Attack Detection Device Using State Estimation and White Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion attack detection systems require a status notification function, necessitating facility renovations and complicating their integration into existing control systems.
Innovation Solution
An attack detection device that estimates the system state from communication data, using a white list storage unit to correlate permitted communications for each system state, allowing for attack detection without the need for a status notification function.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a status notification function is incorporated in existing facilities to enable attack detection, then attack detection capability is improved, but device complexity and ease of operation deteriorate due to facility renovation requirements
Solution Approach 1:
The patent introduces an attack detection device as an intermediary component that sits between the existing control system and the network. This device independently performs state estimation from communication data and attack detection, without requiring modifications to existing facilities. The intermediary device bridges the gap between existing infrastructure and advanced attack detection capabilities.
Solution Approach 2:
The attack detection device performs self-service by autonomously estimating system state from intercepted communication data and conducting attack detection independently. It does not rely on status notification packets from the control system or require configuration changes in existing facilities, making it plug-and-play ready.
2Measurement precision
If status notification packets are transmitted from server device or controller to enable attack detection, then attack detection accuracy is improved, but ease of operation worsens due to additional function incorporation
Solution Approach 1:
The patent replaces the mechanical approach of transmitting status notification packets with an information-theoretic approach. The attack detection device estimates system state by analyzing patterns in communication data (operation amounts and observation amounts) without requiring explicit state notification mechanisms. This substitution eliminates the need for additional transmission functions while maintaining detection accuracy.
Solution Approach 2:
The attack detection device acts as an intermediary that passively observes communication data to infer system state, rather than relying on active status notification from the control system. This intermediary approach maintains measurement precision while preserving ease of operation.
3Reliability
If white list is defined for each system state to improve attack detection accuracy, then attack detection capability is improved, but device complexity increases due to state management requirements
Solution Approach 1:
The patent implements dynamic white list management where the applicable white list automatically changes based on the estimated system state. As the system transitions between states (e.g., from operation state A to operation state B), the attack detection device dynamically switches between corresponding white lists. This dynamic approach maintains high attack detection accuracy while managing complexity through automated state-driven selection.
Solution Approach 2:
Multiple white lists for different system states are pre-configured and stored in the attack detection device before deployment. When the system operates, the device simply selects the appropriate pre-prepared white list based on the current estimated state, eliminating the need for real-time white list creation or complex state management during operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In an attack detection device (200), a white list storage unit (242) correlates and stores, for each system state, a white list (209) defining system information permitted in the system state. A state estimation unit (210) estimates a current system state of a control system (700) on the basis of communication data (601) communicated between a server device (300) and equipment (400). An attack determination unit (220) acquires the white list (209) corresponding to the current system state from the white list storage unit (242), and determines whether or not an attack has been detected, on the basis of the acquired white list (209) and the system information in the current system state.