Industrial Control Instruction Analysis Using Execution Probability Windows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial network behavior analysis methods are inadequate for complex control processes due to their reliance on pre-created trust lists, which are only applicable to simple processes with a limited number of control instructions, leading to poor applicability in securing OT networks from malicious attacks.

Innovation Solution

The method involves defining first and second time windows for industrial control systems to analyze control instructions, calculating execution probability deviations, and determining whether instructions are legal or suspicious based on these deviations, allowing for improved security analysis of both simple and complex control processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a pre-created trust list is used to store identification information of trusted control instructions, then it is easy to determine whether a control instruction is legal, but it is only applicable to simple control processes with a relatively small number of control instructions

Engineering Contradiction:
Improveease of determining legal control instructionsVSAvoidapplicability to complex control processes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent changes the fundamental parameter of control instruction validation from static trust list matching to dynamic execution probability analysis. By calculating execution probabilities based on historical data and comparing against threshold values, the system adapts to both simple and complex control processes without being limited by the number of control instructions

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a probabilistic model that copies the behavioral patterns of legitimate control instructions through historical execution data. Instead of storing actual control instructions in a trust list, it copies the statistical characteristics of their execution, allowing the system to recognize legitimate instructions through probability matching rather than exact pattern matching

Inventive Principle:
Principle #26Copying

2Reliability

If each control instruction is compared with the trust list to determine abnormal operation behaviors, then the security of simple control processes can be ensured, but the analysis method cannot handle complex control processes with large numbers of control instructions

Engineering Contradiction:
Improvesecurity of control processesVSAvoidcomplexity of control processes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security validation function from the trust list approach and separates it from the limitation of storing and comparing individual control instructions. By extracting only the execution probability characteristic and validating against statistical thresholds rather than complete instruction patterns, the system maintains security while handling complex processes

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces dynamic execution probability calculations that adapt to varying control process complexities. Instead of static trust list comparisons, the system dynamically computes probabilities based on historical execution frequencies and adjusts validation thresholds accordingly, enabling effective security analysis across both simple and complex control processes

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11829122B2Industrial network behavior analysis method, apparatus and system, and computer-readable medium
Publication Date: 2023.11.28 SIEMENS AG
  • US11829122B2 patent drawing
  • US11829122B2 patent drawing
  • US11829122B2 patent drawing

AI summary

Various embodiments of the teachings herein include an industrial network behavior analysis method. The method may include: defining a first time window for a target industrial control system, for the target industrial control system to perform a control behavior; respectively determining an execution probability deviation for each control instruction within the first time window and using the execution probability to characterize the ratio of the number of times the corresponding control instruction is executed within a time period to the total number of times the control instruction within the time period; defining a second time window according to the control instruction characterizing a time period when the system performs the corresponding control behavior, and the control behavior is the same as that performed in the first time window. The method may include performing for each second time window: for each control instruction, calculating an execution probability; for each control instruction, determining whether the execution probability meets a target deviation, wherein the target execution probability deviation is the execution probability deviation of the control instruction in the first time window corresponding to the same in the second; determining that the control instruction is legal if the execution probability meets the target deviation; and determining that the instruction is suspicious if the execution probability of the control instruction does not.