Wireless Communication Security Defense and Monitoring in Smart Grids

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher

Abstract

Abstract With the development of smart grids, wireless communication security issues have become increasingly prominent, including data eavesdropping, denial of service attacks, malicious software, and physical layer threats, which pose a serious threat to the stability and security of smart grid systems. In response to this situation, this article studies the security protection and monitoring of wireless communication in smart grids. A comprehensive security defense and monitoring structure is constructed by using the long short-term memory network technology. Firstly, through the analysis of existing protection mechanisms, a defense and monitoring system integration scheme based on a data sharing platform is proposed. Secondly, functional test, performance test, and security test are conducted based on the proposed system architecture. The low orbit ion cannon (LOIC) tool is used to simulate distributed denial of service (DDoS) attacks and verify the performance of the system under different attack intensities. At the same time, load test is conducted using Apache JMeter to evaluate the performance of the system under high loads. Finally, penetration test is carried out using the Metasploit tool to evaluate the system’s ability to resist various attacks. The experimental results show that the accuracy of the system remains between 82.2% and 96.5% under attack frequency of 500–5000 times per second in the functional test, and the response time is extended from 120 milliseconds to 390 milliseconds, indicating high protection capability in low-intensity attacks. The performance test results show that when the number of concurrent requests increases from 500 to 5000, the CPU utilization increases from 30–99%; the memory usage increases from 150MB to 550MB; the system response time is significantly prolonged, reflecting the performance bottleneck under high-load conditions. In the security test, the blocking rates of SQL (structured query language) injection and cross-site scripting (XSS) attacks reach 98% and 97% respectively, demonstrating the system’s effective defense capability against various attacks. In summary, this article provides an effective solution for the security protection of smart grids and points out the shortcomings of the system under high-intensity attacks and loads, providing important references for future research.
Full text 138,799 characters · extracted from preprint-html · click to expand
Wireless Communication Security Defense and Monitoring in Smart Grids | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Wireless Communication Security Defense and Monitoring in Smart Grids Junbao Duan, Gengshuo Liu, Shuyan Zeng, Han Liu, Hongzhi Zhang, and 3 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5352293/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract With the development of smart grids, wireless communication security issues have become increasingly prominent, including data eavesdropping, denial of service attacks, malicious software, and physical layer threats, which pose a serious threat to the stability and security of smart grid systems. In response to this situation, this article studies the security protection and monitoring of wireless communication in smart grids. A comprehensive security defense and monitoring structure is constructed by using the long short-term memory network technology. Firstly, through the analysis of existing protection mechanisms, a defense and monitoring system integration scheme based on a data sharing platform is proposed. Secondly, functional test, performance test, and security test are conducted based on the proposed system architecture. The low orbit ion cannon (LOIC) tool is used to simulate distributed denial of service (DDoS) attacks and verify the performance of the system under different attack intensities. At the same time, load test is conducted using Apache JMeter to evaluate the performance of the system under high loads. Finally, penetration test is carried out using the Metasploit tool to evaluate the system’s ability to resist various attacks. The experimental results show that the accuracy of the system remains between 82.2% and 96.5% under attack frequency of 500–5000 times per second in the functional test, and the response time is extended from 120 milliseconds to 390 milliseconds, indicating high protection capability in low-intensity attacks. The performance test results show that when the number of concurrent requests increases from 500 to 5000, the CPU utilization increases from 30–99%; the memory usage increases from 150MB to 550MB; the system response time is significantly prolonged, reflecting the performance bottleneck under high-load conditions. In the security test, the blocking rates of SQL (structured query language) injection and cross-site scripting (XSS) attacks reach 98% and 97% respectively, demonstrating the system’s effective defense capability against various attacks. In summary, this article provides an effective solution for the security protection of smart grids and points out the shortcomings of the system under high-intensity attacks and loads, providing important references for future research. Smart Grid Wireless Communication Security Security Defense Intelligent Monitoring Long Short-Term Memory Figures Figure 1 Figure 2 1. Introduction As an innovative development mode of modern power systems, smart grids combine advanced information technology, communication technology, and power transmission technology, significantly improving the intelligence level of power systems [ 1 – 2 ]. Through bidirectional data flow, real-time monitoring, and remote control, smart grids can achieve comprehensive optimization and efficient management of power generation, transmission, and consumption. Wireless communication technology has been widely applied and is the key to the efficient operation of smart grids. It covers a vast area and connects a large number of terminal devices (such as smart meters, sensors, distributed energy, etc.), achieving real-time data exchange and device control. However, the widespread application of wireless communication technology has also brought new security challenges. Due to its openness, wireless communication environments are highly susceptible to external attacks, significantly increasing the network security risks faced by smart grids. Common security threats include data eavesdropping, denial of service (DoS) attacks, malicious node hijacking, data tampering, etc. [ 3 – 4 ]. These threats may not only lead to the breach of user privacy, but also seriously affect the stability of the power grid and even cause large-scale power outages. Traditional security protection measures such as encryption and access control are often insufficient when dealing with complex network attacks. At the same time, the existing monitoring system has a lag in detecting and responding to security incidents and lacks an efficient real-time monitoring and early warning mechanism. Therefore, there is an urgent need to build an integrated security defense and monitoring system to comprehensively deal with security threats in smart grids. The objective of this article is to design and implement a system that integrates security defense and intelligent monitoring to address the security challenges in smart grid wireless communications. Through the new security defense mechanism, the confidentiality, integrity and anti-attack capabilities of wireless communication data are enhanced. At the same time, this article also studies a system for real-time monitoring of the status of power grid equipment and communication networks to improve the speed and accuracy of response to abnormal situations and potential attacks. Through the collaboration of defense and monitoring systems, network threats can be dynamically perceived, and timely defense measures can be taken, thus enhancing the security and reliability of smart grids. The main contributions of this article are as follows: A comprehensive smart grid wireless communication security defense system is established, covering encryption, authentication, and multi-level protection strategies, effectively resisting common threats such as data eavesdropping and denial of service attacks. An intelligent monitoring system is designed and implemented, which can monitor devices and communication networks in smart grids in real time and identify potential security issues in a timely manner through anomaly detection technology. Effective integration of defense and monitoring systems is achieved. A collaborative mechanism is proposed to enable the monitoring system to trigger defense mechanisms in real time, and protection strategies can be adaptively adjusted according to different threat scenarios to ensure the efficient and secure operation of the system. The effectiveness and feasibility of the designed system are verified through experiments, and the results show that the system can effectively respond to various security threats with minimal impact on wireless communication performance. 2. Current Status of Wireless Communication Security Issues in Smart Grids (1) Application of the wireless communication technology in smart grids Wireless communication technology provides highly flexible network connectivity and information exchange capabilities for smart grids. Wireless communication technologies such as 4G, 5G, Wi-Fi (wireless fidelity), ZigBee, LoRa (long range radio) and other technologies are widely used in the power grid [5-7]. 4G and 5G, with their advantages of high bandwidth and low latency, are commonly used in remote control and massive data transmission scenarios. For example, smart grid projects in China commonly use 5G technology to enhance real-time response and system reliability. However, despite the superior performance of 5G networks, their high construction costs and insufficient coverage in some areas remain global technological challenges. Low-power consumption communication technologies such as ZigBee and LoRa perform well in distributed energy management and smart meter communication. LoRa is particularly suitable for wide area coverage scenarios and has been widely used in rural and remote areas of countries such as France. At present, the main research focus in China is on how to optimize the practical application of the low-power consumption technologies, and especially in large-scale deployment tasks, improving their reliability and energy conservation is particularly important. However, the current technologies are still insufficient in terms of transmission rate and anti-interference ability, which has become a great obstacle to the further application of them. (2) Security threats of wireless communication in smart grids Current security threat research in wireless communication focuses on data theft, denial of service attacks, malware, and physical layer threats. In particular, rich experience has been accumulated in preventing data theft and defending against cyber-attacks. Key institutions over the world have developed data protection frameworks based on encryption and authentication technologies. These frameworks are effective in preventing unauthorized access and data tampering through public key infrastructure (PKI). In addition, these institutions not only attach importance to encryption technology, but also emphasize the importance of identity authentication and access control to ensure the secure transmission and storage of data in smart grids. Implementing these standards helps to enhance the defense against potential cyber-attacks [8-9]. In recent years, significant progress has also been made in related research in China. An increasing number of studies have begun to combine SM2 and SM4 algorithms to improve data security in communication [10-11]. In addition, scholars have proposed a machine learning-based network attack detection model that can perform real-time detection and early warning for complex attack scenarios such as denial of service attacks, significantly improving the anti attack capability of the power grid. (3) Security protection and monitoring measures In terms of protection measures, a hierarchical security defense strategy is usually adopted, including encryption, authentication, access control, and partition isolation. For example, smart grid projects often adopt role-based access control and multi-layer firewall technology to ensure effective protection at all levels of the system. In recent years, distributed identity authentication schemes based on blockchain have gradually received attention, especially in identity management and protection against malicious nodes in the power grid, showing great potential. In terms of intelligent monitoring systems, research focuses more on the application of big data analysis and artificial intelligence technology [12-13]. For example, some research projects in Europe have used machine learning-based power grid monitoring systems that can analyze historical data, identify potential attack behaviors, and issue early warnings. China places more emphasis on rule-based detection systems. Although deep learning models have been attempted in recent years, there are still certain limitations in their practical applications. However, China has made significant progress in the precision and real-time performance of intelligent monitoring technology, especially in the comprehensive monitoring system that combines power grid operation data and communication network status, demonstrating great application prospects [14]. Overall, other countries have relatively mature research in smart grid security protection and monitoring technologies, especially in the fields of encryption, intrusion detection, and anomaly monitoring, and relatively complete systems have been formed. Although China’s research started relatively late, rapid progress has been made in encryption algorithms and intelligent monitoring systems, gradually forming a security protection framework with Chinese characteristics. 3. Construction of Comprehensive Wireless Communication Security Defense System 3.1 Design Objectives Constructing a comprehensive wireless communication security defense system requires clear design objectives and principles to ensure that smart grids have efficient security protection capabilities in dynamic environments. The design objectives include high efficiency, low resource consumption, adaptability, and improved system robustness. 3.2 Security Defense Mechanisms in Wireless Communication 1. Data encryption and decryption Data encryption and decryption is crucial in smart grid systems. In the security defense system constructed in this article, data encryption is achieved by combining symmetrical encryption (Advanced Encryption Standard, AES) with asymmetrical encryption (Rivest-Shamir-Adleman, RSA) [ 15 – 16 ]. The encryption and decryption formulas of symmetrical encryption algorithm are as follows: $$\:\text{C}=\:{E}_{k}\left(M\right)$$ 1 $$\:\text{M}=\:{D}_{k}\left(C\right)$$ 2 where C is ciphertext, that is, the encrypted data. \(\:{E}_{k}\) is an encryption function using the key k . M is the data before encryption. The encryption and decryption formulas of asymmetrical encryption algorithms are as follows: $$\:\text{C}=\:{E}_{Pk}\left(M\right)$$ 3 $$\:\text{M}=\:{D}_{Sk}\left(C\right)$$ 4 where Pk is the public key, and Sk is the private key. 2. Identity authentication mechanism Identity authentication is a key technology to ensure the legitimacy of both communicating parties. This article adopts a combination of digital certificates and public key infrastructure (PKI) to jointly implement the identity authentication function [ 17 ]. The system generates a unique public-private key pair for each device and obtain a digital certificate through a authentication authority. During communication, devices are authenticated by sending certificates and signature messages. For example, in the smart grid, when device a sends a message M to device b , it uses a private key to digitally sign to ensure the authenticity and integrity of the message. After receiving the message, device b verifies the signature to confirm the identity and source of the message. This mechanism enhances the system’s ability to protect against unauthorized access. The signature formula is as follows: $$\:{S}_{a}={D}_{S{k}_{a}}\left(H\right(M\left)\right)$$ 5 In Formula (5), \(\:{S}_{a}\) is the signature of device a , and H is the hash function. 3. Access control and permission management Role-based access control (RBAC) can set different permissions based on different roles [ 18 ]. Therefore, in the security defense system constructed in this article, a permission matrix X is designed: $$\:{X}_{i,j}=\left\{\begin{array}{c}1\\\:0\end{array}\right.$$ 6 If user i has access permission to j , the system returns 1 after i sends a request to j , and returns 0 if there is no permission, thereby ensuring that only users and devices with corresponding permissions can access specific resources. 4. Wireless link handover security In the smart grid, wireless link handover security is also a key consideration. Through wireless link handover, unauthorized terminals may illegally access the network, steal important information, and pose a security risk to the smart grid. One solution is to strengthen the authentication and management of handover users in the power grid. Considering that user authentication mechanisms already exist in 4G and 5G networks, a secondary authentication mechanism can be introduced on the basis of standard authentication mechanisms. The power terminal monitors the quality of the wireless link through channel quality measurement. When a handover needs is triggered, the dedicated AAA server deployed by the power grid initiates secondary authentication for the terminal. eSIM is commonly used in power grid terminals to store security related parameters, and dedicated mechanisms can be used for secondary authentication to ensure higher levels of security .5. Intrusion detection and prevention systems The design of intrusion detection system (IDS) and intrusion prevention system (IPS) is an important part of achieving the protection goal of this article [ 19 – 20 ]. In this article, Formula (7) is used to measure whether the information flow is abnormal: $$\:\text{A}\text{b}\text{n}\text{o}\text{r}\text{m}\text{a}\text{l}\text{i}\text{t}\text{y}\left(\text{x}\right)=\:\frac{|x-\mu\:|}{\sigma\:}$$ 7 6. Dynamic adaptive defense mechanism The dynamic adaptive defense mechanism is an innovation of the security system constructed in this article. By using artificial intelligence and machine learning technology, the defense system constructed in this article is able to adjust security policies by analyzing and learning from real-time data. When the system detects abnormal access patterns, it automatically increases the security level and take security measures to prevent possible problems. The dynamic adjustment formula of the system is as follows: $$\:{S}_{new}={S}_{old}+{\Delta\:}S$$ 8 7. Multi-level defense To better achieve the protection function of the system, this article constructs a multi-level defense system to ensure the overall security of the smart grid from the three layers of physical layer, network layer and application layer [ 21 ]. At the physical layer, secure communication equipment and signal shielding technology are used to defend against potential physical attacks. At the network layer, data encryption and identity authentication technology are implemented to ensure the security of data transmission. Finally, at the application layer, secure coding practices are adopted, and system vulnerability scans are performed regularly to identify and repair unknown security risks. 4. Design of Intelligent Monitoring System Based on LSTM 4.1 Roles of Detection Target and LSTM Model The main function of the intelligent monitoring system is to monitor the network status and equipment operation of smart grids in real time. To achieve this goal, the key is to quickly identify potential security threats and anomalies. The system constructed in this article achieves the purpose of rapid identification by deeply analyzing time series data, so that the system can not only issue early warnings in a timely manner, but also help operation and maintenance personnel to respond quickly, effectively reducing the impact of security incidents on normal operations. Long short-term memory (LSTM) network is a deep learning model that specializes in processing time series data. It performs well in capturing time series features and is therefore widely used in intelligent monitoring systems [ 22 ]. Using the LSTM model, the system can more precisely predict and identify complex abnormal patterns, further improving the reliability and response speed of monitoring. 4.2 Data Collection and Preprocessing 1. Data collection In the early stage of system construction, data collection is the first step. The data for this article comes from a variety of devices and networks covered by smart grids, and the data types include network traffic, device status, and event logs. During the data collection process, network traffic data is collected through the network packet capture tool Wireshark, and the recorded data includes packet size, traffic rate, source and target IP addresses, etc. Device status data is obtained through the monitoring tool Prometheus, covering central processing unit (CPU) utilization, memory usage and other information. Event logs are generated by the logging mechanism of each device, recording important operations and status changes of the device. About 1,440 pieces of device status data are collected every day, and about 100,000 pieces of event logs are recorded. The total amount of data collected eventually reaches 300,000 pieces. Some of the collected data are shown in Table 1 . Table 1 Part of collected data Data Types Timestamp Source IP Target IP Packet size (bytes) Traffic rate (Mbps) CPU utilization (%) Memory usage (%) Event Description Network traffic 2024-09-01 10:00:00 192.168.1.1 192.168.1.2 1500 10.5 - - - Network traffic 2024-09-01 10:00:01 192.168.1.1 192.168.1.3 1200 12.3 - - - Network traffic 2024-09-01 10:00:02 192.168.1.2 192.168.1.1 1400 9.8 - - - Network traffic 2024-09-01 10:00:03 192.168.1.2 192.168.1.4 1600 11.2 - - - Device Status 2024-09-01 10:00:00 - - - - 45 60 Device is operating normally. Device Status 2024-09-01 10:00:01 - - - - 50 62 CPU utilization increases. Device Status 2024-09-01 10:00:02 - - - - 70 - Device load increases. Event Log 2024-09-01 10:00:00 - - - - - - User login Event Log 2024-09-01 10:00:01 - - - - - - User logout Event Log 2024-09-01 10:00:02 - - - - - - Alert: Abnormal flow (2) Data preprocessing In the data preprocessing stage, the first step is to remove missing values and outliers. Missing values can be processed by filling in the mean, and the formula is as follows $$\:{x}_{i}=\left\{\begin{array}{c}{x}_{i}\:if\:{x}_{i}\:is\:not\:missing\\\:\widehat{x}\:\:if\:{x}_{i}\:is\:missing\:\:\:\end{array}\right.$$ 9 Outliers are identified using the interquartile range (IQR) method. In this identification process, the first step is to calculate the number Q1 in the first quartile and the number Q3 in the third quartile, and IQR is calculated through Q1 and Q3 [ 23 ]. $$\:\text{I}\text{Q}\text{R}=\text{Q}3-\text{Q}1$$ 10 Subsequently, it is necessary to define the upper and lower limits of outliers using the following formulas: $$\:\text{L}\text{o}\text{w}\text{e}\text{r}\:\text{B}\text{o}\text{u}\text{n}\text{d}=\text{Q}1-1.5\times\:\text{I}\text{Q}\text{R}$$ 11 $$\:\text{U}\text{p}\text{p}\text{e}\text{r}\:\text{B}\text{o}\text{u}\text{n}\text{d}=\text{Q}3+1.5\times\:\text{I}\text{Q}\text{R}$$ 12 Next, data normalization processing is performed. All features are scaled to the interval [0,1] for model training. The normalization formula is: $$\:{x}^{{\prime\:}}=\frac{x-\text{m}\text{i}\text{n}\left(x\right)}{\text{m}\text{a}\text{x}\left(x\right)-\text{m}\text{i}\text{n}\left(x\right)}$$ 13 Finally, the sliding window technology is used to construct time series samples. The window size is set to 10. According to the division of every 10 time steps, input samples are formed, and the shape of the samples is (number of samples, 10, number of features). After constructing the samples, the preprocessed data is used for training at a ratio of 80% and for testing at a ratio of 20%, ensuring that the time series of training and testing data do not overlap. 4.3 Model Construction and Training Based on LSTM LSTM is a special recurrent neural network (RNN) that is widely used in the processing and prediction of time series data [ 24 – 25 ]. Compared with traditional RNN, LSTM effectively solves the gradient vanishing problem in long sequence data through “memory cells”. Its core structure includes input gate, forget gate and output gate, which respectively control the storage, discarding and output of information, so that LSTM can capture long-term dependencies in time series and improve prediction accuracy. When building the LSTM model, the input layer with an input shape of (10, number of features) is firstly defined, indicating that the model receives data from the past 10 time steps for prediction. Then, a layer of LSTM cells with 64 cells is added, and the ReLU activation function is used to bring nonlinear characteristics to enhance the expressiveness of the model. Finally, a neuron is set as the output layer to output the predicted value of the next time step. In addition, when training the model, appropriate loss functions and optimizers need to be selected to improve the performance of the model. In terms of regression problems, mean-square error (MSE) is a commonly used as the loss function, and the formula is: $$\:\text{M}\text{S}\text{E}\:=\:\frac{1}{\text{n}}\sum\:_{\text{i}\:=1}^{\text{n}}{({\text{y}}_{\text{i}}-{\widehat{\text{y}}}_{\text{i}})}^{2}$$ 14 In Formula (14), \(\:{\text{y}}_{\text{i}}\) is the actual value, and \(\:{\widehat{\text{y}}}_{\text{i}}\) is the predicted value. The Adam optimizer is widely used due to its adaptive learning rate feature [ 26 – 27 ], with an initial learning rate set to 0.001. During the training process, the total training epochs are set to 100, and the batch size is set to 32. After each training epoch, the training loss and accuracy are recorded, and the performance of the model is verified and evaluated to observe the learning process of the model. The specific training process is shown in Fig. 1 : To improve the performance of the model, hyperparameter optimization is an indispensable step [ 28 ]. Hyperparameters include learning rate, number of LSTM cells, batch size, etc. This article uses the grid search method combined with cross-validation to evaluate the performance of different hyperparameter combinations. Firstly, the hyperparameter ranges are defined. The learning rate range is set to [0.0001, 0.001, 0.01]. The number of LSTM cells is set to [32, 64, 128]. The batch size is set to [16, 32, 64]. The hyperparameter combinations for the experiment are shown in Table 2 . Table 2 Hyperparameter combinations Combination number Learning rate Number of LSTM cells Batch size 1 0.0001 32 16 2 0.0001 32 32 3 0.0001 32 64 4 0.0001 64 16 5 0.0001 64 32 6 0.0001 64 64 7 0.0001 128 16 8 0.0001 128 32 9 0.0001 128 64 10 0.001 32 16 11 0.001 32 32 12 0.001 32 64 13 0.001 64 16 14 0.001 64 32 15 0.001 64 64 16 0.001 128 16 17 0.001 128 32 18 0.001 128 64 19 0.01 32 16 20 0.01 32 32 21 0.01 32 64 22 0.01 64 16 23 0.01 64 32 24 0.01 64 64 25 0.01 128 16 26 0.01 128 32 27 0.01 128 64 Each combination is trained on the training set, and its performance is evaluated on the testing set through cross-validation. The loss value and accuracy of each training session are recorded, and the results are shown in Fig. 2 . In Fig. 2 , the red curve represents the loss value; the blue curve represents accuracy; the black arrows mark the values with the highest accuracy and the smallest loss. Combination 23 has the smallest loss value and the highest accuracy, with a learning rate of 0.01, 64 LSTM cells, and a batch size of 32, resulting in the best performance. Its loss value on the testing set is reduced to 0.029, and its accuracy is improved to 94.7%. Therefore, the hyperparameter configuration selected in this article is with a learning rate of 0.01, 64 LSTM cells, and a batch size of 32. This process ensures the generalization ability and predictive performance of the final model. 4.4 Real-time Monitoring and Response Mechanism for Security Incidents Once the model training is completed, the intelligent monitoring system can receive new time series data in real time, analyze and predict it. When the prediction result shows an abnormality, the system immediately issues an alarm to prompt the operation and maintenance personnel to conduct further inspection. The comparison between each predicted result and the actual situation is recorded by the system. All data is saved in log files for subsequent auditing and analysis. By comparing historical data, the security team can track potential attack sources and abnormal behavior, quickly locate problems, and take corresponding measures. When potential security incidents are identified, the system automatically executes response mechanisms, restricts the access permissions of suspicious devices, and isolates abnormal traffic to prevent it from affecting the entire network. Through this monitoring and response mechanism, the intelligent monitoring system can timely detect potential problems, help operation and maintenance personnel respond quickly, and reduce the risk of system failures, thereby ensuring the secure and stable operation of the power grid. 5. Collaborative Work of Security Defense and Monitoring System 5.1 Collaborative Design of Defense and Monitoring A unified data sharing platform is built in this article to achieve efficient collaboration between security defense and intelligent monitoring systems. The platform can capture data generated by the network and devices in real time, so as to quickly identify abnormal activities or potential threats and alert managers while passing relevant information to the defense system. When there is an abnormal increase in network traffic or a problem with the status of a device, the monitoring system provides instant feedback of critical information so that the defense mechanisms can react quickly. After receiving the alert, the defense system takes necessary measures such as limiting access to suspicious devices, encrypting sensitive data, and starting traffic filtering to reduce the risk of successful attacks. The mechanism is also capable of quickly restoring normal operation after an incident, thus maintaining the stability and security of the system. In addition, the monitoring system is able to continuously and automatically update its algorithms to enhance its ability to detect threats in the future by analyzing historical data and learning new attack patterns. This adaptive security policy ensures that the system can effectively respond to changing security challenges, thereby ensuring the overall security and reliability of smart grids. 5.2 Closed-loop Feedback Mechanism In this article, the feedback mechanism is constructed to realize the closed-loop of adaptive security defense and monitoring functions [ 29 – 30 ]. The feedback mechanism is implemented through the following steps. First, when the defense system successfully isolates a suspicious device, the monitoring system records and analyzes the effectiveness of the event and submit feedback. The feedback not only covers the successful prevention of attacks, but also includes false positives and undetected threats, providing data support for subsequent optimization. The monitoring system adjusts the monitoring strategy accordingly, updating the threshold or adopting a new feature recognition model to increase sensitivity to new attacks. In addition, regular security drills and assessments can further enhance the overall protection capabilities of the system. By simulating different types of network attacks and observing the responses of the defense and monitoring systems, potential weaknesses can be identified. 6. System Testing and Validation After constructing the security protection and monitoring system, comprehensive testing is conducted to ensure its effectiveness and reliability. The testing environment adopts the following configuration. In terms of hardware, the server configuration is Intel Xeon E5-2620; the memory is 16GB; the network bandwidth is 1Gbps. In terms of software, the operating system is Ubuntu 20.04, and the firewall configuration is iptables. Tests are divided into three aspects: functional test, performance test, and security test. The following is a detailed experimental process and results. 6.1 Functional Test Functional test aims to evaluate the system’s ability to protect against simulated attacks. This article uses the low orbit ion cannon (LOIC) tool to simulate distributed denial of service (DDoS) attacks, with a set attack frequency of 500–5000 attacks per second. During the testing process, the system’s response time and accuracy are recorded separately to ensure the accuracy of the results. Multiple tests are conducted for each attack scenario to ensure the stability of results. The experimental results are shown in Table 3 . Table 3 Functional test results Experiment number Attack frequency (times/second) Response time (ms) Accuracy (%) 1 500 120 96.5 2 1000 150 93.7 3 1500 180 92.1 4 2000 210 90.6 5 2500 240 89.5 6 3000 270 87.3 7 3500 300 85.2 8 4000 330 83.7 9 4500 360 82.2 10 5000 390 82.5 In the functional test, DDoS attacks of different scales are simulated. According to Table 3 , experiment numbers 1 to 10 show the system response time and accuracy when the attack frequency varies from 500 times/second to 5000 times/second. As the attack intensity increases, the response time gradually extends, rising from 120 milliseconds to 390 milliseconds, while the accuracy shows a gradually decreasing trend, decreasing from 96.5–82.5%. For example, when the attack frequency is 1000 times/second, the system’s response time is 150 milliseconds, and the accuracy is 93.7%; when the attack frequency is 4000 times per second, the response time reaches 330 milliseconds, and the accuracy drops to 83.7%. The results indicate that the system can still maintain high accuracy and fast response time in the face of low-intensity attacks, reflecting the effective protection capability of the system in the smart grid environment. However, with the increase of attack intensity, although the accuracy is still above 80%, the system’s responsiveness is significantly affected. This suggests that further optimization of system performance is needed when designing protective measures to enhance its defense capability in high-intensity attack situations. 6.2 Performance Test The purpose of performance test is to evaluate the resource consumption of the system under different loads. This article uses Apache JMeter to create a load test, simulating different user request scenarios with 500–5000 concurrent requests. In each scenario, the test lasts for 10 minutes to collect stable data. The test results are shown in Table 4 . Table 4 Performance test results Experiment number Number of requests (times/second) CPU utilization (%) Memory usage (MB) Average response time (ms) Maximum response time (ms) 1 500 30 150 120 150 2 1000 45 180 135 160 3 1500 60 220 180 210 4 2000 75 260 200 230 5 2500 85 300 240 270 6 3000 90 350 260 290 7 3500 92 400 280 310 8 4000 95 450 300 340 9 4500 97 500 330 370 10 5000 99 550 360 400 According to the data in Table 4 , the performance of the system is significantly affected when the number of requests increases from 500 times/second to 5000 times/second. When the number of requests is 500 times/second, the CPU utilization rate is 30%; the memory usage is 150MB; the average response time is 120 milliseconds; the maximum response time is 150 milliseconds, indicating that the system can respond quickly under low load. As the number of requests increases to 2500 times/second, the CPU utilization increases to 85%; the memory usage reaches 300MB; the average response time extends to 240 milliseconds; the maximum response time increases to 270 milliseconds, indicating that the system gradually responds slowly under high-load conditions. Especially when the number of requests reaches 5000 times/second, the CPU utilization rate reaches almost 99%, and the average response time and maximum response time increase to 360 milliseconds and 400 milliseconds respectively, indicating that under extreme load, the system’s performance is close to saturation, which may affect the efficiency of real-time monitoring and protection. 6.3 Security Test The purpose of security test is to evaluate the system’s ability to resist potential attacks. The Metasploit penetration testing tool is used to simulate various attack scenarios, including structured query language (SQL) injection and cross-site scripting (XSS) attacks. During the test, the system is constantly scanned by the test tool, and attempts are made to launch attacks using known vulnerabilities. Each attack lasts for 30 minutes, and the backend records the system’s response and the number of unauthorized accesses during the test. Table 5 shows the test results. Table 5 Security test results Test content Test Number Penetration test blocking rate (%) Unauthorized access count Attack types SQL injection attacks 1 98 2 SQL injection XSS attacks 2 97 1 Cross-site scripting Port scanning attacks 4 98 2 Port scanning Malware detection 5 99 0 Malware Table 5 shows the successful blocking rate of the protection system under different attacks. For SQL injection attacks, the system’s successful blocking rate is 98%, and its number of unauthorized accesses is only 2, which shows that it can effectively prevent SQL injection attacks. When dealing with XSS attacks, the blocking rate is also as high as 97%, and the number of unauthorized accesses is 1, which shows that the system has a good protection effect in cross-site scripting identification. Additionally, in terms of port scanning attacks and malware detection, the system achieves a successful blocking rate of 98% and 99%, and the number of unauthorized accesses is 2 and 0 respectively. These results fully demonstrate the strong ability of the protection system constructed in this article in recognizing and responding to potential threats, which provides a strong guarantee for the overall security. 7. Conclusion To address the security challenges of wireless communication in smart grids, an integrated defense and monitoring system is constructed in this article. By analyzing existing technologies, a monitoring system based on LSTM networks is adopted to achieve real-time identification and response of abnormal traffic. At the same time, a unified data sharing platform is established to ensure efficient collaboration between security defense and monitoring systems. In the functional test, the protection accuracy of the system is verified by simulating DDoS attacks of different intensities, and its response time and performance under high load are analyzed. Although the results are positive, indicating that the system effectively enhances the security of smart grids, the response time is significantly prolonged under high-frequency attacks, and the performance is close to saturation under high load, suggesting that further optimization is needed to improve the stability and responsiveness under extreme conditions. Future research can focus on applying advanced technologies such as quantum teleportation and deep learning to improve the intelligence level of security protection. At the same time, improving policies and industry standards can also provide guarantees for the security of smart grids, promote collaboration and information sharing, and form a securer network ecosystem. Overall, this article provides practical solutions for the security protection of wireless communication in smart grids and points out future research directions. Declarations Funding This work was supported by the State Grid Corporation Headquarters Science and Technology Project (Project Code: 5108-202218280A-2-410-XG). Data Availability The datasets used and/or analysed during the current study available from the corresponding author on reasonable request. There are no human studies involved in the images of my study and the article, so there is no need to publish consent References Salkuti S R. Challenges, issues and opportunities for the development of smart grid[J]. International Journal of Electrical and Computer Engineering (IJECE), 2020, 10(2): 1179-1186. Butt O M, Zulqarnain M, Butt T M. Recent advancement in smart grid technology: Future prospects in the electrical power network[J]. Ain Shams Engineering Journal, 2021, 12(1): 687-695. Islam S N, Baig Z, Zeadally S. Physical layer security for the smart grid: Vulnerabilities, threats, and countermeasures[J]. IEEE Transactions on Industrial Informatics, 2019, 15(12): 6522-6530. Hasan M K, Alkhalifah A, Islam S, et al. Blockchain technology on smart grid, energy trading, and big data: security issues, challenges, and recommendations[J]. Wireless Communications and Mobile Computing, 2022, 2022(1): 9065768-9065794. Zeinali M, Thompson J. Comprehensive practical evaluation of wired and wireless internet base smart grid communication[J]. IET Smart Grid, 2021, 4(5): 522-535. Kocak A, Taplamacioglu M C, Gozde H. General overview of area networks and communication technologies in smart grid applications[J]. International Journal on Technical and Physical Problems of Engineering (IJTPE), 2021 (46): 103-110. Kane L, Liu V, McKague M, et al. An Experimental Field Comparison of Wi-Fi HaLow and LoRa for the Smart Grid[J]. Sensors, 2023, 23(17): 7409-7436. Agarkar A, Agrawal H. A review and vision on authentication and privacy preservation schemes in smart grid network[J]. Security and Privacy, 2019, 2(2): e62-e80. Ahene E, Qin Z, Adusei A K, et al. Efficient signcryption with proxy re-encryption and its application in smart grid[J]. IEEE Internet of Things Journal, 2019, 6(6): 9722-9737. Peng C, Sun H, Yang M, et al. A survey on security communication and control for smart grids under malicious cyber attacks[J]. IEEE Transactions on Systems, Man, and Cybernetics: Systems, 2019, 49(8): 1554-1569. Reda H T, Anwar A, Mahmood A N, et al. A taxonomy of cyber defence strategies against false data attacks in smart grids[J]. ACM Computing Surveys, 2023, 55(14s): 1-37. Omitaomu O A, Niu H. Artificial intelligence techniques in smart grid: A survey[J]. Smart Cities, 2021, 4(2): 548-568. Chehri A, Fofana I, Yang X. Security risk modeling in smart grid critical infrastructures in the era of big data and artificial intelligence[J]. Sustainability, 2021, 13(6): 3196-3215. Hu S, Chen X, Ni W, et al. Modeling and analysis of energy harvesting and smart grid-powered wireless communication networks: A contemporary survey[J]. IEEE Transactions on Green Communications and Networking, 2020, 4(2): 461-496. Kumar N, Mishra V M, Kumar A. Smart grid security with AES hardware chip[J]. International Journal of Information Technology, 2020, 12(1): 49-55. Philips A, Jayaraj J, FT J, et al. Enhanced RSA key encryption application for metering data in smart grid[J]. International Journal of Pervasive Computing and Communications, 2021, 17(5): 596-610. Garg S, Kaur K, Kaddoum G, et al. Secure and lightweight authentication scheme for smart metering infrastructure in smart grid[J]. IEEE Transactions on Industrial Informatics, 2019, 16(5): 3548-3557. Fragkos G, Johnson J, Tsiropoulou E E. Dynamic role-based access control policy for smart grid applications: an offline deep reinforcement learning approach[J]. IEEE Transactions on Human-Machine Systems, 2022, 52(4): 761-773. Kisielewicz T, Stanek S, Zytniewski M. A multi-agent adaptive architecture for smart-grid-intrusion detection and prevention[J]. Energies, 2022, 15(13): 4726-4740. Kumar Y, Kumar V. A Systematic Review on Intrusion Detection System in Wireless Networks: Variants, Attacks, and Applications[J]. Wireless Personal Communications, 2023, 133(1): 395-452. Parween S, Hussain S Z, Hussain M A, et al. A survey on issues and possible solutions of cross-layer design in Internet of Things[J]. Int. J. Comput. Networks Appl, 2021, 8(4): 311-334. Sun W, Li P, Liu Z, et al. LSTM based link quality confidence interval boundary prediction for wireless communication in smart grid[J]. Computing, 2021, 103(2): 251-269. Ghafoor M I, Marjan S, Roomi M S, et al. Cyber-Malware Defense for Smart Grids Using Machine Learning[J]. Journal of Applied and Emerging Sciences, 2022, 12(2): 190-200. Hasan M N, Toma R N, Nahid A A, et al. Electricity theft detection in smart grid systems: A CNN-LSTM based approach[J]. Energies, 2019, 12(17): 3310-3328. Siniosoglou I, Radoglou-Grammatikis P, Efstathopoulos G, et al. A unified deep learning anomaly detection and classification approach for smart grid environments[J]. IEEE Transactions on Network and Service Management, 2021, 18(2): 1137-1151. Gupta K D, Nigam R, Sharma D K, et al. LSTM-based energy-efficient wireless communication with reconfigurable intelligent surfaces[J]. IEEE Transactions on Green Communications and Networking, 2021, 6(2): 704-712. Badr M M, Mahmoud M M E A, Fang Y, et al. Privacy-preserving and communication-efficient energy prediction scheme based on federated learning for smart grids[J]. IEEE Internet of Things Journal, 2023, 10(9): 7719-7736. Sarker M A A, Shanmugam B, Azam S, et al. Enhancing smart grid load forecasting: An attention-based deep learning model integrated with federated learning and XAI for security and interpretability[J]. Intelligent Systems with Applications, 2024, 23: 200422-200439. An D, Zhang F, Yang Q, et al. Data integrity attack in dynamic state estimation of smart grid: Attack model and countermeasures[J]. IEEE Transactions on Automation Science and Engineering, 2022, 19(3): 1631-1644. Wang Y, Zhang Z, Ma J, et al. KFRNN: An effective false data injection attack detection in smart grid based on Kalman filter and recurrent neural network[J]. IEEE Internet of Things Journal, 2021, 9(9): 6893-6904. Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5352293","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":376041853,"identity":"d495564e-cf0d-40dc-90bd-360d4a998757","order_by":0,"name":"Junbao Duan","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA1ElEQVRIiWNgGAWjYDCCAyCCh4HBgIGB8UFCRQ1pWpgNHpw5RqwWBrAWNsmHLcyEdfDdSH72gEHmcJ45++FjFYkNbAz87d0JeLVI3kgzN2DgOVxs2ZOWdiNxhwyDxJmzG/BqMbiRYCYB1JK44UCO2Y3EM2wMBhK5hLSkf4NoOf/GrCCxjZkYLTlQW4AMBqK0SJ55UwbUkp64c8azZImEM8d4CPqF73j6NgnGHuvE7fzJBz/+qKiR42/vxa8FBJj/9iA4PASVQ8APItWNglEwCkbByAQAdDhK67TbTPwAAAAASUVORK5CYII=","orcid":"","institution":"China Electric Power Research Institute Co., Ltd","correspondingAuthor":true,"prefix":"","firstName":"Junbao","middleName":"","lastName":"Duan","suffix":""},{"id":376041854,"identity":"7ed8ce21-3f6b-4dd6-b905-74a74e435b13","order_by":1,"name":"Gengshuo Liu","email":"","orcid":"","institution":"State Grid XiongAn New Area Electric Power Supply Company","correspondingAuthor":false,"prefix":"","firstName":"Gengshuo","middleName":"","lastName":"Liu","suffix":""},{"id":376041855,"identity":"91f3461b-c16b-4304-acd0-f4e8dc1872b2","order_by":2,"name":"Shuyan Zeng","email":"","orcid":"","institution":"China Electric Power Research Institute Co., Ltd","correspondingAuthor":false,"prefix":"","firstName":"Shuyan","middleName":"","lastName":"Zeng","suffix":""},{"id":376041856,"identity":"72bce0b7-8d31-4104-92b3-a9e499488276","order_by":3,"name":"Han Liu","email":"","orcid":"","institution":"State Grid Shandong Electric Power Company","correspondingAuthor":false,"prefix":"","firstName":"Han","middleName":"","lastName":"Liu","suffix":""},{"id":376041857,"identity":"36028f9c-e95c-49ea-a2ff-4a48f17246bb","order_by":4,"name":"Hongzhi Zhang","email":"","orcid":"","institution":"State Grid XiongAn New Area Electric Power Supply Company","correspondingAuthor":false,"prefix":"","firstName":"Hongzhi","middleName":"","lastName":"Zhang","suffix":""},{"id":376041858,"identity":"8c09794b-1455-46db-9bae-babc6c5a3779","order_by":5,"name":"Zhenghao Li","email":"","orcid":"","institution":"State Grid Shandong Electric Power Company","correspondingAuthor":false,"prefix":"","firstName":"Zhenghao","middleName":"","lastName":"Li","suffix":""},{"id":376041859,"identity":"7e5b65f7-20df-44db-b02e-0d2cbe072618","order_by":6,"name":"Cheng Zhong","email":"","orcid":"","institution":"State Grid XiongAn New Area Electric Power Supply Company","correspondingAuthor":false,"prefix":"","firstName":"Cheng","middleName":"","lastName":"Zhong","suffix":""},{"id":376041860,"identity":"6cf56127-7499-49a9-91a4-d1dc31b4eada","order_by":7,"name":"Donglan Liu","email":"","orcid":"","institution":"State Grid Shandong Electric Power Company","correspondingAuthor":false,"prefix":"","firstName":"Donglan","middleName":"","lastName":"Liu","suffix":""}],"badges":[],"createdAt":"2024-10-29 08:08:19","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-5352293/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5352293/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":69996852,"identity":"795aea8e-cef8-4a4e-82d9-20a92b3b5db4","added_by":"auto","created_at":"2024-11-27 10:33:20","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":36507,"visible":true,"origin":"","legend":"\u003cp\u003eTraining process of LSTM model.\u003c/p\u003e","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-5352293/v1/789f73cd376fa4b306cbd017.png"},{"id":69996853,"identity":"6a318d34-6ef8-4312-9fbd-c1258d4bdbbc","added_by":"auto","created_at":"2024-11-27 10:33:20","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":83720,"visible":true,"origin":"","legend":"\u003cp\u003eCurves of loss value and accuracy\u003c/p\u003e","description":"","filename":"floatimage2.png","url":"https://assets-eu.researchsquare.com/files/rs-5352293/v1/661f32c79fade23c3b9ccd33.png"},{"id":81622165,"identity":"031f6ba5-d382-4dbe-acff-e7d932412497","added_by":"auto","created_at":"2025-04-29 09:32:05","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1198542,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5352293/v1/f83a4a86-e5b2-4030-ad87-c5f749cfe6bd.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Wireless Communication Security Defense and Monitoring in Smart Grids","fulltext":[{"header":"1. Introduction","content":"\u003cp\u003eAs an innovative development mode of modern power systems, smart grids combine advanced information technology, communication technology, and power transmission technology, significantly improving the intelligence level of power systems [\u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e1\u003c/span\u003e\u0026ndash;\u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2\u003c/span\u003e]. Through bidirectional data flow, real-time monitoring, and remote control, smart grids can achieve comprehensive optimization and efficient management of power generation, transmission, and consumption. Wireless communication technology has been widely applied and is the key to the efficient operation of smart grids. It covers a vast area and connects a large number of terminal devices (such as smart meters, sensors, distributed energy, etc.), achieving real-time data exchange and device control. However, the widespread application of wireless communication technology has also brought new security challenges. Due to its openness, wireless communication environments are highly susceptible to external attacks, significantly increasing the network security risks faced by smart grids. Common security threats include data eavesdropping, denial of service (DoS) attacks, malicious node hijacking, data tampering, etc. [\u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e3\u003c/span\u003e\u0026ndash;\u003cspan citationid=\"CR4\" class=\"CitationRef\"\u003e4\u003c/span\u003e]. These threats may not only lead to the breach of user privacy, but also seriously affect the stability of the power grid and even cause large-scale power outages. Traditional security protection measures such as encryption and access control are often insufficient when dealing with complex network attacks. At the same time, the existing monitoring system has a lag in detecting and responding to security incidents and lacks an efficient real-time monitoring and early warning mechanism. Therefore, there is an urgent need to build an integrated security defense and monitoring system to comprehensively deal with security threats in smart grids.\u003c/p\u003e \u003cp\u003eThe objective of this article is to design and implement a system that integrates security defense and intelligent monitoring to address the security challenges in smart grid wireless communications. Through the new security defense mechanism, the confidentiality, integrity and anti-attack capabilities of wireless communication data are enhanced. At the same time, this article also studies a system for real-time monitoring of the status of power grid equipment and communication networks to improve the speed and accuracy of response to abnormal situations and potential attacks. Through the collaboration of defense and monitoring systems, network threats can be dynamically perceived, and timely defense measures can be taken, thus enhancing the security and reliability of smart grids.\u003c/p\u003e \u003cp\u003eThe main contributions of this article are as follows:\u003c/p\u003e \u003cp\u003e \u003col\u003e \u003cspan\u003e \u003cli\u003e \u003cp\u003eA comprehensive smart grid wireless communication security defense system is established, covering encryption, authentication, and multi-level protection strategies, effectively resisting common threats such as data eavesdropping and denial of service attacks.\u003c/p\u003e \u003c/li\u003e \u003c/span\u003e \u003cspan\u003e \u003cli\u003e \u003cp\u003eAn intelligent monitoring system is designed and implemented, which can monitor devices and communication networks in smart grids in real time and identify potential security issues in a timely manner through anomaly detection technology.\u003c/p\u003e \u003c/li\u003e \u003c/span\u003e \u003cspan\u003e \u003cli\u003e \u003cp\u003eEffective integration of defense and monitoring systems is achieved. A collaborative mechanism is proposed to enable the monitoring system to trigger defense mechanisms in real time, and protection strategies can be adaptively adjusted according to different threat scenarios to ensure the efficient and secure operation of the system.\u003c/p\u003e \u003c/li\u003e \u003c/span\u003e \u003cspan\u003e \u003cli\u003e \u003cp\u003eThe effectiveness and feasibility of the designed system are verified through experiments, and the results show that the system can effectively respond to various security threats with minimal impact on wireless communication performance.\u003c/p\u003e \u003c/li\u003e \u003c/span\u003e \u003c/ol\u003e \u003c/p\u003e"},{"header":"2. Current Status of Wireless Communication Security Issues in Smart Grids","content":"\u003cp\u003e(1) Application of the wireless communication technology in smart grids\u003c/p\u003e\n\u003cp\u003eWireless communication technology provides highly flexible network connectivity and information exchange capabilities for smart grids. Wireless communication technologies such as 4G, 5G, Wi-Fi (wireless fidelity), ZigBee, LoRa (long range radio) and other technologies are widely used in the power grid [5-7]. 4G and 5G, with their advantages of high bandwidth and low latency, are commonly used in remote control and massive data transmission scenarios. For example, smart grid projects in China commonly use 5G technology to enhance real-time response and system reliability. However, despite the superior performance of 5G networks, their high construction costs and insufficient coverage in some areas remain global technological challenges.\u003c/p\u003e\n\u003cp\u003eLow-power consumption communication technologies such as ZigBee and LoRa perform well in distributed energy management and smart meter communication. LoRa is particularly suitable for wide area coverage scenarios and has been widely used in rural and remote areas of countries such as France. At present, the main research focus in China is on how to optimize the practical application of the low-power consumption technologies, and especially in large-scale deployment tasks, improving their reliability and energy conservation is particularly important. However, the current technologies are still insufficient in terms of transmission rate and anti-interference ability, which has become a great obstacle to the further application of them.\u003c/p\u003e\n\u003cp\u003e(2) Security threats of wireless communication in smart grids\u003c/p\u003e\n\u003cp\u003eCurrent security threat research in wireless communication focuses on data theft, denial of service attacks, malware, and physical layer threats. In particular, rich experience has been accumulated in preventing data theft and defending against cyber-attacks. Key institutions over the world have developed data protection frameworks based on encryption and authentication technologies. These frameworks are effective in preventing unauthorized access and data tampering through public key infrastructure (PKI). In addition, these institutions not only attach importance to encryption technology, but also emphasize the importance of identity authentication and access control to ensure the secure transmission and storage of data in smart grids. Implementing these standards helps to enhance the defense against potential cyber-attacks [8-9].\u003c/p\u003e\n\u003cp\u003eIn recent years, significant progress has also been made in related research in China. An increasing number of studies have begun to combine SM2 and SM4 algorithms to improve data security in communication [10-11]. In addition, scholars have proposed a machine learning-based network attack detection model that can perform real-time detection and early warning for complex attack scenarios such as denial of service attacks, significantly improving the anti attack capability of the power grid.\u003c/p\u003e\n\u003cp\u003e(3) Security protection and monitoring measures\u003c/p\u003e\n\u003cp\u003eIn terms of protection measures, a hierarchical security defense strategy is usually adopted, including encryption, authentication, access control, and partition isolation. For example, smart grid projects often adopt role-based access control and multi-layer firewall technology to ensure effective protection at all levels of the system. In recent years, distributed identity authentication schemes based on blockchain have gradually received attention, especially in identity management and protection against malicious nodes in the power grid, showing great potential.\u003c/p\u003e\n\u003cp\u003eIn terms of intelligent monitoring systems, research focuses more on the application of big data analysis and artificial intelligence technology [12-13]. For example, some research projects in Europe have used machine learning-based power grid monitoring systems that can analyze historical data, identify potential attack behaviors, and issue early warnings. China places more emphasis on rule-based detection systems. Although deep learning models have been attempted in recent years, there are still certain limitations in their practical applications. However, China has made significant progress in the precision and real-time performance of intelligent monitoring technology, especially in the comprehensive monitoring system that combines power grid operation data and communication network status, demonstrating great application prospects [14].\u003c/p\u003e\n\u003cp\u003eOverall, other countries have relatively mature research in smart grid security protection and monitoring technologies, especially in the fields of encryption, intrusion detection, and anomaly monitoring, and relatively complete systems have been formed. Although China\u0026rsquo;s research started relatively late, rapid progress has been made in encryption algorithms and intelligent monitoring systems, gradually forming a security protection framework with Chinese characteristics.\u003c/p\u003e"},{"header":"3. Construction of Comprehensive Wireless Communication Security Defense System","content":"\u003cdiv id=\"Sec4\"\u003e\n \u003ch2\u003e3.1 Design Objectives\u003c/h2\u003e\n \u003cp\u003eConstructing a comprehensive wireless communication security defense system requires clear design objectives and principles to ensure that smart grids have efficient security protection capabilities in dynamic environments. The design objectives include high efficiency, low resource consumption, adaptability, and improved system robustness.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv id=\"Sec5\"\u003e\n \u003ch2\u003e3.2 Security Defense Mechanisms in Wireless Communication\u003c/h2\u003e1. Data encryption and decryption\u003cbr\u003eData encryption and decryption is crucial in smart grid systems. In the security defense system constructed in this article, data encryption is achieved by combining symmetrical encryption (Advanced Encryption Standard, AES) with asymmetrical encryption (Rivest-Shamir-Adleman, RSA) [\u003cspan\u003e15\u003c/span\u003e\u0026ndash;\u003cspan\u003e16\u003c/span\u003e]. The encryption and decryption formulas of symmetrical encryption algorithm are as follows:\u003cdiv id=\"Equ1\"\u003e\n \u003cdiv id=\"FileID_Equ1\" name=\"EquationSource\"\u003e$$\\:\\text{C}=\\:{E}_{k}\\left(M\\right)$$\u003c/div\u003e\n \u003cdiv\u003e1\u003c/div\u003e\n \u003c/div\u003e\n \u003cdiv id=\"Equ2\"\u003e\n \u003cdiv id=\"FileID_Equ2\" name=\"EquationSource\"\u003e$$\\:\\text{M}=\\:{D}_{k}\\left(C\\right)$$\u003c/div\u003e\n \u003cdiv\u003e2\u003c/div\u003e\n \u003c/div\u003ewhere \u003cem\u003eC\u003c/em\u003e is ciphertext, that is, the encrypted data. \u003cspan\u003e\u003cspan\u003e\\(\\:{E}_{k}\\)\u003c/span\u003e\u003c/span\u003e is an encryption function using the key \u003cem\u003ek\u003c/em\u003e. \u003cem\u003eM\u003c/em\u003e is the data before encryption. The encryption and decryption formulas of asymmetrical encryption algorithms are as follows:\u003cdiv id=\"Equ3\"\u003e\n \u003cdiv id=\"FileID_Equ3\" name=\"EquationSource\"\u003e$$\\:\\text{C}=\\:{E}_{Pk}\\left(M\\right)$$\u003c/div\u003e\n \u003cdiv\u003e3\u003c/div\u003e\n \u003c/div\u003e\n \u003cdiv id=\"Equ4\"\u003e\n \u003cdiv id=\"FileID_Equ4\" name=\"EquationSource\"\u003e$$\\:\\text{M}=\\:{D}_{Sk}\\left(C\\right)$$\u003c/div\u003e\n \u003cdiv\u003e4\u003c/div\u003e\n \u003c/div\u003ewhere \u003cem\u003ePk\u003c/em\u003e is the public key, and\u0026nbsp;\u003cem\u003eSk\u003c/em\u003e is the private key.\u003cbr\u003e2. Identity authentication mechanism\u003cbr\u003eIdentity authentication is a key technology to ensure the legitimacy of both communicating parties. This article adopts a combination of digital certificates and public key infrastructure (PKI) to jointly implement the identity authentication function [\u003cspan\u003e17\u003c/span\u003e]. The system generates a unique public-private key pair for each device and obtain a digital certificate through a authentication authority. During communication, devices are authenticated by sending certificates and signature messages. For example, in the smart grid, when device \u003cem\u003ea\u003c/em\u003e sends a message \u003cem\u003eM\u003c/em\u003e to device \u003cem\u003eb\u003c/em\u003e, it uses a private key to digitally sign to ensure the authenticity and integrity of the message. After receiving the message, device \u003cem\u003eb\u003c/em\u003e verifies the signature to confirm the identity and source of the message. This mechanism enhances the system\u0026rsquo;s ability to protect against unauthorized access. The signature formula is as follows:\u003cdiv id=\"Equ5\"\u003e\n \u003cdiv id=\"FileID_Equ5\" name=\"EquationSource\"\u003e$$\\:{S}_{a}={D}_{S{k}_{a}}\\left(H\\right(M\\left)\\right)$$\u003c/div\u003e\n \u003cdiv\u003e5\u003c/div\u003e\n \u003c/div\u003eIn Formula (5), \u003cspan\u003e\u003cspan\u003e\\(\\:{S}_{a}\\)\u003c/span\u003e\u003c/span\u003e is the signature of device \u003cem\u003ea\u003c/em\u003e, and\u0026nbsp;\u003cem\u003eH\u003c/em\u003e is the hash function.\u003cbr\u003e3. Access control and permission management\u003cbr\u003eRole-based access control (RBAC) can set different permissions based on different roles [\u003cspan\u003e18\u003c/span\u003e]. Therefore, in the security defense system constructed in this article, a permission matrix \u003cem\u003eX\u003c/em\u003e is designed:\u003cdiv id=\"Equ6\"\u003e\n \u003cdiv id=\"FileID_Equ6\" name=\"EquationSource\"\u003e$$\\:{X}_{i,j}=\\left\\{\\begin{array}{c}1\\\\\\:0\\end{array}\\right.$$\u003c/div\u003e\n \u003cdiv\u003e6\u003c/div\u003e\n \u003c/div\u003eIf user \u003cem\u003ei\u003c/em\u003e has access permission to \u003cem\u003ej\u003c/em\u003e, the system returns 1 after \u003cem\u003ei\u003c/em\u003e sends a request to\u0026nbsp;\u003cem\u003ej\u003c/em\u003e, and returns 0 if there is no permission, thereby ensuring that only users and devices with corresponding permissions can access specific resources.\u003cbr\u003e4. Wireless link handover security\u003cbr\u003eIn the smart grid, wireless link handover security is also a key consideration. Through wireless link handover, unauthorized terminals may illegally access the network, steal important information, and pose a security risk to the smart grid. One solution is to strengthen the authentication and management of handover users in the power grid. Considering that user authentication mechanisms already exist in 4G and 5G networks, a secondary authentication mechanism can be introduced on the basis of standard authentication mechanisms. The power terminal monitors the quality of the wireless link through channel quality measurement. When a handover needs is triggered, the dedicated AAA server deployed by the power grid initiates secondary authentication for the terminal. eSIM is commonly used in power grid terminals to store security related parameters, and dedicated mechanisms can be used for secondary authentication to ensure higher levels of security\u003cbr\u003e.5. Intrusion detection and prevention systems\u003cp\u003eThe design of intrusion detection system (IDS) and intrusion prevention system (IPS) is an important part of achieving the protection goal of this article [\u003cspan\u003e19\u003c/span\u003e\u0026ndash;\u003cspan\u003e20\u003c/span\u003e]. In this article, Formula (7) is used to measure whether the information flow is abnormal:\u003c/p\u003e\n \u003cdiv id=\"Equ7\"\u003e\n \u003cdiv id=\"FileID_Equ7\" name=\"EquationSource\"\u003e$$\\:\\text{A}\\text{b}\\text{n}\\text{o}\\text{r}\\text{m}\\text{a}\\text{l}\\text{i}\\text{t}\\text{y}\\left(\\text{x}\\right)=\\:\\frac{|x-\\mu\\:|}{\\sigma\\:}$$\u003c/div\u003e\n \u003cdiv\u003e7\u003c/div\u003e\n \u003c/div\u003e6. Dynamic adaptive defense mechanism\u003cp\u003eThe dynamic adaptive defense mechanism is an innovation of the security system constructed in this article. By using artificial intelligence and machine learning technology, the defense system constructed in this article is able to adjust security policies by analyzing and learning from real-time data. When the system detects abnormal access patterns, it automatically increases the security level and take security measures to prevent possible problems. The dynamic adjustment formula of the system is as follows:\u003c/p\u003e\n \u003cdiv id=\"Equ8\"\u003e\n \u003cdiv id=\"FileID_Equ8\" name=\"EquationSource\"\u003e$$\\:{S}_{new}={S}_{old}+{\\Delta\\:}S$$\u003c/div\u003e\n \u003cdiv\u003e8\u003c/div\u003e\n \u003c/div\u003e7. Multi-level defense\u003cp\u003eTo better achieve the protection function of the system, this article constructs a multi-level defense system to ensure the overall security of the smart grid from the three layers of physical layer, network layer and application layer [\u003cspan\u003e21\u003c/span\u003e]. At the physical layer, secure communication equipment and signal shielding technology are used to defend against potential physical attacks. At the network layer, data encryption and identity authentication technology are implemented to ensure the security of data transmission. Finally, at the application layer, secure coding practices are adopted, and system vulnerability scans are performed regularly to identify and repair unknown security risks.\u003c/p\u003e\n\u003c/div\u003e"},{"header":"4. Design of Intelligent Monitoring System Based on LSTM","content":"\u003cdiv id=\"Sec7\" class=\"Section2\"\u003e\n \u003ch2\u003e4.1 Roles of Detection Target and LSTM Model\u003c/h2\u003e\n \u003cp\u003eThe main function of the intelligent monitoring system is to monitor the network status and equipment operation of smart grids in real time. To achieve this goal, the key is to quickly identify potential security threats and anomalies. The system constructed in this article achieves the purpose of rapid identification by deeply analyzing time series data, so that the system can not only issue early warnings in a timely manner, but also help operation and maintenance personnel to respond quickly, effectively reducing the impact of security incidents on normal operations. Long short-term memory (LSTM) network is a deep learning model that specializes in processing time series data. It performs well in capturing time series features and is therefore widely used in intelligent monitoring systems [\u003cspan class=\"CitationRef\"\u003e22\u003c/span\u003e]. Using the LSTM model, the system can more precisely predict and identify complex abnormal patterns, further improving the reliability and response speed of monitoring.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv id=\"Sec8\" class=\"Section2\"\u003e\n \u003ch2\u003e4.2 Data Collection and Preprocessing\u003c/h2\u003e1. Data collection\u003cbr\u003e\n \u003cp\u003eIn the early stage of system construction, data collection is the first step. The data for this article comes from a variety of devices and networks covered by smart grids, and the data types include network traffic, device status, and event logs. During the data collection process, network traffic data is collected through the network packet capture tool Wireshark, and the recorded data includes packet size, traffic rate, source and target IP addresses, etc. Device status data is obtained through the monitoring tool Prometheus, covering central processing unit (CPU) utilization, memory usage and other information. Event logs are generated by the logging mechanism of each device, recording important operations and status changes of the device. About 1,440 pieces of device status data are collected every day, and about 100,000 pieces of event logs are recorded. The total amount of data collected eventually reaches 300,000 pieces. Some of the collected data are shown in Table \u003cspan class=\"InternalRef\"\u003e1\u003c/span\u003e.\u003c/p\u003e\n \u003cdiv\u003e\u0026nbsp;\u003ctable id=\"Tab1\" border=\"1\"\u003e\n \u003ccaption language=\"En\"\u003e\n \u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e\n \u003cdiv class=\"CaptionContent\"\u003e\n \u003cp\u003ePart of collected data\u003c/p\u003e\n \u003c/div\u003e\n \u003c/caption\u003e\n \u003cthead\u003e\n \u003ctr\u003e\n \u003cth align=\"left\"\u003eData Types\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eTimestamp\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eSource IP\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eTarget IP\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003ePacket size (bytes)\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eTraffic rate (Mbps)\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eCPU utilization (%)\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eMemory usage (%)\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eEvent Description\u003cbr\u003e\u003c/th\u003e\n \u003c/tr\u003e\n \u003c/thead\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eNetwork traffic\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:00\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.1\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.2\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e1500\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e10.5\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eNetwork traffic\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.1\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.3\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e1200\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e12.3\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eNetwork traffic\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:02\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.2\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.1\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e1400\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e9.8\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eNetwork traffic\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:03\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.2\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e192.168.1.4\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e1600\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e11.2\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eDevice Status\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:00\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e45\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e60\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eDevice is operating normally.\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eDevice Status\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e50\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e62\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eCPU utilization increases.\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eDevice Status\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:02\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e70\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eDevice load increases.\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eEvent Log\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:00\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eUser login\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eEvent Log\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eUser logout\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003eEvent Log\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e2024-09-01 10:00:02\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003e-\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"left\"\u003eAlert: Abnormal flow\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n \u003c/table\u003e\n \u003c/div\u003e\n \u003cp\u003e(2) Data preprocessing\u003c/p\u003eIn the data preprocessing stage, the first step is to remove missing values and outliers. Missing values can be processed by filling in the mean, and the formula is as follows\u003cdiv id=\"Equ9\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ9\" name=\"EquationSource\"\u003e$$\\:{x}_{i}=\\left\\{\\begin{array}{c}{x}_{i}\\:if\\:{x}_{i}\\:is\\:not\\:missing\\\\\\:\\widehat{x}\\:\\:if\\:{x}_{i}\\:is\\:missing\\:\\:\\:\\end{array}\\right.$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e9\u003c/div\u003e\n \u003c/div\u003eOutliers are identified using the interquartile range (IQR) method. In this identification process, the first step is to calculate the number Q1 in the first quartile and the number Q3 in the third quartile, and IQR is calculated through Q1 and Q3 [\u003cspan class=\"CitationRef\"\u003e23\u003c/span\u003e].\u003cdiv id=\"Equ10\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ10\" name=\"EquationSource\"\u003e$$\\:\\text{I}\\text{Q}\\text{R}=\\text{Q}3-\\text{Q}1$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e10\u003c/div\u003e\n \u003c/div\u003eSubsequently, it is necessary to define the upper and lower limits of outliers using the following formulas:\u003cdiv id=\"Equ11\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ11\" name=\"EquationSource\"\u003e$$\\:\\text{L}\\text{o}\\text{w}\\text{e}\\text{r}\\:\\text{B}\\text{o}\\text{u}\\text{n}\\text{d}=\\text{Q}1-1.5\\times\\:\\text{I}\\text{Q}\\text{R}$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e11\u003c/div\u003e\n \u003c/div\u003e\n \u003cdiv id=\"Equ12\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ12\" name=\"EquationSource\"\u003e$$\\:\\text{U}\\text{p}\\text{p}\\text{e}\\text{r}\\:\\text{B}\\text{o}\\text{u}\\text{n}\\text{d}=\\text{Q}3+1.5\\times\\:\\text{I}\\text{Q}\\text{R}$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e12\u003c/div\u003e\n \u003c/div\u003eNext, data normalization processing is performed. All features are scaled to the interval [0,1] for model training. The normalization formula is:\u003cdiv id=\"Equ13\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ13\" name=\"EquationSource\"\u003e$$\\:{x}^{{\\prime\\:}}=\\frac{x-\\text{m}\\text{i}\\text{n}\\left(x\\right)}{\\text{m}\\text{a}\\text{x}\\left(x\\right)-\\text{m}\\text{i}\\text{n}\\left(x\\right)}$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e13\u003c/div\u003e\n \u003c/div\u003eFinally, the sliding window technology is used to construct time series samples. The window size is set to 10. According to the division of every 10 time steps, input samples are formed, and the shape of the samples is (number of samples, 10, number of features). After constructing the samples, the preprocessed data is used for training at a ratio of 80% and for testing at a ratio of 20%, ensuring that the time series of training and testing data do not overlap.\n\u003c/div\u003e\n\u003cdiv id=\"Sec9\" class=\"Section2\"\u003e\n \u003ch2\u003e4.3 Model Construction and Training Based on LSTM\u003c/h2\u003e\n \u003cp\u003eLSTM is a special recurrent neural network (RNN) that is widely used in the processing and prediction of time series data [\u003cspan class=\"CitationRef\"\u003e24\u003c/span\u003e\u0026ndash;\u003cspan class=\"CitationRef\"\u003e25\u003c/span\u003e]. Compared with traditional RNN, LSTM effectively solves the gradient vanishing problem in long sequence data through \u0026ldquo;memory cells\u0026rdquo;. Its core structure includes input gate, forget gate and output gate, which respectively control the storage, discarding and output of information, so that LSTM can capture long-term dependencies in time series and improve prediction accuracy.\u003c/p\u003e\n \u003cp\u003eWhen building the LSTM model, the input layer with an input shape of (10, number of features) is firstly defined, indicating that the model receives data from the past 10 time steps for prediction. Then, a layer of LSTM cells with 64 cells is added, and the ReLU activation function is used to bring nonlinear characteristics to enhance the expressiveness of the model. Finally, a neuron is set as the output layer to output the predicted value of the next time step.\u003c/p\u003e\n \u003cp\u003eIn addition, when training the model, appropriate loss functions and optimizers need to be selected to improve the performance of the model. In terms of regression problems, mean-square error (MSE) is a commonly used as the loss function, and the formula is:\u003c/p\u003e\n \u003cdiv id=\"Equ14\" class=\"Equation\"\u003e\n \u003cdiv class=\"mathdisplay\" id=\"FileID_Equ14\" name=\"EquationSource\"\u003e$$\\:\\text{M}\\text{S}\\text{E}\\:=\\:\\frac{1}{\\text{n}}\\sum\\:_{\\text{i}\\:=1}^{\\text{n}}{({\\text{y}}_{\\text{i}}-{\\widehat{\\text{y}}}_{\\text{i}})}^{2}$$\u003c/div\u003e\n \u003cdiv class=\"EquationNumber\"\u003e14\u003c/div\u003e\n \u003c/div\u003e\u003cbr\u003e\n \u003cp\u003eIn Formula (14), \u003cspan class=\"InlineEquation\"\u003e\u003cspan class=\"mathinline\"\u003e\\(\\:{\\text{y}}_{\\text{i}}\\)\u003c/span\u003e\u003c/span\u003e is the actual value, and \u003cspan class=\"InlineEquation\"\u003e\u003cspan class=\"mathinline\"\u003e\\(\\:{\\widehat{\\text{y}}}_{\\text{i}}\\)\u003c/span\u003e\u003c/span\u003e is the predicted value. The Adam optimizer is widely used due to its adaptive learning rate feature [\u003cspan class=\"CitationRef\"\u003e26\u003c/span\u003e\u0026ndash;\u003cspan class=\"CitationRef\"\u003e27\u003c/span\u003e], with an initial learning rate set to 0.001. During the training process, the total training epochs are set to 100, and the batch size is set to 32. After each training epoch, the training loss and accuracy are recorded, and the performance of the model is verified and evaluated to observe the learning process of the model. The specific training process is shown in Fig. \u003cspan class=\"InternalRef\"\u003e1\u003c/span\u003e:\u003c/p\u003eTo improve the performance of the model, hyperparameter optimization is an indispensable step [\u003cspan class=\"CitationRef\"\u003e28\u003c/span\u003e]. Hyperparameters include learning rate, number of LSTM cells, batch size, etc. This article uses the grid search method combined with cross-validation to evaluate the performance of different hyperparameter combinations.\u003cp\u003eFirstly, the hyperparameter ranges are defined. The learning rate range is set to [0.0001, 0.001, 0.01]. The number of LSTM cells is set to [32, 64, 128]. The batch size is set to [16, 32, 64]. The hyperparameter combinations for the experiment are shown in Table \u003cspan class=\"InternalRef\"\u003e2\u003c/span\u003e.\u003c/p\u003e\u003cbr\u003e\n \u003cdiv\u003e\u0026nbsp;\u003ctable id=\"Tab2\" border=\"1\"\u003e\n \u003ccaption language=\"En\"\u003e\n \u003cdiv class=\"CaptionNumber\"\u003eTable 2\u003c/div\u003e\n \u003cdiv class=\"CaptionContent\"\u003e\n \u003cp\u003eHyperparameter combinations\u003c/p\u003e\n \u003c/div\u003e\n \u003c/caption\u003e\n \u003cthead\u003e\n \u003ctr\u003e\n \u003cth align=\"left\"\u003eCombination number\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eLearning rate\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eNumber of LSTM cells\u003cbr\u003e\u003c/th\u003e\n \u003cth align=\"left\"\u003eBatch size\u003cbr\u003e\u003c/th\u003e\n \u003c/tr\u003e\n \u003c/thead\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e1\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e2\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e3\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e4\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e5\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e6\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e7\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e8\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e9\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.0001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e10\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e11\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e12\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e13\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e14\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e15\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e17\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e18\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.001\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e19\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e20\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e21\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e22\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e23\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e24\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e25\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e16\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e26\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e32\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd align=\"left\"\u003e27\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e0.01\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e128\u003cbr\u003e\u003c/td\u003e\n \u003ctd align=\"char\"\u003e64\u003cbr\u003e\u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n \u003c/table\u003e\n \u003c/div\u003e\n \u003cp\u003eEach combination is trained on the training set, and its performance is evaluated on the testing set through cross-validation. The loss value and accuracy of each training session are recorded, and the results are shown in Fig. \u003cspan class=\"InternalRef\"\u003e2\u003c/span\u003e.\u003c/p\u003e\u003cbr\u003e\n \u003cp\u003eIn Fig. \u003cspan class=\"InternalRef\"\u003e2\u003c/span\u003e, the red curve represents the loss value; the blue curve represents accuracy; the black arrows mark the values with the highest accuracy and the smallest loss. Combination 23 has the smallest loss value and the highest accuracy, with a learning rate of 0.01, 64 LSTM cells, and a batch size of 32, resulting in the best performance. Its loss value on the testing set is reduced to 0.029, and its accuracy is improved to 94.7%. Therefore, the hyperparameter configuration selected in this article is with a learning rate of 0.01, 64 LSTM cells, and a batch size of 32. This process ensures the generalization ability and predictive performance of the final model.\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv id=\"Sec10\" class=\"Section2\"\u003e\n \u003ch2\u003e4.4 Real-time Monitoring and Response Mechanism for Security Incidents\u003c/h2\u003e\n \u003cp\u003eOnce the model training is completed, the intelligent monitoring system can receive new time series data in real time, analyze and predict it. When the prediction result shows an abnormality, the system immediately issues an alarm to prompt the operation and maintenance personnel to conduct further inspection. The comparison between each predicted result and the actual situation is recorded by the system. All data is saved in log files for subsequent auditing and analysis.\u003c/p\u003e\n \u003cp\u003eBy comparing historical data, the security team can track potential attack sources and abnormal behavior, quickly locate problems, and take corresponding measures. When potential security incidents are identified, the system automatically executes response mechanisms, restricts the access permissions of suspicious devices, and isolates abnormal traffic to prevent it from affecting the entire network. Through this monitoring and response mechanism, the intelligent monitoring system can timely detect potential problems, help operation and maintenance personnel respond quickly, and reduce the risk of system failures, thereby ensuring the secure and stable operation of the power grid.\u003c/p\u003e\n\u003c/div\u003e"},{"header":"5. Collaborative Work of Security Defense and Monitoring System","content":"\u003cdiv id=\"Sec12\" class=\"Section2\"\u003e \u003ch2\u003e5.1 Collaborative Design of Defense and Monitoring\u003c/h2\u003e \u003cp\u003eA unified data sharing platform is built in this article to achieve efficient collaboration between security defense and intelligent monitoring systems. The platform can capture data generated by the network and devices in real time, so as to quickly identify abnormal activities or potential threats and alert managers while passing relevant information to the defense system. When there is an abnormal increase in network traffic or a problem with the status of a device, the monitoring system provides instant feedback of critical information so that the defense mechanisms can react quickly.\u003c/p\u003e \u003cp\u003eAfter receiving the alert, the defense system takes necessary measures such as limiting access to suspicious devices, encrypting sensitive data, and starting traffic filtering to reduce the risk of successful attacks. The mechanism is also capable of quickly restoring normal operation after an incident, thus maintaining the stability and security of the system.\u003c/p\u003e \u003cp\u003eIn addition, the monitoring system is able to continuously and automatically update its algorithms to enhance its ability to detect threats in the future by analyzing historical data and learning new attack patterns. This adaptive security policy ensures that the system can effectively respond to changing security challenges, thereby ensuring the overall security and reliability of smart grids.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec13\" class=\"Section2\"\u003e \u003ch2\u003e5.2 Closed-loop Feedback Mechanism\u003c/h2\u003e \u003cp\u003eIn this article, the feedback mechanism is constructed to realize the closed-loop of adaptive security defense and monitoring functions [\u003cspan citationid=\"CR29\" class=\"CitationRef\"\u003e29\u003c/span\u003e\u0026ndash;\u003cspan citationid=\"CR30\" class=\"CitationRef\"\u003e30\u003c/span\u003e]. The feedback mechanism is implemented through the following steps. First, when the defense system successfully isolates a suspicious device, the monitoring system records and analyzes the effectiveness of the event and submit feedback. The feedback not only covers the successful prevention of attacks, but also includes false positives and undetected threats, providing data support for subsequent optimization. The monitoring system adjusts the monitoring strategy accordingly, updating the threshold or adopting a new feature recognition model to increase sensitivity to new attacks.\u003c/p\u003e \u003cp\u003eIn addition, regular security drills and assessments can further enhance the overall protection capabilities of the system. By simulating different types of network attacks and observing the responses of the defense and monitoring systems, potential weaknesses can be identified.\u003c/p\u003e \u003c/div\u003e"},{"header":"6. System Testing and Validation","content":"\u003cp\u003eAfter constructing the security protection and monitoring system, comprehensive testing is conducted to ensure its effectiveness and reliability. The testing environment adopts the following configuration. In terms of hardware, the server configuration is Intel Xeon E5-2620; the memory is 16GB; the network bandwidth is 1Gbps. In terms of software, the operating system is Ubuntu 20.04, and the firewall configuration is iptables. Tests are divided into three aspects: functional test, performance test, and security test. The following is a detailed experimental process and results.\u003c/p\u003e \u003cdiv id=\"Sec15\" class=\"Section2\"\u003e \u003ch2\u003e6.1 Functional Test\u003c/h2\u003e \u003cp\u003eFunctional test aims to evaluate the system\u0026rsquo;s ability to protect against simulated attacks. This article uses the low orbit ion cannon (LOIC) tool to simulate distributed denial of service (DDoS) attacks, with a set attack frequency of 500\u0026ndash;5000 attacks per second. During the testing process, the system\u0026rsquo;s response time and accuracy are recorded separately to ensure the accuracy of the results. Multiple tests are conducted for each attack scenario to ensure the stability of results. The experimental results are shown in Table\u0026nbsp;\u003cspan refid=\"Tab3\" class=\"InternalRef\"\u003e3\u003c/span\u003e.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab3\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eFunctional test results\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eExperiment number\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eAttack frequency (times/second)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eResponse time (ms)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eAccuracy (%)\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e1\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e120\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e96.5\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e1000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e150\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e93.7\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e3\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e1500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e180\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e92.1\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e4\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e2000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e210\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e90.6\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e5\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e2500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e240\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e89.5\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e6\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e3000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e270\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e87.3\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e7\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e3500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e300\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e85.2\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e8\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e4000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e330\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e83.7\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e9\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e4500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e360\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e82.2\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e10\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e5000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e390\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e82.5\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eIn the functional test, DDoS attacks of different scales are simulated. According to Table\u0026nbsp;\u003cspan refid=\"Tab3\" class=\"InternalRef\"\u003e3\u003c/span\u003e, experiment numbers 1 to 10 show the system response time and accuracy when the attack frequency varies from 500 times/second to 5000 times/second. As the attack intensity increases, the response time gradually extends, rising from 120 milliseconds to 390 milliseconds, while the accuracy shows a gradually decreasing trend, decreasing from 96.5\u0026ndash;82.5%. For example, when the attack frequency is 1000 times/second, the system\u0026rsquo;s response time is 150 milliseconds, and the accuracy is 93.7%; when the attack frequency is 4000 times per second, the response time reaches 330 milliseconds, and the accuracy drops to 83.7%. The results indicate that the system can still maintain high accuracy and fast response time in the face of low-intensity attacks, reflecting the effective protection capability of the system in the smart grid environment. However, with the increase of attack intensity, although the accuracy is still above 80%, the system\u0026rsquo;s responsiveness is significantly affected. This suggests that further optimization of system performance is needed when designing protective measures to enhance its defense capability in high-intensity attack situations.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec16\" class=\"Section2\"\u003e \u003ch2\u003e6.2 Performance Test\u003c/h2\u003e \u003cp\u003eThe purpose of performance test is to evaluate the resource consumption of the system under different loads. This article uses Apache JMeter to create a load test, simulating different user request scenarios with 500\u0026ndash;5000 concurrent requests. In each scenario, the test lasts for 10 minutes to collect stable data. The test results are shown in Table\u0026nbsp;\u003cspan refid=\"Tab4\" class=\"InternalRef\"\u003e4\u003c/span\u003e.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab4\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003ePerformance test results\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"6\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c6\" colnum=\"6\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eExperiment number\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eNumber of requests (times/second)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eCPU utilization (%)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eMemory usage (MB)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c5\"\u003e \u003cp\u003eAverage response time (ms)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c6\"\u003e \u003cp\u003eMaximum response time (ms)\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e1\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e30\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e150\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e120\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e150\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e1000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e45\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e180\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e135\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e160\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e3\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e1500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e60\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e220\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e180\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e210\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e4\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e2000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e75\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e260\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e200\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e230\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e5\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e2500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e85\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e300\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e240\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e270\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e6\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e3000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e90\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e350\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e260\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e290\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e7\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e3500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e92\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e400\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e280\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e310\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e8\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e4000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e95\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e450\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e300\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e340\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e9\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e4500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e500\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e330\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e370\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e10\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e5000\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e99\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e550\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e360\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e400\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eAccording to the data in Table\u0026nbsp;\u003cspan refid=\"Tab4\" class=\"InternalRef\"\u003e4\u003c/span\u003e, the performance of the system is significantly affected when the number of requests increases from 500 times/second to 5000 times/second. When the number of requests is 500 times/second, the CPU utilization rate is 30%; the memory usage is 150MB; the average response time is 120 milliseconds; the maximum response time is 150 milliseconds, indicating that the system can respond quickly under low load. As the number of requests increases to 2500 times/second, the CPU utilization increases to 85%; the memory usage reaches 300MB; the average response time extends to 240 milliseconds; the maximum response time increases to 270 milliseconds, indicating that the system gradually responds slowly under high-load conditions. Especially when the number of requests reaches 5000 times/second, the CPU utilization rate reaches almost 99%, and the average response time and maximum response time increase to 360 milliseconds and 400 milliseconds respectively, indicating that under extreme load, the system\u0026rsquo;s performance is close to saturation, which may affect the efficiency of real-time monitoring and protection.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec17\" class=\"Section2\"\u003e \u003ch2\u003e6.3 Security Test\u003c/h2\u003e \u003cp\u003eThe purpose of security test is to evaluate the system\u0026rsquo;s ability to resist potential attacks. The Metasploit penetration testing tool is used to simulate various attack scenarios, including structured query language (SQL) injection and cross-site scripting (XSS) attacks. During the test, the system is constantly scanned by the test tool, and attempts are made to launch attacks using known vulnerabilities. Each attack lasts for 30 minutes, and the backend records the system\u0026rsquo;s response and the number of unauthorized accesses during the test. Table\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e shows the test results.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab5\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 5\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eSecurity test results\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"5\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eTest content\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eTest Number\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePenetration test blocking rate (%)\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eUnauthorized access count\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c5\"\u003e \u003cp\u003eAttack types\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eSQL injection attacks\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e1\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003eSQL injection\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eXSS attacks\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e97\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e1\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003eCross-site scripting\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003ePort scanning attacks\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e4\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e98\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003ePort scanning\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eMalware detection\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e5\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e99\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e0\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c5\"\u003e \u003cp\u003eMalware\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eTable\u0026nbsp;\u003cspan refid=\"Tab5\" class=\"InternalRef\"\u003e5\u003c/span\u003e shows the successful blocking rate of the protection system under different attacks. For SQL injection attacks, the system\u0026rsquo;s successful blocking rate is 98%, and its number of unauthorized accesses is only 2, which shows that it can effectively prevent SQL injection attacks. When dealing with XSS attacks, the blocking rate is also as high as 97%, and the number of unauthorized accesses is 1, which shows that the system has a good protection effect in cross-site scripting identification. Additionally, in terms of port scanning attacks and malware detection, the system achieves a successful blocking rate of 98% and 99%, and the number of unauthorized accesses is 2 and 0 respectively. These results fully demonstrate the strong ability of the protection system constructed in this article in recognizing and responding to potential threats, which provides a strong guarantee for the overall security.\u003c/p\u003e \u003c/div\u003e"},{"header":"7. Conclusion","content":"\u003cp\u003eTo address the security challenges of wireless communication in smart grids, an integrated defense and monitoring system is constructed in this article. By analyzing existing technologies, a monitoring system based on LSTM networks is adopted to achieve real-time identification and response of abnormal traffic. At the same time, a unified data sharing platform is established to ensure efficient collaboration between security defense and monitoring systems. In the functional test, the protection accuracy of the system is verified by simulating DDoS attacks of different intensities, and its response time and performance under high load are analyzed. Although the results are positive, indicating that the system effectively enhances the security of smart grids, the response time is significantly prolonged under high-frequency attacks, and the performance is close to saturation under high load, suggesting that further optimization is needed to improve the stability and responsiveness under extreme conditions. Future research can focus on applying advanced technologies such as quantum teleportation and deep learning to improve the intelligence level of security protection. At the same time, improving policies and industry standards can also provide guarantees for the security of smart grids, promote collaboration and information sharing, and form a securer network ecosystem. Overall, this article provides practical solutions for the security protection of wireless communication in smart grids and points out future research directions.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cp\u003e\u003cstrong\u003eFunding\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis work was supported by the State Grid Corporation Headquarters Science and Technology Project (Project Code: 5108-202218280A-2-410-XG).\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eData Availability\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe datasets used and/or analysed during the current study available from the corresponding author on reasonable request.\u003c/p\u003e\u003cp\u003eThere are no human studies involved in the images of my study and the article, so there is no need to publish consent\u003c/p\u003e\n"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003eSalkuti S R. Challenges, issues and opportunities for the development of smart grid[J]. International Journal of Electrical and Computer Engineering (IJECE), 2020, 10(2): 1179-1186.\u003c/li\u003e\n\u003cli\u003eButt O M, Zulqarnain M, Butt T M. Recent advancement in smart grid technology: Future prospects in the electrical power network[J]. Ain Shams Engineering Journal, 2021, 12(1): 687-695.\u003c/li\u003e\n\u003cli\u003eIslam S N, Baig Z, Zeadally S. Physical layer security for the smart grid: Vulnerabilities, threats, and countermeasures[J]. IEEE Transactions on Industrial Informatics, 2019, 15(12): 6522-6530.\u003c/li\u003e\n\u003cli\u003eHasan M K, Alkhalifah A, Islam S, et al. Blockchain technology on smart grid, energy trading, and big data: security issues, challenges, and recommendations[J]. Wireless Communications and Mobile Computing, 2022, 2022(1): 9065768-9065794.\u003c/li\u003e\n\u003cli\u003eZeinali M, Thompson J. Comprehensive practical evaluation of wired and wireless internet base smart grid communication[J]. IET Smart Grid, 2021, 4(5): 522-535.\u003c/li\u003e\n\u003cli\u003eKocak A, Taplamacioglu M C, Gozde H. General overview of area networks and communication technologies in smart grid applications[J]. International Journal on Technical and Physical Problems of Engineering (IJTPE), 2021 (46): 103-110.\u003c/li\u003e\n\u003cli\u003eKane L, Liu V, McKague M, et al. An Experimental Field Comparison of Wi-Fi HaLow and LoRa for the Smart Grid[J]. Sensors, 2023, 23(17): 7409-7436.\u003c/li\u003e\n\u003cli\u003eAgarkar A, Agrawal H. A review and vision on authentication and privacy preservation schemes in smart grid network[J]. Security and Privacy, 2019, 2(2): e62-e80.\u003c/li\u003e\n\u003cli\u003eAhene E, Qin Z, Adusei A K, et al. Efficient signcryption with proxy re-encryption and its application in smart grid[J]. IEEE Internet of Things Journal, 2019, 6(6): 9722-9737.\u003c/li\u003e\n\u003cli\u003ePeng C, Sun H, Yang M, et al. A survey on security communication and control for smart grids under malicious cyber attacks[J]. IEEE Transactions on Systems, Man, and Cybernetics: Systems, 2019, 49(8): 1554-1569.\u003c/li\u003e\n\u003cli\u003eReda H T, Anwar A, Mahmood A N, et al. A taxonomy of cyber defence strategies against false data attacks in smart grids[J]. ACM Computing Surveys, 2023, 55(14s): 1-37.\u003c/li\u003e\n\u003cli\u003eOmitaomu O A, Niu H. Artificial intelligence techniques in smart grid: A survey[J]. Smart Cities, 2021, 4(2): 548-568.\u003c/li\u003e\n\u003cli\u003eChehri A, Fofana I, Yang X. Security risk modeling in smart grid critical infrastructures in the era of big data and artificial intelligence[J]. Sustainability, 2021, 13(6): 3196-3215.\u003c/li\u003e\n\u003cli\u003eHu S, Chen X, Ni W, et al. Modeling and analysis of energy harvesting and smart grid-powered wireless communication networks: A contemporary survey[J]. IEEE Transactions on Green Communications and Networking, 2020, 4(2): 461-496.\u003c/li\u003e\n\u003cli\u003eKumar N, Mishra V M, Kumar A. Smart grid security with AES hardware chip[J]. International Journal of Information Technology, 2020, 12(1): 49-55.\u003c/li\u003e\n\u003cli\u003ePhilips A, Jayaraj J, FT J, et al. Enhanced RSA key encryption application for metering data in smart grid[J]. International Journal of Pervasive Computing and Communications, 2021, 17(5): 596-610.\u003c/li\u003e\n\u003cli\u003eGarg S, Kaur K, Kaddoum G, et al. Secure and lightweight authentication scheme for smart metering infrastructure in smart grid[J]. IEEE Transactions on Industrial Informatics, 2019, 16(5): 3548-3557.\u003c/li\u003e\n\u003cli\u003eFragkos G, Johnson J, Tsiropoulou E E. Dynamic role-based access control policy for smart grid applications: an offline deep reinforcement learning approach[J]. IEEE Transactions on Human-Machine Systems, 2022, 52(4): 761-773.\u003c/li\u003e\n\u003cli\u003eKisielewicz T, Stanek S, Zytniewski M. A multi-agent adaptive architecture for smart-grid-intrusion detection and prevention[J]. Energies, 2022, 15(13): 4726-4740.\u003c/li\u003e\n\u003cli\u003eKumar Y, Kumar V. A Systematic Review on Intrusion Detection System in Wireless Networks: Variants, Attacks, and Applications[J]. Wireless Personal Communications, 2023, 133(1): 395-452.\u003c/li\u003e\n\u003cli\u003eParween S, Hussain S Z, Hussain M A, et al. A survey on issues and possible solutions of cross-layer design in Internet of Things[J]. Int. J. Comput. Networks Appl, 2021, 8(4): 311-334.\u003c/li\u003e\n\u003cli\u003eSun W, Li P, Liu Z, et al. LSTM based link quality confidence interval boundary prediction for wireless communication in smart grid[J]. Computing, 2021, 103(2): 251-269.\u003c/li\u003e\n\u003cli\u003eGhafoor M I, Marjan S, Roomi M S, et al. Cyber-Malware Defense for Smart Grids Using Machine Learning[J]. Journal of Applied and Emerging Sciences, 2022, 12(2): 190-200.\u003c/li\u003e\n\u003cli\u003eHasan M N, Toma R N, Nahid A A, et al. Electricity theft detection in smart grid systems: A CNN-LSTM based approach[J]. Energies, 2019, 12(17): 3310-3328.\u003c/li\u003e\n\u003cli\u003eSiniosoglou I, Radoglou-Grammatikis P, Efstathopoulos G, et al. A unified deep learning anomaly detection and classification approach for smart grid environments[J]. IEEE Transactions on Network and Service Management, 2021, 18(2): 1137-1151.\u003c/li\u003e\n\u003cli\u003eGupta K D, Nigam R, Sharma D K, et al. LSTM-based energy-efficient wireless communication with reconfigurable intelligent surfaces[J]. IEEE Transactions on Green Communications and Networking, 2021, 6(2): 704-712.\u003c/li\u003e\n\u003cli\u003eBadr M M, Mahmoud M M E A, Fang Y, et al. Privacy-preserving and communication-efficient energy prediction scheme based on federated learning for smart grids[J]. IEEE Internet of Things Journal, 2023, 10(9): 7719-7736.\u003c/li\u003e\n\u003cli\u003eSarker M A A, Shanmugam B, Azam S, et al. Enhancing smart grid load forecasting: An attention-based deep learning model integrated with federated learning and XAI for security and interpretability[J]. Intelligent Systems with Applications, 2024, 23: 200422-200439.\u003c/li\u003e\n\u003cli\u003eAn D, Zhang F, Yang Q, et al. Data integrity attack in dynamic state estimation of smart grid: Attack model and countermeasures[J]. IEEE Transactions on Automation Science and Engineering, 2022, 19(3): 1631-1644.\u003c/li\u003e\n\u003cli\u003eWang Y, Zhang Z, Ma J, et al. KFRNN: An effective false data injection attack detection in smart grid based on Kalman filter and recurrent neural network[J]. IEEE Internet of Things Journal, 2021, 9(9): 6893-6904.\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Smart Grid, Wireless Communication Security, Security Defense, Intelligent Monitoring, Long Short-Term Memory","lastPublishedDoi":"10.21203/rs.3.rs-5352293/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5352293/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eWith the development of smart grids, wireless communication security issues have become increasingly prominent, including data eavesdropping, denial of service attacks, malicious software, and physical layer threats, which pose a serious threat to the stability and security of smart grid systems. In response to this situation, this article studies the security protection and monitoring of wireless communication in smart grids. A comprehensive security defense and monitoring structure is constructed by using the long short-term memory network technology. Firstly, through the analysis of existing protection mechanisms, a defense and monitoring system integration scheme based on a data sharing platform is proposed. Secondly, functional test, performance test, and security test are conducted based on the proposed system architecture. The low orbit ion cannon (LOIC) tool is used to simulate distributed denial of service (DDoS) attacks and verify the performance of the system under different attack intensities. At the same time, load test is conducted using Apache JMeter to evaluate the performance of the system under high loads. Finally, penetration test is carried out using the Metasploit tool to evaluate the system\u0026rsquo;s ability to resist various attacks. The experimental results show that the accuracy of the system remains between 82.2% and 96.5% under attack frequency of 500\u0026ndash;5000 times per second in the functional test, and the response time is extended from 120 milliseconds to 390 milliseconds, indicating high protection capability in low-intensity attacks. The performance test results show that when the number of concurrent requests increases from 500 to 5000, the CPU utilization increases from 30\u0026ndash;99%; the memory usage increases from 150MB to 550MB; the system response time is significantly prolonged, reflecting the performance bottleneck under high-load conditions. In the security test, the blocking rates of SQL (structured query language) injection and cross-site scripting (XSS) attacks reach 98% and 97% respectively, demonstrating the system\u0026rsquo;s effective defense capability against various attacks. In summary, this article provides an effective solution for the security protection of smart grids and points out the shortcomings of the system under high-intensity attacks and loads, providing important references for future research.\u003c/p\u003e","manuscriptTitle":"Wireless Communication Security Defense and Monitoring in Smart Grids","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-11-27 10:33:15","doi":"10.21203/rs.3.rs-5352293/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"6897f765-e01c-4166-be80-47142ec9c12e","owner":[],"postedDate":"November 27th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2025-04-29T09:23:56+00:00","versionOfRecord":[],"versionCreatedAt":"2024-11-27 10:33:15","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5352293","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5352293","identity":"rs-5352293","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-28T02:00:01.590549+00:00
License: CC-BY-4.0