Unlock instant, AI-driven research and patent intelligence for your innovation.

A method and system for detecting abnormal communication of modbus TCP based on multiple groups

A detection method and anomaly detection technology, applied in transmission systems, digital transmission systems, electrical components, etc., can solve the problems of not considering the combination characteristics of data packet correlation function codes, low detection results, and insufficient connection feature extraction, etc. Easy to deploy to parallel computing platforms and solve the effect of high latency

Active Publication Date: 2022-02-18
湖南匡安网络技术有限公司
View PDF10 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] For the above defects or improvement needs of the prior art, the present invention provides a multi-group based ModbusTCP abnormal communication detection method and system, the purpose of which is to consider the function code and coil address and the function code and The relevance of the data length, extracting two sets of related tuples from the data packet, solving the technical problem of insufficient extraction of connection features existing in the existing PSO-SVM-based Modbus TCP communication anomaly detection method, and the existing decision-based The communication anomaly detection method of the tree does not consider the correlation between data packets and the combination characteristics of function codes, resulting in the technical problem of low detection results, and the existing single-class support vector machine algorithm is too complicated for data processing. Therefore, the technical problem of real-time communication is reduced

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method and system for detecting abnormal communication of modbus TCP based on multiple groups
  • A method and system for detecting abnormal communication of modbus TCP based on multiple groups
  • A method and system for detecting abnormal communication of modbus TCP based on multiple groups

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0039] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present invention, not to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not constitute a conflict with each other.

[0040] The basic idea of ​​the present invention is to perform feature extraction on the data packet sequence in the Modbus TCP connection, considering the correlation between the function code and the coil address and the function code and the data length in the data packet, that is, it can reflect the different function codes. , The combination of coil addresses is different, and the average p...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a multi-group-based Modbus TCP abnormal communication detection method, comprising: obtaining connections from an industrial control network, each connection containing a plurality of Modbus TCP data packets, and dividing the data packet flow according to unit time to obtain multiple sequence of data packets. Analyze each Modbus TCP data packet in the data packet sequence, and extract multiple function codes, coil addresses, and data lengths. In a data packet sequence, each function code corresponds to multiple data packets, and the data packets with the same function code are classified into one category. For each type of data packet, the data length in the data packet is accumulated, summed and averaged. , each function code can correspond to the average data length of a data packet, and the tuple group C is obtained 1 ;Each function code corresponds to multiple coil addresses. The invention solves the technical problem that the prior art only extracts the two features of the Modbus TCP function code and the coil address, resulting in insufficient flow feature extraction and low detection accuracy.

Description

technical field [0001] The invention belongs to the field of industrial network information security, and more specifically relates to a multi-group-based ModbusTCP abnormal communication detection method and system. Background technique [0002] With the advent of the industrial Internet era, more and more industrial control networks are connected to public networks such as the Internet. It is inevitable to start thinking about how to have better security for the industrial control network, so as to resist the complex environment. Internet cyber attack. Moreover, the equipment in the industrial control network usually plays an important role, and users have extremely high requirements on the stability and reliability of the equipment. If the industrial network is attacked, it may affect the normal operation of the industrial control equipment, and even bring users Huge loss. The Modbus TCP protocol is widely used in the field of industrial control. Its security is of grea...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L9/40H04L41/142H04L41/14
CPCH04L63/1425H04L41/142H04L41/145
Inventor 李肯立李政余思洋周旭刘楚波段明星李克勤唐伟黎东
Owner 湖南匡安网络技术有限公司