×

Abnormal traffic detection apparatus and method based on modbus communication pattern learning

  • US 9,699,204 B2
  • Filed: 04/29/2015
  • Issued: 07/04/2017
  • Est. Priority Date: 06/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. An abnormal traffic detection apparatus, comprising:

  • a communication pattern classifier configured to monitor traffic generated in Modbus/TCP communication of a control system monitoring a remote resource during a predetermined period, and generate a Modbus communication pattern based on the monitored traffic; and

    an abnormal behavior detector configured to detect abnormal traffic of the control system based on the generated Modbus communication pattern,wherein the abnormal behavior detector detects the abnormal traffic in the Modbus/TCP communication of the control system based on a Modbus request message received from a client of the control system and the generated Modbus communication pattern, anddetermines whether there is a value of a server IP identical to a value of a source IP (SIP) of the Modbus request message in a server table included in the Modbus communication pattern, and when there is the value of the server IP identical to the value of the SIP in the server table based on the determination result, determines that a server corresponding to the SIP is an abnormal server.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×