首页> 外国专利> L2 INTRUSION PREVENTION SYSTEM AND METHOD CAPABLE OF BLOCKING L2 PACKET

L2 INTRUSION PREVENTION SYSTEM AND METHOD CAPABLE OF BLOCKING L2 PACKET

机译:能够阻止L2数据包的L2入侵预防系统和方法

摘要

Disclosed are an intrusion prevention system capable of blocking an L2 packet and a method thereof, wherein the system comprises: a packet input module receiving a packet; a packet checking module checking whether the packet received in the packet input module is an L2 packet; and an L2 packet filtering module which parses the L2 packet checked by the packet checking module, and blocks or passes the L2 packet corresponding to the parsing result. Therefore, the intrusion prevention system capable of blocking an L2 packet and the method thereof are configured to detect intrusion with respect to the L2 packet which is mainly used under the environment of an industry control system by using a whitelist composed of a MAC address of devices of the industry control system, thereby enabling detection and prevention of the intrusion of the L2 packet, which were not possible according to known technology. Furthermore, the present invention is configured to detect intrusion based on a payload of the packet, and to perform machine learning based on the payload of a non-standard protocol packet which is mainly used under the environment of the industry control system, to automatically generate the whitelist in real time. Therefore, the present invention can detect an unannounced abnormal operation and determine the abnormality thereof in real time.
机译:公开了一种能够阻止L2分组的入侵防御系统及其方法,其中,该系统包括:分组输入模块,用于接收分组;以及分组检查模块,检查在所述分组输入模块中接收到的分组是否为L2分组; L2数据包过滤模块,对所述数据包检查模块检查的L2数据包进行解析,对与解析结果对应的L2数据包进行阻塞或通过。因此,能够阻塞L2分组的入侵防御系统及其方法被配置为通过使用由设备的MAC地址组成的白名单来检测针对主要在工业控制系统的环境下使用的L2分组的入侵。工业控制系统的L2分组,从而使得能够检测和防止L2分组的入侵,这根据已知技术是不可能的。此外,本发明被配置为基于分组的有效载荷来检测入侵,并且基于主要在工业控制系统的环境下使用的非标准协议分组的有效载荷来执行机器学习,以自动生成实时加入白名单。因此,本发明可以检测未通知的异常操作并实时确定其异常。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号