基于告警日志的智能电网重点事件检测模型
ritical Events Detection Based on Alert Logs in Smart Grid
智能电网的告警日志来自多种安全设备和主机,聚合之后不易进行进一步的分析,本文借鉴以往安全事件在爆发过程中存在活动异常的特点,提出了一种基于统计分析的智能电网重点事件检测模型。本文提出的模型充分利用了智能电网监控系统中安全设备产生的日志信息,将统计分析的方法与安全事件日志相结合,设计了重点事件检测算法,对安全事件序列进行检测,检测出安全事件序列中的重点安全事件,以便相关人员及时关注并处理。通过智能电网中的实际数据初步表明,本模型可以有效地检测出重点安全事件,提高设备报警准确率。
lert logs in the smart grid come from a variety of security devices and hosts, which are not easy to conduct further analysis after aggregation. In this paper, a critical event detection model based on statistical analysis is proposed, which takes advantage of the fact that past security events have abnormal activities in the process of explosion. The model makes full use of the log information in the smart grid monitoring system (SGMS), combines the statistical analysis method with the security event logs. And a critical event detection algorithm is designed to detect the security event sequence to find the critical events. The operators can pay attention to the critical events and deal with them in time. The results from real data in China Smart Grid show that the model can effectively detect critical events and improve the accuracy of device alerts.
李文敏、赵浩亮
自动化技术、自动化技术设备电工技术概论安全科学
网络空间安全智能电网重点事件异常检测日志告警
cyberspace securitysmart gridcritical eventanomaly detectionlogalert
李文敏,赵浩亮.基于告警日志的智能电网重点事件检测模型[EB/OL].(2021-03-10)[2025-08-11].http://www.paper.edu.cn/releasepaper/content/202103-107.点此复制
评论