Diagnostic Message Filtering for Industrial Security Alarm Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Security Information Event Management (SIEM) tools in industrial installations are inadequate for identifying sophisticated attacks and deviations, as they rely on predefined security events and lack integration with device diagnostic messages from various components, leading to an overwhelming amount of non-security relevant data and limited ability to detect installation-specific threats.
Innovation Solution
A control system that utilizes a machine learning network, specifically a neural network, to analyze diagnostic messages from technical installations, assess their security relevance, and adapt them to a computer-implemented security module, filtering out non-relevant information and presenting security-relevant data to operators, thereby enhancing the detection of attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all device diagnostic messages are transmitted to security analysis tools, then comprehensive security analysis is possible, but the volume of data to be processed increases significantly
Solution Approach 1:
The system performs preliminary classification of diagnostic messages using a trained machine learning model before transmission to security analysis tools. This preliminary action filters out non-security-relevant messages, reducing the data volume that requires comprehensive security analysis while maintaining reliability for actual security threats.
Solution Approach 2:
The system extracts and transmits only the security-relevant diagnostic messages to external security analysis tools, separating them from the complete set of diagnostic messages. This extraction process reduces the quantity of transmitted data while preserving the essential information needed for comprehensive security analysis.
2Measurement precision
If predefined security events are used for attack detection, then standard attacks can be identified, but sophisticated attacks and installation-specific threats cannot be detected
Solution Approach 1:
The system changes the parameters of attack detection by transitioning from static, predefined security event patterns to dynamic, machine learning-based classification. The model is trained with installation-specific data, allowing it to adapt to sophisticated attacks and installation-specific threats while maintaining detection precision for standard attacks.
Solution Approach 2:
The system performs preliminary training of the machine learning model with installation-specific diagnostic messages and security events before deployment. This preliminary action enables the system to learn and adapt to installation-specific patterns, enhancing detection coverage for sophisticated and customized threats while maintaining accuracy.
3Measurement precision
If machine learning model is trained with installation-specific data, then detection accuracy for installation-specific threats improves, but training time and computational resources increase
Solution Approach 1:
The system performs the machine learning model training as a preliminary action during system setup or maintenance phases, before actual security monitoring begins. This allows the model to be pre-adapted to installation-specific patterns, achieving high detection accuracy without delaying operational security monitoring.
Solution Approach 2:
The system uses copies of historical diagnostic messages and security events for training the machine learning model, rather than requiring real-time data collection during training. This approach reduces training time and computational resources while still achieving installation-specific detection accuracy through pattern learning from representative data samples.
Data Source
AI summary
A method for handling security alarms by a control system of a technical installation includes a) receiving diagnostic messages that have been generated by technical objects (7) of a technical installation; b) analyzing the diagnostic messages such that diagnostic messages relevant to the security of an operation of the technical installation are identified by means of comparative data records, where a machine learning network is used to analyze the diagnostic messages to assess the security relevance of the diagnostic messages, where the network is previously trained using special inputs from operators of the technical installation that have assessed past diagnostic messages with regard to their security relevance; c) if necessary, adapting the previously identified diagnostic messages to requirements of a computer-implemented security module of the technical installation and d) transmitting the previously identified and optionally adapted diagnostic messages to the computer-implemented security module of the technical installation.

