Controller Anomaly Detection Using Input-Output Signal Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) for control systems struggle to detect anomalies caused by attacks that rewrite program logic or firmware in controllers, such as PLCs and DCSs, making it difficult to identify improper operations.

Innovation Solution

An anomaly detection apparatus that learns the relationship between input and output signals of control systems using a neural network-based estimation model, comparing estimated output signals with actual signals to detect deviations and determine anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IDS monitors network packets to detect attacks, then network-based anomalies can be detected, but attacks that rewrite controller programs or firmware cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a state notification signal as an intermediary between the controller and the anomaly detection apparatus. This signal carries information about the controller's internal state (program execution status, firmware version, operational mode) and enables the detection apparatus to monitor controller behavior without directly accessing the controller's internal memory or program code, thus resolving the contradiction between maintaining detection capability and expanding detection scope to include firmware-level attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from monitoring only network communication packets (one dimension) to also monitoring the controller's internal state through state notification signals (another dimension). This multi-dimensional monitoring approach enables detection of attacks that modify controller behavior without generating anomalous network traffic, thereby expanding detection scope while maintaining reliability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If IDS focuses on network packet monitoring, then implementation is straightforward, but it cannot detect attacks that occur within the controller itself

Engineering Contradiction:
Improvesystem implementationVSAvoidanomaly detection accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the monitoring function into two parts: network packet monitoring (external behavior) and state notification signal monitoring (internal state). This segmentation allows the system to maintain the simplicity of network monitoring while adding controller-state monitoring to improve detection accuracy, resolving the contradiction between ease of implementation and detection reliability

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If traditional IDS learns normal network traffic patterns, then network anomalies can be detected, but deviations in controller operation caused by firmware rewriting remain undetected

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent makes the anomaly detection apparatus multi-functional by enabling it to detect both network-based anomalies (through packet monitoring) and controller-based anomalies (through state notification signal monitoring). This universality allows a single system to maintain high detection precision for network attacks while also covering controller firmware attacks, resolving the contradiction between precision and detection coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12050680B2Anomaly detection apparatus, anomaly detection method, and non-transitory storage medium
Publication Date: 2024.07.30 KK TOSHIBA
  • US12050680B2 patent drawing
  • US12050680B2 patent drawing
  • US12050680B2 patent drawing

AI summary

One embodiment of the present invention provides an apparatus, or the like, which detects an anomaly of a controller of a control system by learning relationship between input and output of the controller. An anomaly detection apparatus which is one embodiment of the present invention includes a first acquirer, a second acquirer, a history recorder, an estimator, and a first anomaly determiner. The first acquirer acquires an input signal to a control apparatus which executes control on a controlled apparatus. The second acquirer acquires an output signal from the control apparatus. The history recorder records information regarding the acquired input signal and the acquired output signal as history. The estimator estimates the output signal using the history and an estimation model. The first anomaly determiner determines an anomaly of the control apparatus by comparing the estimated output signal with the acquired output signal.