发明名称 Method for detecting abnormal traffic on control system protocol
摘要 A method for detecting an abnormal traffic on a control system protocol, includes: checking whether session information exists in a management table; adding a new entry to the management table; checking whether a transaction ID in a table entry is the same as that of the received MODBUS request message; and checking whether data and length thereof of the received MODBUS request message are the same as those in the table entry. Further, the method includes detecting an abnormal traffic; and updating the table entry with packet information of the MODBUS request message.
申请公布号 US9298175(B2) 申请公布日期 2016.03.29
申请号 US201313933822 申请日期 2013.07.02
申请人 Electronics and Telecommunications Research Institute 发明人 Kim Byoung-Koo;Kang Dong Ho;Sohn Seon-Gyoung;Heo Youngjun;Na Jung-Chan;Kim Ik Kyun
分类号 H04L12/26;G05B15/02;H04L29/06;H04L12/40 主分类号 H04L12/26
代理机构 William Park & Associates Ltd. 代理人 William Park & Associates Ltd.
主权项 1. A method for detecting an abnormal traffic on a control system protocol, the method comprising: checking whether session information exists in a management table when a received packet is a MODBUS request message; adding a new entry to the management table when the session information does not exist in the management table; checking whether a transaction ID in a table entry is the same as that of the received MODBUS request message when the session information exists in the management table; checking whether data and length thereof of the received MODBUS request message are the same as those in the table entry when the transaction ID of the table entry is not the same as that of the MODBUS request message; detecting an abnormal traffic when the transaction ID of the table entry is the same as that of the MODBUS request message, or the data of the table entry is the same as that of the MODBUS request message; and updating the table entry with packet information of the MODBUS request message when the data of the table entry is not the same as that of the MODBUS request message.
地址 Daejeon KR