The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 22, 2019

Filed:

Nov. 19, 2015
Applicant:

Abb Schweiz Ag, Baden, CH;

Inventors:

Sebastian Obermeier, Schinznach-Dorf, CH;

Roman Schlegel, Wettingen, CH;

Michael Wahler, Baden, CH;

Assignee:

ABB Schweiz AG, Baden, CH;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/54 (2006.01); G06F 17/30 (2006.01); G06F 21/55 (2013.01); H04L 12/24 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 9/542 (2013.01); G06F 17/30345 (2013.01); H04L 63/1416 (2013.01); G05B 2219/23317 (2013.01); G06F 21/554 (2013.01); H04L 41/145 (2013.01);
Abstract

A method and system for automatic signalling an alert when a possible intrusion occurs in an industrial automation and control system, based on security events which occur in the industrial automation and control system or are externally fed into the system. The method includes the steps of: (a) determining a correlation of a first and second security event and storing the correlation in an event database, wherein the correlation includes a probability that the first security event is followed by the second security event within a normalized time period, (b) identifying a candidate event as the first security event, based on event information of the candidate event, upon occurrence of the candidate event, (c) classifying the candidate event as anomalous when the probability exceeds a predetermined threshold and no second security event follows the candidate event within the normalized time period, and (d) signalling the alert indicating the candidate event.


Find Patent Forward Citations

Loading…