Multi-Domain IIoT Threat Detection via Alert Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems fail to effectively detect and identify advanced persistent threats (APTs) across multi-domain IIoT environments, particularly in networks that integrate information technology (IT) and operational technology (OT) domains, due to the complexity of multi-step, multi-domain attacks and the difficulty in correlating alerts across different domains.

Innovation Solution

The method involves receiving and classifying alerts from IT and OT domains using a cyber kill chain framework, determining dependencies between alerts, and generating a graphical visualization to predict potential attack paths, utilizing machine-learning algorithms and threat intelligence data to enrich and correlate alert data, thereby creating an adversary prediction model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security systems monitor multiple domains (IT and OT) separately using traditional methods, then domain-specific detection capability is maintained, but cross-domain attack detection capability deteriorates

Engineering Contradiction:
Improveattack detection capabilityVSAvoidmulti-domain detection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines IT and OT domain monitoring into a unified security system that ingests alerts from both domains simultaneously. The system merges previously siloed security operations centers into a single platform capable of processing and correlating alerts across domain boundaries, enabling detection of multi-domain attacks that span both IT and OT environments.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary alert correlation system that sits between IT and OT domain alerts and the analysis platform. This intermediary layer standardizes and enriches alerts from different domains before they are processed, enabling seamless cross-domain correlation without requiring direct integration between disparate IT and OT security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If traditional security systems process alerts from multiple domains, then alert volume increases, but analysis complexity and time consumption increase exponentially

Engineering Contradiction:
Improvethreat intelligence completenessVSAvoidalert analysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary enrichment of alerts with threat intelligence data, contextual information, and kill chain classifications before the alerts enter the main analysis pipeline. By pre-processing and structuring alert data in advance, the system reduces the computational burden during real-time correlation and analysis, enabling faster processing of multi-domain alert volumes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the alert analysis process into distinct stages: ingestion, enrichment, classification by kill chain phase, correlation, and visualization. This segmentation allows each component to specialize in specific tasks, improving overall processing efficiency and reducing the time required to analyze complex multi-domain attack patterns.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security systems use comprehensive alert correlation across IT and OT domains, then detection accuracy for advanced persistent threats improves, but system complexity increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidcorrelation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter space by classifying alerts according to phases of the cyber kill chain (reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives). This parameter transformation organizes complex multi-domain alerts into standardized phases, making correlation more manageable and reducing system complexity while improving detection reliability for advanced persistent threats.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If security analysts manually analyze alerts from multiple domains, then detailed investigation capability is maintained, but productivity and response time deteriorate

Engineering Contradiction:
Improvethreat analysis precisionVSAvoidthreat response productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual mechanical analysis processes with automated computational systems that perform alert correlation, kill chain classification, and attack path reconstruction. The system automatically generates visualizations of attack paths and correlates alerts across domains without requiring manual intervention, dramatically improving productivity while maintaining analytical precision through sophisticated algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11522882B2Detection of adversary lateral movement in multi-domain IIOT environments
Publication Date: 2022.12.06 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11522882B2 patent drawing
  • US11522882B2 patent drawing
  • US11522882B2 patent drawing

AI summary

Implementations are directed to methods for detecting and identifying advanced persistent threats (APTs) in networks, including receiving first domain activity data from a first network domain and second domain activity data from a second network domain, including multiple alerts from the respective first and second network domains and where each alert of the multiple alerts results from one or more detected events in the respective first or second network domains. A classification determined for each alert of the multiple alerts with respect to a cyber kill chain. A dependency is then determined for each of one or more pairs of alerts and a graphical visualization of the multiple alerts is generated, where the graphical visualization includes multiple nodes and edges between the nodes, each node corresponding to the cyber kill chain and representing at least one alert, and each edge representing a dependency between alerts.