Intrusion Detection System Context Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion detection systems in industrial automation and control systems often fail to detect malicious activities, especially when intruders are disgruntled employees with legitimate access or when physical infrastructure is tampered with, as they do not consider context information beyond network traffic patterns.

Innovation Solution

An Intrusion Detection System that integrates context information from workforce management, physical access control, and approved work orders to evaluate network traffic, determining deviations from expected behavior and adjusting security configurations based on up-to-date context data to identify suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Intrusion Detection Systems monitor only network traffic patterns, then the system complexity remains low, but the detection reliability decreases when intruders have legitimate access or tamper with physical infrastructure

Engineering Contradiction:
Improveintrusion detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple information sources including network traffic data, workforce management information, physical access control data, and work order systems into a unified intrusion detection framework. This merging of previously separate systems enables comprehensive intrusion detection that can identify threats even when intruders have legitimate access credentials, thereby improving detection reliability without proportionally increasing system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The intrusion detection system is designed to handle multiple types of security threats using a single unified platform that can analyze network traffic, verify physical presence, check workforce credentials, and validate work orders. This multi-functional approach allows the system to address various intrusion scenarios (disgruntled employees, physical tampering, authorized user abuse) without requiring separate specialized systems for each threat type

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If the IDS integrates multiple context information sources, then the measurement precision of intrusion detection improves, but the device complexity increases

Engineering Contradiction:
Improveintrusion detection precisionVSAvoidIDS complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the intrusion detection process into distinct functional modules: network traffic analysis module, workforce management integration module, physical access control integration module, and work order verification module. Each module processes specific types of information independently before combining results, which maintains high detection precision while managing system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces context information as an intermediary layer between network traffic monitoring and intrusion determination. This intermediary layer integrates data from workforce management, physical access control, and work order systems to provide additional verification context, thereby improving detection precision without directly increasing the core IDS complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system correlates extensive non-network information with network traffic, then false negative errors reduce, but information overload increases during emergencies

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation overload
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies partial verification by selectively checking context information based on the specific network traffic pattern and threat level. Not all context sources are evaluated for every network event - only relevant ones are queried and cross-checked. This partial action approach maintains high detection accuracy by verifying suspicious activities against appropriate context while avoiding information overload from unnecessary data retrieval and processing

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2656322B1Intrusion detection
Publication Date: 2021.08.25 ABB (SCHWEIZ) AG
  • EP2656322B1 patent drawingFigure 1
  • EP2656322B1 patent drawingFigure 2

AI summary

The present invention is concerned with an Intrusion Detection System (IDS) for an Industrial Automation and Control System (IACS) that takes into account context information representative of conditions or constellations beyond the limits of the IACS. The context information includes, but is not limited to, shift plans describing which work-force individuals should be active on the system, information from the physical access control describing which individuals have local access to different parts of the system and which individuals are physically present where in the system, approved work orders describing which individuals have permission to perform which functions in the system or configuration switches that describe different use scenarios the system may be in and for which rule sets should be applied.