APT Attack Detection of a New Power System based on DPI-transformer

被引:0
|
作者
Zhang, Yazhuo [1 ]
Li, Yuancheng [1 ]
机构
[1] North China Elect Power Univ, Sch Control & Comp Engn, 2 Beinong Rd, Beijing 102206, Peoples R China
关键词
New power system; advanced persistent threat; transformer; deep packet inspection; attacks; transmission;
D O I
10.2174/2352096516666230504111123
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Introduction: In recent years, the frequent occurrence of network security attacks in the power field has brought huge risks to the production, transmission, and supply of power systems, and Advanced Persistent Threat (APT) is a covert advanced network security attack, which has become one of the network security risks that cannot be ignored in the construction of new power systems. Objective: This study aims to resist the increasing risk of APT attacks in the construction of new power systems, this paper proposes an attack detection model based on Deep Packet Inspection (DPI) and Transformer. Methods: Firstly, we extracted 606 traffic characteristics from the original traffic data through the extended CIC Flowmeter and used them all to train the Transformer network. Then, we used the DPI-Transformer model and traffic labels to perform feature analysis on the traffic data and finally obtained the APT-Score. If the APT-Score is greater than the threshold, the alarm module is triggered. Results: By analyzing the headers and payloads of the network traffic in the APT-2020 dataset, the experimental results show that the detection accuracy of APT attacks by the DPI-Transformer detection model is significantly higher than that of the current mainstream APT attack detection algorithms. Conclusion: Combined with the characteristics of the new power system and APT attacks, this paper proposes an attack detection model DPI-Transformer, which proves that the model has greatly improved the detection accuracy.
引用
收藏
页码:99 / 106
页数:8
相关论文
共 50 条
  • [1] An APT Attack Detection Method of a New-type Power System Based on STSA-transformer
    Yuan, Jiexuan
    Li, Yuancheng
    RECENT ADVANCES IN ELECTRICAL & ELECTRONIC ENGINEERING, 2024, 17 (01) : 19 - 28
  • [2] An APT Attack Detection Method Based on eBPF and Transformer
    Qiu, Rixuan
    Luo, Hao
    Jing, Sitong
    Li, Xinxiu
    Li, Yuancheng
    International Journal of Network Security, 2024, 26 (06) : 964 - 972
  • [3] Ontology Modeling for APT Attack Detection in an IoT-Based Power System
    Kim, Gihoon
    Choi, Chang
    Choi, Junho
    PROCEEDINGS OF THE 2018 CONFERENCE ON RESEARCH IN ADAPTIVE AND CONVERGENT SYSTEMS (RACS 2018), 2018, : 160 - 164
  • [4] A Generation Method of New Power System APT Attack Graph Based on DQN
    Wang, Zijia
    Li, Yuancheng
    RECENT ADVANCES IN ELECTRICAL & ELECTRONIC ENGINEERING, 2024, 17 (01) : 82 - 90
  • [5] A Defense Method Based on Moving Target Defense for New Power System APT Attack
    Li, Ruotong
    Li, Yuancheng
    International Journal of Network Security, 2023, 25 (04) : 587 - 594
  • [6] A new framework for APT attack detection based on network traffic
    Hoa Cuong Nguyen
    Cho Do Xuan
    Long Thanh Nguyen
    Hoa Dinh Nguyen
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (03) : 3459 - 3474
  • [7] NGSIEM Based APT Attack Analysis System
    Li, Yanfei
    Wang, Rui
    Li, Haiwei
    2018 4TH INTERNATIONAL CONFERENCE ON ENVIRONMENTAL SCIENCE AND MATERIAL APPLICATION, 2019, 252
  • [8] The APT Detection Method based on Attack Tree for SDN
    Jia Shan-Shan
    Xu Ya-Bin
    ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 116 - 121
  • [9] APT attack threat-hunting network model based on hypergraph Transformer
    Li Y.
    Lin Y.
    Tongxin Xuebao/Journal on Communications, 2024, 45 (02): : 106 - 114
  • [10] APT Attack Detection Based on Graph Convolutional Neural Networks
    Ren, Weiwu
    Song, Xintong
    Hong, Yu
    Lei, Ying
    Yao, Jinyu
    Du, Yazhou
    Li, Wenjuan
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2023, 16 (01)