发明名称 Method for intrusion detection in industrial automation and control system
摘要 The present invention is concerned with a method and a system for automatic signalling an alert when a possible intrusion occurs in an industrial automation and control system, based on security events which occur in the industrial automation and control system or are externally fed into the system. The method comprises steps of: (a) determining a correlation of a first and second security event and storing the correlation in an event database, wherein the correlation includes a probability that the first security event is followed by the second security event within a normalised time period, (b) identifying a candidate event as the first security event, based on event information of the candidate event, upon occurrence of the candidate event, (c) classifying the candidate event as anomalous when the probability exceeds a predetermined threshold and no second security event follows the candidate event within the normalised time period, and (d) signalling the alert indicating the candidate event.
申请公布号 EP3023852(A1) 申请公布日期 2016.05.25
申请号 EP20140194321 申请日期 2014.11.21
申请人 ABB TECHNOLOGY AG 发明人 OBERMEIER, SEBASTIAN;SCHLEGEL, ROMAN;WAHLER, MICHAEL
分类号 H04L29/06;H04L12/24 主分类号 H04L29/06
代理机构 代理人
主权项
地址