ICS Device Classification Using Passive Traffic Latent Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial Control Systems (ICS) face challenges in identifying and managing devices due to the lack of comprehensive records of installed hardware and software, especially across multiple geographical entities, and passive scanning is often restricted for performance and security reasons.

Innovation Solution

A computing system passively captures ICS communications, using a neural network to generate latent vectors representing device identities and behaviors, which are then analyzed by machine learning models to identify and classify devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If active scanning is used to identify ICS devices, then device information can be obtained, but network performance is degraded and security risks increase

Engineering Contradiction:
Improvedevice informationVSAvoidnetwork performance
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent introduces a machine learning model as an intermediary that analyzes passive network traffic to infer device information. Instead of directly scanning devices (which disrupts network performance), the system uses intercepted communications as intermediate data to train models that can identify device types, manufacturers, and software versions without active probing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical active scanning approach with a computational machine learning system. Rather than mechanically probing devices to extract information, the system uses algorithms to analyze patterns in passive traffic data, substituting computational inference for physical/network mechanical interaction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If active scanning is performed to audit ICS devices, then device and software records are updated, but security vulnerabilities increase due to potential attack exploitation

Engineering Contradiction:
Improvedevice recordsVSAvoidsecurity vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The machine learning model serves as an intermediary layer that derives device information indirectly from passive traffic analysis. This intermediary approach avoids direct interaction with devices that could expose security vulnerabilities, while still enabling comprehensive device auditing and software version identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the limitation of having only passive traffic data (which would normally be insufficient for device identification) into a security benefit. The very constraint that prevents active scanning is transformed into a protective feature, as the machine learning model can accurately identify devices and software versions using only the benign passive communications already present in the network.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of operation

If comprehensive device records are maintained across multiple geographical entities, then ICS management is improved, but system complexity increases

Engineering Contradiction:
ImproveICS managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The machine learning system performs self-service by automatically analyzing network traffic and generating device inventory records without requiring manual intervention from ICS operators across multiple geographical entities. The system autonomously tracks device additions, modifications, and software updates, eliminating the need for coordinated manual record-keeping.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal device identification system that works across diverse ICS environments, manufacturers, and geographical locations through a single machine learning framework. The model can identify various device types and software versions using a unified approach, simplifying management across complex multi-entity operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250231549A1Industrial control system device classification
Publication Date: 2025.07.17 LAWRENCE LIVERMORE NAT SECURITY LLC
  • US20250231549A1 patent drawing
  • US20250231549A1 patent drawing
  • US20250231549A1 patent drawing

AI summary

In an industrial control system (ICS), latent vectors are generated to represent identity or behaviors of host devices coupled to the ICS. A computing system captures communications transmitted by a host device across a network associated with the ICS. A set of values are extracted from one or more respective fields in the communication, then applied to a trained neural network. Values of a first set of fields are applied at an input layer of the trained neural network, while values of a second set of fields are applied at an output layer of the neural network. Based on the application of the neural network to the values extracted from the communication, the computing system generates a latent vector.