IACS Configuration Change Detection for Abnormal Event Root Cause
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation and control systems lack effective methods to detect abnormal configuration changes, which can lead to disturbances, cyber security events, or maintenance issues, including potential targeted attacks, and incomplete configuration changes that may result in non-allowable behavior.
Innovation Solution
A method and system that identify abnormal events in industrial automation and control systems by detecting root causes, evaluating the impact of changes on the system, and generating notifications when changes deviate from predefined allowable behaviors, using predefined lists of event types, configuration comparisons, and status monitoring information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If basic cyber security mechanisms (authentication, authorization, logging) are implemented in industrial control devices, then security and traceability are improved, but device complexity and operational overhead increase
Solution Approach 1:
The patent introduces a centralized collection system that acts as an intermediary to receive, store, and analyze configuration data and event logs from multiple industrial control devices. This mediator handles the complexity of security monitoring centrally rather than requiring each device to independently manage complex security analysis, thus improving security while managing device complexity through externalization of the analysis function.
2Stability of the object's composition
If configuration changes are restricted and well-documented in machine readable format, then system stability is improved, but adaptability to new requirements and abnormal change detection capability deteriorate
Solution Approach 1:
The patent implements a feedback mechanism where the centralized collection system continuously monitors configuration changes, compares them against the documented baseline configuration, and generates alerts when abnormal changes are detected. This feedback loop enables the system to maintain stability through documented configurations while simultaneously detecting and responding to unauthorized or abnormal changes, thus resolving the contradiction between stability and adaptability.
Solution Approach 2:
The system performs preliminary comparison of configuration changes against the documented baseline before changes are fully implemented. By预先 (in advance) identifying potential abnormal changes through comparison, the system can prevent or alert on configuration drift before it causes system instability, while still allowing legitimate configuration adaptations to proceed.
3Reliability
If comprehensive logging of all user activities is implemented, then security monitoring and anomaly detection are improved, but data processing load and storage requirements increase
Solution Approach 1:
The patent extracts only the essential and relevant configuration parameters and event data from the comprehensive logs for centralized storage and analysis. Rather than storing and processing all possible log data, the system identifies and extracts only the critical configuration changes and security-relevant events, significantly reducing data volume while maintaining effective security monitoring and anomaly detection capabilities.
Data Source
AI summary
The invention relates to a method for analyzing an abnormal event in an industrial automation and control system, IACS, comprising the following steps: identifying the abnormal event; detecting a root cause of the abnormal event; and generating a notification if the root cause is not a user activity and, if the root cause is a user activity, evaluating the possible impact on the IACS caused by the abnormal event, and generating a notification if the evaluation of the possible impact does not match a predefined list of allowable behavior. The present invention also relates to a corresponding system and corresponding computer program product comprising one or more computer readable media having computer executable instructions for performing the steps of the method.


