Invention Grant
- Patent Title: Systems and methods for identifying compromised devices within industrial control systems
-
Application No.: US14952344Application Date: 2015-11-25
-
Publication No.: US09967274B2Publication Date: 2018-05-08
- Inventor: Ignacio Bermudez Corrales , Alok Tongaonkar
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: FisherBroyles, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G05B19/418

Abstract:
The disclosed computer-implemented method for identifying compromised devices within industrial control systems may include (1) monitoring network traffic within a network that facilitates communication for an industrial control system that includes an industrial device, (2) creating, based at least in part on the network traffic, a message protocol profile for the industrial device that describes (A) a network protocol used to communicate with the industrial device and (B) normal communication patterns of the industrial device, (3) detecting at least one message that involves the industrial device and at least one other computing device included in the industrial control system, (4) determining, by comparing the message with the message protocol profile, that the message represents an anomaly, and then (5) determining, based at least in part on the message representing the anomaly, that the other computing device has likely been compromised. Various other methods, systems, and computer-readable media are also disclosed.
Public/Granted literature
- US20170149811A1 SYSTEMS AND METHODS FOR IDENTIFYING COMPROMISED DEVICES WITHIN INDUSTRIAL CONTROL SYSTEMS Public/Granted day:2017-05-25
Information query