WO2017148559A1 - Procédé et module d'analyse pour vérifier des transmissions de données chiffrées - Google Patents
Procédé et module d'analyse pour vérifier des transmissions de données chiffrées Download PDFInfo
- Publication number
- WO2017148559A1 WO2017148559A1 PCT/EP2016/082535 EP2016082535W WO2017148559A1 WO 2017148559 A1 WO2017148559 A1 WO 2017148559A1 EP 2016082535 W EP2016082535 W EP 2016082535W WO 2017148559 A1 WO2017148559 A1 WO 2017148559A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network communication
- data packet
- network
- analysis
- security policy
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
Definitions
- the invention relates to a method and an analysis module for checking encrypted data transmissions.
- policies are defined via which interfaces which data may be transmitted in which way.
- LAN Local Area Network
- the object of the present invention is to provide a method and an analysis module that allow encrypted data connections to be enforced and checked.
- the object is solved by the features specified in the independent claims.
- advantageous developments of the invention are shown.
- the invention relates to a method for computer-aided checking of a network communication with the following method steps: A method step for detecting a data packet of the network communication, wherein the network communication is assigned a security policy.
- Data package can be understood in the context of patent applica ⁇ -making, for example, an Ethernet frame, Token Ring frame, an IP packet, a data block in higher protocol layers, especially at the application layer, the data of a TCP streams or TCP segment.
- a data packet may include payload, which are preferably encrypted.
- Connection type can be understood in the context of the patent application, for example, a direct connection via a LAN (Engl. Local Area Network) or a virtual private network connection ⁇ factory.
- random bit sequence or a pseudo-random permutation ver ⁇ standing may be related to the patent application random or pseudo-random bit sequences distribute.
- network communication can be understood to mean communication between users of a computer network.
- a connection-oriented, in particular ⁇ sondere be understood to be a TCP / IP-based network communication, or Getting Connected wireless communications, in particular a UDP-based network communications.
- the communication may be realized as a punk-to-point communication or as a group communication.
- network communication in particular communication between the layers of a communication model, such as the OSI model or the TCP / IP model, understood to be.
- the communication is particularly not be on individual layers of a communication model be ⁇ limits. This can be in the network communication, for example, a communication on the application ⁇ layer and / or the network layer and / or bit transmission layer and / or another layer of Kommunikati ⁇ onsmodells act.
- a "security policy" or a directive may, for example, be understood to mean a security policy in connection with the patent application.
- the security directional ⁇ line may indicate for example, whether a Netztechnikkommunika ⁇ tion to take place encrypted and / or on which protocol layers of a network protocol used a Ver ⁇ encryption is to be used and / or certain network protocols for communication purports. Also, the
- a “program component” may be understood with program instructions in connection with the patent application, a software component, the method of the invention menting imple ⁇ .
- By “on-the-fly” can be understood in the context of patent applica ⁇ -making, for example, that data packets are analyzed di ⁇ rectly during processing in a network component.
- a network component can be, for example, a switch that forwards a data packet to the port to which a receiver of the data packet is connected.
- a La ⁇ tenzzeit at a transmission of the data packet is not preferably increased.
- a “network subscriber” or “subscriber” (a network communication) can be understood in connection with the patent application to be a workstation, a field device or a measuring device.
- the network subscribers or subscriber can use, for example, a network communication over a network to communicate with other network devices, and particularly this data or data packets austau ⁇ rule.
- a "protocol” or a "communication protocol” can be understood as a network protocol, for example the TCP / IP protocol or the IPX / SPX protocol, which can be used for network communication between network users.
- a protocol can also be defined on higher OSI layers, such as on the application layer.
- an "insufficient match” can be understood as meaning that, for example, data bits of encrypted data of a data packet of a network communication do not satisfy statistical properties, in particular expected or predetermined statistical properties, in a statistical analysis. These statistical properties can be predetermined, for example, by an encryption algorithm that is required by a security policy for network communication. This may mean that the data bits of the payload of the data packet should comprise, for example, a random distribution sta ⁇ tical to confirm that they are encrypted. Assign the data bits, however, a non-random statistical distribution that have this particular insufficient compliance with specified differently surrounded statistical properties. However, an inadequate agreement can also be understood as meaning that one or more requirements of a security directive are not met in network communication.
- real time can be understood to mean that the analysis and / or the provisioning are carried out reliably within a predetermined period of time, for example in a fixed time grid. For a network communication, this may mean that the analysis and / or the provisioning takes place within a period of time before the data packet has been transmitted to its destination or, if a forwarding of the data packet from the analyzing and / or the provisioning without a notable increase in the data packet Transmission duration of the data packet takes place.
- a "processor” may be understood in connection with the patent application, for example, a machine or electronic ⁇ specific circuit.
- a processor can be a central processing unit (CPU), a microprocessor or a microcontroller.
- CPU central processing unit
- microprocessor or a microcontroller.
- under a processor may be a virtualized processor, also referred to as a soft CPU will be understood.
- It can also be a programmable processor, for example, which is equipped with configuration steps for carrying out the aforementioned method according to the invention or is configured with configuration steps in such a way that the programmable processor has the features according to the invention of the device, the system or parts of the system.
- the method is particularly advantageous since it can be easily integrated, for example, and is transparent to all network users (bump-in-the-wire property), especially in many applications.
- the method can be, for example, in software components in the network subscriber or network components integrate ren.
- a kickback ⁇ free implementation using a data diode is conceivable whereby such a device is relatively easy to integrate in safety-critical systems.
- Consideringskri ⁇ technology systems are in particular to safety and functional safety of the system.
- I also does not limit the method to a single packet of data loading, but can also use multiple data packets for Ana ⁇ analysis.
- the network communication is encrypted in accordance with the security policy, with no need for cryptographic keys for analyzing.
- a use or ei ⁇ ne knowledge of the cryptographic keys that are used to encrypt the network communication, unnecessary for the process and their use can thus be omitted in particular in the analysis.
- the method is for example able to inhibit Studentstra ⁇ supply of unencrypted data.
- the procedure shall in particular no secrets, example ⁇ as secret cryptographic keys, have to assess the encryption status of the transmission.
- the quality of the encryption can be evaluated depending on the selected statistical function by a statistical distribution of data bits of the payload of the data packet out ⁇ upgraded.
- Encryption methods which in particular do not differ statistically from noise, can be regarded as unsafe. It is therefore also possible for example to integration errors or implementation error of a system to detect, for example, when a con ⁇ stant initialization vector is used with an encrypted network communication, which also reduces the Qua ⁇ formality of encryption.
- the data packet is stored and analyzing is performed insbeson ⁇ particular to a definable later. This makes it possible, for example, to perform an analysis at high network load, so that, for example, excessive utilization of a processor that performs the method is prevented.
- the method the
- Analyzing the data packet immediately after detection wherein the analyzing is preferably done in real time.
- the method can be adapted to different application scenarios or different network utilization situations.
- a MAC address and / or an IP address and / or a port and / or features in the protocol header of the data packet are evaluated for the characterization.
- TCP / IP model that is encrypted.
- configuration information is known about the data packet.
- the Minim ⁇ is a statistical function least a chi-squared test and / or Kolmogorov-Smirnov test and / or a G-test.
- the statistical function is not limited to the particular ⁇ to the above statistical func ⁇ nen, but can use other ones statistical functional.
- statistical properties of encrypted user data of the encrypted network communication data packet determined with the analysis are compared with expected statistical properties.
- control information controls a separation of the network communication and / or a transmission of the data packet and / or a triggering of an optical or acoustic signal and / or a logging of a result of the analysis in a secure log file.
- the analysis function in particular determines the Quali ty ⁇ encryption additionally applied an analysis function to the data packet parsing. In this way can check whether a Ver ⁇ encryption of network communication is carried out with a strong cryptographic keys, or with a weak cryptographic key, for example. This can be determined, for example, by the fact that, when using a weak cryptographic key, the payload of the data packet is present in plain text within a short time.
- the analysis function can be a brute-force function to test downgrade attacks (export key length).
- the invention relates to a Analy ⁇ semodul for computer-aided checking a network communication.
- the analysis module comprises a detection device for detecting a data packet of the network communication, wherein the network communication is assigned a security policy.
- the analysis module further comprises an Ana ⁇ lyse worn for analyzing the network communication based on the data packet using at least one statistical function, for analyzing the network communication based on the data packet and / or the security policy cha ⁇ is character-.
- the analysis module additionally includes provisioning means for providing control information if the network communication connection has insufficient compliance with the security policy.
- the analysis module can also include a processor and / or a memory unit in order to control the individual devices.
- the analysis module is a dedicated network component in particular ⁇ sondere between a subscriber and other subscribers of a network that is the network communication, is maral ⁇ tet.
- the analysis module can also be Programmkompo- component in the operating system of a participant of Netztechnikkommu ⁇ communications.
- the analysis module can also be a program component in other network components of the network that serves the network communication, in particular a router or a switch.
- the analysis module can also be a plug-in for a software application, in particular a browser plug-in.
- the invention relates to a system which has an analysis mode according to the invention.
- a computer program product with program examples is claimed for carrying out said method according to the invention.
- a variant of the computer program product with program instructions for configuring a creation device for example a 3D printer or a similar device claimed, wherein the creation device with the program commands ⁇ is configured such that said inventive analysis module is created.
- a provision device for storing and / or providing the computer program product is claimed .
- the provisioning device is, for example, a data carrier which stores and / or makes available the computer program product.
- the provisioning device is, for example, a network service, a computer system, a server system, in particular a network server. partitioned computer system, a cloud-based computer system and / or virtual computer system which comprises Computerpro ⁇ program product preferably in the form of a data stream, stores and / or provides.
- This provision takes place, for example, as a download in the form of a program data block and / or command data block, preferably as a file, in particular as a download file, or as a data stream, in particular as a download data stream, of the complete computer program product.
- This provision for example, but also as a partial download SUC ⁇ gen, which consists of several parts, in particular through a peer-to-peer network downloaded or is provided as a data stream.
- Such a computer program product is read, for example, using the provision device in the form of the data carrier in a system and executes the program commands, so that the inventive method executed on a computer or the authoring device is configured such that it creates the analysis module according to the invention.
- FIG. 1 shows a flowchart of a first exemplary embodiment of the disclosed method
- FIG. 2 shows an implementation of a second among others;
- FIG. 3 shows an implementation of a third among others;
- Fig. 4 is an analysis module of a fourthheldsbei ⁇ game;
- 5 shows a system with an analysis module.
- FIG. 1 shows a flowchart of a first exemplary embodiment of the disclosed method.
- the method is a network communication in a position, for example a connection-oriented or verbin ⁇ dung-free communication of one or more participants of the network communication to check.
- the method is able to check whether the network communication per se or the network communication between subscribers corresponds to specifications of a security policy, for example whether the network communication is encrypted.
- the method comprises a first method step for detecting 110 a data packet of the network communication, wherein the network communication is assigned a security policy.
- the data packet can be, for example, an Ethernet frame which contains an IP packet as user data, whereby according to the security policy, for example, the IP packet or the payload of the IP packet should be encrypted.
- the IP packet may only include certain source and / or destination addresses and / or source and / or destination address ranges. This ⁇ be limited not only to the IP packet, similar Anforde ⁇ conclusions can provide the security policy to the MAC address in the Ethernet frame.
- the security policy can specify different parameters on different layers of the network communication alone and in combination.
- the method includes a second method step of analyzing network communication 120 of the data packet using at least one statistical radio ⁇ tion, wherein for analyzing the network communication based on the data packet and / or the security policy is characte ized ⁇ .
- the statistical function By means of the statistical function the statistical properties during Ana ⁇ lysing can be evaluated examples play as. For example, can using a chi-square test, a statistical function entschie ⁇ be the whether encryption is still intact or whether it was deliberate or accidental fourth deactivated by manipulation.
- a control information is provided 130.
- this control information is provided if the network ⁇ communication inadequate compliance with the security policy having.
- the method analyzes to determine whether a network communication is encrypted, the payload of the pa ⁇ kets. For this purpose, for example, a statistical distribution of the data bits of the user data is evaluated by means of the statistical function. If the user data is encrypted, the statistical distribution of the data bits should preferably be uniformly distributed - ie the data bits of the user data should correspond to a statistical distribution of a random bit sequence .
- the method can avoid the use of cryptographic keys. As a result, the method can be used flexibly and ensures high security of the encrypted network communication , since only the subscribers of the encrypted network communication must have the cryptographic keys.
- Encryption algorithms that do not have these properties are considered broken.
- the statistical function analyzes these statistical property accordingly, examples play by means of a chi-square tests to ⁇ by deciding depending as whether encryption is still intact or has been disabled by intentional or accidental manipulation. If the method is particularly notice a significant difference in the statistics, with On the other reindeer words, the network communication is insufficient in accordance with the security policy to, in such a case a predefined action could run ⁇ to where the action is, for example, with the Steuerinformati ⁇ on can be controlled.
- the control information or the pre-seen action for example, the transfer interrup ⁇ chen.
- the access to the data traffic through the process can take place within the communication path of the network communication within a network, for example by the imple mentation of the process as a separate ⁇ analysis module.
- the method can be realized, for example, by extending existing components.
- An example would be a router or switch that analyzes the data stream or packets on-the-fly. It is not necessarily important, the analysis in real time or in very much 1 b
- the method is characterized to preferably the compound and the corresponding de ⁇ security policy of the network communication.
- connection type of Netztechnikkom ⁇ munication can be identified by the following features depending on the communication path:
- a control information which controls a defined Ak ⁇ tion for example, triggering a termination of the compound or an alarm message can be provided.
- the method can be realized in particular in different ways as an analysis module.
- the analysis module can be used, for example, as
- the network station FGD be lome, for example in the Linux kernel
- a program component of a network device to be implemen ⁇ advantage for example in a router or a switch, or
- a plugin for software application implemented, for example as a browser plugin. It is also conceivable, for example, for an existing network component to be expanded by the analysis module by means of a program component. This can be done for example by means of a firmware update.
- the analysis module may include its own processor and / or memory for carrying out the method, or the processor and / or memory of the network device may be used to perform the method. If the method is implemented as a program component in the operating system or as a plug-in, the processor and / or memory used by the operating system or the plug-in can be used to execute the method.
- the step of analyzing or the analysis module ⁇ can observe, for example, different protocols or communications pro ⁇ layers of network communication. Depending on the application, different layers and / or protocol parts can be monitored for their encryption. For this example, the transport layer are lysed at ⁇ play, when TLS protocol, and / or the application ⁇ layer, for example, the HTTPS protocol, and / or the network layer, for example when IPsec protocol ana ⁇ .
- the verification of the statistical properties by means of the statistical function relates in particular to the encrypted part or the encrypted user data of the data packet which is transmitted with a specific protocol.
- a statistical function For example, several algorithms are available as a statistical function to preferably calculate a continuous statistic of transmitted data packets to determine if a network communication and thus the data packets and their payload are encrypted.
- the chi-square test can be used as a statistical function, which checks whether existing data ⁇ bits of the payload of the data packet are distributed in a certain way.
- the Kolmogorov-Smirnov test it is also possible to use the Kolmogorov-Smirnov test as a statistical function, which is based on
- Sampling checks whether a random variable follows in the form of the data ⁇ bits of the payload of the data packet to a probability distribution previously adopted.
- G-test a statistical function, which checks whether occurrence frequencies of data bits of the user data of the data packet have come about by chance.
- Security guideline pretends to encrypt these ver ⁇ send, different actions can be controlled by a control information.
- a multiplicity of reactions is conceivable which can be controlled individually or in combination by the control information.
- the connection between participants of the network communication can be disconnected, a visual and / or acoustic signal can be triggered and / or the change and / or the illegal match can be stored in a secure (protected) log file.
- FIG. 2 shows an implementation of a second embodiment of the disclosed method.
- FIG. 2 shows an analysis module 201 that plemented the above method in ⁇ .
- the analysis module 201 is above ⁇ preferably as a separate network component removable ⁇ det in this embodiment, but may be in a network component, beispielswei ⁇ se a router or a switch as hardware or program component to be integrated.
- the analysis module 201 is a computer-aided in a position before ⁇ preferably using a processor and / or SpeI ⁇ Chers to check a network communication and possibly with- means of a control information to enforce a security policy in the situation.
- the analysis module 201 comprises a capture device 210, an analysis device 220, a delivery device 230 and a security policy storage device 240.
- the detection device 210 detects a data packet of the network communication, wherein the network communication is assigned the security policy.
- detection device 210 is communicatively connected to a network by means of a first data line 205.
- the data packet is subsequently transmitted to the analysis device 220.
- the analysis means 220 analyzes the Netzwerkkommunika ⁇ tion on the basis of the data package using at least one statistical ⁇ tables function, for analyzing the network communication based on the data packet and / or the security directional ⁇ line, which is stored in the security policy storage device 240 and through the first bus 207 to the Analysis ⁇ means 220 communicatively connected, is characterized.
- the security policy can be transmitted via a second data line 206. line to be considered by the analyzer 220.
- the result of the analysis is provided via the first bus 207 of the providing device 230.
- the providing means 230 provides the basis of the analysis result ⁇ control information available in case the network ⁇ network communication has insufficient accordance with the security policy.
- the control information may be enthusiastsge ⁇ represents, for example via a third data line 255th
- the analysis module 201 can decide if the data packet of the Netztechnikkommu ⁇ munication is passed, if the network communication and the data packet network communication has sufficient accordance with the security policy on ⁇ after analysis. For this purpose, the data packet is inserted, for example, via a fourth data line 256 back into the communication path of the network communication.
- the data packet network communication a unzurei ⁇ -reaching compliance with the security policy, so it is also conceivable that the data packet is filtered out and transfer to subscribers of the network communication is inhibited.
- This filter function can also take over the direction Metellungsein- 230 or is provided an additional compo ⁇ nent this.
- the analysis module 201 is integrated into another or existing network component, for example a router, a switch or an access point.
- a data packet reception unit of the network ⁇ component to the functionality of the detector 210 is extended to the data packet to the analysis means 220 can be transmitted.
- the functionality of the Ready ⁇ provision means 230 and possibly the filter function can for example be integrated into a data packet transmission unit of the network ⁇ component.
- analyzing the data packets i. checking the network communication continuously, at predetermined times or at predetermined times for a predetermined time interval. If an analysis is carried out, then preferably all the data packets of the network communication are analyzed.
- the analysis module 201 is thus to check the network communication network capable by means of the Analy ⁇ Sierens of the data packet or multiple data packets, such as whether an encryption according to the security policy is before ⁇ hands.
- FIG. 3 shows an implementation of a third embodiment of the disclosed method.
- FIG. 3 shows an analysis module 301, the plemented the above method in ⁇ .
- the analysis module 301 is proposed in this embodiment preferably in a network component, such as a router or a switch, integrated as hardware or Programmkompo ⁇ component, but may also be configured as an independent network ⁇ component.
- the analysis module 301 is able, computer-aided, before ⁇ preferably using a processor and / or Spei ⁇ chers to check a network communication and possibly with ⁇ means of control information in a position to enforce a security policy.
- the analysis module 301 comprises a detection device 210, an analysis device 220, a provisioning device 230 and a security policy storage device 240.
- the operation of the detecting means 210, Analy ⁇ se healed 220, the deployment device 230 and the security policy storage device 240 corresponds to the remarks and explanations of the second exemplary embodiment of FIG. 2 and the variations indicated.
- the analysis module to a Auslei ⁇ processing device 310th This discharge device 310 is activated by the analysis device 220 in order to analyze data packets only on a random basis. This random extraction of data packets can also be carried out, for example, via a statistical function and / or randomly. If an inadequate compliance with the security policy is identified, the
- Provisioning device 230 provided control information and / or a filter function is turned on to filter out the corresponding data packet.
- the analysis module 301 is thus able to check by means of Ana ⁇ lysing of the data packet or multiple data packets, the network communication random sampling, for example, whether an encryption according to Secure ⁇ uniform policy is still present.
- FIG. 4 shows an implementation of a fourth embodiment of the disclosed method.
- FIG. 4 shows an analysis module 401, which plemented the above method in ⁇ .
- the analysis module 401 is in this embodiment, before ⁇ preferably an intrinsically stands network component, but may also be in a network component, such as a router or a switch as hardware or program component be inte- grated.
- the analysis module 401 is capable, with computer assistance, before ⁇ preferably using a processor and / or storage chers, to check a network communication and is possibly by means of a control information in a position to enforce a security policy.
- the analysis module 401 comprises a detection device 210, an analysis device 220, a supply device 230 and an interface 410, which communicatively communicate with each other via a second bus 480.
- Security policy can be placed in memory or in a security policy storage device.
- the detector 210 is capable of over
- Interface 410 to capture a data packet of the network communication, wherein the network communication is associated with the security policy.
- the data packet is then carry to the analysis device 220 via ⁇ .
- the analysis means 220 analyzes the network communication based on the data packet using at least one statistical tables ⁇ function, wherein the network communication for analyzing be taken into account on the basis of the data packet and / or the security ⁇ directional line.
- the result of the analysis is provided via the second bus 480 of the providing device 230.
- the providing means 230 provides the basis of the analysis result ⁇ control information available in case the network ⁇ network communication has insufficient accordance with the security policy.
- the control information can, for example, via the interface 410 a device in ⁇ example, a packet filter of a firewall or a
- the analysis module 401 is thus able to check the network communication by means of the analysis of the data packet or of several data packets, for example if a Encryption still exists according to the security policy.
- the analysis module 401 can also be part of a system beispiels- example of a network 510 be such as is provided in Fig. 5 ⁇ . 5 shows the network 510, for example an Ethernet network, an analysis module 401 which is connected to the network 510 via the interface 410, a first user of a network communication 530, a second user of the network communication 540, a third user of the network communication 550 and a network component 590, such as a switch.
- a network component 590 such as a switch.
- the first participant of a network communication 530, the second participant of a network communication 540, the third participant of a network communication 550, the analysis module 401 and the network component are communicatively connected via the network 510.
- the first subscriber is for example a workstation, for example an IBM compatible computer system, comprising a display device 532, for example a screen and several input devices, for example a computer mouse 533 and a keyboard 530.
- the second subscriber or third participant may also be a workstation act.
- the system may for example be part of a communication ⁇ infrastructure of a power plant and the participants field devices or meters of the power plant.
- Is Netzwerkkommunika ⁇ tion, for example, an unencrypted
- the Be ⁇ riding provision device 230 may provide control information over the interface 410 of the network component 590th
- the network component 590 can then, for example, prevent the network ⁇ factory communication between the participants to prevent data from being exchanged unencrypted between network communication subscribers.
- analysis module can also be designed as in the preceding exemplary embodiments and thus also integrated into the network component 590.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
L'invention concerne un procédé pour réaliser une vérification assistée par ordinateur d'une communication réseau. Le procédé comprend une étape consistant à détecter (110) un paquet de données de la communication réseau, une politique de sécurité étant associée à la communication réseau. Le procédé comprend une autre étape consistant à analyser (120) la communication réseau grâce au paquet de données au moyen d'au moins une fonction statistique, la communication réseau étant caractérisée grâce au paquet de données et/ou à la politique de sécurité pour permettre l'analyse. Le procédé comprend une autre étape consistant à fournir (130) des informations de commande dans le cas où la communication réseau présenterait une concordance insuffisante avec la politique de sécurité.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102016203534.7A DE102016203534A1 (de) | 2016-03-03 | 2016-03-03 | Verfahren und Analysemodul zur Überprüfung von verschlüsselten Datenübertragungen |
| DE102016203534.7 | 2016-03-03 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017148559A1 true WO2017148559A1 (fr) | 2017-09-08 |
Family
ID=57749929
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2016/082535 Ceased WO2017148559A1 (fr) | 2016-03-03 | 2016-12-23 | Procédé et module d'analyse pour vérifier des transmissions de données chiffrées |
Country Status (2)
| Country | Link |
|---|---|
| DE (1) | DE102016203534A1 (fr) |
| WO (1) | WO2017148559A1 (fr) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020069852A1 (fr) * | 2018-10-02 | 2020-04-09 | Continental Automotive Gmbh | Procédé de sécurisation d'un paquet de données par un centre de commutation dans un réseau, centre de commutation et véhicule automobile |
Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040196970A1 (en) * | 2003-04-01 | 2004-10-07 | Cole Eric B. | Methodology, system and computer readable medium for detecting file encryption |
| US20050166066A1 (en) * | 2004-01-22 | 2005-07-28 | Ratinder Paul Singh Ahuja | Cryptographic policy enforcement |
| US20070088845A1 (en) * | 2005-09-19 | 2007-04-19 | Nasir Memon | Effective policies and policy enforcement using characterization of flow content and content-independent flow information |
| EP2369810A1 (fr) * | 2010-03-16 | 2011-09-28 | Siemens Aktiengesellschaft | Procédé et système de protection d'un système de communication ou d'un réseau de communication |
| US8300811B2 (en) | 2008-12-10 | 2012-10-30 | Siemens Aktiengesellschaft | Method and device for processing data |
| US8531247B2 (en) | 2008-04-14 | 2013-09-10 | Siemens Aktiengesellschaft | Device and method for generating a random bit sequence |
| US8843761B2 (en) | 2007-08-16 | 2014-09-23 | Siemens Aktiengesellschaft | Method and apparatus for protection of a program against monitoring flow manipulation and against incorrect program running |
| US8892616B2 (en) | 2007-08-27 | 2014-11-18 | Siemens Aktiengesellschaft | Device and method for generating a random bit sequence |
| EP2870565A1 (fr) | 2012-09-28 | 2015-05-13 | Siemens Aktiengesellschaft | Test d'intégrité de données sur les propriétés d'un appareil par un appareil de test |
| EP2891102A1 (fr) | 2013-01-02 | 2015-07-08 | Siemens Aktiengesellschaft | Etiquette rfid et procédé permettant de faire fonctionner une étiquette rfid |
| US9147088B2 (en) | 2011-04-18 | 2015-09-29 | Siemens Aktiengesellschaft | Method for monitoring a tamper protection and monitoring system for a field device having tamper protection |
| EP2605445B1 (fr) | 2011-12-14 | 2015-09-30 | Siemens Aktiengesellschaft | Procédé et dispositif de sécurisation de chiffrement par blocs contre les attaques par templates |
-
2016
- 2016-03-03 DE DE102016203534.7A patent/DE102016203534A1/de not_active Withdrawn
- 2016-12-23 WO PCT/EP2016/082535 patent/WO2017148559A1/fr not_active Ceased
Patent Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040196970A1 (en) * | 2003-04-01 | 2004-10-07 | Cole Eric B. | Methodology, system and computer readable medium for detecting file encryption |
| US20050166066A1 (en) * | 2004-01-22 | 2005-07-28 | Ratinder Paul Singh Ahuja | Cryptographic policy enforcement |
| US20070088845A1 (en) * | 2005-09-19 | 2007-04-19 | Nasir Memon | Effective policies and policy enforcement using characterization of flow content and content-independent flow information |
| US8843761B2 (en) | 2007-08-16 | 2014-09-23 | Siemens Aktiengesellschaft | Method and apparatus for protection of a program against monitoring flow manipulation and against incorrect program running |
| US8892616B2 (en) | 2007-08-27 | 2014-11-18 | Siemens Aktiengesellschaft | Device and method for generating a random bit sequence |
| US8531247B2 (en) | 2008-04-14 | 2013-09-10 | Siemens Aktiengesellschaft | Device and method for generating a random bit sequence |
| US8300811B2 (en) | 2008-12-10 | 2012-10-30 | Siemens Aktiengesellschaft | Method and device for processing data |
| EP2369810A1 (fr) * | 2010-03-16 | 2011-09-28 | Siemens Aktiengesellschaft | Procédé et système de protection d'un système de communication ou d'un réseau de communication |
| US9147088B2 (en) | 2011-04-18 | 2015-09-29 | Siemens Aktiengesellschaft | Method for monitoring a tamper protection and monitoring system for a field device having tamper protection |
| EP2605445B1 (fr) | 2011-12-14 | 2015-09-30 | Siemens Aktiengesellschaft | Procédé et dispositif de sécurisation de chiffrement par blocs contre les attaques par templates |
| EP2870565A1 (fr) | 2012-09-28 | 2015-05-13 | Siemens Aktiengesellschaft | Test d'intégrité de données sur les propriétés d'un appareil par un appareil de test |
| EP2891102A1 (fr) | 2013-01-02 | 2015-07-08 | Siemens Aktiengesellschaft | Etiquette rfid et procédé permettant de faire fonctionner une étiquette rfid |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020069852A1 (fr) * | 2018-10-02 | 2020-04-09 | Continental Automotive Gmbh | Procédé de sécurisation d'un paquet de données par un centre de commutation dans un réseau, centre de commutation et véhicule automobile |
Also Published As
| Publication number | Publication date |
|---|---|
| DE102016203534A1 (de) | 2017-09-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3542511B1 (fr) | Processus pour un réseau de communication et unité de commande électronique | |
| DE102012109212B4 (de) | Methoden, Vorrichtung und Herstellungsprodukte zur Bereitstellung von Firewalls für Prozesssteuerungssysteme | |
| EP2448182B1 (fr) | Procédé de communication dans un système d'automatisation | |
| EP3192226B1 (fr) | Dispositif et procédé de commande d'un réseau de communication | |
| EP1494401B1 (fr) | Routeur et procédé d'activation d'un ordinateur désactivé | |
| EP3105898B1 (fr) | Procédé de communication entre des systèmes informatiques sécurisés et infrastructure de réseau informatique | |
| WO2017148559A1 (fr) | Procédé et module d'analyse pour vérifier des transmissions de données chiffrées | |
| WO2021197822A1 (fr) | Procédé pour traiter une anomalie de données, en particulier dans un véhicule automobile | |
| DE202015004439U1 (de) | Überwachungsvorrichtung und Netzwerkteilnehmer | |
| WO2018215209A1 (fr) | Procédé et dispositif de protection d'une communication entre au moins un premier dispositif de communication et au moins un deuxième dispositif de communication, en particulier dans un réseau de communication d'une production et/ou automatisation industrielle | |
| EP3813314B1 (fr) | Système de sécurisation et procédé de filtration d'un trafic des données | |
| EP4300883A1 (fr) | Adaptateur de réseau conçu pour prendre en charge un envoi et/ou une réception autorisés des données | |
| EP1473614A2 (fr) | Ordinateur pour un véhicle et procédé de contrôle des échanges de données associés | |
| DE102022107431B3 (de) | Verfahren zum Nachrüsten einer Socks-Kompatibilität für zumindest eine Anwendung in einem Kraftfahrzeug sowie entsprechend eingerichtetes Kraftfahrzeug | |
| EP2186285A1 (fr) | Procédé et dispositif d'authentification de données utiles transférées | |
| EP3603011B1 (fr) | Dispositifs et procédé de fonctionnement d'une communication mobile avec un dispositif côté trajet | |
| EP3382976A1 (fr) | Dispositif de protection, procédé et appareil comprenant un dispositif de protection destiné à protéger un réseau de communication connecté à l'appareil | |
| DE102016221496B4 (de) | Verfahren und vorrichtung zum betreiben eines fahrzeugbordnetzes, computerprogramm und computerprogrammprodukt | |
| EP4625886A1 (fr) | Contrôleur, réseau et transmission de données d'un contrôleur dans un réseau | |
| EP3248137A1 (fr) | Dispositif de commande électronique | |
| DE102015212037A1 (de) | Überwachen eines Übertragungsstreckenabschnitts zur Übertragung von Daten zwischen zwei Teilnehmern einer Kommunikationsverbindung | |
| DE102024106264A1 (de) | Verfahren zur Gewährleistung einer Kommunikation bei einem Fernzugriff auf eine Sicherheitsanlage mittels eines einem Bediener zugeordneten Bediengeräts und System, umfassend zumindest eine Sicherheitsanlage und wenigstens ein einem Bediener zugeordnetes Bediengerät, zur Kommunikation bei einem Fernzugriff auf die Sicherheitsanlage mittels des Bediengeräts | |
| DE102015116601A1 (de) | Verfahren zum Freischalten externer Computersysteme in einer Computernetz-Infrastruktur, verteiltes Rechnernetz mit einer solchen Computernetz-Infrastruktur sowie Computerprogramm-Produkt | |
| DE102013000147A1 (de) | Endgeräte-Chip mit Firewall | |
| WO2024235789A1 (fr) | Système de communication et véhicule |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16822681 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16822681 Country of ref document: EP Kind code of ref document: A1 |