Factory Control Emulation Using Behavioral Patterns for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware attacks on factory control systems are becoming sophisticated and can evade conventional IT and process control security solutions, posing a risk to factory operations by causing subtle changes that are difficult to detect.

Innovation Solution

A system and method that involves initiating a simulated process using an emulator and simulator to generate control signals and response data, which is then analyzed by a deep learning processor to compare with actual process data, identifying anomalous activity and initiating an alert protocol when malicious behavior is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional IT and process control security solutions are used, then basic security coverage is provided, but they cannot detect subtle changes caused by sophisticated malware attacks

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by creating simulated malware attack scenarios and training the deep learning model before actual malware attacks occur. The emulator generates control signals that mimic malware behavior, and the deep learning processor learns to recognize these patterns in advance, enabling precise detection when real attacks happen without requiring complex real-time analysis systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating virtual copies of malware attack patterns through the emulator. Instead of directly analyzing complex real malware, the system generates copied representations of malware control signals and behavioral patterns in a simulated environment, which the deep learning processor then uses for training and detection, simplifying the overall system while maintaining high detection precision.

Inventive Principle:
Principle #26Copying

2Measurement precision

If deep learning analysis is applied to detect malware behavior, then detection precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary training of the deep learning processor using emulator-generated data before actual malware detection is needed. This pre-training establishes baseline behavioral patterns and detection thresholds in advance, so that during actual operation, the system can quickly compare real process data against pre-established patterns without requiring extensive real-time computation, thus reducing processing time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system monitors all process data in real-time, then comprehensive security coverage is achieved, but system performance and productivity decrease

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanufacturing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the essential features and behavioral patterns from process data that are relevant to malware detection. The deep learning processor identifies and extracts key indicators of compromise from the control signals and process data, focusing analysis on specific anomalies rather than processing all data in detail, thus maintaining comprehensive security coverage while minimizing impact on manufacturing efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11669617B2Method, systems and apparatus for intelligently emulating factory control systems and simulating response data
Publication Date: 2023.06.06 NANOTRONICS IMAGING INC
  • US11669617B2 patent drawing
  • US11669617B2 patent drawing
  • US11669617B2 patent drawing

AI summary

A simulated process is initiated. The simulated process includes generating, by an emulator, a control signal based on external inputs. The simulated process further includes processing, by a simulator, the control signal to generate simulated response data. The simulated process further includes generating, by a deep learning processor, expected behavioral pattern data based on the simulated response data. An actual process is initiated by initializing setpoints for a process station in a manufacturing system. The actual process includes generating, by the deep learning processor, actual behavioral pattern data based on actual process data from the at least one process station. The deep learning processor compares the expected behavioral pattern to the actual behavioral pattern. Based on the comparing, the deep learning processor determines that anomalous activity is present in the manufacturing system. Based on the anomalous activity being present, the deep learning processor initiates an alert protocol.