Data Processing Device for Industrial Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial control network environments, the high bandwidth required for transmitting large network data streams poses a challenge, necessitating a method to reduce data transmission and alleviate bandwidth pressure by identifying and simplifying known data while processing unknown data alone.

Innovation Solution

A data processing device and method that collects network data, divides it into known and unknown attack data, and uses a mapping database to replace portions of unknown attack data with identification codes, reducing the data sent to a central network security monitoring center, thereby improving security analysis speed and accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network data streams are transmitted to the central monitoring center, then complete security analysis can be performed, but bandwidth requirements become excessively high

Engineering Contradiction:
Improvesecurity analysis completenessVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and processes data locally at the edge device before transmission. The edge device performs preliminary security analysis, filters known attack patterns, and only transmits relevant or unknown data to the central monitoring center, thereby reducing transmission volume while maintaining analysis effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the data processing function into two parts: local preprocessing at the edge device and central analysis at the monitoring center. This segmentation allows bandwidth-intensive processing to occur locally, reducing the amount of data that needs to be transmitted over the network

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If data is compressed or simplified before transmission, then bandwidth pressure is reduced, but data analysis accuracy may be compromised

Engineering Contradiction:
Improvedata transmission volumeVSAvoidsecurity analysis accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by establishing a mapping database locally at the edge device before transmission. This database contains identification codes for known attack patterns, allowing the system to quickly recognize and encode common threats without transmitting the actual large-volume raw data, thus maintaining accuracy while reducing bandwidth usage

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If a mapping database is used to replace data with identification codes, then data transmission is reduced, but system complexity increases

Engineering Contradiction:
Improvedata transmission volumeVSAvoiddata processing system complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements a dynamic mapping database that can be updated and adapted over time. The system learns from new attack patterns and updates the mapping database accordingly, allowing it to handle evolving threats while maintaining an efficient encoding scheme. This dynamic approach balances the complexity of maintaining the database against the benefits of reduced transmission

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3576365B1Data processing device and method
Publication Date: 2022.10.26 SIEMENS AG
  • EP3576365B1 patent drawingFigure 1
  • EP3576365B1 patent drawingFigure 2
  • EP3576365B1 patent drawingFigure 3

AI summary

A data processing device and method. The data processing device comprises: a data collection unit (100), configured to collect data transmitted in a network, and divide the collected data, according to a predetermined feature, into known attack data and unknown attack data; and a data conversion unit (300), configured to replace, according to a mapping database, at least a portion of the content included in the unknown attack data with corresponding identification codes. Therefore, the size of data transmitted in the network can be reduced.