents for power grid.In the context,this thesis conducts research on the cyber security protection methodology of smart substation and distribution systems from three perspectives "node level","function level" and "system level".The closed-loop control idea driven by the model and data is adopted to improve the resilience against advanced cyber attacks,gain insight on security situations,optimize the defensive resources deployment and ensure the power system is safe and reliable.The main summary is shown as followings:(1)In terms of node importance quantification,a weighted and directed static complex network dynamics model is established for the 61850 Substation Automation System(SAS),and a method is proposed to integrate the topology value and information adjunction value of logical nodes by introducing a first-order linear feedback controller.On this basis,some definitions for equivalent network conversion are proposed to greatly reduce the complexity of original network topology.Also,the absolute value and relative value are introduced to quantify logical node importance from the perspective of node’s necessity and influence,respectively.Case studies show that the proposed method can accurately evaluate the importance of logical nodes.(2)In terms of intrusion detection,a PWM-like traffic fingerprint model inspired by pulse width modulation(PWM)is proposed to capture the features of SAS network traffic.Furthermore,the thesis establishes a Bernstein polynomial-based nonparametric R-vine copula model to do train dataset sampling for data balance.To preserve the key information of original features and reduce the risk of false negative,a both process-and objective-oriented loss function is proposed to construct an improved Deep Autoencoding Gaussian Mixture Model(MDAGMM)for intrusion detection.Case studies show that the proposed detection framework has good performance to detect both known and unknown attacks.(3)In terms of risk assessment,an integrated attack model with limited adversarial knowledge is established on the basis of the general state estimation model for the 61850 distribution network cyber-physical system.A calculation method of risk probability interval based on fuzzy Bayesian Network(BN)is proposed.On this basis,this thesis proposes to use the integrated deviation of system states and measurements under cyberattacks as the physical impact metric to realize the cross-space risk assessment from the cyber system to the physical system.Case studies show that the proposed method can fully reveal the nonlinear relationship between system risk and related attack factors.(4)In terms of defense decision-making,a robust active distribution network islanding defensive strategy considering multi-uncertainties is proposed to make full use of active resources.Aiming at the uncertainties of renewable outputs and attack strategy,a trilevel Defender-Attacker-Defender(DAD)and two-stage robust mathematical model is established.The first stage is to pre-allocate defensive resources.In the second stage,the emergent defensive resources are dispatched in the worst scenario to minimize the load shedding.The model is solved using Column and Constraint Generation(C&CG)algorithm.Case studies show that the proposed defensive strategy can effectively allocate defensive resources and reduce the load shedding.
【Key words】 smart grid; IEC61850; node importance; intrusion detection; deep learning; risk assessment; fuzzy Bayesian network; defensive strategy; two-stage robust optimization;