PACKET MONITORING DEVICE AND PACKET MONITORING METHOD FOR COMMUNICATION PACKET
    1.
    发明申请
    PACKET MONITORING DEVICE AND PACKET MONITORING METHOD FOR COMMUNICATION PACKET 审中-公开
    分组监控设备和通信分组的分组监控方法

    公开(公告)号:US20160277547A1

    公开(公告)日:2016-09-22

    申请号:US15069831

    申请日:2016-03-14

    CPC classification number: H04L43/18 H04L43/028 H04L63/1425

    Abstract: Provided is a packet monitoring method for a communication packet transmitted and received between a server and a control device including receiving the communication packet transmitted and received between the server and the control device; determining whether the received communication packet is abnormal, based on a history table including control information on communication packets received before the received communication packet and control information on the received communication packet; and performing a security operation according to results of the determination.

    Abstract translation: 提供了一种用于在服务器和控制设备之间发送和接收的通信分组的分组监视方法,包括:接收在服务器和控制设备之间发送和接收的通信分组; 基于包括在接收到的通信分组之前接收的通信分组的控制信息的历史表和关于所接收的通信分组的控制信息,确定接收到的通信分组是否异常; 以及根据确定的结果执行安全操作。

    METHOD FOR DETECTING ABNORMAL TRAFFIC ON CONTROL SYSTEM PROTOCOL
    2.
    发明申请
    METHOD FOR DETECTING ABNORMAL TRAFFIC ON CONTROL SYSTEM PROTOCOL 有权
    检测控制系统协议异常通信的方法

    公开(公告)号:US20140297004A1

    公开(公告)日:2014-10-02

    申请号:US13933822

    申请日:2013-07-02

    Abstract: A method for detecting an abnormal traffic on a control system protocol, includes: checking whether session information exists in a management table; adding a new entry to the management table; checking whether a transaction ID in a table entry is the same as that of the received MODBUS request message; and checking whether data and length thereof of the received MODBUS request message are the same as those in the table entry. Further, the method includes detecting an abnormal traffic; and updating the table entry with packet information of the MODBUS request message.

    Abstract translation: 一种用于检测控制系统协议上的异常业务的方法,包括:检查会话信息是否存在于管理表中; 在管理表中添加新条目; 检查表条目中的事务ID是否与接收的MODBUS请求消息的事务ID相同; 并检查其接收到的MODBUS请求消息的数据和长度是否与表条目中的相同。 此外,该方法包括检测异常业务; 以及使用所述MODBUS请求消息的分组信息更新所述表条目。

    APPARATUS AND METHOD FOR DETECTING ANOMALITY SIGN IN CONTROLL SYSTEM
    3.
    发明申请
    APPARATUS AND METHOD FOR DETECTING ANOMALITY SIGN IN CONTROLL SYSTEM 有权
    用于检测控制系统中异常标志的装置和方法

    公开(公告)号:US20140298399A1

    公开(公告)日:2014-10-02

    申请号:US13927794

    申请日:2013-06-26

    CPC classification number: H04L63/1416

    Abstract: An apparatus for detecting an abnormality sign in a control system, the control system comprising control equipments, network equipments, security equipments or server equipments, the apparatus includes an information collection module configured to collect system information, network information, security event information or transaction information in interworking with a control equipments, network equipments, security equipments or server equipments. The apparatus includes storage module that stores the information collected by the information collection module. The apparatus includes an abnormality detection module configured to analyze a correlation between the collected information and a prescribed security policy to detect whether there is an abnormality sign in the control system.

    Abstract translation: 一种用于检测控制系统中的异常信号的装置,所述控制系统包括控制设备,网络设备,安全设备或服务器设备,所述设备包括:信息收集模块,用于收集系统信息,网络信息,安全事件信息或交易信息 与控制设备,网络设备,安全设备或服务器设备相互配合。 该装置包括存储由信息收集模块收集的信息的存储模块。 该装置包括:异常检测模块,被配置为分析所收集的信息与规定的安全策略之间的相关性,以检测控制系统中是否存在异常信号。

Patent Agency Ranking