Intrusion Detection Device Whitelist Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems in industrial control systems struggle to detect attacks when normal communication patterns, defined by device-specific whitelists, result in abnormal operations due to the inability to account for combined device states.

Innovation Solution

An intrusion detection device that includes a state detection section to identify device states, a selection section to choose the appropriate whitelist based on these states, and an attack detection section to detect anomalies using the selected whitelist.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If device-specific whitelists are used to define normal communication, then false positives are reduced, but attacks combining multiple device communications are undetected

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem operation safety
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the monolithic whitelist approach into multiple device-specific whitelists, each managing communication rules for individual devices. This segmentation allows precise control per device while enabling comprehensive multi-device attack detection through coordinated whitelist evaluation across all devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal detection framework that evaluates communication against multiple device-specific whitelists simultaneously. This multi-functional approach enables the system to detect both single-device anomalies and multi-device coordinated attacks using a unified detection mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If communication is monitored using device-specific whitelists, then normal device communication is permitted, but coordinated attacks across multiple devices are missed

Engineering Contradiction:
Improvenormal communication flowVSAvoidattack pattern detection
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent merges multiple device-specific whitelist evaluations into a coordinated detection process. By combining the results of whitelist checks across all devices, the system identifies coordinated attacks that individual device monitoring would miss, while maintaining smooth normal communication flow.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If a single whitelist is used for all devices, then system complexity is reduced, but detection accuracy for multi-device attacks decreases

Engineering Contradiction:
Improvewhitelist management complexityVSAvoidattack detection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the whitelist system into device-specific components, improving detection precision for multi-device attacks. The segmentation is managed through automated coordination logic that handles the complexity of multiple whitelists without significantly increasing operational burden.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic coordination between multiple whitelists, where the detection process adapts based on the states of multiple devices. This dynamic evaluation enables precise attack detection while the system automatically manages the complexity of coordinating multiple device-specific rules.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11089033B2Intrusion detection device, intrusion detection method, and computer readable medium
Publication Date: 2021.08.10 MITSUBISHI ELECTRIC CORP
  • US11089033B2 patent drawing
  • US11089033B2 patent drawing
  • US11089033B2 patent drawing

AI summary

A state detection section (105) detects states of a plurality of controllers (300, 400) included in a communication system (600). An attack determination section (103) selects, from among a plurality of whitelists (110) each of which is associated with a combination of states, a whitelist (110) associated with the combination of the states of the plurality of controllers (300, 400) detected by the state detection section (105). The attack determination section (103) detects an attack on the communication system (600) by using the selected whitelist (110).