Attack Detection Device Using State Estimation and White Lists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion attack detection systems require a status notification function, necessitating facility renovations and complicating their integration into existing control systems.

Innovation Solution

An attack detection device that estimates the system state from communication data, using a white list storage unit to correlate permitted communications for each system state, allowing for attack detection without the need for a status notification function.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a status notification function is incorporated in existing facilities to enable attack detection, then attack detection capability is improved, but device complexity and ease of operation deteriorate due to facility renovation requirements

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfacility renovation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an attack detection device as an intermediary component that sits between the existing control system and the network. This device independently performs state estimation from communication data and attack detection, without requiring modifications to existing facilities. The intermediary device bridges the gap between existing infrastructure and advanced attack detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The attack detection device performs self-service by autonomously estimating system state from intercepted communication data and conducting attack detection independently. It does not rely on status notification packets from the control system or require configuration changes in existing facilities, making it plug-and-play ready.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If status notification packets are transmitted from server device or controller to enable attack detection, then attack detection accuracy is improved, but ease of operation worsens due to additional function incorporation

Engineering Contradiction:
Improvesystem state detection accuracyVSAvoidsystem operation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent replaces the mechanical approach of transmitting status notification packets with an information-theoretic approach. The attack detection device estimates system state by analyzing patterns in communication data (operation amounts and observation amounts) without requiring explicit state notification mechanisms. This substitution eliminates the need for additional transmission functions while maintaining detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The attack detection device acts as an intermediary that passively observes communication data to infer system state, rather than relying on active status notification from the control system. This intermediary approach maintains measurement precision while preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If white list is defined for each system state to improve attack detection accuracy, then attack detection capability is improved, but device complexity increases due to state management requirements

Engineering Contradiction:
Improveattack detection accuracyVSAvoidstate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic white list management where the applicable white list automatically changes based on the estimated system state. As the system transitions between states (e.g., from operation state A to operation state B), the attack detection device dynamically switches between corresponding white lists. This dynamic approach maintains high attack detection accuracy while managing complexity through automated state-driven selection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Multiple white lists for different system states are pre-configured and stored in the attack detection device before deployment. When the system operates, the device simply selects the appropriate pre-prepared white list based on the current estimated state, eliminating the need for real-time white list creation or complex state management during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3547190B1Attack detection device, attack detection method, and attack detection program
Publication Date: 2020.12.23 MITSUBISHI ELECTRIC CORP
  • EP3547190B1 patent drawingFigure 1
  • EP3547190B1 patent drawingFigure 2
  • EP3547190B1 patent drawingFigure 3

AI summary

In an attack detection device (200), a white list storage unit (242) correlates and stores, for each system state, a white list (209) defining system information permitted in the system state. A state estimation unit (210) estimates a current system state of a control system (700) on the basis of communication data (601) communicated between a server device (300) and equipment (400). An attack determination unit (220) acquires the white list (209) corresponding to the current system state from the white list storage unit (242), and determines whether or not an attack has been detected, on the basis of the acquired white list (209) and the system information in the current system state.