Invention Grant
- Patent Title: Heuristics-based protocol labeling for industrial control systems
- Patent Title (中): 基于启发式的工业控制系统协议标签
-
Application No.: US14142115Application Date: 2013-12-27
-
Publication No.: US09384066B1Publication Date: 2016-07-05
- Inventor: Corrado Leita , Marc Dacier
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Womble Carlyle Sandridge & Rice LLP
- Main IPC: G06F9/54
- IPC: G06F9/54

Abstract:
A method for learning aspects of messages in an industrial control system is provided. The method includes obtaining a plurality of messages. The method includes starting at a first message field, proceeding via recursion to each next message field, and identifying message values at that message field as constant when constant in messages in a group, as random when random in messages in a group, as length when expressive of a shared length of messages in a group, as opcode when correlated with a shared structure of messages in a group, and otherwise as parameter. The method includes subdividing message groups into subgroups according to the identified message values at that message field, with the recursion applied to each subgroup. A method and system for monitoring messages in an industrial control system is provided.
Information query