System and method of protection of technological systems from cyber attacks

    公开(公告)号:US10469527B2

    公开(公告)日:2019-11-05

    申请号:US15255773

    申请日:2016-09-02

    申请人: AO Kaspersky Lab

    IPC分类号: H04L29/06 H04L29/08

    摘要: Disclosed are systems and methods for protection of a technological system (TS) from cyber attacks. An exemplary method comprises: obtaining a real state of the TS; initializing a cybernetic control system (CCS) by synchronizing the CCS with the TS; comparing, by the CCS, the real state of the TS with an ideal state of the TS; based on the comparison, identifying a deviation of the real state of the TS from the ideal state of the TS; when the deviation is identified, checking an integrity of at least functional interconnections of the states of one or more elements of the TS; determining whether the ideal state of the TS is a modeling error based on one or more confirmed sustained functional interconnections between elements of the TS; and identifying anomalies in the TS based on one or more disturbed functional interconnections between elements of the TS.

    SYSTEM AND METHOD FOR DETECTING ANOMALIES IN A CYBER-PHYSICAL SYSTEM IN REAL TIME

    公开(公告)号:US20240333742A1

    公开(公告)日:2024-10-03

    申请号:US18618334

    申请日:2024-03-27

    申请人: AO Kaspersky Lab

    IPC分类号: H04L9/40

    CPC分类号: H04L63/1425

    摘要: Disclosed herein are systems and methods for detection of anomalies in a cyber-physical system in real-time. In one aspect, an exemplary method comprises: obtaining, in real-time, randomly distributed stream of observations of CPS parameters; converting an observation of the CPS parameter to a uniform temporal grid (UTG); when at least a criterion for unloading at least one UTG node of the converted observations is satisfied, unloading the UTG nodes corresponding to the satisfied criterion; for each unloaded UTG node, calculating a value of each output CPS parameter of a set of output CPS parameters; and detecting an anomaly in the CPS based on the values of the output CPS parameters.

    SYSTEM FOR IDENTIFYING PATTERNS AND ANOMALIES IN THE FLOW OF EVENTS FROM A CYBER-PHYSICAL SYSTEM

    公开(公告)号:US20240070444A1

    公开(公告)日:2024-02-29

    申请号:US18361976

    申请日:2023-07-31

    申请人: AO Kaspersky Lab

    IPC分类号: G06N3/049 G06N3/08

    CPC分类号: G06N3/049 G06N3/08

    摘要: Disclosed herein are systems for identifying the structure of patterns and anomalies in flow of events from the cyber-physical system or information system. In one aspect, an exemplary method comprises, using at least one connector, getting event data, generating at least one episode consisting of a sequence of events, and transferring the generated episodes to an event processor; and using the event processor, process episodes using a neurosemantic network, wherein the processing includes recognizing events and patterns previously learned by the neurosemantic network, training the neurosemantic network, identifying a structure of patterns by mapping to the patterns of neurons on a hierarchy of layers of the neurosemantic network, attributing events and patterns corresponding to neurons of the neurosemantic network to an anomaly depending on a number of activations of the corresponding neuron, and storing the state of the neurosemantic network.