-
公开(公告)号:WO2020036850A1
公开(公告)日:2020-02-20
申请号:PCT/US2019/046112
申请日:2019-08-12
Applicant: NEC LABORATORIES AMERICA, INC.
Inventor: RHEE, Junghwan , TANG, LuAn , CHEN, Zhengzhang , KIM, Chung , LI, Zhichun , ZHOU, Ziqiao
IPC: G05B23/02 , G05B19/42 , G05B19/418
Abstract: A computer-implemented method for implementing protocol-independent anomaly detection within an industrial control system (ICS) includes implementing a detection stage (1400), including performing byte filtering using a byte filtering model based on at least one new network packet associated with the ICS (1430), performing horizontal detection to determine whether a horizontal constraint anomaly exists in the at least one network packet based on the byte filtering and a horizontal model (1440), including analyzing constraints across different bytes of the at least one new network packet, performing message clustering based on the horizontal detection to generate first cluster information (1450), and performing vertical detection to determine whether a vertical anomaly exists based on the first cluster information and a vertical model (1460), including analyzing a temporal pattern of each byte of the at least one new network packet.