User Station Security Protection Method Based on Random Domain Name Detection and Active Defense
- 1 School of Information Engineering, University of Shenyang, Shenyang, China
- 2 Shenyang Institute of Computing Technology, Chinese Academy of Sciences, Shenyang, China
- 3 Shenyang Institute of Computing Technology Co. Ltd., CAS, Chinese Academy of Sciences, Shenyang, China
- 4 Shenyang Institute of Computing Technology, Chinese Academy of Sciences, Shenyang, China
- 5 Turpan Electric Power Supply Company, State Grid Xinjiang Electric Power Company Limited, Turpan, China
Abstract
The power monitoring system is the most important production management system in the power industry. As an important part of the power monitoring system, the user station that lacks grid binding will become an important target of network attacks. In order to perceive the network attack events on the user station side in time, a method combining real-time detection and active defense of random domain names on the user station side was proposed. Capsule network (CapsNet) combined with long short-term memory network (LSTM) was used to classify the domain names extracted from the traffic data. When a random domain name is detected, it sent instructions to routers and switched to update their security policies through the remote terminal protocol (Telnet) , o r shut down the service interfaces of routers and switched to block network attacks. The experimental results show ed that the use of CapsNet combined with LSTM classification algorithm can achieve 99.16% accuracy and 98% recall rate in random domain name detection. Through the Telnet protocol, routers and switches can be linked to make active defense without interrupting services.
- Zhang, L. (2020) Analysis of Network Security Threat Traceability Technology of Power Monitoring System. Telecom Power Technology, 37, 3.
- Du, H.L., Kong, P.H., Jin, X.Q. and Huang, Y.Q. (2021) Traffic Anomaly Detection of Power Communication Networks Based on Deep Learning. Zhejiang Electric Power, 40, 117-123.
- Liu, D., Jiang, Z.W., Zhu, Y.W., et al. (2022) Network Traffic Anomaly Detection of Power Monitoring System Based on LDSAD. Zhejiang Electric Power, 41, 87-92.
- Yang, H., Liu, Y.S., Liu, G.H. and Zhou, F.Y. (2020) Safety Monitoring Technology of Power Grid Industrial Control System Based on Abnormal Detection of Network Traffic. Electronic Technology & Software Engineering, 22, 259-260.
- Li, Y.C. (2019) Research on Anomaly Detection Technology of Power Industrial Control Network Traffic Based on Machine Learning. Thesis, Shanghai Jiao Tong University, Shanghai.
- Liu, Y.L., Meng, L.Y. and Ding, Y.F. (2018) Application and Algorithm Improvement of Abnormal Traffic Detection in Smart Grid Industrial Control System. Computer Systems & Applications, 27, 173-178.
- Liu, B., Li, L., Liu, J.N., et al. (2021) Analysis of Weak Links in Network Security of Power Monitoring System in New Energy Fields. Electric Engineering, 18, 78-80.
- Jin, X.Q., Su, D., Mao, N.P., et al. (2019) Research on Active Monitoring and Early Warning Technology for New Energy Station. Zhejiang Electric Power, 38, 106-112.
- Gunduz, M.Z. and Das, R. (2020) Cyber-Security on Smart Grid: Threats and Potential Solutions. Computer Networks, 169, Article ID: 107094. https://doi.org/10.1016/j.comnet.2019.107094
- Yadav, S., Reddy, A.K.K. and Reddy, A.L.N. (2010) Detecting Algorithmically Generated Malicious Domain Names. Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement, Melbourne, 1-30 November 2010, 48-61. https://doi.org/10.1145/1879141.1879148
- Schiavoni, S., Maggi, F. and Cavallaro, L. (2014) Phoenix: DGA-Based Botnet Tracking and Intelligence. In: International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Springer, Cham, 192-211. https://doi.org/10.1007/978-3-319-08509-8_11
- Zhang, W.W., Gong, J., Liu, Q., et al. (2016) Lightweight Domain Name Detection Algorithm Based on Morpheme Features. Journal of Software, 27, 2348-2364.
- Truong, D.T. and Cheng, G. (2016) Detecting Domain-Flux Botnet Based on DNS Traffic Features in Managed Network. Security and Communication Networks, 9, 2338-2347. https://doi.org/10.1002/sec.1495