METHOD AND DEVICE FOR MONITORING CONTROL SYSTEMS
Patent Information
- Application Number
- DE502016017031
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2015-09-22
- Filing Date
- 2016-09-22
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2036-09-22
AI Technical Summary
Existing control systems, particularly industrial control systems, face vulnerabilities to external attacks and internal data loss during communication, with existing methods failing to reliably detect errors and anomalies.
A machine-learning based method that records and compares communication data within control systems, generating messages for new or unusual data patterns, using communication parameters like hardware and IP addresses, application protocols, and message types, to identify potential errors or anomalies.
The method provides rapid and reliable detection of errors and anomalies in control systems, enhancing their resilience to failures and ensuring proper functioning by passively monitoring communication patterns outside the network.
Description
[0001] The present invention relates to a method for monitoring control systems according to the preamble of claim 1 and a device for monitoring control systems according to the preamble of claim 10.
[0002] Such control systems are mainly used in industrial manufacturing and logistics and this is also the main field of application of the present invention.
[0003] Such control systems are used to control and monitor production processes, as well as storage and transport procedures. Previously, for example, monitoring was done to determine whether a specific device integrated into the control system was operating properly or whether errors were occurring, with the device's parameters being queried and monitored.
[0004] Today's modern control systems are based on Ethernet, for example, and communication within the control system takes place via IP (Internet Protocol). While this is very easy to handle, it also presents a significant vulnerability not only to external attacks but also to internal data loss during communication. Such errors in the control system have not yet been satisfactorily detected. German patent application DE 10 2010 033229 A1 discloses a method and system for the tamper-proof transmission of control data between control units in a network.
[0005] The scientific article publication "Network Traffic Features for Anomaly Detection in Specific Industrial Control System Network", by MATTI MANTERE ET AL: with the publication numbers XP055317286, ISSN: 1999-5903, DOI: 10.3390 / fi5040460, discloses an analysis of traffic features from the perspective of their suitability for identifying abnormal traffic flows in a communication network for application in an industrial control environment.
[0006] US patent US 7 644 150 B1 discloses a self-learning system for managing a peer-to-peer network, comprising a server for extracting a signature in a traffic flow, at the application layer, based on layer 3 / layer 4 information of the observed traffic flow and on a temporal correlation metric of the traffic flow.
[0007] The object of the present invention is therefore to enable monitoring of control systems, in particular industrial control systems, which detects errors in the context of communication, in particular reliably detects the errors mentioned above.
[0008] This object is achieved with the inventive method according to claim 1, the inventive device according to claim 10 and the inventive computer program product according to claim 14.
[0009] Advantageous further developments are specified in the following description and the dependent subclaims.
[0010] The inventors have recognized that the object of the present invention can be achieved in a surprisingly simple way by machine-learning the communication and then evaluating any new communication that occurs as a potential error and this is done by generating a corresponding message. This solution is based on the assumption that communication in control systems always proceeds in a determined manner and that this determination is only interrupted in the event of errors or malfunctions. In fact, for example, in an industrial control system of a production line, internal communication occurs in constantly recurring paths, whereby individual parameters, for example with regard to unit numbers, etc., may change. However, the devices communicating with each other and the type of communication do not change, so that new communication is initially potentially error-prone.For example, industrial control systems are based on the Ethernet standard. However, this can sometimes lead to data congestion or even data loss, which would be detected by the present invention.
[0011] The method according to the invention for monitoring control systems, in particular industrial control systems, wherein the control system has at least one communication network and at least two communication endpoints connected to the communication network, which exchange data via the communication network, is therefore characterized in that the data exchanged between the communication endpoints is recorded and, after comparing the currently recorded data with previously recorded data, a message is generated when new data is recorded.
[0012] "Communication networks" within the meaning of the present invention can be both wired and wireless networks over which data is communicated. For example, it can be an Ethernet-based communication network.
[0013] "Communication endpoints" in the sense of the present invention are points in the communication network where data is generated, processed, received, and forwarded. These can be devices, for example. Such communication endpoints typically have a device number (hardware address, MAC address) and an application protocol address (IP address). Simple lines are therefore not considered communication endpoints, whereas devices such as production machines, network interfaces, servers, and the like are.
[0014] "Application protocols" do not refer to basic communication protocols such as Ethernet, Internet Protocol (IP), or Transmission Control Protocol (TCP), but rather to so-called Layer 7 protocols based on the OSI model of data communication. Examples of application protocols include Siemens' Profinet, Modbus, and EtherCAT.
[0015] At least two communication endpoints are involved in a communication, but more than two communication endpoints can also be involved. If two communication endpoints are involved, then it is a 1-to-1 communication ("unicast"). If one communication endpoint communicates with a selection of communication endpoints, then it is a 1-n(m) communication ("multicast"). If one communication endpoint communicates with all other communication endpoints, then it is a 1-n(n) communication ("broadcast").
[0016] "Data" within the meaning of the present invention refers to all types of data connections or packets of data connections within the context of communication within the control system. "Messages" within the meaning of the present invention include not only character-based messages, but also optical and / or acoustic signals, as well as control signals for activating certain machine processes.
[0017] The monitoring takes place outside the existing communications network, meaning that the data acquisition does not take place within the communications network itself, but outside of it. While there is a connection to the communications network for capturing the data, the acquisition—i.e., storage, analysis, etc.—of the data takes place independently of the existing communications network. "Outside" in this invention therefore means that these are means without whose presence the communications network is nevertheless fully functional for the operation of the control system.
[0018] The data is intended to be captured passively. This means there is no active data capture, forwarding, or processing, as would be the case with a proxy server, for example. This makes the control system highly resistant to failure.
[0019] The exchanged data is analyzed for communication parameters contained therein, whereby the communication parameters include at least one parameter from the group: Hardware address of the communication endpoint involved in the communication, IP address of the communication endpoint involved in the communication, application protocol used to exchange the data and message used to communicate with the exchanged data, This allows for more precise specification of the communication, whether the communicated new data is error-relevant or whether it only involves, for example, device-specific changed parameters that do not affect the functionality of the entire control system. It is preferred that the application protocol be selected from the group: Profinet, Modbus, Ethercat, or device-specific protocols of the communication endpoints. The IP address can, of course, only be analyzed if the data traffic is actually IP. Therefore, not all of these communication parameters always have to be present for every data traffic, but they can be.
[0020] It is also intended that combinations for defining data types are formed from the analyzed communication parameters. The data types are preferably at least one combination of communication parameters from the group:Hardware address of the communication endpoint involved in the communication, IP address of the communication endpoint involved in the communication, application protocol used to exchange the data, hardware address of the communication endpoint involved in the communication combined with the application protocol used to exchange the data, IP address of the communication endpoint involved in the communication combined with the application protocol used to exchange the data, combination of the hardware addresses of the communication endpoints involved in the communication, combination of the IP addresses of the communication endpoints involved in the communication, combination of the hardware addresses of the communication endpoints involved in the communication and the application protocol used to exchange the data, combination of the IP addresses of the communication endpoints involved in the communication and the application protocol,with which the data is exchanged, combination of the hardware address and the IP address of the communication endpoint involved in the communication, combination of the hardware address and the message of the communication endpoint involved in the communication, combination of the IP address and the message of the communication endpoint involved in the communication, combination of the hardware addresses of the communication endpoints involved in the communication and the message and combination of the IP addresses of the communication endpoints involved in the communication and the message, These data types indicate relevant faults or errors in the control system particularly well and make the type of error or disturbance very easy to identify.
[0021] The message is generated when such a new data type is recorded .
[0022] A message will then not necessarily be generated for every new type of communicated data, but only when a new data type is detected. "New data type" in this context means not only that a previously unknown type of data type, i.e., a previously unanalyzed combination of communication parameters, is detected during ongoing monitoring, but also, and above all, that the content of the data type is new. This means that although the type of communication parameters contained was known, the content of the communication parameters is new, meaning it is a new instance of a known data type.
[0023] Since a control system requires not only a uniform application protocol, but also, for example, different standard or proprietary application protocols may exist in different areas of the control system, the application protocol used is analyzed by examining the exchanged data for patterns associated with a known application protocol and / or heuristically. This allows the application protocol used to communicate the new data to be determined in order to determine the other communication parameters. This protocol detection uses several characteristics of a data connection or its packets to determine which application protocol is being used in the communication.Deep packet inspection primarily examines the payload of packets to determine the underlying application protocol by finding specific patterns or applying heuristics. This analysis can also be used to individually identify unknown application protocols.
[0024] In an advantageous further development, the exchanged data is decoded using the application protocol in order to analyze the communicated message. A protocol decoder is preferably used to decode the message from the data, with each application protocol having its own protocol decoder. The message type, which is analyzed from the message, is preferably used as the communication parameter instead of the message itself. The message type is in particular one from the group: error message, authentication command, read data command, write data command, and time synchronization command of two communication endpoints. This also significantly simplifies monitoring, since the content of the message no longer needs to be analyzed in detail; instead, only the message type is used for monitoring.
[0025] If no suitable protocol decoder is available, the application protocol cannot be determined or a corresponding decoder may be added to the monitoring system, whereby this process could be performed manually or automatically.
[0026] On the other hand, it may also be provided that the application protocol can be recognized, but for reasons of complexity or due to a lack of demand from the user, the protocol decoder is not implemented, so that the application protocol can be recognized, but the message or message type cannot be read out.
[0027] In an advantageous further development, a hash value is generated from the new data or data type using a hash function. Since such hash values are unique, monitoring can be significantly accelerated, as the data or data types no longer need to be compared during monitoring, but only their hash values are used as an index.
[0028] In an advantageous development, the new data, the new data types, and / or the associated hash values are stored in a memory, preferably with an indexed data structure, wherein the new data, the new data types, and / or the associated hash values are preferably stored chronologically, in particular together with a timestamp. This ensures precise assignment to the actual course of events in the control system.
[0029] In an advantageous further development, it is also provided that the time stamp is renewed for the data types or hash values that were not recognized as new but were already stored previously, since this then results in an exact image of the control system at the time of the message.
[0030] In an advantageous further development, the timestamps for each piece of data, each data type, or each hash value are stored for a specified period of time. This allows monitoring for lost communication to detect errors and malfunctions, for example, due to the failure of a device in the control system. This specified period can be predefined but fixed, or the data can be stored until an authorized user deletes the data, for example, to account for the changed communication after a modification and restart of the control system.
[0031] Furthermore, it can be provided that the new data, the new data types, or the associated hash values are deleted from memory after a first, definable period of time, whereby this first, definable period is preferably no more than 1 year, preferably no more than 4 weeks, in particular 1 to 2 weeks. This allows an update of the monitoring bases to be performed. On the other hand, the time can also be unlimited, so that no such update takes place.
[0032] In an advantageous further development, the exchanged data is analyzed for missing communication. For example, there are cyclical communication events in which data is exchanged at periodically recurring intervals within the framework of a specific transmission protocol to ensure protocol conformity. After analyzing the periodicity of the recorded data, if necessary, it can be checked whether such data is being exchanged properly, possibly with a certain temporal inaccuracy, or whether this communication is missing, which then generates a message as a deviation from the normal case.
[0033] Independent protection is claimed for the inventive device for monitoring control systems according to claim 10.
[0034] The sensor is a passive element. This means that the sensor only passively captures the communication, but does not actively process it, nor does it forward it within the monitored communication network, as a proxy server, for example, does. This makes the control system highly immune to failure.
[0035] In an advantageous further development, it is provided that the device is adapted to carry out the method according to the invention.
[0036] In an advantageous development, at least one sensor is provided that is connected to the communications network and adapted to capture the exchanged data without altering this exchanged data. Such a sensor can be implemented as a physical device, but also as software, for example, as an application, or even as a hybrid. Monitoring can then be carried out entirely or at least partially within this sensor, or entirely or partially centrally, for example, on a server.
[0037] These "sensors" can be dedicated devices or simply points for passively capturing traffic from the communications network. For example, the replication ports of a network tap can represent such "sensors."
[0038] In an advantageous further development, it is provided that the sensor is configured to calculate hash values by means of a scatter value function, wherein the sensor is preferably adapted to store the hash values, wherein the memory in particular has an indexed data structure.
[0039] In an advantageous further development, it is provided that the sensor is configured to supply at least the new data to a quality management system, wherein the device is adapted to analyze the new data for communication parameters contained therein, wherein the communication parameters preferably comprise at least one parameter from the group: This includes the hardware address of a communication endpoint, the IP address of a communication endpoint, the application protocol used to exchange data, and the message that is communicated with the exchanged data. This not only allows monitoring for errors and faults, but also provides deeper insights into the control system for quality management purposes.
[0040] Furthermore, the invention can be implemented in the form of a computer program product accessible from a computer-usable or computer-readable medium and providing program code for use by or in connection with a computer or any instruction execution system. Therefore, independent protection is also claimed for a computer program product stored on a computer-readable medium and comprising computer-readable program means that cause the computer to carry out the inventive method when the program means are executed on the computer, as defined in claim 14.
[0041] For the purposes of this description, computer-usable or computer-readable media may be any device or apparatus that contains, stores, communicates, distributes, or transports the program for use by or in connection with the instruction execution system, apparatus, or device. This may also include mobile communication devices, such as mobile phones, tablet computers, and the like.
[0042] The medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or device or apparatus), or a propagation medium. Examples of a computer-readable medium include semiconductor or solid-state memory, magnetic tape, a removable computer diskette, random access memory (RAM), read-only memory (ROM), a fixed magnetic disk, and an optical disk. Current examples of optical disks include compact disk read-only memory (CD-ROM), compact disk read / write (CD-R / W), and DVD.
[0043] A data processing system suitable for storing and / or executing the program code comprises at least one processor connected directly or indirectly to at least one memory element via a system bus. The memory element may include local memory active during the actual execution of the program code, mass storage, and buffer memory that provides temporary storage of at least some program code to reduce the number of times the code is retrieved from mass storage during execution.
[0044] Input / output or I / O devices, which may include but are not limited to keyboards, displays, pointing devices, etc., may be coupled to the system either directly or through intermediate I / O controllers.
[0045] Network adapters may also be connected to the system to enable the data processing system to connect to other data processing systems or remote printers or storage devices through intermediate private or public networks. Modems, cable modems, or Ethernet cards are just a few examples of the types of network adapters currently available.
[0046] The characteristics and further advantages of the present invention will become clear below from the description of a preferred embodiment in conjunction with the figures, which show purely schematically: Fig. 1 the inventive monitoring of a control system in a first preferred embodiment, Fig. 2 the inventive monitoring of a control system in a second preferred embodiment, Fig. 3 the inventive monitoring of a control system in a third preferred embodiment, Fig. 4 block diagram of the analysis of the data types from the acquired data and Fig. 5 flow chart of the message generation.
[0047] In Fig. 1 For a control system 10, a first preferred embodiment of the monitoring according to the invention by means of the device 12 for monitoring the control system 10 is shown purely schematically.
[0048] It can be seen that the control system 10 is an industrial control system 10, such as is used, for example, in a production line (not shown) to control and synchronize the actions of individual devices (not shown) of the production line. This control system 10 is based, for example, on the Ethernet standard. The devices of the production line are arranged, for example, as a star-shaped communication network 14.
[0049] At various locations, in this case at the nodes of the star-shaped network 14, so-called switches 16 are arranged, which are equipped with mirror ports 18. These mirror ports 18 read the aggregated data traffic 20 of the other ports 22, i.e., the data 20 communicated in the control system 10 (see Fig. 4), purely passively, without changing this data 20, and feed this data 20 to the sensors 24 connected to the switches 16, which in turn are connected to a central control unit 26. This central control unit 26 is connected to an operating unit 28, which is used, on the one hand, to update the device 12 and, on the other hand, to configure it and evaluate the obtained results.
[0050] The sensors 24 can be physical or software-based, for example, in the form of applications. They forward the data traffic 20 to the control unit 26 so that this can be centrally located. They also multiply the distribution options for the recorded data traffic. Furthermore, they form a buffer for the data 20, preventing confusion and data loss. The clock speed of the mirror port 18 should preferably be as high as the sum of the clock speeds of the mirrored ports 22. Furthermore, the sensors 24 package the data 20 so that no subsequent attempt is made to retransmit the data to the recipients. This packaging is then removed first during the analysis of the data 20.
[0051] If necessary, an additional switch layer (not shown) can be inserted between the sensors 24 and the central control unit 26. In addition to the analysis of the data traffic 20 and possible quality management, the software for the sensors 24 can also operate in the central control unit 26.
[0052] In contrast to Fig. 1 are used in the monitoring device 12' of the Fig. 2 no switches are used, but so-called network taps 30, in which each port 32', 32" is assigned its own port 34', 34", which passively forwards the data 20 of the respective port 32', 32" to the sensors 35', 35", independently of the remaining data traffic 20 running in the control system 10'.
[0053] In Fig. 3In this monitoring device 12", switches 16' with mirror ports 18 are used. However, no dedicated sensors are used here; instead, the data traffic 20 in the control system 10" is forwarded directly from the switches 16' to the central control unit 26, for example via throw cables 36 or wirelessly. The sensors here are thus embodied by the mirror ports 18 and the throw cable 36.
[0054] In Fig. 4 It can be seen that the data 20 read by the sensors 24, 35', 35" are first analyzed for the communication parameters contained in the data 20, namely the IP addresses 38 and MAC addresses 40 of the production line devices involved in the communication, the application protocol 42 used in the communication, and the messages actually exchanged in the communication. These can be one or more messages.
[0055] In the example shown, it is assumed that two devices are involved in the communication, which is why two different IP addresses 38 and MAC addresses 42 are analyzed. The application protocol 44 is either a proprietary device-specific protocol or, for example, the Profinet application protocol from Siemens. The messages exchanged concern, for example, the request for synchronization, error messages, the request for or subsequent execution of authentication, or the like. In this case, the preferred analysis does not process the actual messages, i.e., the exact contents of the messages, but rather the underlying message types 44 are determined from these messages, i.e., synchronization commands, error messages, authentication commands, and the like. Various message types 44 can occur, as in Fig.4 is shown.
[0056] From these communication parameters 38, 40, 42, and 44, 14 different data types 46 (type 0 to type 13) are generated by using individual communication parameters 38, 40, 42, and 44 and / or combining them. These data types 46 are then either single, such as type 3, or duplicated due to the two communicating devices, such as type 9. Depending on the number of message types 44, types 10, 11, 12, and 13 are duplicated accordingly.
[0057] Accordingly Fig. 5 The corresponding hash values 48 are then calculated from each data type 46 as soon as it has been recorded. Then, in a memory (not shown) which is located in the sensor 24, 35', 35" itself (cf. Fig. 1 and 2) or in the central control unit 26, compared 50 whether this hash value already exists and the time stamp of this hash value is updated 52 if it already exists, or the hash value is stored 54 with the current time stamp if the hash value was not yet present in the memory.
[0058] If the timestamp was updated because the hash value was already present in memory 52, nothing further is done 56. If, on the other hand, a new hash value is stored in memory 54, then a completely new type of communication occurred and a message 58 is generated indicating that this is a completely new type of communication that has not previously occurred in the control system 10. For example, two devices are now communicating with each other that have never done so before (type 5), or message types are being exchanged between two devices that have never been exchanged between these devices before (type 12). Since communication in a control system 10 is deterministic and no new, unexpected communication can occur during normal operation, this reported new communication could be an error, a malfunction, or even an unauthorized external attack.
[0059] Depending on the design of the monitoring system according to the invention, the generated message 58 is then examined by the monitoring personnel to determine whether a critical condition of the control system 10 actually exists and what further action may be required. Alternatively, the message is linked to an automated mechanism that independently performs certain actions to secure the control system 10, which, in extreme cases, may include its controlled shutdown and shutdown.
[0060] Messages 58 can contain only a reference to the determined new hash value or detailed information about the communication parameters, data types, or communicated messages. Furthermore, these messages 58 can be forwarded to a suitable quality management system. There, a comparison can then be made between the determined quality and communication disruptions, for example, to be able to attribute quality losses to specific communication disruptions or to determine that certain communication errors do occur but have no impact on the achieved quality. In the latter case, message 58 could then be omitted in the future, and the underlying communication state could be considered the standard case of the control system.
[0061] If it finally turns out that the new hash value is linked to an undesirable state of the control system 10, this hash value can be deleted from the memory after the evaluation or automation has been carried out, so that this state can be recognized as a deviation from the normal state the next time using this hash value.
[0062] It can be seen that the monitoring according to the invention is achieved by learning the communication typically occurring in the control system 10, i.e., typing and storing it. When a new communication type occurs, a message 58 is generated to indicate this. In this context, the content of the communication is essentially irrelevant; what matters is whether the communication is typical, i.e., whether it would occur during normal operation. This allows anomalies in the communication to be detected immediately.
[0063] The monitoring system according to the invention can be used in two different ways. Either a settling process is performed, during which all communication is stored and only then is the monitoring system "activated," or monitoring is initiated from the beginning. The first variant is less time-consuming, but there is also the risk that anomalous communication is stored and thus treated as normal, so that its occurrence would not be reported later. The second variant is more time-consuming, since each new communication results in a message 58, which must then be checked by the monitoring personnel. However, this essentially eliminates errors.
[0064] In contrast to the previously known monitoring of parameters of individual devices, these parameters are now of less or no interest at all. Instead, the entire communication within the control system is monitored to ensure its proper functioning. Due to the pure hash value comparisons (36), monitoring is particularly fast and resource-efficient. Instead of hash values (50), other identifiers that allow for unique assignment can of course also be used.
[0065] From the above description, it has become clear that the present invention provides a monitoring system that detects communication errors in control systems, particularly in industrial control systems, particularly quickly and reliably. These errors can be subsequently linked to quality management, if necessary, to determine whether quality losses correlate with such detected errors.
[0066] Unless otherwise stated, all features of the present invention can be freely combined with one another. The features described in the description of the figures can also be freely combined with the other features as features of the invention, unless otherwise stated. In this case, physical features of the device can also be used within the scope of the method, and method features can be used within the scope of the device. List of reference symbols
[0067] 10, 10', 10"Control system 12, 12', 12"Device for monitoring the control system 10 14Star-shaped communication network 16Switches 18Mirror ports of the switches 14 20Data traffic, data 22Ports of the switches 16 24Sensors 26Central control unit 28Operating unit of the central control unit 26 30Network taps 32', 32"Ports of the network taps 30 34', 34"Ports of the network taps 30, Replication ports 36Drop cables 38IP addresses 40MAC addresses 42Application protocol 44Message types 46Data types (type 0 to type 13) 48Calculating hash values 50Comparing hash value with memory 52Updating hash value 54Hash value with current timestamp and save 56End 58Generation of message
Claims
1. A method for monitoring control systems (10, 10', 10"), wherein the control system (10, 10', 10") has at least one communication network (14) and at least two communication end points connected to the communication network (14), which communication end points exchange data (20) via the communication network (14), wherein the data (20) exchanged between the communication end points is acquired and after comparing the currently acquired data (20) with previously acquired data (20), an alert (58) is raised when new data is acquired (20), wherein the exchanged data (20) are deterministic in that no new data (20) are generated in the normal operation of the control system (10, 10', 10") by the at least two communication end points, wherein the monitoring exists outside the existing communication network (14) and the data (20) is passively captured, wherein the exchanged data (20) are analyzed for communication parameters (38, 40, 42, 44) contained therein, wherein the communication parameters (38, 40, 42, 44) preferably comprise at least one parameter from the group: - hardware address (38) of the communication end point involved in the communication, - IP address (40) of the communication end point involved in the communication, - application protocol (42) with which the data (20) are exchanged and - message that is communicated with the exchanged data (20), wherein the application protocol used to communicate the new data is determined in order to determine the other communication parameters, wherein for analyzing the application protocol (42) used the exchanged data (20) are examined heuristically and / or on the patterns associated with a known application protocol (42), wherein combinations for defining data types (46) are formed from the analyzed communication parameters (38, 40, 42, 44), wherein the alert is raised upon acquisition of a new data type (46).
2. The method according to claim 1, characterized in that the application protocol (42) is a layer 7 protocol according to the OSI model, which in particular is selected from the group: Profinet, Modbus, Ethercat or device-specific protocols of communication end points.
3. The method according to claim 2, characterized in that the data types (46) preferably comprise a combination of communication parameters (38, 40, 42, 44) from the group: - hardware address of the communication end point involved in the communication, - IP address of the communication end point involved in the communication, - application protocol with which the data are exchanged, - hardware address of the communication end point involved in the communication combined with the application protocol with which the data are exchanged, - IP address of the communication end point involved in the communication combined with the application protocol with which the data are exchanged, - combination of the hardware addresses of the communication end points involved in the communication, - combination of the IP addresses of the communication end points involved in the communication, - combination of the hardware addresses of the communication end points involved in the communication and the application protocol with which the data are exchanged, - combination of the IP addresses of the communication end points involved in the communication and the application protocol with which the data are exchanged, - combination of the hardware address and the IP address of the communication end point involved in the communication, - combination of the hardware address and the message of the communication end point involved in the communication, - combination of the IP address and the message of the communication end point involved in the communication, - combination of the hardware addresses of the communication end points involved in the communication and the message and - combination of the IP addresses of the communication end points involved in the communication and the message, wherein in particular it is provided that the alert is raised upon acquisition of a new data type.
4. The method according to one of claims 2 or 3, characterized in that, for the analysis of the communicated message, the exchanged data (20) are decoded with the aid of the application protocol (42), wherein the message type (44) of the message is preferably used as a communication parameter instead of the message, which is analyzed from the message, wherein the message type (44) in particular is one of the group: error message, command to authenticate, command to read data, command to write data and command to synchronize time of two communication end points.
5. The method according to one of the preceding claims, characterized in that a hash value (48) is formed from the new data (20) or the new data type (46) by means of a hash function.
6. The method according to one of the preceding claims, characterized in that the new data (20), the new data types (46) and / or the associated hash values (48) are stored in a memory, preferably with an indexed data structure, wherein the new data, the new data types or the associated hash values are preferably stored chronologically, in particular together with a timestamp.
7. The method according to claim 6, characterized in that the timestamps are updated when the data (20), the data types (46) or hash values (48) reoccur, wherein the timestamps are collected for each data, data type or hash value.
8. The method according to claim 6 or 7, characterized in that the timestamps are stored for a predetermined period.
9. The method according to one of the preceding claims, characterized in that the exchanged data (20) are analyzed for an absence of communication.
10. A device (12, 12', 12") for monitoring control systems (10, 10', 10"), wherein the control system (10, 10', 10") has at least one communication network (14) and at least two communication end points connected to the communication network (14), which communication end points exchange data (20) via the communication network, wherein means (24, 30, 35', 35") are provided for acquiring the data (20) exchanged between the communication end points data and means (26) are provided for comparing the currently acquired data (20) with previously acquired data (20), which are configured to raise an alert (58) when new data (20) are acquired, wherein the exchanged data are deterministic in that no new data are generated in the normal operation of the control system (10, 10', 10") by the at least two communication end points, wherein the device (12, 12', 12") is adapted to make the monitoring outside of the existing communication network (14) and to passively capture the data, wherein the device is adapted to analyze the exchanged data (20) for communication parameters (38, 40, 42, 44) contained therein, wherein the communication parameters (38, 40, 42, 44) comprise at least one parameter from the group: - hardware address (38) of the communication end point involved in the communication, - IP address (40) of the communication end point involved in the communication, - application protocol (42) with which the data (20) are exchanged and - message that is communicated with the exchanged data (20), wherein the application protocol used to communicate the new data is determined in order to determine the other communication parameters, wherein for analyzing the application protocol (42) used the exchanged data (20) are examined heuristically and / or on the patterns associated with a known application protocol (42), wherein combinations for defining data types (46) are formed from the analyzed communication parameters (38, 40, 42, 44), wherein the alert is raised upon acquisition of a new data type.
11. The device (12, 12', 12") according to claim 10, characterized in that the device (12, 12', 12") is adapted to perform the method according to one of claims 1 to 8 and / or that at least one sensor (24, 35', 35") is provided, which is connected to the communication network (14) and is adapted to acquire the exchanged data (20) without changing this exchanged data (20).
12. The device (12, 12', 12") according to claim 11, characterized in that the sensor (24, 35', 35") is arranged to calculate hash values (48) by means of a hash function, wherein the sensor (24, 35', 35") is preferably adapted to store the hash values (48), wherein the memory in particular has an indexed data structure.
13. The device (12, 12', 12") according to claim 11 or 12, characterized in that the sensor (24, 35', 35") is configured to provide at least the new data (20) to a quality management, wherein the device (12) is adapted to analyze the new data (20) for communication parameters (38, 40, 42, 44) contained therein, wherein the communication parameters (38, 40, 42, 44) preferably comprise at least one parameter from the group: hardware address of a communication end point, IP address of a communication end point, application protocol with which the data are exchanged and message that is communicated with the exchanged data.
14. A computer program product that is stored on a computer readable medium comprising computer readable program means for causing the computer to execute a method according to one of claims 1 to 9 when the program means are executed on the computer.