发明名称 ABNORMAL TRAFFIC DETECTION METHOD ON CONTROL SYSTEM PROTOCOL
摘要 <p>The present invention relates to an abnormal traffic detection method on a control system protocol. The disclosed abnormal traffic detection method comprises the steps of testing whether session information exists in a management table if a received packet is a MODBUS request message; adding a new entry in the management table if the session information does not exist in the management table; testing whether a transaction ID within a corresponding table entry is the same as a transaction ID of the received MODBUS request message, if the session information exists in the management table; testing whether data of the received MODBUS request message is the same as data within a table entry, if the transaction ID of the table entry is not the same as that of the MODBUS request message; detecting the received data as an abnormal traffic if the transaction ID or the data of the data entry is the same as that of the MODBUS request message; and updating the table entry with packet information of the MODBUS request message if the data of the table entry is not the same as that of the MODBUS request message. Therefore, the present invention can detect and handle the abnormal traffic that disturbs a normal service connection or causes an error on the control system protocol, at an early stage, thereby providing a stable connection system between control systems which can rapidly detect and handle the abnormal traffic caused by a system and a network error as well as an intentional behavior of an invader.</p>
申请公布号 KR20140117753(A) 申请公布日期 2014.10.08
申请号 KR20130032212 申请日期 2013.03.26
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 KIM, BYOUNG KOO;KANG, DONG HO;SOHN, SEON GYOUNG;HEO, YOUNG JUN;NA, JUNG CHAN;KIM, IK KYUN
分类号 H04L12/22;H04L12/26 主分类号 H04L12/22
代理机构 代理人
主权项
地址