WO2015024315A1 - 核电站网络入侵报警方法和系统 - Google Patents
核电站网络入侵报警方法和系统 Download PDFInfo
- Publication number
- WO2015024315A1 WO2015024315A1 PCT/CN2013/087737 CN2013087737W WO2015024315A1 WO 2015024315 A1 WO2015024315 A1 WO 2015024315A1 CN 2013087737 W CN2013087737 W CN 2013087737W WO 2015024315 A1 WO2015024315 A1 WO 2015024315A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- warning information
- information
- historical
- instant
- module
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y04—INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
- Y04S—SYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
- Y04S40/00—Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
- Y04S40/18—Network protocols supporting networked applications, e.g. including control of end-device applications over a network
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y04—INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
- Y04S—SYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
- Y04S40/00—Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
- Y04S40/20—Information technology specific aspects, e.g. CAD, simulation, modelling, system security
Definitions
- the invention belongs to the field of nuclear power station security, and particularly relates to a network intrusion alarm method and system for a nuclear power plant.
- BACKGROUND Intrusion Detection System refers to a system for identifying and processing malicious use behaviors of computers and network resources. As the scale of the network grows larger and larger, the resources on the network become more and more abundant, and the threats from the network are increasing, and the attacks are more and more secret.
- the data of nuclear power operation is related to national security and social stability. Therefore, it is imperative to construct a network security system to ensure the security of the data center.
- the industrial control system including the nuclear power plant control system, is an independent network because it is not connected to the Internet. Under normal circumstances, it will not have a virus, and outside hackers can not attack. In addition, the usual hacker and network virus attacks are directed at computer devices, and there is generally no virus for control devices in the industrial control system network.
- the data of nuclear power operation is related to national security and social stability. Therefore, it is imperative to construct a network security system to ensure the security of the data center.
- the existing network security system usually consists of a firewall, anti-virus software, and an Intrusion Detection System (IDS) or an Intrusion Prevention System (IPS).
- IDS Intrusion Detection System
- IPS Intrusion Prevention System
- the commercial intrusion detection system is not deployed in the nuclear power control system for network defense, or the deployed commercial intrusion detection system is also an intrusion detection system based on misuse detection. Since the nuclear power industry network is not connected to the Internet, the virus database for intrusion detection cannot be updated in time in the nuclear power industry network. It is impossible to detect a new virus or a virus designed for a specific industrial control system using a commercial intrusion detection system.
- the object of the present invention is: a nuclear power control system provides a network intrusion alarm method and system based on a nuclear power plant for virus intrusion from a network, and improves the network intrusion by the nuclear power plant control system by using an anomaly detection technology and a misuse detection technology.
- the detection capability and the perfection of the intrusion alarm mechanism effectively meet the requirements of the nuclear power plant industrial network for network security protection.
- the present invention provides a network intrusion alarm method for a nuclear power plant, which includes:
- Detecting data information sent by the access object where the detection includes misuse detection and protocol abnormal data detection;
- the intrusion alarm information is sent.
- the method further includes:
- the historical early warning information includes a field of the number of early warnings, and if the matching result of the instant warning information and the historical early warning information meets a preset matching value, the early warning The number of times increases.
- the method further includes: performing association analysis on the instant warning information and the historical early warning information, and determining the access object according to a preset association rule. Purpose of the visit.
- the method further includes: if the access purpose of the access object cannot be determined according to a preset association rule, establishing a new association rule according to the instant warning information, And update the association rules in real time.
- the method further comprises: saving the instant warning information to a database, and updating the database.
- the method further includes: performing blocking of the IP address or port access of the access object according to the intrusion alarm information.
- the present invention also provides a network intrusion alarm system for a nuclear power plant, comprising:
- a detecting module configured to detect data information sent by the access object, where the detecting includes misuse detection and protocol abnormal data detection;
- the warning module is configured to generate instant warning information if the result of detecting the data information by the detecting module is abnormal;
- a matching module configured to match the early warning information generated by the early warning module with historical warning information in a database
- the alarm module is configured to: if the matching result of the instant warning information and the historical warning information does not meet the preset matching value, issue an intrusion alarm message.
- the system further includes: a receiving module, configured to receive data information sent by the access object.
- a receiving module configured to receive data information sent by the access object.
- the system further includes: a database, configured to store historical warning information, wherein the historical early warning information includes a field of the number of early warnings, if the instant warning information and the The matching result of the historical warning information meets a preset matching value, and the number of the warnings is increased once.
- the system further includes: an analysis module, configured to perform correlation analysis on the instant warning information and the historical early warning information, and determine according to a preset association rule The access purpose of the access object.
- the system further includes: an adaptive module, configured to save a preset association rule, if the analysis module cannot determine the according to a preset association rule Accessing the object's access purpose, establishing a new association rule according to the instant warning information, and updating the association rule in real time.
- the system further includes: an update module, configured to save the instant warning information to a database, and update the database.
- an execution module configured to perform blocking of an IP address or port access of the access object according to the intrusion alarm information.
- the network intrusion alarm method and system of the nuclear power plant of the invention has the following beneficial technical effects:
- the analysis and matching are performed on the basis of the above detection, and the alarm is performed according to the matching result, thereby realizing the invasion of the adaptive network environment of the nuclear power plant control system;
- the detection capability and alarm mechanism of the nuclear power plant control system for network intrusion are improved, and the requirements of the nuclear power plant industrial network for network security protection are effectively met, and good technical results are obtained.
- FIG. 1 provides a flow chart of one embodiment of a network intrusion alarm method for a nuclear power plant of the present invention.
- Figure 2 provides a schematic diagram of one embodiment of a network intrusion alarm system for a nuclear power plant of the present invention.
- Figure 3 provides a schematic diagram of yet another embodiment of a network intrusion alarm system for a nuclear power plant of the present invention. detailed description
- Network intrusion detection technology is divided into two categories: misuse detection technology and anomaly detection technology according to its working principle.
- the misuse detection technology is based on the matching of data message features. This detection technology has high accuracy, but the problem is that the new intrusion mode cannot be found and the omission is reported.
- Anomaly detection technology such as Protocol Anomaly Detection System (PADS)
- PADS Protocol Anomaly Detection System
- PADS Protocol Anomaly Detection System
- the detection technology can discover new network intrusion, but there is a problem that the false positive rate is high and a large number of training samples are needed. At present, the combination of misuse detection technology and anomaly detection technology in the field of nuclear power control systems is still blank.
- FIG. 1 provides a network intrusion alarm method for a nuclear power plant, which specifically includes: Step 101: Detecting data information sent by an access object, including detection of misuse detection and protocol abnormal data detection.
- the nuclear power intrusion alarm management system receives the data information sent by the access object, and specifically, the accessed data information enters the control system application server through the switch.
- Intrusion Detection Alert Management System installed in a computer server The ND-IDAMS obtains the data information of the accessed object through the switch.
- the nuclear power intrusion alarm management system receives the data information sent by the access object.
- the access object can also send data information to the nuclear power plant control system through the server.
- the nuclear power intrusion alarm management system detects the data information sent by the access object, including: the detection includes misuse detection and protocol abnormal data detection. Specifically, the nuclear power intrusion alarm management system calls the misuse detection module to detect the data information; further, the protocol abnormal data detection for the data information PADS, PADS can use the Markov model to detect the protocol in the network data.
- the nuclear power intrusion alarm management system can detect data information through a networked commercial intrusion detection system (IPS or IDS).
- IPS or IDS networked commercial intrusion detection system
- the nuclear power intrusion alarm management system can be connected to multiple commercial intrusion detection systems (IPS or IDS).
- Step 103 Generate an instant warning information if the result of detecting the data information is abnormal.
- the relevant system can be accessed normally. If the result of detecting the data information is abnormal, the nuclear power intrusion alarm management system generates instant warning information.
- Step 105 Match the instant warning information with the historical warning information in the database.
- the nuclear power intrusion alarm management system matches the instant warning information with the historical warning information stored in the database, and the classification algorithm determines that the historical warning information exists in the database and is the same as the instant warning information.
- the foregoing method further includes: pre-setting a matching value between the instant warning information and the historical warning information.
- the matching value of the instant warning information and the historical warning information may be preset. For example, if the matching value is set to 75%, if the instant warning information and the historical warning information are more than 75% (including 75%), the instant warning information is matched with the historical warning information. Match values can be adjusted as needed.
- the historical warning information includes a field of the number of warnings. If the matching result of the instant warning information and the historical warning information meets a preset matching value, the number of warnings increases once.
- the historical warning information includes at least the content of the warning and the number of warnings. When the instant warning information matches the historical warning information, the content of the warning is unchanged, and the number of warnings is increased once.
- correlation analysis is performed on the instant warning information and the historical warning information, and the access purpose of the access object is determined according to the association rule set in advance.
- Step 107 If the matching result of the instant warning information and the historical warning information does not meet the preset matching value, the intrusion alarm information is sent.
- the matching value is set to 75%
- the instant warning information and the historical warning information are less than 75%
- the immediate warning information and the historical warning information are determined to be mismatched. If the matching result of the instant warning information and the historical warning information does not meet the preset matching value, the nuclear power intrusion alarm management system issues the intrusion alarm information.
- the received real-time warning information cannot find historical warning information of similar or matching matching values in the database. Confirmed by the administrator, and establish a new alert fusion classification, association rules for it. View the attack alert association table that has occurred, and the administrator can update the association rules that have occurred.
- the instant warning information is saved to the database, and the database is updated. Establish new early warning fusion classification and association rules, and update the database in real time.
- the IP address or port access of the blocking access object is performed according to the intrusion alarm information. Associate with a firewall or IPS to block access to the IP address or port to which the access object belongs.
- the detecting module 201 is configured to detect data information sent by the access object, and the detecting includes misuse detection and protocol abnormal data detection;
- the warning module 203 is configured to generate an instant warning information if the result of detecting the data information by the detecting module 201 is abnormal;
- the matching module 205 is configured to match the generated early warning information generated by the early warning module 203 with the historical warning information in the database;
- the alarm module 207 is configured to issue an intrusion "3 ⁇ 4" alarm information if the matching result of the instant warning information and the historical warning information does not meet the preset matching value.
- Figure 3 provides a schematic diagram of one embodiment of a network intrusion alarm system for a nuclear power plant.
- the system includes: a receiving module 301, a detecting module 303, an alerting module 305, a matching module 307, an alarm module, an updating module 311, a database 313, an analyzing module, an adaptive module 317, and an executing module 319.
- the receiving module 301 is configured to receive data information sent by the access object.
- the accessed data information enters the control system application server through the switch.
- the receiving module 301 in the nuclear power intrusion alarm management system ND-IDAMS installed in the computer server obtains the data information of the access object through the switch.
- the receiving module 301 receives the data information transmitted by the access object.
- the access object may also send data information to the nuclear power plant control system through the server, and then the receiving module 301 receives the data information.
- the detecting module 303 is configured to detect data information sent by the access object, where the detecting includes misuse detection and protocol abnormal data detection;
- the detecting module 303 detects the data information sent by the access object received by the receiving module 301, and includes: the detecting module 303 detects the misuse detection and the protocol abnormal data detection.
- the detecting module 303 performs protocol anomaly data detection PADS on the data information, and the PADS can detect the protocol in the network data by using the Markov model.
- the detection module 303 can detect the data information through a networked commercial intrusion detection system (IPS or IDS).
- IPS or IDS networked commercial intrusion detection system
- the detection module 303 can be connected to a plurality of commercial intrusion detection systems (IPS or IDS).
- the warning module 305 is configured to generate an instant warning information if the result of detecting the data information by the detecting module is abnormal;
- the detecting module 303 can detect the passed normal data to access the related system normally. If the result of detecting the data information is abnormal, the early warning module 305 generates the instant warning information.
- the matching module 307 is configured to match the generated early warning information generated by the early warning module 35 with the historical warning information in the database;
- the matching module 307 matches the instant warning information with the historical warning information stored in the database, and determines, by the classification algorithm, that the historical warning information exists in the database 313 is the same as the instant warning information.
- the system further includes a setting module, configured to preset a matching value between the instant warning information and the historical warning information.
- the matching module 307 can preset a matching value that matches the real-time warning information with the historical warning information. For example, if the matching value is set to 75%, if the instant warning information and the historical warning information are more than 75% (including 75%), the instant warning information is matched with the historical warning information. Match values can be adjusted as needed.
- the historical warning information matching the instant warning information is found, it is classified into the same type of early warning. No matter how many instant warning information is available, as long as it matches the historical warning information, the return of the early warning information is the historical warning information, which can be greatly Reduce the repeatability of similar warnings.
- the database 313 is configured to save historical warning information, and the historical warning information includes a field of the number of early warnings. If the matching result of the instant warning information and the historical warning information meets the preset matching value, the number of warnings is increased once.
- the historical warning information includes at least the content of the warning and the number of warnings. When the instant warning information matches the historical warning information, the content of the warning is unchanged, and the number of warnings is increased once.
- the update module 311 is configured to save the instant alert information to the database 313 and update the database 313.
- the analysis module 315 is configured to perform association analysis on the instant warning information and the historical warning information, and determine the access purpose of the access object according to the association rule set in advance.
- the adaptation module 317 is configured to save a preset association rule. If the analysis module 315 cannot determine the access destination of the access object according to the preset association rule, the adaptation module 317 establishes a new association rule according to the instant warning information, and updates the file immediately. Association rules.
- the alarm module 309 is configured to: if the matching module 307 determines that the matching result of the instant warning information and the historical warning information does not meet the preset matching value, issue the intrusion alarm information.
- the executing module 319 is configured to perform blocking of the IP address or port access of the access object according to the intrusion alarm information.
- the present invention has at least the following advantageous technical effects with respect to the prior art:
- the analysis and matching are performed on the basis of the above detection, and the alarm is performed according to the matching result, thereby realizing the invasion of the adaptive network environment of the nuclear power plant control system;
- anomaly detection technology and misuse detection technology the detection capability and alarm mechanism of the nuclear power plant control system for network intrusion are improved, and the requirements for network security protection of the nuclear power plant industrial network are effectively met.
- the intrusion alarm information since the intrusion alarm information is discovered in time, it can pass Adaptively constantly update the database and intrusion types, and perform policy processing alarms, such as blocking IP or ports, so that nuclear power plant control security is guaranteed, and good technical results are achieved.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Virology (AREA)
- Medical Informatics (AREA)
- Testing And Monitoring For Control Systems (AREA)
- Alarm Systems (AREA)
- Monitoring And Testing Of Nuclear Reactors (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| GB1602102.4A GB2532630B (en) | 2013-08-19 | 2013-11-24 | Network intrusion alarm method and system for nuclear power plant |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310361837.4A CN103888282A (zh) | 2013-08-19 | 2013-08-19 | 基于核电站的网络入侵报警方法和系统 |
| CN201310361837.4 | 2013-08-19 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015024315A1 true WO2015024315A1 (zh) | 2015-02-26 |
Family
ID=50957009
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/087737 Ceased WO2015024315A1 (zh) | 2013-08-19 | 2013-11-24 | 核电站网络入侵报警方法和系统 |
Country Status (3)
| Country | Link |
|---|---|
| CN (1) | CN103888282A (zh) |
| GB (1) | GB2532630B (zh) |
| WO (1) | WO2015024315A1 (zh) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111325463A (zh) * | 2020-02-18 | 2020-06-23 | 深圳前海微众银行股份有限公司 | 数据质量检测方法、装置、设备及计算机可读存储介质 |
| CN113904811A (zh) * | 2021-09-16 | 2022-01-07 | 深圳供电局有限公司 | 异常检测方法、装置、计算机设备和存储介质 |
| CN113985226A (zh) * | 2021-10-25 | 2022-01-28 | 广东电网有限责任公司 | 电缆处理方法和系统 |
| CN116401157A (zh) * | 2023-03-29 | 2023-07-07 | 中国铁道科学研究院集团有限公司 | 一种周界入侵检测设备的测试评价方法及系统 |
| CN120896779A (zh) * | 2025-09-26 | 2025-11-04 | 南通大学 | 基于异常行为分析的计算机网络入侵检测系统及方法 |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106571886B (zh) * | 2016-11-03 | 2019-02-01 | 福建宁德核电有限公司 | 一种数据采集系统dcs与有线广播系统dtp联动的实现方法 |
| CN106921676B (zh) * | 2017-04-20 | 2020-05-08 | 电子科技大学 | 一种基于OPCClassic的入侵检测方法 |
| CN108693391A (zh) * | 2018-05-19 | 2018-10-23 | 安徽国电京润电力科技有限公司 | 一种核电站电能量检测系统 |
| CN112118141B (zh) * | 2020-09-21 | 2021-12-17 | 中山大学 | 面向通信网络的告警事件关联压缩方法及装置 |
| CN112235304A (zh) * | 2020-10-15 | 2021-01-15 | 唐琪林 | 一种工业互联网的动态安全防护方法和系统 |
| CN113708959B (zh) * | 2021-08-11 | 2023-08-25 | 新华三技术有限公司 | 一种规则库更新方法、装置及设备 |
| CN114742247B (zh) * | 2022-04-08 | 2024-10-22 | 广东电网有限责任公司 | 一种基于配电网配变异常告警信息的特征提取方法及装置 |
| CN116668078A (zh) * | 2023-05-04 | 2023-08-29 | 成都老鹰信息技术有限公司 | 一种互联网入侵安全防御系统 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1909488A (zh) * | 2006-08-30 | 2007-02-07 | 北京启明星辰信息技术有限公司 | 一种结合病毒检测与入侵检测的方法及系统 |
| CN101741847A (zh) * | 2009-12-22 | 2010-06-16 | 北京锐安科技有限公司 | 一种ddos攻击检测方法 |
| CN102075516A (zh) * | 2010-11-26 | 2011-05-25 | 哈尔滨工程大学 | 一种网络多步攻击识别和预测方法 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101399710B (zh) * | 2007-09-29 | 2011-06-22 | 北京启明星辰信息技术股份有限公司 | 一种协议格式异常检测方法及系统 |
| FI20096394A0 (fi) * | 2009-12-23 | 2009-12-23 | Valtion Teknillinen | Tunkeutumisen havaitseminen viestintäverkoissa |
| JP5731223B2 (ja) * | 2011-02-14 | 2015-06-10 | インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation | 異常検知装置、監視制御システム、異常検知方法、プログラムおよび記録媒体 |
-
2013
- 2013-08-19 CN CN201310361837.4A patent/CN103888282A/zh active Pending
- 2013-11-24 WO PCT/CN2013/087737 patent/WO2015024315A1/zh not_active Ceased
- 2013-11-24 GB GB1602102.4A patent/GB2532630B/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1909488A (zh) * | 2006-08-30 | 2007-02-07 | 北京启明星辰信息技术有限公司 | 一种结合病毒检测与入侵检测的方法及系统 |
| CN101741847A (zh) * | 2009-12-22 | 2010-06-16 | 北京锐安科技有限公司 | 一种ddos攻击检测方法 |
| CN102075516A (zh) * | 2010-11-26 | 2011-05-25 | 哈尔滨工程大学 | 一种网络多步攻击识别和预测方法 |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111325463A (zh) * | 2020-02-18 | 2020-06-23 | 深圳前海微众银行股份有限公司 | 数据质量检测方法、装置、设备及计算机可读存储介质 |
| CN113904811A (zh) * | 2021-09-16 | 2022-01-07 | 深圳供电局有限公司 | 异常检测方法、装置、计算机设备和存储介质 |
| CN113904811B (zh) * | 2021-09-16 | 2023-11-24 | 深圳供电局有限公司 | 异常检测方法、装置、计算机设备和存储介质 |
| CN113985226A (zh) * | 2021-10-25 | 2022-01-28 | 广东电网有限责任公司 | 电缆处理方法和系统 |
| CN116401157A (zh) * | 2023-03-29 | 2023-07-07 | 中国铁道科学研究院集团有限公司 | 一种周界入侵检测设备的测试评价方法及系统 |
| CN116401157B (zh) * | 2023-03-29 | 2024-04-02 | 中国铁道科学研究院集团有限公司 | 一种周界入侵检测设备的测试评价方法及系统 |
| CN120896779A (zh) * | 2025-09-26 | 2025-11-04 | 南通大学 | 基于异常行为分析的计算机网络入侵检测系统及方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| GB2532630B (en) | 2018-04-25 |
| GB201602102D0 (en) | 2016-03-23 |
| GB2532630A (en) | 2016-05-25 |
| CN103888282A (zh) | 2014-06-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2015024315A1 (zh) | 核电站网络入侵报警方法和系统 | |
| CN114363044B (zh) | 一种分层告警方法、系统、存储介质和终端 | |
| JP6894003B2 (ja) | Apt攻撃に対する防御 | |
| CA2926579C (en) | Event correlation across heterogeneous operations | |
| CN110881049B (zh) | 一种计算机网络安全智能控制系统 | |
| CN110149350A (zh) | 一种告警日志关联的网络攻击事件分析方法及装置 | |
| US20150341380A1 (en) | System and method for detecting abnormal behavior of control system | |
| CN107454109A (zh) | 一种基于http流量分析的网络窃密行为检测方法 | |
| CN104901960A (zh) | 一种基于告警策略的网络安全管理设备及方法 | |
| CA2926603A1 (en) | Event correlation across heterogeneous operations | |
| WO2018218537A1 (zh) | 工业控制系统及其网络安全的监视方法 | |
| JP2014530419A (ja) | 脅威に対してリアルタイムでカスタマイズされた保護を行うシステム及び方法 | |
| CN106657019A (zh) | 网络安全防护方法和装置 | |
| WO2018099206A1 (zh) | 一种apt检测方法、系统及装置 | |
| CN110113336B (zh) | 一种用于变电站网络环境的网络流量异常分析与识别方法 | |
| CN113381980B (zh) | 信息安全防御方法及系统、电子设备、存储介质 | |
| CN111786986B (zh) | 一种数控系统网络入侵防范系统及方法 | |
| CN114666088A (zh) | 工业网络数据行为信息的侦测方法、装置、设备和介质 | |
| CN114726579A (zh) | 防御网络攻击的方法、装置、设备、存储介质及程序产品 | |
| CN110417578B (zh) | 一种异常ftp连接告警处理方法 | |
| CN103036998A (zh) | 云计算中一种基于免疫原理的入侵检测系统 | |
| CN117955729A (zh) | 一种基于流量的恶意软件检测方法、装置及电子设备 | |
| CN116614260A (zh) | 复杂网络攻击检测方法、系统、电子设备及存储介质 | |
| CN101546367B (zh) | 带预警功能的网络木马综合检测方法 | |
| Das et al. | On the edge realtime intrusion prevention system for DoS attack |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13891904 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 201602102 Country of ref document: GB Kind code of ref document: A Free format text: PCT FILING DATE = 20131124 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 06/06/2016) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 13891904 Country of ref document: EP Kind code of ref document: A1 |