Electric power communication protocol exception detection method based on dynamic extensible finite state

A finite state machine, power communication technology, applied in the field of abnormal detection of network communication protocols, can solve problems such as limited functions, poor scalability, time-consuming and labor-intensive, and achieve good application prospects and convenient support.

Active Publication Date: 2015-02-18
STATE GRID CORP OF CHINA +3
View PDF4 Cites 17 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] At present, the methods adopted for the identification and analysis of application layer protocols in the electric power communication industry are roughly divided into the following categories: 1. Using hard coding, the identification and analysis of the supported application layer protocols are directly written into the program code, When using this method, when it is necessary to modify the protocol analysis method or to expand and support more application layer protocols, it needs to be hard-coded again, and the scalability is poor; Expand support for new application layer protocols, but program coders are required to carry out customized development, which is time-consuming and laborious; 3. Use an intermediate scripting language to realize the analysis of network protocols. For example, Wireshark supports adding support for new network protocols through Lua scripting language Analysis support, but users need to master the syntax of Lua, and the functions provided by Lua are limited, so it is not suitable for complex processing such as state detection and tracking of data packet context

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Electric power communication protocol exception detection method based on dynamic extensible finite state

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0033] The present invention will be further described below in conjunction with the accompanying drawings.

[0034] The dynamically scalable power communication protocol anomaly detection method based on the finite state machine of the present invention describes the definition of the L2-L7 layers (link layer to application layer) of the power communication protocol, protocol state machine logic and exception processing logic through protocol description rules , form a protocol rule definition file, and then translate the protocol rule definition file into a protocol rule library through the protocol rule analysis engine, and perform protocol analysis, status detection, and exception handling on network data packets according to the protocol rule library, such as figure 1 As shown, it specifically includes the following steps,

[0035] Step (1): Analyze the message format and interaction process of the power application layer protocol used in power communication, and establis...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses an electric power communication protocol exception detection method based on a dynamic extensible finite state. The method includes describing definitions of L2 to L7 (link layer to the application layer) of an electric power communication protocol, protocol state machine logic and exception handling logic according to protocol description rules, acquiring protocol rule definition files, translating the protocol rule definition files to form a protocol rule database through a protocol rule analytic engine, and performing protocol analysis, state detection and exception processing on network data packages according to the protocol rule database. The dynamic extensible support is provided for various application layer protocols and is further provided for application layer context state detection and exception processing, electric power communication protocol exception detection is facilitated, and the method has promised application prospect.

Description

technical field [0001] The invention relates to an anomaly detection method of a network communication protocol, in particular to a dynamically scalable power communication protocol anomaly detection method based on a finite state machine. Background technique [0002] In recent years, network attacks against specific application-layer services have occurred continuously. Traditional network security protection devices (such as firewalls, IDS, etc.) are difficult to detect such application-layer attacks because they only detect the network layer. Therefore, it is urgent to strengthen the protection against Security monitoring of network application layer data. [0003] Compared with the communication protocols at the network layer, there are a large number of application layer protocols, not only a large number of general application layer protocols (such as HTTP, FTP, SSH, etc.), but also many industry-specific application layer protocols (such as the power communication in...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L12/26H04L29/08
Inventor 黄益彬金倩倩杨维永俞皓朱应飞朱世顺宋述停王强
Owner STATE GRID CORP OF CHINA
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products