首页> 外国专利> Method for intrusion detection in industrial automation and control system

Method for intrusion detection in industrial automation and control system

机译:工业自动化控制系统中入侵检测的方法

摘要

The present invention is concerned with a method and a system for automatic signalling an alert when a possible intrusion occurs in an industrial automation and control system, based on security events which occur in the industrial automation and control system or are externally fed into the system. The method comprises steps of: (a) determining a correlation of a first and second security event and storing the correlation in an event database, wherein the correlation includes a probability that the first security event is followed by the second security event within a normalised time period, (b) identifying a candidate event as the first security event, based on event information of the candidate event, upon occurrence of the candidate event, (c) classifying the candidate event as anomalous when the probability exceeds a predetermined threshold and no second security event follows the candidate event within the normalised time period, and (d) signalling the alert indicating the candidate event.
机译:本发明涉及一种方法和系统,用于基于工业自动化和控制系统中发生的安全事件或从外部馈入系统的安全事件,在工业自动化和控制系统中发生可能的入侵时自动发出警报信号。该方法包括以下步骤:(a)确定第一和第二安全事件的相关性并将该相关性存储在事件数据库中,其中该相关性包括在归一化时间内第一安全事件之后是第二安全事件的概率。期间,(b)在候选事件发生时,基于候选事件的事件信息将候选事件识别为第一安全事件,(c)当概率超过预定阈值且没有第二个时,将候选事件分类为异常安全事件在标准化时间段内紧随候选事件之后,并且(d)发出警报以指示候选事件。

著录项

  • 公开/公告号EP3023852B1

    专利类型

  • 公开/公告日2017-05-03

    原文格式PDF

  • 申请/专利权人 ABB SCHWEIZ AG;

    申请/专利号EP20140194321

  • 申请日2014-11-21

  • 分类号H04L29/06;H04L12/24;

  • 国家 EP

  • 入库时间 2022-08-21 14:06:05

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号