Apparatus and method for detecting abnormality sign in control system
    1.
    发明授权
    Apparatus and method for detecting abnormality sign in control system 有权
    用于检测控制系统异常信号的装置和方法

    公开(公告)号:US09130983B2

    公开(公告)日:2015-09-08

    申请号:US13927794

    申请日:2013-06-26

    CPC classification number: H04L63/1416

    Abstract: An apparatus for detecting an abnormality sign in a control system, the control system comprising control equipments, network equipments, security equipments or server equipments, the apparatus includes an information collection module configured to collect system information, network information, security event information or transaction information in interworking with a control equipments, network equipments, security equipments or server equipments. The apparatus includes storage module that stores the information collected by the information collection module. The apparatus includes an abnormality detection module configured to analyze a correlation between the collected information and a prescribed security policy to detect whether there is an abnormality sign in the control system.

    Abstract translation: 一种用于检测控制系统中的异常信号的装置,所述控制系统包括控制设备,网络设备,安全设备或服务器设备,所述设备包括:信息收集模块,用于收集系统信息,网络信息,安全事件信息或交易信息 与控制设备,网络设备,安全设备或服务器设备相互配合。 该装置包括存储由信息收集模块收集的信息的存储模块。 该装置包括:异常检测模块,被配置为分析所收集的信息与规定的安全策略之间的相关性,以检测控制系统中是否存在异常信号。

    Apparatus and method for analyzing rule-based security event association
    2.
    发明授权
    Apparatus and method for analyzing rule-based security event association 有权
    用于分析基于规则的安全事件关联的装置和方法

    公开(公告)号:US09158894B2

    公开(公告)日:2015-10-13

    申请号:US13714362

    申请日:2012-12-13

    Inventor: Dong Ho Kang

    CPC classification number: G06F21/00 G06F21/554

    Abstract: An apparatus for analyzing rule-based security event association includes a rule management unit to check whether an security event is a candidate security event requiring association analysis, and an event management unit to analyze the candidate security event and check whether the analyzed security event is the candidate security event requiring association analysis. An association processing unit analyzes whether an association event of a rule DB corresponding to a user ID of the candidate security event is matched with a user event list to generate an association analysis result.

    Abstract translation: 用于分析基于规则的安全事件关联的装置包括:规则管理单元,用于检查安全事件是否是需要关联分析的候选安全事件;以及事件管理单元,用于分析候选安全事件并检查分析的安全事件是否为 候选安全事件需要关联分析。 关联处理单元分析与候选安全事件的用户ID相对应的规则DB的关联事件是否与用户事件列表匹配以生成关联分析结果。

Patent Agency Ranking