Process Control Hypervisor Security via Behavioral Trace Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Process control systems in industrial plants face challenges in maintaining tight security over a long period due to the end-of-life issues of operating systems, making it difficult to obtain corrective patches and requiring costly retraining and verification for new systems, which increases vulnerability to cyberattacks and potential risks like explosions from unauthorized access.
Innovation Solution
A process control apparatus and system that includes a controller, storage, and determiner, which runs on hardware and a virtual device, collecting and comparing traces of interactive motions to determine normal operation, allowing for continuous security without relying on corrective patches, by using a hypervisor to manage operating systems and applications independently and discarding unauthorized data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If corrective patches are applied to correct vulnerabilities in the operating system and application, then security is improved, but system complexity and maintenance burden increase
Solution Approach 1:
The patent applies preliminary action by creating a baseline profile of normal system behavior before vulnerabilities can be exploited. The system establishes security rules and behavioral patterns in advance, enabling it to detect and prevent unauthorized access without requiring continuous patches. The baseline is created by collecting normal operation data and establishing what constitutes acceptable system behavior, allowing the system to proactively identify deviations that indicate security threats.
2Reliability
If the operating system is updated to a new version, then security vulnerabilities are corrected, but verification time and operational disruption increase
Solution Approach 1:
The patent uses copying by creating virtual copies of the system's normal operational behavior patterns. Instead of physically updating the operating system, the system maintains copies of baseline behavior data and uses these to detect anomalies. The behavioral profiles serve as reference copies that can be compared against current system activity, allowing security monitoring without actual system changes or lengthy verification processes.
3Reliability
If security monitoring is implemented to detect unauthorized access, then protection from cyberattacks is improved, but system performance and response time may deteriorate
Solution Approach 1:
The system applies preliminary action by pre-establishing security rules and behavioral baselines before threats occur. Normal system behavior patterns are captured and stored as reference data, enabling rapid comparison against current activity. When deviations are detected, the system can quickly identify potential security incidents without requiring complex real-time analysis, thus maintaining fast response times while providing comprehensive protection.
Data Source
AI summary
A process control apparatus includes a hypervisor, a controller configured to run on the hypervisor and to communicate with a field apparatus to control an industrial process, an operation model definer configured to define an operation model, which is information establishing operation specifications derived from specifications of the controller, a trace information collector configured to collect traces of interactive motions between hardware and the controller, and a normality determiner configured to compare the operation model defined by the operation model definer with the information collected by the trace information collector and to determine the normality of the operation of the process control apparatus.


