Industrial Event Aggregation for Cyber Anomaly Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems face vulnerabilities to cyber threats due to network access, compromising safety and security, and conventional methods for analyzing security events are tedious and prone to human error.
Innovation Solution
A system and method for aggregating and normalizing event data from various sources in industrial automation systems, integrating context information, and using deterministic algorithms and AI to identify anomalies, enabling automated responses to mitigate security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network access is provided to control plane for remote monitoring, then operational efficiency and safety are improved, but vulnerability to cyber threats increases
Solution Approach 1:
The system segments security event analysis into automated components that process different types of events through specialized algorithms. The analytics engine divides security monitoring into multiple analysis streams handling authentication events, network traffic, device status, and other security-relevant data separately, then integrates findings to provide comprehensive threat detection while maintaining operational efficiency.
Solution Approach 2:
The patent introduces an intermediary analytics engine that sits between the networked control plane and the industrial automation devices. This intermediary layer provides remote monitoring capabilities while filtering and analyzing security events before they reach the control systems, thereby maintaining productivity benefits while reducing cyber threat vulnerability through automated security analysis.
2Measurement precision
If manual analysis of security events is performed, then detection accuracy can be maintained, but time consumption and human error increase
Solution Approach 1:
The system implements self-service through automated algorithms that independently analyze security events without requiring continuous human intervention. The analytics engine autonomously processes authentication events, network traffic patterns, and device status changes, performing security analysis automatically while maintaining detection accuracy and reducing time consumption associated with manual review.
Solution Approach 2:
The patent replaces manual mechanical analysis with automated computational algorithms. Deterministic algorithms analyze structured security events while AI algorithms handle unstructured data and pattern recognition, substituting human analysts with automated systems that provide equivalent or superior detection accuracy while eliminating time consumption and human error associated with manual analysis.
3Reliability
If multiple data sources are integrated for comprehensive analysis, then detection capability is improved, but system complexity increases
Solution Approach 1:
The analytics engine is designed with multi-functionality to handle diverse data sources including authentication events, network traffic, device status, and unstructured logs through a single unified platform. This universal approach improves detection capability by comprehensively analyzing multiple data types while managing system complexity through integrated processing rather than separate specialized systems.
Solution Approach 2:
The system manages complexity by dynamically adjusting analysis parameters based on data source characteristics. Deterministic algorithms process structured parameters efficiently while AI algorithms handle unstructured data with adaptive parameter tuning. This parameter-based approach enables comprehensive multi-source analysis while maintaining manageable system complexity through flexible, configurable processing.
Data Source
AI summary
Technology disclosed herein describes a system and method for aggregating event information in an industrial automation system for analysis and response. In an implementation, industrial automation devices perform industrial automation processes in an industrial automation environment. A computing device receives event data relating to events that occurred on an associated industrial automation device of the industrial automation devices. The computing device normalizes the event data to generate normalized event data which describes the events. The computing device supplements the normalized event data with context information relevant to the associated industrial automation device to generate complete event data. The computing device identifies an anomaly for an industrial automation device of the industrial automation devices based on analyzing the complete event data associated with the industrial automation device. In response to identifying an anomaly, the computing device performs an action to mitigate damage from the anomaly.


