FIELD: physics.
SUBSTANCE: invention relates to safety monitoring means. Disclosed is a method of detecting anomalies in the operation of an AC network, which includes the following steps: receiving a network packet intercepted in an AC network and identifying address fields and data fields therein; detecting address and interface of sender node and address and interface of receiving node, and for detected pair find record in signal dictionary; detecting response of receiving node to detected record of signals dictionary and comparing this reaction with expected reaction; returning an abnormality card to the user, wherein the anomaly card includes information including at least one of the types of information selected from the group: automatically generated network packet parsing rules; an address and/or interface of a source node and/or a destination node not found in an interface catalogue; deviation between observed and expected response to signal dictionary recording.
EFFECT: technical result consists in improvement of accuracy in detection of anomalies in the operation of an automated system network.
9 cl, 13 tbl, 12 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD FOR DETECTION OF ANOMALIES IN OPERATION OF HIGHLY LOADED NETWORK OF AUTOMATED TELECOMMUNICATION SYSTEM | 2021 |
|
RU2787078C1 |
METHOD FOR DETECTING NORMAL REACTIONS OF COMPUTER NETWORK NODES TO NETWORK PACKETS RELATED TO UNKNOWN TRAFFIC | 2022 |
|
RU2802164C1 |
METHOD FOR MONITORING NETWORK ACTIVITY OF COMPUTER NETWORK NODES | 2023 |
|
RU2809918C1 |
METHOD OF ROUTING TRAFFIC, HAVING PRIORITY CLASS IN COMMUNICATION NETWORK, INCLUDING TWO AND MORE OPERATORS | 2016 |
|
RU2631144C1 |
FIREWALL SYSTEM | 2017 |
|
RU2691192C1 |
METHOD OF PROCESSING NETWORK TRAFFIC USING FIREWALL METHOD | 2017 |
|
RU2697698C2 |
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR HIDING CORRESPONDING PAIRS OF SUBSCRIBERS OF INFORMATION-TELECOMMUNICATION SYSTEMS | 2014 |
|
RU2586840C1 |
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR PROTECTING INFORMATION COMPUTER SYSTEMS (VERSIONS) | 2012 |
|
RU2472217C1 |
METHOD FOR PROCESSING NETWORK TRAFFIC DATAGRAMS TO HIDE CORRESPONDING PAIRS OF SUBSCRIBERS OF INFORMATION AND TELECOMMUNICATION SYSTEMS | 2020 |
|
RU2763261C1 |
METHOD OF NETWORK PROTOCOL DEEP REVIEW FOR ANALYSIS AND FILTRATION OF THEIR CONTENTS | 2016 |
|
RU2640295C1 |
Authors
Dates
2020-12-14—Published
2020-02-26—Filed