Kernel-Level Event Logging for ICS Data Provenance and Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in monitoring and detecting cybersecurity threats due to complex network configurations and the intertwining of operational technology and IT networks, which can lead to difficulties in tracing security events and detecting anomalies in real-time.

Innovation Solution

Generating a time-ordered event data stream that captures kernel-level events across different types of computing devices, allowing for real-time monitoring and analysis of security threats by detecting events in the kernel space and transmitting them to a remote server for aggregation and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If kernel-level events are monitored and logged across different computing devices, then data provenance and security threat detection capability are improved, but system complexity and processing burden increase

Engineering Contradiction:
Improvesecurity event detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a logging agent as an intermediary component that operates at the user space level to capture and log kernel-level events. This agent acts as a mediator between the kernel space and the analysis system, allowing detailed security monitoring without requiring direct kernel modification or increasing kernel space complexity. The logging agent intercepts and records events such as process creation, file access, and network connections, providing comprehensive security visibility while maintaining system architecture simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time monitoring of kernel-level events is implemented, then response time to security threats is improved, but processing burden and resource consumption increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidprocessing resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements selective logging of only relevant security-critical events rather than monitoring all kernel events. The logging agent filters and captures specific events such as process creation, file system access, registry modifications, and network connections that are most indicative of security threats. This partial monitoring approach enables real-time threat detection while significantly reducing processing overhead and resource consumption compared to comprehensive event logging.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If detailed logging of security events is performed, then forensic analysis capability is improved, but data volume and storage requirements increase

Engineering Contradiction:
Improvesecurity event information completenessVSAvoidlog data volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent applies different logging strategies to different event types and system components based on their security relevance. Critical security events such as process creation, file access to sensitive resources, and network connections are logged with high detail including timestamps, process identifiers, and contextual information. Less critical events are logged with reduced detail or not logged at all. This differentiated logging approach ensures complete forensic information for security-relevant events while minimizing overall data volume and storage requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4022405B1Systems and methods for enhancing data provenance by logging kernel-level events
Publication Date: 2024.05.15 FIRST WATCH LIMITED
  • EP4022405B1 patent drawingFigure 1A
  • EP4022405B1 patent drawingFigure 1B
  • EP4022405B1 patent drawingFigure 1C

AI summary

The present disclosure generally relates to capturing events of interest relevant to security and data provenance within a cyber-physical system. The present disclosure also relates to systems and methods for monitoring, capturing, logging, analyzing, and reporting of kernel-level events. Systems and methods for generating a time-ordered event data stream of kernel-level events captured across different types of computing devices (e.g., devices running operating systems and devices running real-time operating systems) included in an industrial control system, are described.