首页> 外国专利> MODBUS TCP COMMUNICATION BEHAVIOUR ANOMALY DETECTION METHOD BASED ON OCSVM DUAL-OUTLINE MODEL

MODBUS TCP COMMUNICATION BEHAVIOUR ANOMALY DETECTION METHOD BASED ON OCSVM DUAL-OUTLINE MODEL

机译:基于OCSVM双外线模型的MODBUS TCP通信行为异常检测方法

摘要

Proposed is an anomaly detection method for communication behaviours in an industrial control system based on an OCSVM algorithm. According to the present invention, a normal behaviour profile model and an abnormal behaviour profile model, i.e. a dual-outline model, of communication behaviours in an industrial control system are established, parameter optimization is performed by means of a particle swarm optimization (PSO) algorithm, an optimal intrusion detection model is obtained, and abnormal Modbus TCP communication traffic is identified. According to the present invention, the false alarm rate is reduced by means of cooperative discrimination of the dual-outline detection model, the efficiency and reliability of anomaly detection are improved, and the method is more applicable to practical applications.
机译:提出了一种基于OCSVM算法的工业控制系统中通信行为的异常检测方法。根据本发明,建立了工业控制系统中通信行为的正常行为分布模型和异常行为分布模型,即双轮廓模型,并通过粒子群优化(PSO)进行了参数优化。该算法获得了最佳的入侵检测模型,并识别了异常的Modbus TCP通信流量。根据本发明,通过双重判别检测模型的协同判别,降低了误报率,提高了异常检测的效率和可靠性,更加适用于实际应用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号