Industrial Control Network Monitoring for Abnormal Behavior Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional industrial control systems are vulnerable to external network attacks due to increased connectivity, which can disrupt normal operations and cause damage to industrial devices, highlighting the need for effective network security monitoring to prevent and mitigate such threats.

Innovation Solution

A method and system for monitoring network security in industrial control systems by selecting relevant data sources, acquiring and analyzing data to establish behavior models, determining normal versus abnormal behavior, and triggering alarms based on predefined priority levels to address potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional industrial control systems are connected to external networks including the Internet, then the system can achieve better connectivity and communication capabilities, but the system becomes vulnerable to external network attacks that can tamper with control processes and cause damage to industrial devices

Engineering Contradiction:
Improvenetwork connectivityVSAvoidexternal network attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network security monitoring system as an intermediary component between the industrial control system and external networks. This monitoring system captures and analyzes network packets, establishing behavior models to detect abnormal activities and attacks before they can compromise the control system, thus enabling connectivity while mitigating attack risks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures by pre-establishing behavior models of normal industrial control system operations. These models are created before actual attacks occur, allowing the system to proactively identify and block abnormal behaviors and attacks, preventing damage before it happens

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network security monitoring is implemented to detect external attacks, then the system can identify possible network attacks and protect critical devices, but the monitoring system increases device complexity and requires additional resources

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the network security monitoring system to self-learn and automatically establish behavior models by analyzing normal operation data. The system uses machine learning algorithms to autonomously identify patterns and detect anomalies without requiring manual configuration of security rules, reducing operational complexity while maintaining high security reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the monitoring system continuously analyzes network traffic, compares it against established behavior models, and adjusts its detection parameters based on detected patterns. This feedback loop improves detection accuracy over time while automating the security monitoring process, reducing the need for manual intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11747799B2Industrial control system and network security monitoring method therefor
Publication Date: 2023.09.05 SIEMENS AG
  • US11747799B2 patent drawing
  • US11747799B2 patent drawing
  • US11747799B2 patent drawing

AI summary

The present invention relates to the technical field of industrial networks and information security, and in particular to an industrial control system and a network security monitoring method therefor, for effectively monitoring the network security of an industrial control system. The method comprises: selecting at least one first data source related to an industrial control system and acquiring first data therefrom; counting time-varying features of the first data to serve as a behavior model for the industrial control system; acquiring second data from some or all of the at least one first data source; and determining whether the second data has the features described by the behavior model, and if so, determining that the industrial control system exhibits normal behavior, and if not, determining that the industrial control system exhibits abnormal behavior. In consideration of the certainty of the behavior of the industrial control system, a system behavior model is obtained by means of counting. A judgement regarding an abnormal system behavior is made based on the relatively determined behavior model, so that the obtained determination result is more accurate.