Device fingerprinting for cyber-physical systems
Abstract
Disclosed are various embodiment's for fingerprinting devices that are part of a network. A network monitoring device monitors traffic between devices in the network. A fingerprint is generated based upon response times of the devices in the network. Embodiment's of the present disclosure provide for device fingerprinting in cyber-physical system, such as a control system environment. Embodiment's of the present disclosure can be used in conjunction with traditional intrusion detection system (IDS) in a control systems environment. Embodiment's of the present disclosure can be used to achieve device fingerprinting from software, hardware, and physics-based perspectives. Embodiment's of the present disclosure can prevent security compromises by accurately fingerprinting devices in a control system environment, and other networked environments, as may be appreciated. Embodiment's of the present disclosure can generate fingerprints of a device which reflects identifiable characteristics of a device, such as, e.g., processing speed, processing load, memory speed, and protocol stack implementation.
Claims
exact text as granted — not AI-modified1 . A method of fingerprinting devices in a control system, comprising:
sending a plurality of read requests to at least one device in the control system; receiving a corresponding response for each of the plurality of read requests from the at least one device in the control system; measuring, via a network monitoring device, an amount of time between an acknowledgment of each of the plurality of read requests and the corresponding response; and generating a fingerprint for the at least one device based at least in part upon the amount of time between the acknowledgment of each of the plurality of read requests and the corresponding response.
2 . The method of claim 1 , wherein the network monitoring device is configured to parse a control system application layer header.
3 . The method of claim 1 , further comprising:
storing, via the network monitoring device, identifying information for each of the plurality of read requests.
4 . The method of claim 1 , further comprising storing, via the network monitoring device, a time when the corresponding response appears.
5 . The method of claim 1 , further comprising recording, by the network monitoring device, a time when the acknowledgment is seen.
6 . The method of claim 1 , wherein the fingerprint is defined by a vector of a plurality of bin counts from a histogram of the amount of time.
7 . The method of claim 6 , wherein a final bin among the plurality of bin counts comprises all values greater than a heuristic threshold.
8 . The method of claim 1 , wherein the network monitoring device comprises a network tap.
9 . The method of claim 8 , wherein the network tap is placed in a communication path of the network.
10 . The method of claim 1 , wherein the at least one device comprises a remote terminal unit.
11 . A method of fingerprinting devices in a cyber-physical system:
sending a command from a master device to a field device to perform a physical operation; observing an event change at a slave device; sending, via the slave device, a message indicating the event change; calculating an operation time of the field device based at least in part upon a time at which the message was observed; and generating a fingerprint for the field device based at least in part upon the operation time.
12 . The method of claim 11 , wherein the operation time is further based at least in part upon a difference between the time at which the message was observed and a timestamp generated.
13 . The method of claim 12 , wherein the timestamp indicates a duration of the physical operation.
14 . The method of claim 13 , further comprising monitoring, by a network monitoring device, traffic in the control system.
15 . The method of any one of claim 14 , wherein the network monitoring device comprises a network tap.
16 . The method of claim 15 , wherein the message is observed at the network tap.
17 . The method of claim 14 , wherein the network monitoring device comprises a sniffer.
18 . The method of claim 14 , wherein the network monitoring device is configured to parse packets comprising the message.
19 . The method of claim 11 , wherein the slave device is connected to the field device via a hardwire connection.
20 . The method of claim 11 , wherein the field device comprises at least one physical actuator and the command comprises a request to operate the at least one physical actuator.Join the waitlist — get patent alerts
Track US2018048550A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.