Intrusion Detection Device Whitelist Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional intrusion detection systems in industrial control systems struggle to detect attacks when normal communication patterns, defined by device-specific whitelists, result in abnormal operations due to the inability to account for combined device states.
Innovation Solution
An intrusion detection device that includes a state detection section to identify device states, a selection section to choose the appropriate whitelist based on these states, and an attack detection section to detect anomalies using the selected whitelist.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If device-specific whitelists are used to define normal communication, then false positives are reduced, but attacks combining multiple device communications are undetected
Solution Approach 1:
The patent segments the monolithic whitelist approach into multiple device-specific whitelists, each managing communication rules for individual devices. This segmentation allows precise control per device while enabling comprehensive multi-device attack detection through coordinated whitelist evaluation across all devices.
Solution Approach 2:
The patent creates a universal detection framework that evaluates communication against multiple device-specific whitelists simultaneously. This multi-functional approach enables the system to detect both single-device anomalies and multi-device coordinated attacks using a unified detection mechanism.
2Ease of operation
If communication is monitored using device-specific whitelists, then normal device communication is permitted, but coordinated attacks across multiple devices are missed
Solution Approach 1:
The patent merges multiple device-specific whitelist evaluations into a coordinated detection process. By combining the results of whitelist checks across all devices, the system identifies coordinated attacks that individual device monitoring would miss, while maintaining smooth normal communication flow.
3Device complexity
If a single whitelist is used for all devices, then system complexity is reduced, but detection accuracy for multi-device attacks decreases
Solution Approach 1:
The patent segments the whitelist system into device-specific components, improving detection precision for multi-device attacks. The segmentation is managed through automated coordination logic that handles the complexity of multiple whitelists without significantly increasing operational burden.
Solution Approach 2:
The patent introduces dynamic coordination between multiple whitelists, where the detection process adapts based on the states of multiple devices. This dynamic evaluation enables precise attack detection while the system automatically manages the complexity of coordinating multiple device-specific rules.
Data Source
AI summary
A state detection section (105) detects states of a plurality of controllers (300, 400) included in a communication system (600). An attack determination section (103) selects, from among a plurality of whitelists (110) each of which is associated with a combination of states, a whitelist (110) associated with the combination of the states of the plurality of controllers (300, 400) detected by the state detection section (105). The attack determination section (103) detects an attack on the communication system (600) by using the selected whitelist (110).


