A svm-based IEC60870-5-104 abnormal traffic detection method
A technology of abnormal traffic and detection method, which is applied in transmission systems, electrical components, etc., and can solve problems such as inability to prevent attacks and inability to identify firewalls
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment
[0020] In order to better illustrate the technical solution of the present invention, a brief introduction to the IEC60870-5-104 protocol is firstly made. The application protocol data unit (APDU) of the IEC60870-5-104 protocol is composed of the application protocol control information (APCI) and the application service data unit (ASDU). APCI mainly defines the start and end of ASDU, which consists of start character (68H), length, and control field. The control field defines the control information to protect the message from loss and repeated transmission, the start and stop of message transmission, and the monitoring of transmission links. According to the different control fields, the message structure of IEC60870-5-104 is divided into three different formats, namely I format (Information Transmit Format), S format (Numbered supervisory Functions), and U format (Unnumbered Control Format). Only I-format messages can be used to transmit ASDUs. figure 1 It is the structur...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


