ICS Cybersecurity Platform for Legacy PLC Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems, particularly those involving legacy devices like PLCs, face security issues due to vulnerabilities in communication networks, which can lead to unauthorized access and malicious activities.
Innovation Solution
A cybersecurity platform is introduced that includes an anomaly detection module with dynamic port connection monitoring, network port scanning, system time monitoring, and intrusion event logging, along with an Industrial Security as a Service (SaaS) toolset for defining and delivering Public Key Infrastructure (PKI) keys, to detect and mitigate potential threats and ensure secure communications using the OPC UA standard.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If legacy PLCs and ICS devices are used for industrial control, then device compatibility and ease of operation are improved, but security vulnerabilities and susceptibility to unauthorized access increase
Solution Approach 1:
The patent introduces a cybersecurity platform as an intermediary component that sits between the legacy ICS devices and the network. This platform includes anomaly detection modules, port scanning modules, and intrusion event logging modules that monitor and protect communications without requiring changes to the legacy devices themselves, thus maintaining compatibility while adding security
2Reliability
If comprehensive security monitoring and anomaly detection are implemented, then security detection capability is improved, but system complexity and computational resources increase
Solution Approach 1:
The cybersecurity platform is divided into separate functional modules including anomaly detection modules, dynamic port connection monitoring modules, network port scanning modules, system time monitoring modules, and intrusion event logging modules. Each module performs a specific security function independently, making the overall system more manageable and easier to deploy on resource-constrained ICS devices
Solution Approach 2:
The cybersecurity platform is designed to perform multiple security functions simultaneously - anomaly detection, port monitoring, scanning detection, time manipulation detection, and intrusion logging - all within a single integrated system that can operate on legacy ICS devices without requiring multiple separate systems
3Reliability
If real-time anomaly detection and port monitoring are performed continuously, then security response time is improved, but energy consumption and processing load increase
Solution Approach 1:
The cybersecurity platform implements periodic scanning and monitoring cycles rather than continuous full-scale analysis. The port scanning module performs scans at scheduled intervals, and the anomaly detection modules analyze traffic in periodic batches, reducing peak processing loads and energy consumption while maintaining effective security monitoring
Solution Approach 2:
The system focuses monitoring resources on critical areas such as communication ports and system time, performing detailed analysis only where security risks are most likely to manifest. This partial monitoring approach concentrates computational energy on high-risk areas rather than uniformly analyzing all system traffic
Data Source
AI summary
A method of providing cyber security to an industrial control system is described. The method includes detecting an anomaly and recording and reporting the detected anomaly to a control system within a network associated with the industrial control system. Detecting the anomaly may include recording all unauthorized attempts to connect to a communication port in the network, capturing identifying information associated with the unauthorized attempts, detecting scanning activity of a hacker in the network, detecting an attempt to manipulate a log file to conceal malicious activity in the network; and recording and reporting the detected anomaly to a controller within the network


