A Data Mining Method for Analyzing Alarm Logs Generated by Network Boundary Defense Equipment In Power Grid

Hongyu Zhu, Hai Lin, Yizhen Sun, Mingguang Li, Dali Deng, Xin Xiao, Zhang Yile · 2023

Network boundary defense equipment is crucial for the power grid cyber-security. Alert logs generated by network boundary equipment serve as important data source for detecting potential attacks. However, the lack of direct correlation between alerts and network attacks make it difficult to pinpoint equipment at risk of attack from the extensive pool of alert logs. This paper proposes a data mining method for analyzing alarm logs generated by network boundary defense equipment. The method conducts data mining in four perspectives: ontology mining, carrier mining, transverse mining, and vertical mining. Compared to traditional alert analysis techniques, this method integrates cyber-security with power grid characteristics such as topology, enabling the identification of boundary equipment with substantial state changes and facilitating precise localization of devices at risk of attack.

Read the paper · More papers on PaperTik