IACS Configuration Change Detection for Abnormal Event Root Cause

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation and control systems lack effective methods to detect abnormal configuration changes, which can lead to disturbances, cyber security events, or maintenance issues, including potential targeted attacks, and incomplete configuration changes that may result in non-allowable behavior.

Innovation Solution

A method and system that identify abnormal events in industrial automation and control systems by detecting root causes, evaluating the impact of changes on the system, and generating notifications when changes deviate from predefined allowable behaviors, using predefined lists of event types, configuration comparisons, and status monitoring information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If basic cyber security mechanisms (authentication, authorization, logging) are implemented in industrial control devices, then security and traceability are improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvecyber securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized collection system that acts as an intermediary to receive, store, and analyze configuration data and event logs from multiple industrial control devices. This mediator handles the complexity of security monitoring centrally rather than requiring each device to independently manage complex security analysis, thus improving security while managing device complexity through externalization of the analysis function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If configuration changes are restricted and well-documented in machine readable format, then system stability is improved, but adaptability to new requirements and abnormal change detection capability deteriorate

Engineering Contradiction:
Improvesystem stabilityVSAvoidconfiguration adaptability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the centralized collection system continuously monitors configuration changes, compares them against the documented baseline configuration, and generates alerts when abnormal changes are detected. This feedback loop enables the system to maintain stability through documented configurations while simultaneously detecting and responding to unauthorized or abnormal changes, thus resolving the contradiction between stability and adaptability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary comparison of configuration changes against the documented baseline before changes are fully implemented. By预先 (in advance) identifying potential abnormal changes through comparison, the system can prevent or alert on configuration drift before it causes system instability, while still allowing legitimate configuration adaptations to proceed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive logging of all user activities is implemented, then security monitoring and anomaly detection are improved, but data processing load and storage requirements increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant configuration parameters and event data from the comprehensive logs for centralized storage and analysis. Rather than storing and processing all possible log data, the system identifies and extracts only the critical configuration changes and security-relevant events, significantly reducing data volume while maintaining effective security monitoring and anomaly detection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11243508B2Detection of abnormal configuration changes
Publication Date: 2022.02.08 HITACHI ENERGY LTD
  • US11243508B2 patent drawing
  • US11243508B2 patent drawing
  • US11243508B2 patent drawing

AI summary

The invention relates to a method for analyzing an abnormal event in an industrial automation and control system, IACS, comprising the following steps: identifying the abnormal event; detecting a root cause of the abnormal event; and generating a notification if the root cause is not a user activity and, if the root cause is a user activity, evaluating the possible impact on the IACS caused by the abnormal event, and generating a notification if the evaluation of the possible impact does not match a predefined list of allowable behavior. The present invention also relates to a corresponding system and corresponding computer program product comprising one or more computer readable media having computer executable instructions for performing the steps of the method.