Application Layer Intrusion Detection for Industrial Control Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to attacks and intrusions from third parties due to the lack of authentication mechanisms in communication protocols, making it difficult to detect and respond to such threats effectively.

Innovation Solution

A system and method for identifying application layer behavior in industrial control systems, which involves analyzing packets between master and slave devices to determine if the system is under attack by comparing current behavior to a normal behavior status list, allowing for detection of abnormalities even if they occur only at the application layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication mechanisms are added to communication protocols, then security against third-party attacks is improved, but device complexity and communication overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary intrusion detection system that monitors communication packets between master and slave devices. This mediator analyzes application layer behavior patterns and detects attacks without requiring modification of the existing communication protocols, thus improving security while avoiding the complexity of protocol changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of communication patterns during normal operation to establish baseline behavior profiles. By pre-characterizing normal application layer interactions, the system can quickly detect deviations indicating attacks without requiring complex real-time authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If intrusion detection mechanisms are implemented, then detection capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The intrusion detection system is segmented into distinct functional modules: packet capture module, protocol parsing module, behavior analysis module, and alarm generation module. This segmentation allows each component to perform a specific function efficiently, reducing overall system complexity while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection system operates as an intermediary that passively monitors communication traffic without interfering with normal master-slave operations. By using promiscuous mode network interfaces and analyzing copied packets, the system achieves detection capability without adding complexity to the control system's operational path.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If application layer behavior analysis is performed on all packets, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvebehavior detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial analysis by focusing only on the application layer portion of packets rather than analyzing entire packet structures. By extracting and analyzing only the relevant application data portions against established behavior profiles, the system achieves high detection accuracy while reducing processing time compared to full packet analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Behavior profiles are pre-computed during normal system operation, establishing baseline patterns of legitimate master-slave communication. This preliminary characterization allows the detection system to quickly compare incoming packets against known good behavior without performing complex real-time analysis, thus improving detection accuracy while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3493002B1System and method for identifying application layer behaviour
Publication Date: 2023.05.03 INSTITUTE FOR INFORMATION INDUSTRY
  • EP3493002B1 patent drawingFigure 1
  • EP3493002B1 patent drawingFigure 2
  • EP3493002B1 patent drawingFigure 3

AI summary

A system and method for identifying application layer behavior are disclosed. In order to detect intrusion into an industrial control system, the system and method determine a current status of application layer behavior of the industrial control system by analyzing a current packet which is propagated between a master device and a slave device in the industrial control system, and identify whether the current status of the application layer behavior is normal according to a normal behavior status list.