Patent · US Active

Knowledge graph for real time industrial control system security event monitoring and management

US11973777B2 · kind B2 · utility

1Cited by
1References
14Claims
0Family size

Assignees

Inventors

Key dates

Filing dateJul 9, 2019
Grant dateApr 30, 2024
Priority date
Expiry dateFeb 3, 2041

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/562
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Methods and systems are disclosed for security management in an industrial control system (ICS). An event entity detection and linking module generates a model for a plurality of event entities extracted from a plurality of different data sources including one ICS data source and one IT data source. The model encodes a set of linked event entities and their relationships, each event entity associated with a vector of attribute value pairs. A data standardization of domain knowledge includes translating, by a machine learning application, extracted knowledge base information to rules for the constraints and using the rules to validate the constraints and to add new constraints. A fusion module performs temporal correlation detection across data streams of the different data sources for establishing causality between triplets of association models within a defined time span.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.