Factory Process Behavior Monitoring for Malware-Driven Anomalies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware attacks on factory processes and equipment are becoming increasingly sophisticated, capable of evading conventional IT security solutions and process control systems, leading to subtle yet catastrophic disruptions in operation and control, which can result in irreversible damage and yield loss.

Innovation Solution

A computer-implemented method using machine learning algorithms, specifically deep learning processors, to dynamically monitor and secure manufacturing processes by generating expected behavioral pattern data and detecting anomalous activity through the comparison of actual and expected patterns, identifying the source and type of anomalies, and providing alerts to prevent damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional IT security solutions and process control systems are used to monitor factory operations, then basic security monitoring is provided, but subtle anomalous activity caused by sophisticated malware attacks cannot be detected

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system dynamically adapts its monitoring approach by continuously learning normal operational patterns through machine learning algorithms. The monitoring parameters and thresholds are not static but evolve with the system's operational characteristics, enabling detection of subtle anomalies that deviate from learned normal behavior while adapting to changing operational conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces conventional rule-based IT security monitoring with machine learning-based behavioral pattern recognition. Instead of relying on predefined security rules and thresholds, the system uses AI algorithms to learn and recognize normal operational patterns, substituting mechanical monitoring approaches with intelligent behavioral analysis that can detect subtle malware-induced anomalies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If machine learning algorithms are implemented to detect subtle anomalous activity, then detection precision is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary learning during normal operational periods to establish baseline behavioral patterns before malware attacks occur. By pre-training machine learning models on normal operational data, the system prepares detection algorithms in advance, enabling rapid anomaly detection during actual attacks without requiring extensive real-time computational analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements efficient processing by skipping detailed analysis of normal operational patterns that have already been learned. Once behavioral patterns are established, the system rapidly compares current operations against learned norms, rushing through the detection process for routine operations while focusing computational resources only on identifying deviations that indicate potential malware activity.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If comprehensive monitoring of all factory processes is implemented, then detection capability is improved, but system complexity and computational load increase

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and focuses monitoring efforts on critical operational parameters and key process areas that are most vulnerable to malware attacks. Rather than uniformly monitoring all factory processes, the machine learning algorithm identifies and extracts the most significant behavioral patterns from operational data, concentrating monitoring resources on parameters that provide the highest detection value while reducing complexity of less critical monitoring areas.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal monitoring framework that uses the same machine learning-based behavioral pattern recognition approach across diverse factory processes and equipment types. This multi-functional system can adapt to monitor different process areas (manufacturing, logistics, quality control) using a unified algorithmic approach, reducing overall system complexity compared to implementing separate specialized monitoring systems for each process area.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11063965B1Dynamic monitoring and securing of factory processes, equipment and automated systems
Publication Date: 2021.07.13 NANOTRONICS IMAGING INC
  • US11063965B1 patent drawing
  • US11063965B1 patent drawing
  • US11063965B1 patent drawing

AI summary

A system including a deep learning processor obtains response data of at least two data types from a set of process stations performing operations as part of a manufacturing process. The system analyzes factory operation and control data to generate expected behavioral pattern data. Further, the system uses the response data to generate actual behavior pattern data for the process stations. Based on an analysis of the actual behavior pattern data in relation to the expected behavioral pattern data, the system determines whether anomalous activity has occurred as a result of the manufacturing process. If it is determined that anomalous activity has occurred, the system provides an indication of this anomalous activity.