Cyber Defense Automation Engine for OT Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems in operational technology (OT) environments face vulnerabilities due to gaps in network security systems, which can lead to undetected cyberattacks as hacking techniques evolve.
Innovation Solution
A cybersecurity simulator is used to create a virtual network security system within a virtual network, configured based on real network security system parameters, to simulate cyberattacks and identify undetected threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a network security system is deployed to monitor network activity in an OT environment, then security monitoring capability is improved, but undetected cyberattacks may occur due to gaps in the security system
Solution Approach 1:
The system performs preliminary actions by deploying simulated cyberattacks against the virtual network security system before real attacks occur. The cyberattack engine generates and executes multiple simulated attacks in advance, allowing the system to identify detection gaps before they can be exploited by real adversaries.
Solution Approach 2:
The system creates a copy of the real network security system in the form of a virtual network security system. This virtual replica is configured with the same detection rules and parameters as the actual system, allowing safe testing and validation without affecting production security monitoring.
2Measurement precision
If simulated cyberattacks are deployed against a virtual network security system, then vulnerabilities can be identified, but the system complexity increases
Solution Approach 1:
The system introduces an intermediary layer - the virtual network environment - that mediates between the cyberattack engine and the actual network security system. This intermediary allows complex attack simulations to be conducted without directly complicating the real security infrastructure, isolating complexity to the testing domain.
Solution Approach 2:
The testing system is segmented into distinct modular components: a cyberattack engine for generating attacks, a virtual network environment for isolation, and a virtual network security system for testing. This segmentation allows each component to be developed and maintained independently, managing overall system complexity.
3Adaptability or versatility
If multiple simulated cyberattacks are executed to comprehensively test security rules, then detection coverage is improved, but the time and resources required for testing increase
Solution Approach 1:
The system implements periodic action by executing simulated cyberattacks in repeated cycles against the virtual network security system. The cyberattack engine can run multiple attack scenarios systematically, allowing comprehensive detection coverage to be achieved through structured, periodic testing rather than continuous operation.
Solution Approach 2:
The system applies partial action by focusing simulated attacks on specific detection rules and vulnerability types rather than attempting to test every possible scenario simultaneously. This allows comprehensive coverage of critical security gaps to be achieved in reasonable time by concentrating testing effort on the most important detection capabilities.
Data Source
AI summary
A non-transitory computer readable medium stores instructions that, when executed by a processor, cause the processor to retrieve, from a catalog, a set of characteristics associated with a cyberattack, generate a plurality of packets having the set of cyberattack characteristics, wherein the plurality of packets collectively simulate the cyberattack, transmit the plurality of packets over a virtual operational technology (OT) network comprising a virtual network security system, and receive an alert indicating whether one or more of the plurality of packets was detected by the virtual network security system.


