Factory Control Emulation Using Behavioral Pattern Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware attacks on factory control systems are becoming sophisticated and can evade conventional IT security solutions, posing a risk to the operation of physical equipment and processes by causing subtle changes that are difficult to detect.

Innovation Solution

A system and method that involves initiating a simulated process using an emulator and simulator to generate control signals and response data, which is then analyzed by a deep learning processor to compare with actual process data, detecting anomalous activity and initiating an alert protocol when malicious behavior is identified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IT security solutions are used to protect factory control systems, then basic security coverage is provided, but sophisticated malware attacks can evade detection and cause subtle undetected changes

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of the factory control system environment using emulators that replicate PLCs, HMI interfaces, and control logic. This virtual environment allows security analysis without affecting the actual production system, enabling detection of sophisticated malware while maintaining system reliability through behavioral comparison between virtual and real system responses

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary analysis layer that sits between the control system and security monitoring. This intermediary captures control signals, processes them through emulated environments, and compares behavioral patterns to detect anomalies. The intermediary enables deep inspection of malware behavior without direct interference with the actual control system operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deep learning analysis is applied to detect malware behavior, then detection precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-training deep learning models with extensive malware behavior data and establishing baseline behavioral patterns for normal operations. The system pre-processes control signals into standardized formats and pre-configures comparison algorithms. This preliminary preparation enables rapid real-time detection without requiring complex computations during actual security monitoring, thus reducing processing time while maintaining high precision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the analysis process into distinct stages: signal capture, emulation processing, behavioral pattern extraction, and anomaly comparison. Each segment handles specific tasks with optimized algorithms. The segmentation allows parallel processing of multiple control signals and enables the system to focus computational resources only on suspicious patterns, reducing overall processing time while maintaining detection precision

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11947671B2Method, systems and apparatus for intelligently emulating factory control systems and simulating response data
Publication Date: 2024.04.02 NANOTRONICS IMAGING INC
  • US11947671B2 patent drawing
  • US11947671B2 patent drawing
  • US11947671B2 patent drawing

AI summary

A simulated process is initiated. The simulated process includes generating, by an emulator, a control signal based on external inputs. The simulated process further includes processing, by a simulator, the control signal to generate simulated response data. The simulated process further includes generating, by a deep learning processor, expected behavioral pattern data based on the simulated response data. An actual process is initiated by initializing setpoints for a process station in a manufacturing system. The actual process includes generating, by the deep learning processor, actual behavioral pattern data based on actual process data from the at least one process station. The deep learning processor compares the expected behavioral pattern to the actual behavioral pattern. Based on the comparing, the deep learning processor determines that anomalous activity is present in the manufacturing system. Based on the anomalous activity being present, the deep learning processor initiates an alert protocol.