Industrial control network threat automatic isolation method and system
A technology of industrial control network and industrial control system, which is applied in the field of automatic threat isolation of industrial control network, and can solve the problem of slow update of threat signature database, false negative rate and accuracy rate of security protection system, inability to effectively update threat signature database, lack of local automatic Blocking mechanism and other issues to achieve the effect of improving the recall rate and precision rate, improving the detection accuracy rate, and reducing the false negative rate
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0038] The present invention will be further described below in conjunction with the accompanying drawings. The following examples are only used to illustrate the technical solution of the present invention more clearly, but not to limit the protection scope of the present invention.
[0039] Such as figure 1 Shown, a kind of industrial control network threat automatic isolation method comprises the following steps;
[0040] Step 1, obtain the operation information of each device in the industrial control system, and extract the characteristics of the operation information.
[0041] Operation information includes industrial control system logs, network connection information and business operation information; among them, by installing probe programs on various devices, the acquisition of logs and network connection information is realized; real-time capture of network application layer messages through switch mirroring technology, Obtain the service operation information of...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


