首页> 外国专利> Content-aware firewalling, policy regulation, and policy management for industrial automation, machine-to-machine communications, and embedded devices

Content-aware firewalling, policy regulation, and policy management for industrial automation, machine-to-machine communications, and embedded devices

机译:用于工业自动化,机器对机器通信和嵌入式设备的内容感知防火墙,策略法规和策略管理

摘要

In one embodiment, a processor-implemented method for controlling network traffic to and/or from at least one industrial machine, including: (a) receiving, as input, (i) a stored policy object in language form defining at least one desired behavior and/or operational constraint for the at least one industrial machine, and (ii) a stored machine profile defining an association between the language of the stored policy object and at least one control signal or instruction for the at least one industrial machine; (b) detecting, in network traffic to and/or from the at least one industrial machine, a transaction; (c) applying the received policy object and machine profile to the detected transaction to determine whether a desired behavior exists and/or whether an operational constraint is satisfied; and (d) modifying network traffic to and/or from the at least one industrial machine based on the determination in step (c). This permits expression and enforcement of constraints on actual industrial machine behaviors by filtering, modifying or blocking network communications (e.g., control signals and telemetry) that violate constraints or could cause unsafe or inefficient operation.
机译:在一个实施例中,一种用于控制去往和/或来自至少一个工业机器的网络流量的处理器实现的方法,包括:(a)作为输入接收(i)以定义至少一种期望行为的语言形式的存储的策略对象。和/或至少一台工业机器的操作约束,以及(ii)定义了存储的策略对象的语言和至少一台工业机器的至少一个控制信号或指令之间的关联的存储的机器配置文件; (b)在去往和/或来自至少一台工业机器的网络流量中检测交易; (c)将接收到的策略对象和机器配置文件应用于检测到的事务,以确定是否存在期望的行为和/或是否满足操作约束; (d)基于步骤(c)中的确定,修改去往和/或来自至少一台工业机器的网络流量。这允许通过过滤,修改或阻止违反约束或可能导致不安全或低效操作的网络通信(例如,控制信号和遥测)来表达和实施对实际工业机器行为的约束。

著录项

  • 公开/公告号US10476844B2

    专利类型

  • 公开/公告日2019-11-12

    原文格式PDF

  • 申请/专利权人 BAYSHORE NETWORKS INC.;

    申请/专利号US201816126401

  • 发明设计人 FRANCIS CIANFROCCA;

    申请日2018-09-10

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 11:29:33

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号