The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 27, 2023

Filed:

Mar. 15, 2017
Applicant:

Sri International, Menlo Park, CA (US);

Inventors:

Gabriela Ciocarlie, New York, NY (US);

Michael E. Locasto, Lebanon, NJ (US);

Cherita Corbett, Rockville, MD (US);

Dejan Jovanovic, Brooklyn, NY (US);

Assignee:

SRI INTERNATIONAL, Menlo Park, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); H04L 67/12 (2022.01); H04L 9/40 (2022.01); H04L 67/50 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); H04L 63/1408 (2013.01); H04L 67/535 (2022.05); H04L 67/12 (2013.01);
Abstract

Intrusion detection systems and methods monitor legal control messages in an operational control system to detect subtly malicious sequences of control messages with undesirable emergent effects on devices in the operational control system. A message provenance component may investigate system-level correlations between messages rather than detecting if individual messages are anomalous. A semantic fuzzing component may search, based on the operational effect of candidate message sequences, the space of legal messages for sequences that cause actual harm. Behavior oracles may be used to test message sequences to identify sequences that induce drift towards a failure state. The intrusion detection system is able to prevent harm and disruption arising from control messages that individually appear legitimate and benign but that, in combination with other messages, can cause undesirable outcomes.


Find Patent Forward Citations

Loading…