Connection anomaly detection methods, electronic devices, and computer-readable storage media

By filtering business traffic and resetting message analysis, combined with time thresholds and network probing, the accuracy problem of detecting disconnected and reconnected industrial communication protocols in the Industrial Internet has been solved, improving the accuracy and reliability of detection.

CN119629030BActive Publication Date: 2026-05-26BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2024-12-16
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing industrial communication protocol disconnection and reconnection detection technologies are insufficient to accurately determine the cause of transmission problems in the Industrial Internet, especially when multiple identical industrial control protocol services are running on a device, which can easily lead to missed or incorrect detections.

Method used

By filtering business traffic, identifying the business packets to be detected, determining whether the source port has changed, and combining reset packets and session establishment data, the cause of connection anomalies is determined, including application layer disconnection or reconnection events. Time thresholds are set to improve detection accuracy, and further confirmation is achieved through network probing and protocol layer anomaly analysis.

Benefits of technology

It enables accurate, timely, and comprehensive detection of industrial communication protocol disconnections or reconnections, reducing the probability of missed or false detections and improving the stability and reliability of industrial internet communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119629030B_ABST
    Figure CN119629030B_ABST
Patent Text Reader

Abstract

This application provides a connection anomaly detection method, an electronic device, and a computer-readable storage medium. The method may include: filtering acquired service traffic to identify service packets to be identified; identifying the service packets to be identified to determine whether their source port has changed; and, if the source port of the service packets to be identified has not changed and a reset message is received, determining the cause of the connection anomaly based on the current session establishment data of the target protocol used by the service packets to be identified. This method can more accurately determine the cause of disconnections or reconnections in communication protocols between devices.
Need to check novelty before this filing date? Find Prior Art