首页> 外国专利> INTRUSION DETECTION VIA SEMANTIC FUZZING AND MESSAGE PROVENANCE

INTRUSION DETECTION VIA SEMANTIC FUZZING AND MESSAGE PROVENANCE

机译:通过语义模糊和消息来源进行入侵检测

摘要

Intrusion detection systems and methods monitor legal control messages in an operational control system to detect subtly malicious sequences of control messages with undesirable emergent effects on devices in the operational control system. A message provenance component may investigate system-level correlations between messages rather than detecting if individual messages are anomalous. A semantic fuzzing component may search, based on the operational effect of candidate message sequences, the space of legal messages for sequences that cause actual harm. Behavior oracles may be used to test message sequences to identify sequences that induce drift towards a failure state. The intrusion detection system is able to prevent harm and disruption arising from control messages that individually appear legitimate and benign but that, in combination with other messages, can cause undesirable outcomes.
机译:入侵检测系统和方法监视操作控制系统中的合法控制消息,以检测对控制消息的微妙恶意序列,从而对操作控制系统中的设备产生不良影响。消息出处组件可以调查消息之间的系统级相关性,而不是检测单个消息是否异常。语义模糊组件可以基于候选消息序列的操作效果,在合法消息的空间中搜索导致实际危害的序列。行为预言机可用于测试消息序列,以识别导致向故障状态漂移的序列。入侵检测系统能够防止由于控制消息而造成的伤害和破坏,这些消息单独看起来是合法的和良性的,但与其他消息结合使用会导致不良后果。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号