Cybersecurity with edge computing

US11399038B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11399038-B2
Application numberUS-201916675493-A
CountryUS
Kind codeB2
Filing dateNov 6, 2019
Priority dateNov 6, 2018
Publication dateJul 26, 2022
Grant dateJul 26, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosure provides for a two-stage method for analyzing data from an oil and gas field operation site for cyber threats. The method includes, in a first stage of analysis, filtering captured events using local edge computing at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data. The method includes transmitting the filtered data to a second stage of analysis and, in the second stage of analysis, analyzing the filtered data in a cloud by applying system context and referring vulnerability databases. The disclosure provides for a system for analyzing data, including an edge computing device that includes computer instructions to filter captured events to perform initial cyber anomaly detection, forming filtered data. The system includes a cloud-based ML cluster to implement a second stage of analysis to analyze the filtered.

First claim

Opening claim text (preview).

What is claimed is: 1. A two-stage method for analyzing data from an oil and gas field operation site for cyber threats, the method comprising: in a first stage of analysis, filtering captured events using local edge computing at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data; transmitting the filtered data to a second stage of analysis; and in the second stage of analysis, analyzing the filtered data in a cloud by applying system context and referring to vulnerability databases. 2. The method of claim 1 , wherein, in the first stage of analysis, edge analytics, resident on dedicated hardware or available devices, are used to analyze the captured events. 3. The method of claim 1 , wherein the first stage of analysis is capable of detecting highly critical events. 4. The method of claim 1 , wherein computational capabilities of the first stage of analysis exhibit local survivability in the case of network failures to the cloud. 5. The method of claim 1 , wherein the filtering of the captured events using local edge computing forms local alerts at the site. 6. The method of claim 1 , wherein the filtered data is transmitted to the second stage in combination with external intelligence. 7. The method of claim 1 , wherein the filtered data, and optionally external intelligence, includes only cyber threat events of interest. 8. The method of claim 1 , further comprising, in the second stage of analysis, forming alerts of cyber threats based on the second stage of analysis. 9. The method of claim 1 , wherein, in the second stage of analysis, global scale anomaly detection is performed based on the filtered data. 10. The method of claim 1 , wherein, in the second stage of analysis, the flirted data is analyzed using cloud analytics that is performed on servers. 11. The method of claim 1 , wherein the second stage of analysis is capable of detecting all potential security threats. 12. The method of claim 1 , wherein the captured events are transmitted from physical processes at the site to the first stage of analysis. 13. The method of claim 12 , wherein the captured events include data from include programmed logic controllers and human machine interfaces. 14. The method of claim 1 , wherein the filtered data is transmitted from to the second stage of analysis via a gateway and communications equipment. 15. The method of claim 1 , wherein the analysis of the filtered data in the second stage of analysis is performed using cloud-based ML clusters. 16. The method of claim 1 , wherein alerts are formed based on the second stage of analysis. 17. The method of claim 16 , wherein the alerts are transmitted to a security operations center. 18. A cyber threat analysis system for analyzing data from an oil and gas field operation site for cyber threats, the system comprising: an edge computing device, the edge computing device including computer instructions to implement a first stage of analysis to filter captured events at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data; a cloud-based ML cluster, the cloud-based ML cluster including computer instructions to implement a second stage of analysis to analyze the filtered data by applying system context and referring to vulnerability databases. 19. The system of claim 18 , wherein, in the first stage of analysis, edge analytics, resident on the edge computing device, are used to analyze the captured events. 20. The system of claim 18 , wherein the first stage of analysis is capable of detecting highly critical events.

Assignees

Inventors

Classifications

  • G06N20/00Primary

    Machine learning · CPC title

  • Vulnerability analysis · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Inference or reasoning models · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11399038B2 cover?
The disclosure provides for a two-stage method for analyzing data from an oil and gas field operation site for cyber threats. The method includes, in a first stage of analysis, filtering captured events using local edge computing at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data. The method includes transmittin…
Who is the assignee on this patent?
Schlumberger Technology Corp
What technology area does this patent fall under?
Primary CPC classification G06N20/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 26 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).