Industrial Control Instruction Analysis Using Execution Probability Windows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial network behavior analysis methods are inadequate for complex control processes due to their reliance on pre-created trust lists, which are only applicable to simple processes with a limited number of control instructions, leading to poor applicability in securing OT networks from malicious attacks.
Innovation Solution
The method involves defining first and second time windows for industrial control systems to analyze control instructions, calculating execution probability deviations, and determining whether instructions are legal or suspicious based on these deviations, allowing for improved security analysis of both simple and complex control processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a pre-created trust list is used to store identification information of trusted control instructions, then it is easy to determine whether a control instruction is legal, but it is only applicable to simple control processes with a relatively small number of control instructions
Solution Approach 1:
The patent changes the fundamental parameter of control instruction validation from static trust list matching to dynamic execution probability analysis. By calculating execution probabilities based on historical data and comparing against threshold values, the system adapts to both simple and complex control processes without being limited by the number of control instructions
Solution Approach 2:
The patent creates a probabilistic model that copies the behavioral patterns of legitimate control instructions through historical execution data. Instead of storing actual control instructions in a trust list, it copies the statistical characteristics of their execution, allowing the system to recognize legitimate instructions through probability matching rather than exact pattern matching
2Reliability
If each control instruction is compared with the trust list to determine abnormal operation behaviors, then the security of simple control processes can be ensured, but the analysis method cannot handle complex control processes with large numbers of control instructions
Solution Approach 1:
The patent extracts the essential security validation function from the trust list approach and separates it from the limitation of storing and comparing individual control instructions. By extracting only the execution probability characteristic and validating against statistical thresholds rather than complete instruction patterns, the system maintains security while handling complex processes
Solution Approach 2:
The patent introduces dynamic execution probability calculations that adapt to varying control process complexities. Instead of static trust list comparisons, the system dynamically computes probabilities based on historical execution frequencies and adjusts validation thresholds accordingly, enabling effective security analysis across both simple and complex control processes
Data Source
AI summary
Various embodiments of the teachings herein include an industrial network behavior analysis method. The method may include: defining a first time window for a target industrial control system, for the target industrial control system to perform a control behavior; respectively determining an execution probability deviation for each control instruction within the first time window and using the execution probability to characterize the ratio of the number of times the corresponding control instruction is executed within a time period to the total number of times the control instruction within the time period; defining a second time window according to the control instruction characterizing a time period when the system performs the corresponding control behavior, and the control behavior is the same as that performed in the first time window. The method may include performing for each second time window: for each control instruction, calculating an execution probability; for each control instruction, determining whether the execution probability meets a target deviation, wherein the target execution probability deviation is the execution probability deviation of the control instruction in the first time window corresponding to the same in the second; determining that the control instruction is legal if the execution probability meets the target deviation; and determining that the instruction is suspicious if the execution probability of the control instruction does not.


