电器与能效管理技术 ›› 2021, Vol. 0 ›› Issue (8): 16-23.doi: 10.16628/j.cnki.2095-8188.2021.08.004

• 研究与分析 • 上一篇    下一篇

基于机器学习算法的电力信息网络安全态势感知研究

张小飞1, 张道银1, 郑珞琳1, 陈德成2, 付蓉2   

  1. 1.国网电力科学研究院有限公司,江苏 南京 211106
    2.南京邮电大学 自动化学院, 江苏 南京 210023
  • 收稿日期:2021-03-21 出版日期:2021-08-30 发布日期:2021-10-14
  • 作者简介:张小飞(1981—),男,高级工程师,主要从事信息安全与软件测试方面的研究。|张道银(1980—),男,高级工程师,主要从事信息安全与软件测试方面的研究。|郑珞琳(1987—),女,高级工程师,主要从事信息安全与软件测试方面的研究。
  • 基金资助:
    *国家电网总部科技项目资助(5108-202118056A-0-0-00)

Research on Power Information Network Security Situation Awareness Based on LDA-RBF

ZHANG Xiaofei1, ZHANG Daoyin1, ZHENG Luolin1, CHEN Decheng2, FU Rong2   

  1. 1. State Grid Electric Power Research Institute,Nanjing 211106,China
    2. College of Automation,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
  • Received:2021-03-21 Online:2021-08-30 Published:2021-10-14

摘要:

为精准预测电力信息网络安全态势,提出一种基于机器学习算法的电力信息网络安全态势感知方法,将感知问题抽象化,通过感知模型来表征感知结果。基于线性判别分析方法进行样本数据的预处理,优化样本数据以获取组合特征,找出最佳投影;然后将处理后的数据作为RBF神经网络训练输入,找出与网络态势值的映射关系,从而量化系统的安全态势。最后通过KDD Cup99数据集与电力信息网络的攻击数据进行仿真比较,验证所提方法在网络安全态势分析中的可靠性。

关键词: 网络安全态势感知, 电力信息网络, 网络攻击, 线性判别分析(LDA), RBF神经网络

Abstract:

To accurately predict the security situation of power information network,a network security situation awareness method based on machine learning is proposed.In this method,the network security situation awareness is abstracted as a numerical quantization problem,and a large number of test samples are used as data sources to input the situational awareness model to characterize the perceived results.Based on the linear discriminant analysis (LDA),the test data is preprocessed to optimize the sample data to obtain combined features and find out the best projection.Then the processed data are used as input of RBF neural network to find the nonlinear mapping relation of the network situation value,and the network security situation is quantified.Finally,the effectiveness of the proposed method in the security situation analysis is verified through KDD Cup99 dataset and the cyber attack data in the power information network.

Key words: network security situation awareness, power information network, cyber attack, linear discriminant analysis(LDA), RBF neural network

中图分类号: