IP Library › Granted Patent US 10,681,079
Granted Patent B2
US 10,681,079 · App. 16/024,924 · Granted Jun 9, 2020

Method for mitigation of cyber attacks on industrial control systems

Inventors: Omer Schneider (Kibbutz Yakum, IL); Nir Giller (Hod Hasharon, IL)
Assignee: Cyberx Israel Ltd.
H04L63/1441H04L63/1425G05B23/0254G06F21/55H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,681,079
App. No.
16/024,924
Granted
Jun 9, 2020
Kind
B2
Abstract

Methods and systems for detecting a potential compromise of cyber security in an industrial network are disclosed. These methods and systems comprise elements of hardware and software for generating and analyzing vectors indicative of network behavioral states to establish thresholds for anomalous behavior in the industrial network.

Claims (10)

1. A method for detecting a potential compromise of cyber security in an industrial network utilizing a protocol for controlling an industrial process, comprising:

polling specific fields of packet data, obtained from packets, at a fixed frequency, for a plurality of programmable logic controllers (PLCs), to establish network behavior;

determining a protocol type from the specific packet data fields;

deriving a vector based on the specific packet data fields, wherein the specific packet data fields represent the protocol which signifies particular network communications, including communications using a stateful protocol as the determined protocol type;

generating a value based on the vector indicative of a network behavioral state;

maintaining a network behavior state machine comprising a list of network states and transition counts in accordance with the stateful protocol, wherein the transition count is maintained in accordance to the value;

determining a transition probability corresponding to the transition counts, wherein the transition probability denotes an estimated probability of a first network state being followed temporally by a second network state, during normal network operation;

establishing, for the network behavior state machine, a threshold representing the probability below which a sequence of network states is anomalous;

determining, by the network behavior state machine, a probability for the occurrence of a sequence of network states, according to the derived vector; and,

taking protective action according to whether the determined probability is below the established threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2020
From: CYBERX ISRAEL LTD.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 054029/0351 →
Continuity (2)
Continuation 14830776 · Aug 20, 2015
Related Publication 20180316719A1 · Nov 1, 2018