首页> 外国专利> ANOMALY DETECTION IN INDUSTRIAL COMMUNICATIONS NETWORKS, ANOMALY DETECTION SYSTEM, AND METHODS FOR PERFORMING ANOMALY DETECTION

ANOMALY DETECTION IN INDUSTRIAL COMMUNICATIONS NETWORKS, ANOMALY DETECTION SYSTEM, AND METHODS FOR PERFORMING ANOMALY DETECTION

机译:工业通信网络中的异常检测,异常检测系统以及执行异常检测的方法

摘要

PROBLEM TO BE SOLVED: To detect intrusions into control and maintenance communications networks, such as those used in process and industrial control systems.SOLUTION: An anomaly detection system 10 includes various data collection modules 30, 32 at each of nodes 22A to 22N of a network 20 which operate to view message traffic into and out of the node and to generate metadata pertaining to the message traffic. The communication modules 33 at the nodes send the traffic metadata to an anomaly analysis engine 34, which processes the metadata using a rules engine that analyzes the metadata using a set of logic rules and traffic pattern baseline data to determine if current traffic patterns at one or more network nodes are anomalous.SELECTED DRAWING: Figure 1
机译:解决的问题:检测对诸如过程和工业控制系统中使用的控制和维护通信网络的入侵。解决方案:异常检测系统10在一个节点的节点22A至22N的每个节点上包括各种数据收集模块30、32。网络20操作以查看进出节点的消息流量并生成与消息流量有关的元数据。节点处的通信模块33将流量元数据发送到异常分析引擎34,异常分析引擎34使用规则引擎处理元数据,该规则引擎使用一组逻辑规则和流量模式基线数据来分析元数据,以确定当前流量模式是否为一个或多个。更多网络节点异常。选定的图纸:图1

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号