Anomaly traffic detection and attack traceability for power communication networks
Abstract
Power communication networks carry protection, metering, dispatching, and automated-control messages whose abnormal traffic may rapidly evolve into cyber-physical incidents. Existing intrusion detectors usually report an attack label but provide limited evidence about the source path, protocol cause, and affected electrical asset. This paper proposes a protocol-aware method that combines normalized flow features, a dynamic evidence graph, a spatio-temporal graph attention encoder, and a temporal autoencoder. The detector converts heterogeneous network observations into a calibrated anomaly score and then ranks traceback paths according to timing, protocol compatibility, attention contribution, and grid-impact evidence. To strengthen the empirical basis, a regional substation communication testbed with IEC 61850, MMS, DNP3, and Modbus traffic is used to compare random forest, LSTM, GraphSAGE, ST-GAT, and the proposed dual-channel model. The proposed method achieves 97.4% macro-F1 and a 92.6% top-1 traceback hit rate, while producing ranked evidence chains within 7.2 s after alarm triggering. The framework is also suitable for optical-fiber-supported automated-control networks and energy-facility communication scenarios where reliable traffic forensics is required.