Industrial Control Network Behavior Modeling for Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional industrial control systems are vulnerable to network attacks due to their increased connectivity, which can disrupt the control processes and compromise critical devices, necessitating effective network security monitoring methods to identify and respond to potential threats.
Innovation Solution
A network security monitoring method for industrial control systems that involves selecting relevant data sources, acquiring and analyzing time-varying features to establish a behavior model, and determining abnormal behavior based on this model, with optional alarm reporting and attack source positioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional industrial control systems are connected to external networks including the Internet, then the system can achieve better connectivity and communication capabilities, but the system becomes vulnerable to external network attacks that can tamper with control processes and compromise critical devices
Solution Approach 1:
The patent introduces a behavior model as an intermediary layer between the networked industrial control system and external threats. The behavior model analyzes system behavior patterns and serves as a mediator to distinguish normal operations from malicious attacks, allowing the system to maintain network connectivity while protecting against vulnerabilities through intelligent behavior analysis rather than direct security filtering
2Reliability
If network security monitoring is implemented to identify potential attacks, then the system can detect abnormal behaviors, but the monitoring may generate false alarms that reduce operational efficiency
Solution Approach 1:
The patent applies preliminary action by establishing a behavior model through offline learning from normal system operations before actual security monitoring begins. This pre-established model captures legitimate behavior patterns, enabling the system to accurately distinguish normal variations from actual attacks during operation, thereby reducing false alarms and maintaining high operational efficiency while ensuring reliable attack detection
Data Source
Figure 1A~1C
Figure 2
Figure 3~5
AI summary
The present invention relates to the technical field of industrial networks and information security, and in particular to an industrial control system and a network security monitoring method therefor, for effectively monitoring the network security of an industrial control system. The method comprises: selecting at least one first data source related to an industrial control system and acquiring first data therefrom; counting time-varying features of the first data to serve as a behavior model for the industrial control system; acquiring second data from some or all of the at least one first data source; and determining whether the second data has the features described by the behavior model, and if so, determining that the industrial control system exhibits normal behavior, and if not, determining that the industrial control system exhibits abnormal behavior. In consideration of the certainty of the behavior of the industrial control system, a system behavior model is obtained by means of counting. A judgement regarding an abnormal system behavior is made based on the relatively determined behavior model, so that the obtained determination result is more accurate.