Invention Grant
- Patent Title: Protocol-independent anomaly detection
-
Application No.: US16535521Application Date: 2019-08-08
-
Publication No.: US11297082B2Publication Date: 2022-04-05
- Inventor: Junghwan Rhee , LuAn Tang , Zhengzhang Chen , Chung Hwan Kim , Zhichun Li , Ziqiao Zhou
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: US NJ Princeton
- Assignee: NEC Laboratories America, Inc.
- Current Assignee: NEC Laboratories America, Inc.
- Current Assignee Address: US NJ Princeton
- Agent Joseph Kolodka
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G05B19/418

Abstract:
A computer-implemented method for implementing protocol-independent anomaly detection within an industrial control system (ICS) includes implementing a detection stage, including performing byte filtering using a byte filtering model based on at least one new network packet associated with the ICS, performing horizontal detection to determine whether a horizontal constraint anomaly exists in the at least one network packet based on the byte filtering and a horizontal model, including analyzing constraints across different bytes of the at least one new network packet, performing message clustering based on the horizontal detection to generate first cluster information, and performing vertical detection to determine whether a vertical anomaly exists based on the first cluster information and a vertical model, including analyzing a temporal pattern of each byte of the at least one new network packet.
Public/Granted literature
- US20200059484A1 PROTOCOL-INDEPENDENT ANOMALY DETECTION Public/Granted day:2020-02-20
Information query