Kernel-Level Event Logging for ICS Data Provenance and Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face challenges in monitoring and detecting cybersecurity threats due to complex network configurations and the intertwining of operational technology and IT networks, which can lead to difficulties in tracing security events and detecting anomalies in real-time.
Innovation Solution
Generating a time-ordered event data stream that captures kernel-level events across different types of computing devices, allowing for real-time monitoring and analysis of security threats by detecting events in the kernel space and transmitting them to a remote server for aggregation and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If kernel-level events are monitored and logged across different computing devices, then data provenance and security threat detection capability are improved, but system complexity and processing burden increase
Solution Approach 1:
The patent introduces a logging agent as an intermediary component that operates at the user space level to capture and log kernel-level events. This agent acts as a mediator between the kernel space and the analysis system, allowing detailed security monitoring without requiring direct kernel modification or increasing kernel space complexity. The logging agent intercepts and records events such as process creation, file access, and network connections, providing comprehensive security visibility while maintaining system architecture simplicity.
2Speed
If real-time monitoring of kernel-level events is implemented, then response time to security threats is improved, but processing burden and resource consumption increase
Solution Approach 1:
The patent implements selective logging of only relevant security-critical events rather than monitoring all kernel events. The logging agent filters and captures specific events such as process creation, file system access, registry modifications, and network connections that are most indicative of security threats. This partial monitoring approach enables real-time threat detection while significantly reducing processing overhead and resource consumption compared to comprehensive event logging.
3Loss of information
If detailed logging of security events is performed, then forensic analysis capability is improved, but data volume and storage requirements increase
Solution Approach 1:
The patent applies different logging strategies to different event types and system components based on their security relevance. Critical security events such as process creation, file access to sensitive resources, and network connections are logged with high detail including timestamps, process identifiers, and contextual information. Less critical events are logged with reduced detail or not logged at all. This differentiated logging approach ensures complete forensic information for security-relevant events while minimizing overall data volume and storage requirements.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
The present disclosure generally relates to capturing events of interest relevant to security and data provenance within a cyber-physical system. The present disclosure also relates to systems and methods for monitoring, capturing, logging, analyzing, and reporting of kernel-level events. Systems and methods for generating a time-ordered event data stream of kernel-level events captured across different types of computing devices (e.g., devices running operating systems and devices running real-time operating systems) included in an industrial control system, are described.