Industrial Control System Anomaly Detection via Protocol Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security technologies are ineffective in monitoring network traffic and detecting compromised devices within industrial control systems due to undocumented network protocols, making these systems susceptible to attacks.

Innovation Solution

A computer-implemented method that monitors network traffic, creates a message protocol profile to describe normal communication patterns, detects anomalies, and determines if a device has been compromised by comparing messages with the profile, allowing for appropriate security actions to be taken.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security technologies are used to monitor network traffic, then security monitoring is performed, but the monitoring is ineffective due to undocumented network protocols

Engineering Contradiction:
Improveeffectiveness of security monitoringVSAvoiddetectability of compromised devices
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary action by creating a message protocol profile that captures normal communication patterns before security incidents occur. This profile serves as a baseline for future anomaly detection, enabling the system to proactively identify compromised devices rather than reacting to known threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The message protocol profile acts as an intermediary between the undocumented network protocol and the security monitoring system. By translating and characterizing protocol behavior into a profile format, the system can effectively monitor traffic without requiring access to proprietary protocol documentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network protocols are kept undocumented for security reasons, then system security is maintained, but conventional security technologies cannot detect suspicious behavior

Engineering Contradiction:
Improvesecurity of industrial control systemVSAvoidavailability of protocol information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies self-service by automatically learning and characterizing the network protocol through passive observation of communication patterns. Instead of requiring external protocol documentation or configuration, the system generates its own message protocol profile from observed traffic, enabling security monitoring without compromising protocol confidentiality.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If message protocol profiling is implemented to detect anomalies, then compromised devices can be identified, but system complexity increases

Engineering Contradiction:
Improvedetectability of anomaliesVSAvoidcomplexity of security system
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system replaces complex manual security analysis with automated computational processes. The message protocol profile creation and anomaly detection are performed automatically through software analysis of network traffic patterns, substituting mechanical expert review with algorithmic processing that scales efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9967274B2Systems and methods for identifying compromised devices within industrial control systems
Publication Date: 2018.05.08 CA TECH INC
  • US9967274B2 patent drawing
  • US9967274B2 patent drawing
  • US9967274B2 patent drawing

AI summary

The disclosed computer-implemented method for identifying compromised devices within industrial control systems may include (1) monitoring network traffic within a network that facilitates communication for an industrial control system that includes an industrial device, (2) creating, based at least in part on the network traffic, a message protocol profile for the industrial device that describes (A) a network protocol used to communicate with the industrial device and (B) normal communication patterns of the industrial device, (3) detecting at least one message that involves the industrial device and at least one other computing device included in the industrial control system, (4) determining, by comparing the message with the message protocol profile, that the message represents an anomaly, and then (5) determining, based at least in part on the message representing the anomaly, that the other computing device has likely been compromised. Various other methods, systems, and computer-readable media are also disclosed.