Invention Grant
- Patent Title: Modbus TCP communication behaviour anomaly detection method based on OCSVM dual-outline model
-
Application No.: US15527208Application Date: 2014-12-30
-
Publication No.: US10261502B2Publication Date: 2019-04-16
- Inventor: Wenli Shang , Jianming Zhao , Ming Wan , Peng Zeng , Haibin Yu
- Applicant: SHENYANG INSTITUTE OF AUTOMATION, CHINESE ACADEMY OF SCIENCES
- Applicant Address: CN Shenyang, Liaoning
- Assignee: SHENYANG INSTITUTE OF AUTOMATION, CHINESE ACADEMY OF SCIENCES
- Current Assignee: SHENYANG INSTITUTE OF AUTOMATION, CHINESE ACADEMY OF SCIENCES
- Current Assignee Address: CN Shenyang, Liaoning
- Agency: Smith, Gambrell & Russell, LLP
- Priority: CN201410699413 20141126
- International Application: PCT/CN2014/095576 WO 20141230
- International Announcement: WO2016/082284 WO 20160602
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G05B19/418 ; H04L12/40

Abstract:
Proposed is an anomaly detection method for communication behaviors in an industrial control system based on an OCSVM algorithm. According to the present invention, a normal behavior profile model and an abnormal behavior profile model, i.e. a dual-outline model, of communication behaviors in an industrial control system are established, parameter optimization is performed by means of a particle swarm optimization (PSO) algorithm, an optimal intrusion detection model is obtained, and abnormal Modbus TCP communication traffic is identified. According to the present invention, the false alarm rate is reduced by means of cooperative discrimination of the dual-outline detection model, the efficiency and reliability of anomaly detection are improved, and the method is more applicable to practical applications.
Public/Granted literature
- US20170329314A1 MODBUS TCP COMMUNICATION BEHAVIOUR ANOMALY DETECTION METHOD BASED ON OCSVM DUAL-OUTLINE MODEL Public/Granted day:2017-11-16
Information query