发明名称 Method for Detecting Anomalies in a Control Network
摘要 A method for monitoring and controlling, industrial or building automation to detect anomalies in a control network, wherein a technology of an intrusion detection system (IDS) is configured to analyze a time sequence and time intervals of correct messages in the network traffic and to use the messages to train an anomaly detection system. Detecting a time sequence and a rhythm of correct messages allows for the detection of malfunctions or manipulations of devices and attacks that are performed using regular monitoring or control stations that have been taken over by attackers or that are defect, and that cannot be detected using content-based methods or by a considerable increase of data traffic. An additional security barrier is thus provided that can continue monitoring and protecting a technical unit from possible acts of sabotage, even if the control network of the technical unit has already been corrupted.
申请公布号 US2012198277(A1) 申请公布日期 2012.08.02
申请号 US201013497461 申请日期 2010.08.12
申请人 BUSSER JENS-UWE;KAESTNER JAN;MUNZERT MICHAEL;STOERMANN CHRISTOF;SIEMENS AKTIENGESELLSCHAFT 发明人 BUSSER JENS-UWE;KAESTNER JAN;MUNZERT MICHAEL;STOERMANN CHRISTOF
分类号 G06F11/07;G06F15/18 主分类号 G06F11/07
代理机构 代理人
主权项
地址