Dynamic Blacklist Anomaly Detection for Control System Registers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems struggle with anomaly detection in control systems with unclear transition boundaries between system states, such as those in continuous operation, and are ineffective against spoofing attacks that utilize authorized protocols, leading to inadequate anomaly detection.

Innovation Solution

An anomaly detection system that includes a register value collector, a future state predictor, a blacklist creator, a blacklist manager, and an anomaly determiner, which dynamically creates a blacklist based on predicted register values and their ranges to identify potential anomalous states, allowing for real-time anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a whitelist-based intrusion detection system is used for control systems with clear transition boundaries, then anomaly detection accuracy is improved, but the system becomes ineffective against spoofing attacks and cannot handle systems with unclear transition boundaries

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidapplicability to different system states
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by transitioning from a static whitelist approach to a dynamic blacklist approach. The blacklist is continuously updated based on predicted future states of the control system, allowing the detection mechanism to adapt to changing system conditions while maintaining high detection accuracy across diverse operational scenarios

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of anomaly detection from whitelist-based allowed states to blacklist-based prohibited states. This parameter change enables the system to detect anomalies by identifying deviations from predicted future states, making it effective against spoofing attacks and applicable to systems with unclear transition boundaries

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If a whitelist is defined for each IP-address communication pair or communication protocol, then the system can detect clear anomalies, but it cannot detect spoofing attacks that use authorized protocols

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidspoofing attack vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional whitelist approach by implementing a blacklist system. Instead of defining what communications are allowed, the system defines what communications are prohibited based on predicted future states. This inversion enables detection of spoofing attacks that use authorized protocols, as the blacklist focuses on identifying malicious deviations rather than permitting legitimate communications

Inventive Principle:
Principle #13The other way round (Inversion)

3Device complexity

If the whitelist approach is applied to control systems with unclear transition boundaries, then the system complexity is reduced, but appropriate anomaly detection cannot be performed

Engineering Contradiction:
Improvesystem configuration simplicityVSAvoidanomaly detection appropriateness
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies self-service by enabling the control system to automatically generate its own detection rules through prediction of future states. The system uses its own operational data to create the blacklist, eliminating the need for manual whitelist configuration while maintaining high detection appropriateness for systems with unclear transition boundaries

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240086548A1Anomaly detection system, anomaly detection method, and recording medium
Publication Date: 2024.03.14 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US20240086548A1 patent drawing
  • US20240086548A1 patent drawing
  • US20240086548A1 patent drawing

AI summary

An anomaly detection system includes: a register value collector that collects register values of register numbers from a controller; a future state predictor that predicts a future state of the control system; a blacklist creator that creates a blacklist based on a prediction result; an anomaly determiner that determines whether the control system enters an anomalous state by checking the collected register values against the blacklist; and an outputter that outputs a determination result. The blacklist creator defines, as the blacklist: a predicted register number that is predicted, if a register value of the predicted register number is changed, to cause the control system to enter the anomalous state in the future; and a range of the register value within which the control system is predicted to enter the anomalous state, and dynamically creates the blacklist corresponding to a combination of the collected register values.