US 11,856,012 B2
Passive physical layer distinct native attribute cyber security monitor
Christopher M. Rondeau, Kettering, OH (US); Michael A. Temple, Huber Heights, OH (US); Juan Lopez, Jr., Loudon, TN (US); and J. Addison Betances, Beavercreek, OH (US)
Assigned to United States of America as represented by the Secretary of the Air Force, Wright-Patterson AFB, OH (US)
Filed by Government of the United States, as represented by the Secretary of the Air Force, Wright-Patterson AFB, OH (US)
Filed on Feb. 7, 2023, as Appl. No. 18/106,533.
Application 18/106,533 is a continuation of application No. 16/886,874, filed on May 29, 2020, abandoned.
Claims priority of provisional application 63/031,132, filed on May 28, 2020.
Claims priority of provisional application 62/856,784, filed on Jun. 4, 2019.
Prior Publication US 2023/0179610 A1, Jun. 8, 2023
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 63/0869 (2013.01); H04L 63/145 (2013.01)] 19 Claims
OG exemplary drawing
 
1. A cyber security monitor comprising:
a receiver having a network interface that is input-only configured to surreptitiously and covertly receive bit-level, physical layer communication between networked field devices comprising at least one field device control element and one or more field device sensors within a network;
a memory containing one or more distinct native attribute (DNA) fingerprinting methods for detecting one or more of remote access attacks (RAA) and physical access attack (PAA) of the networked field devices;
an external security engine interface communicatively coupled for input and output with an external security engine;
a controller that is communicatively coupled to the receiver, the memory, and the external security engine interface, and which:
receives, via the receiver, respective transmissions from the networked field devices;
generates a DNA fingerprint for each networked field device using the one or more DNA fingerprint methods; and
transmits an alert, via the external security engine interface, to the external security engine indicating a detected at least one of RAA and PAA based on a change in the DNA fingerprint of one or more networked field devices.