Abnormality Detection in Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to cyber threats, including insider attacks, due to the use of public operating systems and standard protocols, which can lead to malfunctions and physical disasters, and existing security products are ineffective in detecting internal infiltration paths.

Innovation Solution

An apparatus and method for detecting abnormality signs in control systems by collecting system, network, and security event information, analyzing correlations with a prescribed security policy to identify potential threats, including unauthorized access and resource overloads, and providing rapid response mechanisms for both external and internal attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security products are installed on edge area to perform guard security response, then external network attacks can be blocked, but internal infiltration paths and insider threats cannot be detected

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoiddetection coverage against diverse attack paths
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The detection system is divided into multiple independent modules: information collection module that gathers data from various sources, storage module for data retention, and abnormality detection module for analysis. This segmentation allows each module to specialize in specific functions while working together to detect both external and internal threats comprehensively

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary detection system positioned between the control systems and monitoring infrastructure. This intermediary collects information from multiple sources including control equipment, network equipment, security equipment, and server equipment, then analyzes correlations to detect abnormality signs that indicate insider threats or internal infiltration paths

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If public operating systems and standard protocols are used in industrial control systems, then system compatibility and ease of operation are improved, but security vulnerability to cyber threats increases

Engineering Contradiction:
Improvesystem compatibilityVSAvoidcyber threat vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously collects information from control equipment, network equipment, security equipment, and server equipment, then feeds this data back through the abnormality detection module which analyzes correlations with security policies. This feedback mechanism enables real-time detection of cyber threats while maintaining the use of standard public operating systems and protocols

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements preliminary security measures by establishing security policies before threats occur and using the abnormality detection module to proactively identify potential security breaches. The system collects and analyzes information in advance to detect abnormality signs indicating cyber threats before they can cause significant damage

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9130983B2Apparatus and method for detecting abnormality sign in control system
Publication Date: 2015.09.08 ELECTRONICS & TELECOMM RES INST
  • US9130983B2 patent drawing
  • US9130983B2 patent drawing
  • US9130983B2 patent drawing

AI summary

An apparatus for detecting an abnormality sign in a control system, the control system comprising control equipments, network equipments, security equipments or server equipments, the apparatus includes an information collection module configured to collect system information, network information, security event information or transaction information in interworking with a control equipments, network equipments, security equipments or server equipments. The apparatus includes storage module that stores the information collected by the information collection module. The apparatus includes an abnormality detection module configured to analyze a correlation between the collected information and a prescribed security policy to detect whether there is an abnormality sign in the control system.