Netinfo Security ›› 2023, Vol. 23 ›› Issue (2): 26-34.doi: 10.3969/j.issn.1671-1122.2023.02.004

Previous Articles     Next Articles

An Advanced Persistent Threat Model of New Power System Based on ATT&CK

LI Yuancheng(), LUO Hao, WANG Qingle, LI Jianbin   

  1. School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
  • Received:2022-10-09 Online:2023-02-10 Published:2023-02-28
  • Contact: LI Yuancheng E-mail:ycli@ncepu.edu.cn

Abstract:

The establishment of a new power system with new energy as the main body has greatly increased the proportion of new energy and multiple load forms. The high proportion of renewable energy and power electronic equipment access, as well as the randomness of the supply side and the demand side, lead to an increase in the attack surface of the power grid. Advanced persistent threat (APT), which tamper or block data, seriously affect grid scheduling and energy consumption. Based on the ATT&CK knowledge base, a kill chain model for APT attacks on new power systems was established. It is difficult to divide the APT attack technology into the kill chain attack stage, resulting in the inability of security personnel to make defense decision-making quickly, a method of dividing APT attack technology stages based on the kill chain model was proposed. The Bert model was used to perform semantic analysis on technical texts, and the attack technologies were automatically divided into their respective stages by training the model. Experimental results show that this method achieves better results than existing models.

Key words: new power system, advanced persistent threat, ATT&CK, attack modeling, Bert model

CLC Number: