METHOD FOR DETECTING ANOMALIES IN SSL AND/OR TLS COMMUNICATIONS, CORRESPONDING DEVICE, AND COMPUTER PROGRAM PRODUCT

    公开(公告)号:EP4106268A1

    公开(公告)日:2022-12-21

    申请号:EP22174800.7

    申请日:2022-05-23

    申请人: Aizoon S.r.l.

    IPC分类号: H04L9/40

    摘要: Described herein is a method and network-security monitoring platform, also identified as Security Network Monitoring Platform (SNMP), for detecting anomalies in SSL and/or TLS communications set up in a communications network. The SNMP analyses (1004) data packets (DP) for detecting anomalous SSL and/or TLS handshake procedures in a monitoring interval, wherein each SSL and/or TLS handshake procedure comprises a first message sent by a respective client to a respective server for starting the respective SSL or TLS communication, and a corresponding second message sent by the respective server to the respective client. Next, the SNMP determines for each handshake procedure a first signature as a function of the data sent with the first message and a second signature as a function of the data of one or more certificates of the chain of certificates (CERT) sent with the second message. The SNMP then analyses the first and the second signatures to determine the respective popularity values. Moreover, the SNMP analyses each chain of certificates (CERT) to extract the information that indicates the fact that at least one of the certificates (CERT) of the chain is self-signed, and/or at least one of the certificates (CERT) has expired.
    During a training step, the SNMP trains a classifier (1008) using the popularity values and the information extracted from the certificates (CERT), so that the classifier (1042) supplies as output a value that indicates whether a given handshake procedure corresponds to a usual or to an anomalous handshake procedure. Consequently, during operation in steady-state conditions, the SNMP can use the classifier (1008) to supply, for each handshake procedure, a respective value that indicates whether the respective handshake procedure corresponds to a usual handshake procedure or to an anomalous handshake procedure and, in the case where (1010) at least one handshake procedure has been classified as anomalous, generate (1012) a notification that indicates the fact that the respective SSL or TLS communication presents an anomaly.

    WIDEBAND MEASUREMENT DATA PROCESSING METHOD AND APPARATUS, ELECTRONIC DEVICE AND MEDIUM

    公开(公告)号:EP4033261A1

    公开(公告)日:2022-07-27

    申请号:EP19945662.5

    申请日:2019-11-29

    IPC分类号: G01R31/00

    摘要: Provided are a wideband measurement data processing method and apparatus, an electronic device and a medium. The method comprises: acquiring wideband measurement data of a substation; carrying out preprocessing analysis on the wideband measurement data to obtain a preprocessing analysis file; carrying out diagnosis analysis on the wideband measurement data, and obtaining a substation area analysis brief report in conjunction with the preprocessing analysis file; and transmitting the wideband measurement data, the preprocessing analysis file and the substation area analysis brief report to a master scheduling station, and receiving an operation control instruction of the master scheduling station, wherein the wideband measurement data comprises a wideband measurement value, a fault wave record file and alarm information, and the wideband measurement value comprises a fundamental wave measurement value, a harmonic measurement value and an inter-harmonic measurement value.

    A BINARY-TO-GRAY CONVERSION CIRCUIT, RELATED FIFO MEMORY, INTEGRATED CIRCUIT AND METHOD

    公开(公告)号:EP3531560A1

    公开(公告)日:2019-08-28

    申请号:EP19157120.7

    申请日:2019-02-14

    IPC分类号: H03M7/16 G06F5/06 G11C7/22

    摘要: A Binary-to-Gray conversion circuit (240b is described. The Binary-to-Gray conversion circuit (240b) comprises:
    - an input configured to receive a first binary signal (PTR_target),
    - a register (61) configured to store a second binary signal (PTRf),
    - a prediction circuit (62) configured to receive at input said second binary signal (PTRf) and provide at output a set of binary candidate values (63a-63c), wherein the respective Gray equivalent of each binary candidate value (63a-63c) has a Hamming distance of one from the Gray equivalent of said second binary signal (PTRf),
    - an arbiter (66) configured to select one of said binary candidate values (63a-63c) as a function of said first binary signal (PTR_target) and said second binary signal (PTRf), wherein the selected binary candidate value is provided at input to said register (61);
    - an encoder block (68) configured to receive the selected binary candidate value and output the Gray encoded equivalent (PTR_gray) of the selected binary candidate value.