首页> 外国专利> PROCESS SEMANTIC BASED CAUSAL MAPPING FOR SECURITY MONITORING AND ASSESSMENT OF CONTROL NETWORKS

PROCESS SEMANTIC BASED CAUSAL MAPPING FOR SECURITY MONITORING AND ASSESSMENT OF CONTROL NETWORKS

机译:基于过程语义的因果映射,用于安全监控和控制网络评估

摘要

Systems and methods are disclosed for security assessment in an Industrial Control System (ICS). A plurality of agents, disposed in the network at different control levels of the ICS, collects data including process variables related to control processes. A causal mapping module constructs a causal graph of nodes by mapping each of the process variables to a node, mapping semantics based directional relationships to edges between nodes, and assigning edge weights based on calculated pairwise causality measurements between nodes. An anomaly detection module analyzes dynamics of the causal graph over time to detect an anomaly in response to observing an abnormal edge weight evolution. A security assessment module performs a security assessment for a target node in the causal graph by assessing a criticality threshold for the target node based on number of causal relationships with the target node.
机译:公开了用于工业控制系统(ICS)中的安全性评估的系统和方法。布置在网络中ICS的不同控制级别的多个代理收集数据,其中包括与控制过程有关的过程变量。因果映射模块通过将每个过程变量映射到节点,将基于语义的方向关系映射到节点之间的边缘,并基于计算的节点间成对因果关系度量来分配边缘权重,从而构造节点的因果图。异常检测模块分析因果图随时间变化的动态,以响应于观察到异常边缘权重演变而检测到异常。安全评估模块通过基于与目标节点之间因果关系的数量评估目标节点的临界阈值,对因果图中的目标节点执行安全评估。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号