Embedded ICS Attack Detection Using Two-Dimensional Sensor Checks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face increased security threats due to inherent vulnerabilities and improved attack capabilities, with existing defense mechanisms lacking sufficient capability to monitor and respond to continuously changing threats.
Innovation Solution
A two-dimensionality detection method that involves real-time data collection from sensors, transmission to a PLC and an embedded attack detection system, refining data distribution characteristics to create a health data model, and comparing sensor data with SCADA system data and the model to detect attacks through statistical and probabilistic analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If defense-in-depth ideology is used to protect industrial control systems, then system security is improved, but the capability to monitor and respond to continuously changing security threats is insufficient
Solution Approach 1:
The patent introduces a two-dimensional detection framework that adds a new dimension of security monitoring. The first dimension compares sensor data with SCADA system data to detect SCADA attacks, while the second dimension compares sensor statistical patterns with health data models to detect sensor attacks. This multi-dimensional approach enables the system to monitor and respond to different types of threats simultaneously, resolving the contradiction between maintaining security and adapting to changing threats.
2Reliability
If an embedded attack detection system is added to detect attacks, then detection reliability is improved, but system cost increases
Solution Approach 1:
The patent introduces an embedded attack detection system as an intermediary component that sits between the sensors and the existing SCADA/PLC systems. This intermediary collects sensor data, performs statistical analysis, and generates attack alerts without requiring replacement of the entire control system. By adding only this intermediate detection layer, the system achieves high detection reliability while minimizing cost increase compared to replacing the whole system.
3Measurement precision
If comprehensive data analysis is performed to detect attacks from multiple channels, then detection precision is improved, but computational complexity increases
Solution Approach 1:
The patent segments the attack detection process into two distinct dimensional analyses. The first dimension segments the comparison between sensor data and SCADA data for detecting SCADA system attacks. The second dimension segments the statistical pattern analysis against health data models for detecting sensor attacks. This segmentation allows comprehensive detection precision while managing computational complexity by dividing the analysis into manageable, specialized sub-tasks rather than performing one monolithic complex analysis.
Data Source
AI summary
A two-dimensionality detection method for industrial control system attacks: collecting data; transmitting the data to a PLC and an embedded attack detection system; uploading, by the PLC, received data to an SCADA system; transmitting, by the SCADA system, the data to the embedded attack detection system after classifying and counting the data; before starting detection, directly reading, by the embedded attack detection system, the data measured by sensors; refining data association relationships and probability distribution characteristics of the sensors of normal operation to complete storage of health data model; after starting detection, in first dimensionality, comparing the data collected directly by the sensors with statistical data of the SCADA system to judge the attacked condition of the SCADA system, and in second dimensionality, comparing the characteristics of the data collected directly by the sensors and counted online with the health data model to judge the attacked condition of the sensors.

