ML Security Intelligence Correlating OT and IT Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems for operational technology (OT) environments lack accurate and actionable security monitoring and event-activity correlation tools, leading to false positive and false negative security alerts, which waste resources and hinder the detection of actual security issues due to their focus on IT aspects without considering the cyber-physical impact on industrial processes.

Innovation Solution

A machine learning model is trained with historical OT and IT data to generate a trained model that processes real-time data to determine trust and risk scores, providing actionable security intelligence by correlating network communications with physical process conditions, thereby reducing false alerts and improving response times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity systems focus on IT aspects for security monitoring, then security alert generation is enabled, but false positive and false negative alerts increase, wasting resources and hindering detection of actual security issues

Engineering Contradiction:
Improvesecurity alert accuracyVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges IT data and OT data into a unified security monitoring system. The security system correlates network communication events with physical process conditions by integrating data from both IT infrastructure and OT operational processes, enabling more accurate security assessment that reduces false alerts and resource waste.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system changes the parameters used for security assessment by incorporating OT-specific parameters (physical process conditions, operational technology events) alongside traditional IT security parameters. This multi-dimensional parameter approach transforms security monitoring from IT-only to a combined IT-OT framework, improving alert accuracy.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If cybersecurity systems monitor only IT network communications, then network security is protected, but cyber-physical impact on industrial processes cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines IT network monitoring capabilities with OT process monitoring into a single security system. The system simultaneously processes network communication events and physical process conditions, correlating them to detect security issues that have cyber-physical impact while maintaining a unified architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system acts as an intermediary that correlates and integrates data from IT and OT domains. It mediates between network security events and operational technology events, using correlation logic to connect disparate data sources and provide comprehensive security intelligence without requiring complete system restructuring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security systems generate multiple security alerts for potential threats, then threat detection coverage is improved, but resource consumption increases and response efficiency decreases

Engineering Contradiction:
Improvethreat detection coverageVSAvoidresponse efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system changes alert generation parameters by incorporating OT operational context into the alerting logic. Instead of generating alerts based solely on IT security events, the system evaluates multiple parameters including physical process conditions, operational state, and correlated event patterns, generating alerts only when genuine threats are identified.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security system implements feedback mechanisms where alert generation is influenced by correlated data from both IT and OT domains. The system continuously monitors and adjusts alert generation based on the correlation between network events and operational conditions, reducing false positives and improving response efficiency through intelligent filtering.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11870788B2Utilizing a machine learning model to determine real-time security intelligence based on operational technology data and information technology data
Publication Date: 2024.01.09 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11870788B2 patent drawing
  • US11870788B2 patent drawing
  • US11870788B2 patent drawing

AI summary

A device may receive historical operational technology data and historical information technology data associated with historical systems and may train a machine learning model with the historical operational technology data and the historical information technology data to generate a trained machine learning model. The device may receive real-time operational technology data and real-time information technology data associated with a system and may process the real-time operational technology data and the real-time information technology data, with the trained machine learning model, to determine a trust score and a risk score for an event or set of events associated with the real-time operational technology data and the real-time information technology data. The device may perform one or more actions based on the trust score and the risk score.