IP Library › Granted Patent US 11,962,604
Granted Patent B2
US 11,962,604 · App. 16/027,241 · Granted Apr 16, 2024

Home-based physical and cyber integrated security-intrusion detection system (PCIS-IDS)

Inventor: Olugbenga Erinle (Laurel, MD)
H04L63/1416H04L63/1425G06F16/22G08B13/00H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,604
App. No.
16/027,241
Filed
Jul 3, 2018
Granted
Apr 16, 2024
Kind
B2
Art Unit
2437
USPC
726/23
Abstract

Provided is an integrated physical security and cyber security intrusion and anomaly detection method for determining physical or electronic ingress/egress of a person/device and/or data/information from a home/facility/premise. The method includes processing data and information obtained from physical security system sensors, wired/wireless network traffic, and third-party sources, and creating sensor and network traffic profile, baselines and detecting anomalies and writing all related data to either a local database or a remotely managed database at a monitoring center.

Claims (20)

1. An integrated cyber-physical security system for providing physical and cyber security for a facility based on profile anomalies, comprising:

a physical security alarm system (PSAS) including electronic sensors configured for sensing real-time facility intrusion activity;

a wired or wireless network system (WWNS) configured for coupling to the PSAS and Internet of Things (IoT) components, the WWNS configured for detecting real-time IoT intrusion activity and detecting network traffic and intrusion activity; and

a security sensor gateway (SSG) configured for:

monitoring traffic and detecting anomalies on the WWNS by analyzing the sensed facility intrusion activity and the detected network traffic and intrusion activity;

creating a plurality of intrusion traffic activity profiles (i) based on the analyzed real-time facility intrusion activity and the analyzed network traffic and intrusion activity and (ii) including egress/ingress activity and traffic type and traffic volume, each of the profiles including active devices, network protocols, and categorization of the detected network traffic into types;

establishing a network activity baseline for each of the sensors, each of the IoT components, and the WWNS derived from the plurality of intrusion traffic activity profiles; and

providing activity alerts based on comparing the real-time facility intrusion activity, the real-time IoT intrusion activity, and the network traffic and intrusion activity to a respective one or more of the network activity baselines;

wherein the monitoring traffic and detecting anomalies, the creating intrusion traffic activity profiles, establishing a network activity baseline, and the providing activity alerts are performed within the security sensor gateway.

2. The integrated cyber-physical security system of claim 1 , wherein the SSG is further configured to compare the monitored traffic and the collected intrusion activity with each network activity baseline to produce a threat anomaly detection level and trigger a security alert when the threat anomaly detection level exceeds a predetermined threshold.

3. The integrated cyber-physical security system of claim 2 , further comprising a remote monitoring station responsive to the triggered security alert.

4. A method for providing physical and cyber security for a facility based on profile anomalies, comprising:

sensing, via a physical security alarm system (PSAS) including electronic sensors, real-time facility intrusion activity;

detecting, via a wired or wireless network system (WWNS) coupled to the PSAS and Internet of Things (IoT) components, real-time IoT intrusion activity, and network traffic and intrusion activity;

monitoring, via a security sensor gateway (SSG), traffic and detecting anomalies on the WWNS by analyzing the sensed real-time intrusion activity and the detected network traffic and intrusion activity;

creating a plurality of intrusion traffic activity profiles (i) based on the analyzed sensed intrusion activity and the analyzed network traffic and intrusion activity and (ii) including egress/ingress activity and traffic type and traffic volume, each of the profiles including active devices, network protocols, and categorization of the detected network traffic into types;

establishing a network activity baseline for each of the sensors, each of the IoT components, and the WWNS derived from the plurality of intrusion traffic profiles; and

providing activity alerts based on comparing the sensed real-time facility intrusion activity, the real-time IoT intrusion activity, and the network traffic and intrusion activity to a respective one or more of the network activity baselines;

wherein the monitoring traffic and detecting anomalies, the creating intrusion traffic activity profiles, establishing a network activity baseline, and the providing activity alerts are performed within the security sensor gateway.

5. The method of claim 4 , further comprising comparing the monitored traffic and the collected intrusion activity with each network activity baseline to produce a threat anomaly detection level and (ii) triggering a security alert when the threat anomaly detection level exceeds a predetermined threshold.

Continuity (2)
Provisional Application 62528322 · Jul 3, 2017
Related Publication 20190007429A1 · Jan 3, 2019