Patent · US Active

Modbus TCP communication behaviour anomaly detection method based on OCSVM dual-outline model

US10261502B2 · kind B2 · utility

0Cited by
0References
8Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 30, 2014
Grant dateApr 16, 2019
Priority date
Expiry dateJan 13, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2012/40228
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Proposed is an anomaly detection method for communication behaviors in an industrial control system based on an OCSVM algorithm. According to the present invention, a normal behavior profile model and an abnormal behavior profile model, i.e. a dual-outline model, of communication behaviors in an industrial control system are established, parameter optimization is performed by means of a particle swarm optimization (PSO) algorithm, an optimal intrusion detection model is obtained, and abnormal Modbus TCP communication traffic is identified. According to the present invention, the false alarm rate is reduced by means of cooperative discrimination of the dual-outline detection model, the efficiency and reliability of anomaly detection are improved, and the method is more applicable to practical applications.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.