ICS Traffic Validation Architecture for Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems, such as those in nuclear power plants, are vulnerable to malicious manipulation and deception attacks due to their technical know-how being well understood by adversaries and lack of encryption in control traffic, making existing defense methods ineffective against sophisticated attacks that bypass perimeter defenses.

Innovation Solution

A system architecture with active monitoring protocols that introduce small perturbations to industrial control system traffic to detect intrusions by using reduced order modeling and data mining techniques, generating unique signatures that can identify and validate inputs and outputs, thereby providing an additional layer of defense beyond conventional perimeter security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter defenses (routers, firewalls, cryptography) are used to protect industrial control systems, then unauthorized access is blocked, but sophisticated attacks can still bypass these defenses through systematic falsification of performance data and modification of commands to actuators

Engineering Contradiction:
Improvesecurity protectionVSAvoidmalicious manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors control room traffic and compares actual system behavior against expected behavior models, creating a feedback loop that detects deviations caused by malicious manipulation. The monitoring system provides real-time feedback on whether control commands and sensor readings are consistent with normal operational patterns, enabling detection of attacks that bypass perimeter defenses.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary monitoring system positioned between the control room traffic and the industrial control system. This intermediary layer analyzes control commands and sensor readings before they reach the target system, acting as a mediator that can identify and block malicious traffic without interfering with legitimate control operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If control room traffic is monitored using passive monitoring techniques, then data trustworthiness can be assessed, but attackers with access to the same data and engineering models can potentially bypass detection

Engineering Contradiction:
Improvedata trustworthiness assessmentVSAvoiddetection effectiveness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary analysis of control room traffic using multiple validation protocols before malicious manipulation can succeed. By pre-establishing expected behavior models and validating control commands against these models in advance, the system detects attacks before they can escalate, preventing rather than merely identifying malicious actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs a composite defense approach combining multiple validation protocols (input validation, output validation, consistency checking) that work together synergistically. Just as composite materials combine different properties to achieve superior performance, the combination of multiple validation methods creates detection capabilities that are more robust than any single method alone, making it harder for attackers to bypass all checks simultaneously.

Inventive Principle:
Principle #40Composite materials

3Reliability

If encryption is applied to control traffic to prevent manipulation, then data integrity is protected, but control systems cannot operate in real-time due to processing overhead

Engineering Contradiction:
Improvedata integrityVSAvoidreal-time operation
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces heavy cryptographic encryption mechanisms with lighter computational validation protocols that verify control traffic against behavioral models. Instead of using computationally intensive encryption/decryption operations, the system uses model-based validation that achieves similar security goals with minimal processing overhead, maintaining real-time operational speed while protecting data integrity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11886158B2System architecture and method of processing data therein
Publication Date: 2024.01.30 PURDUE RES FOUND
  • US11886158B2 patent drawing

AI summary

A system architecture encoded on a non-transitory computer readable medium, the system architecture includes a first protocol. The first protocol is configured to receive a plurality of outputs from an ICS used in controlling an industrial system. The first protocol is configured to receive a plurality of inputs from a physical module. The physical module includes at least one of a component, a sensor, or the ICS. Additionally, the system architecture includes a second protocol, wherein the second protocol is configured to validate the plurality of inputs from the first protocol. Moreover, the system architectures includes a third protocol, wherein the third protocol is configured to validate the plurality of outputs from the first protocol. Further, the system architecture includes a fourth protocol, wherein the fourth protocol is configured to manage the ICS based on the second protocol and the third protocol.