IL259472A - מערכת ושיטה לזיהוי אנומליות - Google Patents

מערכת ושיטה לזיהוי אנומליות

Info

Publication number
IL259472A
IL259472A IL259472A IL25947218A IL259472A IL 259472 A IL259472 A IL 259472A IL 259472 A IL259472 A IL 259472A IL 25947218 A IL25947218 A IL 25947218A IL 259472 A IL259472 A IL 259472A
Authority
IL
Israel
Prior art keywords
network traffic
baseline
anomaly detection
pattern
authorized
Prior art date
Application number
IL259472A
Other languages
English (en)
Other versions
IL259472B (he
Inventor
Cohen-Sason Daniel
Dagan Yuval
Rosenfeld Philippe
Original Assignee
Cyberbit Ltd
Daniel Cohen Sason
Dagan Yuval
Rosenfeld Philippe
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cyberbit Ltd, Daniel Cohen Sason, Dagan Yuval, Rosenfeld Philippe filed Critical Cyberbit Ltd
Priority to IL259472A priority Critical patent/IL259472B/he
Publication of IL259472A publication Critical patent/IL259472A/he
Publication of IL259472B publication Critical patent/IL259472B/he
Priority to PCT/IL2019/050521 priority patent/WO2019220427A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • H04L41/145Network analysis or design involving simulating, designing, planning or modelling of a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0894Policy-based network configuration management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/06Generation of reports
    • H04L43/062Generation of reports related to network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0876Network utilisation, e.g. volume of load or congestion level
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/20Manipulation of established connections
    • H04W76/25Maintenance of established connections

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Environmental & Geological Engineering (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
IL259472A 2018-05-17 2018-05-17 מערכת ושיטה לזיהוי אנומליות IL259472B (he)

Priority Applications (2)

Application Number Priority Date Filing Date Title
IL259472A IL259472B (he) 2018-05-17 2018-05-17 מערכת ושיטה לזיהוי אנומליות
PCT/IL2019/050521 WO2019220427A1 (en) 2018-05-17 2019-05-07 An anomaly detection system and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
IL259472A IL259472B (he) 2018-05-17 2018-05-17 מערכת ושיטה לזיהוי אנומליות

Publications (2)

Publication Number Publication Date
IL259472A true IL259472A (he) 2018-07-04
IL259472B IL259472B (he) 2019-03-31

Family

ID=63014188

Family Applications (1)

Application Number Title Priority Date Filing Date
IL259472A IL259472B (he) 2018-05-17 2018-05-17 מערכת ושיטה לזיהוי אנומליות

Country Status (2)

Country Link
IL (1) IL259472B (he)
WO (1) WO2019220427A1 (he)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111314294A (zh) * 2020-01-15 2020-06-19 福建奇点时空数字科技有限公司 一种基于周期性和移动窗口基线算法的异常流量检测方法
CN111614611B (zh) * 2020-04-01 2022-11-08 中国电力科学研究院有限公司 一种用于电网嵌入式终端的网络安全审计方法及装置
CN115348339B (zh) * 2022-08-12 2023-11-21 北京威努特技术有限公司 一种基于功能码和业务数据相关性的工控异常检测方法
CN115801538A (zh) * 2022-11-10 2023-03-14 云南电网有限责任公司 场站服务器应用资产深度识别方法、系统及设备

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011116813A1 (en) * 2010-03-22 2011-09-29 Telefonaktiebolaget Lm Ericsson (Publ) Apparatus and method in a telecommunications network
US8908507B2 (en) * 2011-07-21 2014-12-09 Movik Networks RAN analytics, control and tuning via multi-protocol, multi-domain, and multi-RAT analysis
US9215746B1 (en) * 2012-09-25 2015-12-15 Sprint Spectrum L.P. Systems and methods for dynamically controlling active-to-dormant timers in radio access networks

Also Published As

Publication number Publication date
IL259472B (he) 2019-03-31
WO2019220427A1 (en) 2019-11-21

Similar Documents

Publication Publication Date Title
EP3528459B1 (en) A cyber security appliance for an operational technology network
US20230042552A1 (en) Cyber security using one or more models trained on a normal behavior
Zolanvari et al. Machine learning-based network vulnerability analysis of industrial Internet of Things
EP3215944B1 (en) A system for implementing threat detection using daily network traffic community outliers
Rubio et al. Analysis of Intrusion Detection Systems in Industrial Ecosystems.
EP2040435B1 (en) Intrusion detection method and system
Garitano et al. A review of SCADA anomaly detection systems
Barbosa Anomaly detection in SCADA systems: a network based approach
WO2019220427A1 (en) An anomaly detection system and method
Repalle et al. Intrusion detection system using ai and machine learning algorithm
Li et al. A critical review of cyber-physical security for building automation systems
Deka et al. Network defense: Approaches, methods and techniques
US9961047B2 (en) Network security management
CN214306527U (zh) 一种燃气管网调度监控网络安全系统
Sperotto Flow-based intrusion detection
US20230283621A1 (en) Systems, Methods, and Media for Distributed Network Monitoring Using Local Monitoring Devices
Granat et al. Big data analytics for event detection in the IoT-multicriteria approach
Chen et al. Towards realizing self-protecting SCADA systems
US20170099304A1 (en) Automatic generation of cluster descriptions
Brenner et al. Better safe than sorry: Risk Management based on a safety-augmented Network Intrusion Detection System
Pan et al. Anomaly behavior analysis for building automation systems
Waagsnes SCADA intrusion detection system test framework
Calvo et al. Key Vulnerabilities of Industrial Automation and Control Systems and Recommendations to Prevent Cyber-Attacks.
Iudica A monitoring system for embedded devices widely distributed
Jadidi et al. Cyber Security Resilience in Industrial Control Systems using Defence-in-Depth and Zero Trust

Legal Events

Date Code Title Description
FF Patent granted
KB Patent renewed