Cyber Defense Automation Engine for OT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems in operational technology (OT) environments face vulnerabilities due to gaps in network security systems, which can lead to undetected cyberattacks as hacking techniques evolve.

Innovation Solution

A cybersecurity simulator is used to create a virtual network security system within a virtual network, configured based on real network security system parameters, to simulate cyberattacks and identify undetected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network security system is deployed to monitor network activity in an OT environment, then security monitoring capability is improved, but undetected cyberattacks may occur due to gaps in the security system

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidundetected cyberattacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by deploying simulated cyberattacks against the virtual network security system before real attacks occur. The cyberattack engine generates and executes multiple simulated attacks in advance, allowing the system to identify detection gaps before they can be exploited by real adversaries.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the real network security system in the form of a virtual network security system. This virtual replica is configured with the same detection rules and parameters as the actual system, allowing safe testing and validation without affecting production security monitoring.

Inventive Principle:
Principle #26Copying

2Measurement precision

If simulated cyberattacks are deployed against a virtual network security system, then vulnerabilities can be identified, but the system complexity increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces an intermediary layer - the virtual network environment - that mediates between the cyberattack engine and the actual network security system. This intermediary allows complex attack simulations to be conducted without directly complicating the real security infrastructure, isolating complexity to the testing domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The testing system is segmented into distinct modular components: a cyberattack engine for generating attacks, a virtual network environment for isolation, and a virtual network security system for testing. This segmentation allows each component to be developed and maintained independently, managing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple simulated cyberattacks are executed to comprehensively test security rules, then detection coverage is improved, but the time and resources required for testing increase

Engineering Contradiction:
Improvedetection coverageVSAvoidtesting duration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements periodic action by executing simulated cyberattacks in repeated cycles against the virtual network security system. The cyberattack engine can run multiple attack scenarios systematically, allowing comprehensive detection coverage to be achieved through structured, periodic testing rather than continuous operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial action by focusing simulated attacks on specific detection rules and vulnerability types rather than attempting to test every possible scenario simultaneously. This allows comprehensive coverage of critical security gaps to be achieved in reasonable time by concentrating testing effort on the most important detection capabilities.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250039192A1Cyber defense automation engine
Publication Date: 2025.01.30 ROCKWELL AUTOMATION TECH INC
  • US20250039192A1 patent drawing
  • US20250039192A1 patent drawing
  • US20250039192A1 patent drawing

AI summary

A non-transitory computer readable medium stores instructions that, when executed by a processor, cause the processor to retrieve, from a catalog, a set of characteristics associated with a cyberattack, generate a plurality of packets having the set of cyberattack characteristics, wherein the plurality of packets collectively simulate the cyberattack, transmit the plurality of packets over a virtual operational technology (OT) network comprising a virtual network security system, and receive an alert indicating whether one or more of the plurality of packets was detected by the virtual network security system.