首页> 外国专利> APPARATUS TO DETECT ABNORMAL BEHAVIOR OF NONSTANDARD PROTOCOL PAYLOAD BY USING DNN ALGORITHM AND METHOD THEREOF

APPARATUS TO DETECT ABNORMAL BEHAVIOR OF NONSTANDARD PROTOCOL PAYLOAD BY USING DNN ALGORITHM AND METHOD THEREOF

机译:用DNN算法检测非标准协议有效载荷异常行为的装置及其方法

摘要

Disclosed is an apparatus to detect the abnormal behavior of nonstandard protocol payload by using a DNN algorithm. The abnormal behavior detecting apparatus includes: a data packet collecting module collecting a data packet in real time in accordance with a nonstandard protocol under an industrial control system environment; a data packet classification module outputting payload by parsing the data packet collected in real time by the data packet collecting module; a payload mask pattern generating module generating a payload mask pattern in relation to the payload outputted from the data packet classification module; a payload mask pattern application module applying the payload mask pattern generated by the payload mask pattern generating module to the payload of the data packet collected in real time by the data packet collecting module; a payload normalizing module normalizing the payload to which the payload mask pattern has been applied by the payload mask pattern application module; a learning data set generating module generating a learning data set for deep learning through a DNN algorithm by using the payload normalized by the payload normalizing module; and an abnormal behavior detecting module detecting the abnormal behavior of the nonstandard protocol data packet collected by the data packet collecting module by conducting deep learning based on the DNN algorithm by using the learning data set generated by the learning data set generating module.;COPYRIGHT KIPO 2019
机译:公开了一种通过使用DNN算法来检测非标准协议有效载荷的异常行为的装置。异常行为检测装置包括:数据包收集模块,在工业控制系统环境下,根据非标准协议实时收集数据包。数据包分类模块通过解析数据包采集模块实时采集的数据包,输出有效载荷;有效载荷掩模图案生成模块,生成与从数据分组分类模块输出的有效载荷有关的有效载荷掩模图案;有效载荷掩模图案应用模块,将有效载荷掩模图案生成模块生成的有效载荷掩模图案应用于数据包收集模块实时收集的数据包的有效载荷;有效载荷归一化模块,对由有效载荷掩模图案应用模块施加了有效载荷掩模图案的有效载荷进行归一化;学习数据集生成模块,通过有效载荷归一化模块归一化后的有效载荷,通过DNN算法生成用于深度学习的学习数据集; COPYRIGHT KIPO;异常行为检测模块,通过基于DNN算法进行深度学习,通过DNN算法进行深度学习,检测出数据包收集模块收集到的非标准协议数据包的异常行为。 2019年

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号