IDS Inspection Delay Compensation for TSN Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Time-synchronized networks face challenges in maintaining precise synchronization due to the introduction of latency caused by intrusion detection systems (IDS) that inspect and correct protocol messages, leading to unpredictable delays and potential desynchronization of nodes and applications.
Innovation Solution
Implementing techniques to account for inspection delays by measuring and adjusting the inference time associated with security measures within the IDS, such as adding the inspection time to a correction field in protocol messages or reporting it out-of-band, to ensure accurate synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If intrusion detection systems inspect and correct protocol messages to enhance security, then security against attacks is improved, but synchronization precision deteriorates due to inspection delays
Solution Approach 1:
The system performs preliminary actions by measuring the inspection delay before the synchronization message reaches the destination node. The IDS records the time it takes to inspect the message and communicates this delay information to the destination node, allowing the node to compensate for the delay in advance when calculating synchronization timing.
Solution Approach 2:
The system implements feedback by communicating the inspection delay information from the IDS back to the destination node. This feedback loop allows the destination node to adjust its timing calculations based on the actual delay introduced by security inspection, ensuring accurate synchronization despite the security measures in place.
2Reliability
If intrusion detection systems are deployed to detect security attacks, then security monitoring is improved, but message delivery time increases due to inspection processes
Solution Approach 1:
The system uses an intermediary approach by introducing a delay measurement message that travels through the IDS along with the synchronization message. This intermediary mechanism allows the system to measure and account for the inspection delay without requiring the IDS to slow down its inspection process, as the delay is measured and compensated rather than eliminated.
3Difficulty of detecting and measuring
If protocol messages are inspected for security attacks, then detection capability is improved, but synchronization accuracy deteriorates due to unpredictable delays
Solution Approach 1:
The system performs preliminary measurement of the inspection delay by having the IDS record the time it takes to inspect each message. This preliminary action allows the destination node to know exactly how much time was spent on security inspection, enabling it to compensate for this delay when calculating synchronization timing, thus maintaining synchronization accuracy despite the inspection process.
Data Source
AI summary
Techniques include receiving a message with time information at an ingress queue for an ingress interface of an intrusion detection system (IDS), the IDS to monitor a network node of a time-synchronized network (TSN), generating an entrance timestamp for the message, the entrance timestamp to comprise a time value representing when the message is received at the ingress queue of the ingress interface of the IDS, inspecting the message for indications of a security attack by the IDS, generating an exit timestamp for the message, the exit timestamp to comprise a time value representing when the message is received at an egress queue of an egress interface of the IDS, and generating an inspection time interval associated with the IDS, the inspection time interval to represent a time interval between the entrance timestamp and the exit timestamp for the message while transiting the IDS. Other embodiments are described and claimed.


