The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 14, 2019

Filed:

Mar. 04, 2015
Applicant:

Fisher-rosemount Systems, Inc., Round Rock, TX (US);

Inventors:

Robert A. Mixer, Cedar Park, TX (US);

Gary K. Law, Georgetown, TX (US);

Andrew E. Cutchin, Killeen, TX (US);

Assignee:

FISHER-ROSEMOUNT SYSTEMS, INC., Round Rock, TX (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 12/26 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 43/12 (2013.01); H04L 43/04 (2013.01); H04L 63/00 (2013.01);
Abstract

An anomaly detection system installed in a plant communications network detects unexpected changes or anomalies in the traffic patterns over the communications network to detect infected or potentially infected nodes. The anomaly detection system includes various data collection modules at each of the nodes of the network which operate to view the message traffic into and out of the node and to generate metadata pertaining to the message traffic. The communication modules at the nodes send the traffic metadata to an anomaly analysis engine, which processes the metadata using a rules engine that analyzes the metadata using a set of logic rules and traffic pattern baseline data to determine if current traffic patterns at one or more network nodes are anomalous. If so, the analysis engine may generate an alert or message to a user informing the user of the potentially infected node, may automatically disconnect the node from the network, or may take some other action to minimize the effects of an infected node.


Find Patent Forward Citations

Loading…