Factory Control Signal Correlation for Malware-Tampered Processes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Factory processes and automated systems are vulnerable to malware attacks that can disrupt operations by altering control signals and providing false feedback, leading to equipment damage and yield reduction, with existing IT security solutions often failing to detect these subtle changes effectively.
Innovation Solution
A deep learning processor is trained on input operating instructions and output control signals to detect anomalies by correlating expected and actual values, providing an indication of anomalous activity before damage occurs, using a training dataset that includes input instructions, output signals, and measured control values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep learning processor is trained to correlate input operating instructions with output control signals, then detection precision of anomalous activity is improved, but device complexity increases
Solution Approach 1:
The deep learning processor is trained in advance using a training dataset containing input operating instructions and corresponding output control signals. This preliminary training establishes expected correlations between inputs and outputs, enabling the system to detect anomalies without requiring complex real-time analysis mechanisms during operation.
Solution Approach 2:
The deep learning processor acts as an intermediary component that correlates input operating instructions with output control signals. Rather than directly monitoring equipment parameters, the system uses this intermediate correlation layer to detect deviations indicating malware activity, simplifying the overall detection architecture.
2Reliability
If deep learning processor monitors multiple data types including control values, then reliability of anomaly detection is improved, but use of energy increases
Solution Approach 1:
The system monitors a selected set of control values rather than all possible parameters. The deep learning processor is trained to correlate specific input-output pairs and monitor corresponding control values, performing partial monitoring that achieves sufficient reliability without the excessive energy consumption of comprehensive monitoring.
3Ease of operation
If signal splitters are used to distribute input instructions and output signals, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The system uses signal splitters to divide input operating instructions and output control signals into separate pathways. One pathway directs signals to the deep learning processor for correlation analysis, while another pathway maintains normal control flow. This segmentation simplifies the integration of security monitoring without disrupting existing factory operations.
Data Source
AI summary
A training set that includes at least two data types corresponding to operations and control of a manufacturing process is obtained. A deep learning processor is trained to predict expected characteristics of output control signals that correspond with one or more corresponding input operating instructions. A first input operating instruction is received from a first signal splitter. A first output control signal is received from a second signal splitter. The deep learning processor correlates the first input operating instruction and the first output control signal. Based on the correlating, the deep learning processor determines that the first output control signal is not within a range of expected values based on the first input operating instruction. Responsive to the determining, an indication of an anomalous activity is provided as a result of detection of the anomalous activity in the manufacturing process.


