Dynamic Blacklist Anomaly Detection for Control System Registers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intrusion detection systems struggle with anomaly detection in control systems with unclear transition boundaries between system states, such as those in continuous operation, and are ineffective against spoofing attacks that utilize authorized protocols, leading to inadequate anomaly detection.
Innovation Solution
An anomaly detection system that includes a register value collector, a future state predictor, a blacklist creator, a blacklist manager, and an anomaly determiner, which dynamically creates a blacklist based on predicted register values and their ranges to identify potential anomalous states, allowing for real-time anomaly detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a whitelist-based intrusion detection system is used for control systems with clear transition boundaries, then anomaly detection accuracy is improved, but the system becomes ineffective against spoofing attacks and cannot handle systems with unclear transition boundaries
Solution Approach 1:
The patent applies dynamics by transitioning from a static whitelist approach to a dynamic blacklist approach. The blacklist is continuously updated based on predicted future states of the control system, allowing the detection mechanism to adapt to changing system conditions while maintaining high detection accuracy across diverse operational scenarios
Solution Approach 2:
The patent changes the fundamental parameter of anomaly detection from whitelist-based allowed states to blacklist-based prohibited states. This parameter change enables the system to detect anomalies by identifying deviations from predicted future states, making it effective against spoofing attacks and applicable to systems with unclear transition boundaries
2Measurement precision
If a whitelist is defined for each IP-address communication pair or communication protocol, then the system can detect clear anomalies, but it cannot detect spoofing attacks that use authorized protocols
Solution Approach 1:
The patent inverts the traditional whitelist approach by implementing a blacklist system. Instead of defining what communications are allowed, the system defines what communications are prohibited based on predicted future states. This inversion enables detection of spoofing attacks that use authorized protocols, as the blacklist focuses on identifying malicious deviations rather than permitting legitimate communications
3Device complexity
If the whitelist approach is applied to control systems with unclear transition boundaries, then the system complexity is reduced, but appropriate anomaly detection cannot be performed
Solution Approach 1:
The patent applies self-service by enabling the control system to automatically generate its own detection rules through prediction of future states. The system uses its own operational data to create the blacklist, eliminating the need for manual whitelist configuration while maintaining high detection appropriateness for systems with unclear transition boundaries
Data Source
AI summary
An anomaly detection system includes: a register value collector that collects register values of register numbers from a controller; a future state predictor that predicts a future state of the control system; a blacklist creator that creates a blacklist based on a prediction result; an anomaly determiner that determines whether the control system enters an anomalous state by checking the collected register values against the blacklist; and an outputter that outputs a determination result. The blacklist creator defines, as the blacklist: a predicted register number that is predicted, if a register value of the predicted register number is changed, to cause the control system to enter the anomalous state in the future; and a range of the register value within which the control system is predicted to enter the anomalous state, and dynamically creates the blacklist corresponding to a combination of the collected register values.


