Unsupervised Network Anomaly Detection for Industrial Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial security measures are inadequate in protecting against electronic and telecommunication-based attacks, particularly failing to detect new and unknown attack patterns, and are prone to false positives.

Innovation Solution

The implementation of unsupervised machine learning techniques that utilize predictive models of normal industrial network behavior to detect anomalies and identify potential attacks without relying on known attack patterns, using autoencoding and principal component analysis to generate reconstruction error thresholds for real-time attack detection and source identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security techniques rely on knowledge of known attacks with predefined patterns (signatures), then they can protect against known attacks, but they are unable to detect new and unknown attacks with unknown patterns

Engineering Contradiction:
Improveprotection against known attacksVSAvoiddetection of unknown attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of training the system to recognize known attack patterns (supervised learning), the patent inverts the approach by training the system to learn normal network behavior patterns and then detecting deviations from this baseline. This unsupervised learning approach enables detection of unknown attacks without requiring prior knowledge of attack signatures.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs self-learning by automatically establishing a baseline of normal network behavior through continuous monitoring and analysis. The machine learning model autonomously identifies patterns in normal traffic and uses this self-acquired knowledge to detect anomalies, eliminating the need for manual programming of attack signatures.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security systems continuously monitor and analyze network traffic to detect attacks, then detection capability improves, but false positives increase due to short term fluctuations and long term changes

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system dynamically adapts to changing network conditions by continuously updating its understanding of normal behavior. The machine learning model evolves with the network, adjusting to long-term changes in traffic patterns while maintaining sensitivity to short-term anomalies that indicate attacks, thereby reducing false positives.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where detection results and ongoing traffic analysis continuously refine the baseline model. This feedback loop allows the system to distinguish between legitimate variations in network behavior and actual attack patterns, improving accuracy while minimizing false alarms.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11457026B2Systems and methods for securing industrial networks
Publication Date: 2022.09.27 NOKIA SOLUTIONS & NETWORKS OY
  • US11457026B2 patent drawing
  • US11457026B2 patent drawing
  • US11457026B2 patent drawing

AI summary

Network-based, unsupervised classifiers are provided. The classifiers identify both known and unknown attacks aimed at industrial networks without the need to have a priori knowledge of known malicious attack patterns.