发明名称 Methods and systems for use in identifying abnormal behavior in a control system including independent comparisons to user policies and an event correlation model
摘要 Methods and apparatus for use in identifying abnormal behavior in a control system. Operating events associated with a control system are received, and an actual behavior of the control system is determined based on the received operating events. The actual behavior is compared to expected behavior to determine whether the actual behavior differs from the expected behavior. The expected behavior includes a correlation between a plurality of operating events associated with the control system. The expected behavior is updated based on an indication of whether the actual behavior is abnormal from a user.
申请公布号 US8949668(B2) 申请公布日期 2015.02.03
申请号 US201113113529 申请日期 2011.05.23
申请人 The Boeing Company 发明人 Hanks Carl J.;Dorris Steven A.;Ayyagari Arun
分类号 G06F11/00;G06F11/30;H04L29/08;G06F21/55;H04L29/06;H04L29/14;G05B23/02 主分类号 G06F11/00
代理机构 Armstrong Teasdale LLP 代理人 Armstrong Teasdale LLP
主权项 1. A method for use in identifying abnormal behavior in a supervisory control and data acquisition (SCADA) system including a learning system, said method comprising: receiving, by a computing device, a plurality of operating events associated with the SCADA system, wherein the operating events represent at least one physical operating event; determining, by the computing device, an actual behavior of the SCADA system based on the operating events; dynamically identifying, by the learning system, at least one correlation between a plurality of past operating events stored in a past event database; creating an artificial intelligence (AI) event correlation model based on the at least one correlation identified by the learning system; comparing, by the computing device, the actual behavior of the SCADA system to the AI event correlation model to determine whether the actual behavior differs from the AI event correlation model; comparing, by the computing device and independent of said comparing the actual behavior of the SCADA system to the AI event correlation model, the actual behavior of the SCADA system to user policies using a complex event processing component; receiving, by the computing device, an indication of whether the actual behavior is abnormal from a user when the actual behavior differs from the AI event correlation model; and updating, by the computing device, the AI event correlation model based on the received indication.
地址 Chicago IL US