Data Analysis Device for Manufacturing Abnormality Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing manufacturing systems lack effective mechanisms to detect abnormalities without extensive modifications, and current attack detection devices are not capable of precise detection of failures or unauthorized activities within manufacturing networks.
Innovation Solution
A data analysis device that receives packets between manufacturing control devices and manufacturing devices, determines the type of data from IP addresses and port numbers, and identifies abnormalities by checking against predefined syntax or rules, allowing for real-time detection of system anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an attack detection device is introduced to detect abnormalities in manufacturing systems, then the security level and detection capability are improved, but the device complexity and system modification requirements increase
Solution Approach 1:
The patent introduces a data analysis device as an intermediary component that sits between the manufacturing control device and manufacturing devices. This mediator analyzes packet data flowing through the system without requiring modification of the core manufacturing control logic, thereby improving detection capability while minimizing system complexity changes
Solution Approach 2:
The data analysis device creates a copy of the packet data for analysis purposes. By analyzing copies of the data rather than intercepting or modifying original data flows, the system achieves detection capability without disrupting existing manufacturing control operations or requiring extensive system modifications
2Ease of operation
If attack detection is performed only from packet header information, then the ease of operation is improved, but the measurement precision of attack detection deteriorates
Solution Approach 1:
The patent segments the packet data analysis into multiple levels: header information analysis for quick filtering and basic detection, and payload information analysis for detailed verification. This segmentation allows the system to maintain operational simplicity through hierarchical processing while achieving high detection precision by examining relevant portions of packet data at appropriate depths
Solution Approach 2:
The system performs partial analysis of packet data by focusing on specific fields and portions of packets based on detection needs. Rather than analyzing every byte of every packet, the device selectively examines relevant header fields and payload sections, achieving sufficient detection precision with reduced computational overhead and maintained operational simplicity
3Measurement precision
If comprehensive packet analysis is performed to improve detection precision, then the measurement precision is improved, but the productivity and processing speed deteriorate
Solution Approach 1:
The data analysis device employs periodic analysis of packet data, where packets are sampled and analyzed at specific intervals rather than every single packet being fully analyzed. This periodic approach maintains detection precision for critical abnormalities while improving overall processing speed and system productivity by reducing the computational burden on the detection system
Solution Approach 2:
The system performs partial analysis on selected packets based on detection priorities and system state. High-priority packets or those showing anomaly indicators undergo comprehensive analysis, while normal packets receive lighter processing. This selective approach achieves necessary detection precision without sacrificing overall processing throughput and productivity
Data Source
AI summary
An abnormality in a manufacturing system is detected without extensive modification to the existing manufacturing systems. The data analysis device includes: a receiver configured to receive a packet transmitted between a manufacture control device and a manufacturing device; an analyzer configured to obtain the type of data included in a payload of the received packet from an IP address and a port number included in a header of the packet; a selector configured to select, based on the type of the data obtained by the analyzer, a syntax or rule corresponding to the type of the data; and a determiner configured to determine that the manufacturing system has an abnormality if the data included in the payload does not follow the syntax or rule corresponding to the type of the data.


