首页> 外国专利> APPARATUS AND METHOD FOR ANOMALY DETECTION IN SCADA NETWORK USING SELF-SIMILARITY

APPARATUS AND METHOD FOR ANOMALY DETECTION IN SCADA NETWORK USING SELF-SIMILARITY

机译:基于自相似的SCADA网络异常检测的装置和方法

摘要

PURPOSE: An apparatus and a method for detecting symptom data of a SCADA(Supervisory Control And Data Acquisition) network are provided to solve a problem for detecting an evasion attack or new type attacks. CONSTITUTION: A storage unit(10) measures self-similarity from one or more attribution information which indicates a traffic state of a network in a normal state. The storage unit stores a set threshold value. A measuring unit(20) measures the self-similarity in real time from one or more attribution information in the network. A determination unit(30) compares the measured real-time self-similarity value with the set threshold value. The determination unit determines an abnormal state of the network. [Reference numerals] (10) Storage unit; (20) Measuring unit; (23) Network; (25) Event log; (30) Determination unit
机译:目的:提供一种用于检测SCADA(监督控制和数据采集)网络的症状数据的设备和方法,以解决用于检测逃避攻击或新型攻击的问题。构成:存储单元(10)根据一个或多个指示正常状态下网络流量状态的属性信息来测量自相似性。存储单元存储设置的阈值。测量单元(20)根据网络中的一个或多个属性信息实时测量自相似性。确定单元(30)将所测量的实时自相似度值与所设置的阈值进行比较。确定单元确定网络的异常状态。 [附图标记](10)存储单元; (20)测量单位; (23)网络; (25)事件日志; (30)确定单位

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号