ICS Network Security Assessment via Timing Baselines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICSs) face challenges in detecting security breaches and configuration changes due to their deterministic communication schemes, which are often masked by normal operational patterns, making it difficult to differentiate between anomalies and legitimate system performance.

Innovation Solution

Establishing communication timing baselines using jitter analysis to identify deviations in network traffic patterns, employing software-defined networks and Hidden Markov Models to detect anomalies and abnormal operating conditions, and using machine learning to model baseline changes and detect malicious actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deterministic communication schemes are used in ICSs to ensure real-time performance and control reliability, then system reliability and real-time performance are improved, but security assessment difficulty increases because normal operational patterns mask anomalies

Engineering Contradiction:
Improvereal-time performanceVSAvoidsecurity breach detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system establishes communication timing baselines during normal operation by collecting and analyzing timing parameters (inter-event intervals, packet transmission times, response times) before security breaches occur. These baselines capture the deterministic communication patterns under normal conditions, enabling future anomaly detection by comparing actual timing data against the pre-established baseline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical/content-based security detection with timing-based statistical analysis. Instead of inspecting communication content or using complex intrusion detection systems, the solution uses timing parameters and statistical models (including machine learning) to detect anomalies, substituting a simpler, more scalable approach that leverages the deterministic nature of ICS communications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If traditional security monitoring methods are used in ICSs, then implementation complexity is reduced, but detection precision deteriorates because they cannot effectively distinguish anomalies from legitimate operational variations

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidanomaly detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system changes the monitoring parameter from traditional content-based inspection to timing parameter analysis. By collecting timing parameters such as inter-event intervals, packet transmission times, and response times, the system transforms the detection approach to focus on temporal patterns. Statistical analysis and machine learning models then process these timing parameters to identify anomalies with high precision, distinguishing them from legitimate operational variations.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If configuration changes are made in ICSs to adapt to new requirements, then system adaptability is improved, but security vulnerability increases due to potential introduction of malicious actions without adequate compensation

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors communication timing parameters and compares actual timing data against established baselines. When configuration changes occur or potential security breaches are detected, the system provides feedback by identifying deviations from expected timing patterns. This feedback mechanism enables real-time detection of malicious actions or unauthorized changes, allowing operators to respond promptly to maintain security while preserving configuration flexibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11165802B2Network security assessment using a network traffic parameter
Publication Date: 2021.11.02 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11165802B2 patent drawing
  • US11165802B2 patent drawing
  • US11165802B2 patent drawing

AI summary

Systems and methods may be used to assess network communications by generating one or more thresholds for network traffic parameters based at least in part on a generated baseline for the network traffic parameter in the supervisory control and data acquisition system based on communications within the industrial network. Network communications may be assessed by determining whether the communications in the industrial network fall within the one or more thresholds for the network traffic parameter.