Controller Anomaly Detection Using Input-Output Signal Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems (IDS) for control systems struggle to detect anomalies caused by attacks that rewrite program logic or firmware in controllers, such as PLCs and DCSs, making it difficult to identify improper operations.
Innovation Solution
An anomaly detection apparatus that learns the relationship between input and output signals of control systems using a neural network-based estimation model, comparing estimated output signals with actual signals to detect deviations and determine anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IDS monitors network packets to detect attacks, then network-based anomalies can be detected, but attacks that rewrite controller programs or firmware cannot be detected
Solution Approach 1:
The patent introduces a state notification signal as an intermediary between the controller and the anomaly detection apparatus. This signal carries information about the controller's internal state (program execution status, firmware version, operational mode) and enables the detection apparatus to monitor controller behavior without directly accessing the controller's internal memory or program code, thus resolving the contradiction between maintaining detection capability and expanding detection scope to include firmware-level attacks
Solution Approach 2:
The patent transitions from monitoring only network communication packets (one dimension) to also monitoring the controller's internal state through state notification signals (another dimension). This multi-dimensional monitoring approach enables detection of attacks that modify controller behavior without generating anomalous network traffic, thereby expanding detection scope while maintaining reliability
2Ease of manufacture
If IDS focuses on network packet monitoring, then implementation is straightforward, but it cannot detect attacks that occur within the controller itself
Solution Approach 1:
The patent segments the monitoring function into two parts: network packet monitoring (external behavior) and state notification signal monitoring (internal state). This segmentation allows the system to maintain the simplicity of network monitoring while adding controller-state monitoring to improve detection accuracy, resolving the contradiction between ease of implementation and detection reliability
3Measurement precision
If traditional IDS learns normal network traffic patterns, then network anomalies can be detected, but deviations in controller operation caused by firmware rewriting remain undetected
Solution Approach 1:
The patent makes the anomaly detection apparatus multi-functional by enabling it to detect both network-based anomalies (through packet monitoring) and controller-based anomalies (through state notification signal monitoring). This universality allows a single system to maintain high detection precision for network attacks while also covering controller firmware attacks, resolving the contradiction between precision and detection coverage
Data Source
AI summary
One embodiment of the present invention provides an apparatus, or the like, which detects an anomaly of a controller of a control system by learning relationship between input and output of the controller. An anomaly detection apparatus which is one embodiment of the present invention includes a first acquirer, a second acquirer, a history recorder, an estimator, and a first anomaly determiner. The first acquirer acquires an input signal to a control apparatus which executes control on a controlled apparatus. The second acquirer acquires an output signal from the control apparatus. The history recorder records information regarding the acquired input signal and the acquired output signal as history. The estimator estimates the output signal using the history and an estimation model. The first anomaly determiner determines an anomaly of the control apparatus by comparing the estimated output signal with the acquired output signal.


