Two-Stage Cyber Threat Analysis for Oil and Gas Edge Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber threat detection in oil and gas field operations is hindered by intermittent connectivity, high bandwidth requirements, resource usage, latency, and the lack of domain-specific knowledge in machine learning algorithms, leading to false positives, false negatives, and inefficiencies in existing cloud-based ML systems.

Innovation Solution

A two-stage cyber threat analysis method utilizing local edge computing for initial anomaly detection and filtering of events, followed by cloud-based analysis with system context and vulnerability databases to minimize false positives and negatives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If cloud-based ML analysis is used for cyber threat detection, then comprehensive analysis capability is improved, but bandwidth requirements and latency increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system segments the threat detection process into two stages: edge-based initial filtering and cloud-based comprehensive analysis. This segmentation allows local preprocessing of data to reduce bandwidth consumption while maintaining accurate threat detection through cloud-based ML analysis of filtered data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The edge computing device performs preliminary action by filtering and preprocessing security events before transmission to the cloud. This preliminary filtering reduces the volume of data requiring cloud bandwidth, thereby reducing overall bandwidth consumption while preserving detection accuracy.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If cloud-based ML analysis is used for cyber threat detection, then comprehensive analysis capability is improved, but response latency increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresponse latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments the threat detection process into local real-time filtering and cloud-based comprehensive analysis. Critical filtering operations occur locally at the edge device with minimal latency, while non-critical comprehensive analysis occurs in the cloud, optimizing overall response time while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The edge computing device performs preliminary filtering of security events before cloud transmission. This preliminary action reduces response latency by handling time-sensitive filtering operations locally, allowing the system to respond quickly to potential threats without waiting for cloud-based analysis.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If domain-agnostic ML algorithms are deployed, then versatility across IT and OT is improved, but false positives and negatives increase

Engineering Contradiction:
Improvedeployment flexibilityVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies local quality by customizing the ML model with domain-specific knowledge and parameters tailored to oil and gas operations. This allows the algorithm to maintain versatility across different deployment scenarios while achieving high reliability by adapting to specific operational contexts and reducing false positives.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by configuring the ML algorithm with domain-specific parameters and knowledge relevant to oil and gas operations. This parameter customization enables the algorithm to maintain broad adaptability while achieving high detection accuracy and reliability for specific industrial contexts.

Inventive Principle:
Principle #35Parameter changes

4Loss of energy

If edge computing is used for initial anomaly detection, then bandwidth requirements are reduced, but device complexity increases

Engineering Contradiction:
Improvebandwidth consumptionVSAvoidedge device complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The system extracts only the essential filtering and preprocessing functions to the edge device, leaving comprehensive analysis in the cloud. This extraction approach reduces bandwidth requirements by performing local filtering while avoiding excessive edge device complexity by not implementing the full ML analysis pipeline at the edge.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11399038B2Cybersecurity with edge computing
Publication Date: 2022.07.26 SCHLUMBERGER TECH CORP
  • US11399038B2 patent drawing
  • US11399038B2 patent drawing
  • US11399038B2 patent drawing

AI summary

The disclosure provides for a two-stage method for analyzing data from an oil and gas field operation site for cyber threats. The method includes, in a first stage of analysis, filtering captured events using local edge computing at the site to perform initial cyber anomaly detection by applying classification models to the captured events, forming filtered data. The method includes transmitting the filtered data to a second stage of analysis and, in the second stage of analysis, analyzing the filtered data in a cloud by applying system context and referring vulnerability databases. The disclosure provides for a system for analyzing data, including an edge computing device that includes computer instructions to filter captured events to perform initial cyber anomaly detection, forming filtered data. The system includes a cloud-based ML cluster to implement a second stage of analysis to analyze the filtered.