Two-Stage Cyber Threat Analysis for Oil and Gas Edge Cloud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber threat detection in oil and gas field operations is hindered by intermittent connectivity, high bandwidth requirements, resource usage, latency, and the lack of domain-specific knowledge in machine learning algorithms, leading to false positives, false negatives, and inefficiencies in existing cloud-based ML systems.
Innovation Solution
A two-stage cyber threat analysis method utilizing local edge computing for initial anomaly detection and filtering of events, followed by cloud-based analysis with system context and vulnerability databases to minimize false positives and negatives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If cloud-based ML analysis is used for cyber threat detection, then comprehensive analysis capability is improved, but bandwidth requirements and latency increase
Solution Approach 1:
The system segments the threat detection process into two stages: edge-based initial filtering and cloud-based comprehensive analysis. This segmentation allows local preprocessing of data to reduce bandwidth consumption while maintaining accurate threat detection through cloud-based ML analysis of filtered data.
Solution Approach 2:
The edge computing device performs preliminary action by filtering and preprocessing security events before transmission to the cloud. This preliminary filtering reduces the volume of data requiring cloud bandwidth, thereby reducing overall bandwidth consumption while preserving detection accuracy.
2Measurement precision
If cloud-based ML analysis is used for cyber threat detection, then comprehensive analysis capability is improved, but response latency increases
Solution Approach 1:
The system segments the threat detection process into local real-time filtering and cloud-based comprehensive analysis. Critical filtering operations occur locally at the edge device with minimal latency, while non-critical comprehensive analysis occurs in the cloud, optimizing overall response time while maintaining detection accuracy.
Solution Approach 2:
The edge computing device performs preliminary filtering of security events before cloud transmission. This preliminary action reduces response latency by handling time-sensitive filtering operations locally, allowing the system to respond quickly to potential threats without waiting for cloud-based analysis.
3Adaptability or versatility
If domain-agnostic ML algorithms are deployed, then versatility across IT and OT is improved, but false positives and negatives increase
Solution Approach 1:
The system applies local quality by customizing the ML model with domain-specific knowledge and parameters tailored to oil and gas operations. This allows the algorithm to maintain versatility across different deployment scenarios while achieving high reliability by adapting to specific operational contexts and reducing false positives.
Solution Approach 2:
The system changes parameters by configuring the ML algorithm with domain-specific parameters and knowledge relevant to oil and gas operations. This parameter customization enables the algorithm to maintain broad adaptability while achieving high detection accuracy and reliability for specific industrial contexts.
4Loss of energy
If edge computing is used for initial anomaly detection, then bandwidth requirements are reduced, but device complexity increases
Solution Approach 1:
The system extracts only the essential filtering and preprocessing functions to the edge device, leaving comprehensive analysis in the cloud. This extraction approach reduces bandwidth requirements by performing local filtering while avoiding excessive edge device complexity by not implementing the full ML analysis pipeline at the edge.
Data Source
AI summary
The disclosure provides for a two-stage method for analyzing data from an oil and gas field operation site for cyber threats. The method includes, in a first stage of analysis, filtering captured events using local edge computing at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data. The method includes transmitting the filtered data to a second stage of analysis and, in the second stage of analysis, analyzing the filtered data in a cloud by applying system context and referring vulnerability databases. The disclosure provides for a system for analyzing data, including an edge computing device that includes computer instructions to filter captured events to perform initial cyber anomaly detection, forming filtered data. The system includes a cloud-based ML cluster to implement a second stage of analysis to analyze the filtered.


