Kernel-Level Event Logging for ICS Data Provenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in monitoring and detecting cybersecurity threats in real-time due to complex network topologies and the intertwining of operational technology and IT networks, which can lead to significant economic and safety risks.

Innovation Solution

Generating a time-ordered event data stream that captures kernel-level events across different types of computing devices within an industrial control system, allowing for real-time monitoring and analysis of security threats by detecting events in the kernel space and transmitting them to a remote server for processing and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If kernel-level event logging is implemented across all computing devices in an industrial control system, then security monitoring capability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the industrial control network into multiple computing devices (PLCs, RTUs, HMIs, servers) and implements logging agents on each device independently. Each agent captures kernel-level events locally and transmits them to a centralized server, allowing granular security monitoring without requiring complete system redesign. This segmentation enables precise security tracking while maintaining individual device functionality and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized logging server acts as an intermediary that receives, aggregates, and processes kernel-level events from multiple computing devices. The server consolidates security-relevant events, correlates them across devices, and generates comprehensive security reports. This intermediary approach centralizes the complexity of security analysis while keeping individual computing devices relatively simple, resolving the contradiction between monitoring precision and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time kernel-level event capture is implemented, then threat detection speed is improved, but processing overhead and resource consumption increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidprocessing overhead
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The logging agents on each computing device are configured to capture only security-relevant kernel-level events (such as authentication attempts, file access, registry changes) rather than all system events. This selective event capture reduces processing overhead and resource consumption while maintaining fast threat detection capability for security-critical operations. The local quality principle ensures that each device processes only the events necessary for security monitoring.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial logging by focusing on specific kernel-level events that are most indicative of security threats, rather than logging all possible system events. The logging agents use predefined filters and monitoring rules to capture only relevant events (e.g., unauthorized access attempts, suspicious process executions). This partial action approach achieves fast threat detection for critical security events while minimizing processing overhead and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If comprehensive event logging is implemented across diverse computing devices, then data provenance is improved, but device compatibility and integration difficulty increase

Engineering Contradiction:
Improvedata provenanceVSAvoiddevice compatibility
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The logging server implements a universal event processing platform that can handle kernel-level events from multiple types of computing devices (PLCs, RTUs, HMIs, servers, workstations) with different operating systems and architectures. The system uses standardized event schemas and protocols to normalize events from diverse sources, enabling comprehensive data provenance tracking across the entire industrial control system while maintaining compatibility with various device types through a unified processing approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20220327219A1Systems and methods for enhancing data provenance by logging kernel-level events
Publication Date: 2022.10.13 FIRST WATCH LIMITED
  • US20220327219A1 patent drawing
  • US20220327219A1 patent drawing
  • US20220327219A1 patent drawing

AI summary

The present disclosure generally relates to capturing events of interest relevant to security and data provenance within a cyber-physical system. The present disclosure also relates to systems and methods for monitoring, capturing, logging, analyzing, and reporting of kernel-level events. Systems and methods for generating a time-ordered event data stream of kernel-level events captured across different types of computing devices (e.g., devices running operating systems and devices running real-time operating systems) included in an industrial control system, are described.