首页> 外国专利> Method for intrusion detection in industrial automation and control system

Method for intrusion detection in industrial automation and control system

机译:工业自动化控制系统中入侵检测的方法

摘要

A method and system for automatic signalling an alert when a possible intrusion occurs in an industrial automation and control system, based on security events which occur in the industrial automation and control system or are externally fed into the system. The method includes the steps of: (a) determining a correlation of a first and second security event and storing the correlation in an event database, wherein the correlation includes a probability that the first security event is followed by the second security event within a normalized time period, (b) identifying a candidate event as the first security event, based on event information of the candidate event, upon occurrence of the candidate event, (c) classifying the candidate event as anomalous when the probability exceeds a predetermined threshold and no second security event follows the candidate event within the normalized time period, and (d) signalling the alert indicating the candidate event.
机译:一种基于在工业自动化和控制系统中发生或从外部馈入系统的安全事件,在工业自动化和控制系统中发生可能的入侵时自动发出警报信号的方法和系统。该方法包括以下步骤:(a)确定第一和第二安全事件的相关性并将该相关性存储在事件数据库中,其中该相关性包括在归一化的范围内第一安全事件之后是第二安全事件的概率。时间段,(b)在候选事件发生时,基于候选事件的事件信息将候选事件识别为第一安全事件,(c)当概率超过预定阈值时将候选事件分类为异常,并且第二安全事件在标准化时间段内紧随候选事件之后,并且(d)发出警报以指示候选事件。

著录项

  • 公开/公告号US10187411B2

    专利类型

  • 公开/公告日2019-01-22

    原文格式PDF

  • 申请/专利权人 ABB SCHWEIZ AG;

    申请/专利号US201514945692

  • 申请日2015-11-19

  • 分类号H04L29/06;G06F9/54;G06F17/30;G06F21/55;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-21 12:11:09

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号