Factory Control Emulation for Malware Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware attacks on factory control systems are becoming sophisticated and can evade conventional IT and process control security solutions, posing a risk to the operation of physical equipment and processes.

Innovation Solution

A system and method that involves generating simulated response data through a deep learning processor to emulate factory control systems, allowing for the comparison of expected and actual behavioral patterns to detect anomalous activity, thereby initiating an alert protocol when malicious activity is present.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IT and process control security solutions are used, then the system is simple to operate, but the system cannot detect sophisticated malware attacks that evade conventional security solutions

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a digital twin (virtual replica) of the factory control system that mirrors the actual system's behavior, structure, and processes. This virtual model is used to train machine learning algorithms to recognize normal operational patterns, enabling the detection of sophisticated malware attacks that deviate from these patterns, thereby improving detection capability without directly complicating the actual control system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary training of machine learning models using historical operational data and simulated attack scenarios before deployment. This pre-training establishes a baseline of normal behavior and prepares the detection algorithms to identify anomalies, allowing the system to detect sophisticated attacks without requiring complex real-time analysis infrastructure.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If a deep learning processor is used to generate simulated response data and compare behavioral patterns, then the detection precision is improved, but the device complexity increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidprocessing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a deep learning processor as an intermediary component that sits between the factory control system and the security monitoring infrastructure. This processor generates simulated response data from the digital twin and compares it with actual system behavior, serving as a specialized mediator that handles the complex pattern recognition tasks while leaving the core control system unchanged.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the security detection function into a separate deep learning processing module that operates independently from the main control system. This modular approach allows the complex anomaly detection functionality to be developed, trained, and maintained separately, reducing the complexity burden on the overall system architecture.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If simulated process data is generated through an emulator and simulator, then the training data quality is improved, but the time required for system setup increases

Engineering Contradiction:
Improvedata qualityVSAvoidsetup time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent creates a virtual replica (digital twin) of the factory control system that copies the actual system's architecture, processes, and operational characteristics. This virtual model can generate realistic simulated response data without requiring physical duplication of equipment, thereby maintaining data quality while reducing setup time compared to building physical test environments.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system replaces physical simulation equipment and manual data collection methods with a software-based emulator and simulator that runs on standard computing infrastructure. This substitution eliminates the need for physical test rigs and manual experimentation, significantly reducing setup time while maintaining or improving data quality through programmable simulation scenarios.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12118089B2Method, systems and apparatus for intelligently emulating factory control systems and simulating response data
Publication Date: 2024.10.15 NANOTRONICS IMAGING INC
  • US12118089B2 patent drawing
  • US12118089B2 patent drawing
  • US12118089B2 patent drawing

AI summary

A simulated process is initiated. The simulated process includes generating, by an emulator, a control signal based on external inputs. The simulated process further includes processing, by a simulator, the control signal to generate simulated response data. The simulated process further includes generating, by a deep learning processor, expected behavioral pattern data based on the simulated response data. An actual process is initiated by initializing setpoints for a process station in a manufacturing system. The actual process includes generating, by the deep learning processor, actual behavioral pattern data based on actual process data from the at least one process station. The deep learning processor compares the expected behavioral pattern to the actual behavioral pattern. Based on the comparing, the deep learning processor determines that anomalous activity is present in the manufacturing system. Based on the anomalous activity being present, the deep learning processor initiates an alert protocol.