Industrial Control Network Behavior Modeling for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional industrial control systems are vulnerable to network attacks due to their increased connectivity, which can disrupt the control processes and compromise critical devices, necessitating effective network security monitoring methods to identify and respond to potential threats.

Innovation Solution

A network security monitoring method for industrial control systems that involves selecting relevant data sources, acquiring and analyzing time-varying features to establish a behavior model, and determining abnormal behavior based on this model, with optional alarm reporting and attack source positioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional industrial control systems are connected to external networks including the Internet, then the system can achieve better connectivity and communication capabilities, but the system becomes vulnerable to external network attacks that can tamper with control processes and compromise critical devices

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a behavior model as an intermediary layer between the networked industrial control system and external threats. The behavior model analyzes system behavior patterns and serves as a mediator to distinguish normal operations from malicious attacks, allowing the system to maintain network connectivity while protecting against vulnerabilities through intelligent behavior analysis rather than direct security filtering

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security monitoring is implemented to identify potential attacks, then the system can detect abnormal behaviors, but the monitoring may generate false alarms that reduce operational efficiency

Engineering Contradiction:
Improveattack detection accuracyVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by establishing a behavior model through offline learning from normal system operations before actual security monitoring begins. This pre-established model captures legitimate behavior patterns, enabling the system to accurately distinguish normal variations from actual attacks during operation, thereby reducing false alarms and maintaining high operational efficiency while ensuring reliable attack detection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3618354B1Industrial control system and network security monitoring method therefor
Publication Date: 2025.08.06 SIEMENS AG
  • EP3618354B1 patent drawingFigure 1A~1C
  • EP3618354B1 patent drawingFigure 2
  • EP3618354B1 patent drawingFigure 3~5

AI summary

The present invention relates to the technical field of industrial networks and information security, and in particular to an industrial control system and a network security monitoring method therefor, for effectively monitoring the network security of an industrial control system. The method comprises: selecting at least one first data source related to an industrial control system and acquiring first data therefrom; counting time-varying features of the first data to serve as a behavior model for the industrial control system; acquiring second data from some or all of the at least one first data source; and determining whether the second data has the features described by the behavior model, and if so, determining that the industrial control system exhibits normal behavior, and if not, determining that the industrial control system exhibits abnormal behavior. In consideration of the certainty of the behavior of the industrial control system, a system behavior model is obtained by means of counting. A judgement regarding an abnormal system behavior is made based on the relatively determined behavior model, so that the obtained determination result is more accurate.