Data Processing Device for Industrial Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial control network environments, the high bandwidth required for transmitting large network data streams poses a challenge, necessitating a method to reduce data transmission and alleviate bandwidth pressure by identifying and simplifying known data while processing unknown data alone.
Innovation Solution
A data processing device and method that collects network data, divides it into known and unknown attack data, and uses a mapping database to replace portions of unknown attack data with identification codes, reducing the data sent to a central network security monitoring center, thereby improving security analysis speed and accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network data streams are transmitted to the central monitoring center, then complete security analysis can be performed, but bandwidth requirements become excessively high
Solution Approach 1:
The patent extracts and processes data locally at the edge device before transmission. The edge device performs preliminary security analysis, filters known attack patterns, and only transmits relevant or unknown data to the central monitoring center, thereby reducing transmission volume while maintaining analysis effectiveness
Solution Approach 2:
The patent segments the data processing function into two parts: local preprocessing at the edge device and central analysis at the monitoring center. This segmentation allows bandwidth-intensive processing to occur locally, reducing the amount of data that needs to be transmitted over the network
2Quantity of substance
If data is compressed or simplified before transmission, then bandwidth pressure is reduced, but data analysis accuracy may be compromised
Solution Approach 1:
The patent performs preliminary actions by establishing a mapping database locally at the edge device before transmission. This database contains identification codes for known attack patterns, allowing the system to quickly recognize and encode common threats without transmitting the actual large-volume raw data, thus maintaining accuracy while reducing bandwidth usage
3Quantity of substance
If a mapping database is used to replace data with identification codes, then data transmission is reduced, but system complexity increases
Solution Approach 1:
The patent implements a dynamic mapping database that can be updated and adapted over time. The system learns from new attack patterns and updates the mapping database accordingly, allowing it to handle evolving threats while maintaining an efficient encoding scheme. This dynamic approach balances the complexity of maintaining the database against the benefits of reduced transmission
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A data processing device and method. The data processing device comprises: a data collection unit (100), configured to collect data transmitted in a network, and divide the collected data, according to a predetermined feature, into known attack data and unknown attack data; and a data conversion unit (300), configured to replace, according to a mapping database, at least a portion of the content included in the unknown attack data with corresponding identification codes. Therefore, the size of data transmitted in the network can be reduced.