Anomaly detection system for detecting anomaly in multiple control systems
First Claim
1. An anomaly detection system for detecting an anomaly in a plurality of control systems, the anomaly detection system comprising:
- a plurality of analysis devices that are associated with the respective control systems and that acquire an event occurring in an associated control system and analyze the event to determine whether there is an anomaly, wherein;
a first analysis device among the plurality of analysis devices determines whether an event occurring in the associated control system is to be indicated to a second analysis device among the plurality of analysis devices; and
the second analysis device determines that there is an anomaly on condition that the event indicated by the first analysis device has correlation with an event indicated by an analysis device other than the first analysis device.
1 Assignment
0 Petitions
Accused Products
Abstract
An anomaly detection system for detecting an anomaly in a plurality of control systems comprises a plurality of analysis devices that are associated with the respective control systems and that acquire an event occurring in an associated control system and analyze the event to determine whether there is an anomaly. A first analysis device among the plurality of analysis devices determines whether an event occurring in the associated control system is to be indicated to a second analysis device among the plurality of analysis devices, and the second analysis device determines that there is an anomaly on condition that the event indicated by the first analysis device has correlation with an event indicated by an analysis device other than the first analysis device.
19 Citations
14 Claims
-
1. An anomaly detection system for detecting an anomaly in a plurality of control systems, the anomaly detection system comprising:
a plurality of analysis devices that are associated with the respective control systems and that acquire an event occurring in an associated control system and analyze the event to determine whether there is an anomaly, wherein; a first analysis device among the plurality of analysis devices determines whether an event occurring in the associated control system is to be indicated to a second analysis device among the plurality of analysis devices; and the second analysis device determines that there is an anomaly on condition that the event indicated by the first analysis device has correlation with an event indicated by an analysis device other than the first analysis device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
14. An anomaly detecting method for detecting an anomaly in a plurality of control systems, comprising:
-
providing a plurality of analysis devices, wherein the plurality of analysis devices are associated with the respective control systems and that acquire an event occurring in an associated control system and analyze the event to determine whether there is an anomaly, the method comprising; determining, by a first analysis device among the plurality of analysis devices, whether an event occurring in the associated control system is to be indicated to a second analysis device among the plurality of analysis devices; and determining by the second analysis device that there is an anomaly on condition that the event indicated by the first analysis device has correlation with an event indicated by an analysis device other than the first analysis device.
-
Specification