ML Security Intelligence Correlating OT and IT Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems for operational technology (OT) environments lack accurate and actionable security monitoring and event-activity correlation tools, leading to false positive and false negative security alerts, which waste resources and hinder the detection of actual security issues due to their focus on IT aspects without considering the cyber-physical impact on industrial processes.
Innovation Solution
A machine learning model is trained with historical OT and IT data to generate a trained model that processes real-time data to determine trust and risk scores, providing actionable security intelligence by correlating network communications with physical process conditions, thereby reducing false alerts and improving response times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cybersecurity systems focus on IT aspects for security monitoring, then security alert generation is enabled, but false positive and false negative alerts increase, wasting resources and hindering detection of actual security issues
Solution Approach 1:
The patent merges IT data and OT data into a unified security monitoring system. The security system correlates network communication events with physical process conditions by integrating data from both IT infrastructure and OT operational processes, enabling more accurate security assessment that reduces false alerts and resource waste.
Solution Approach 2:
The system changes the parameters used for security assessment by incorporating OT-specific parameters (physical process conditions, operational technology events) alongside traditional IT security parameters. This multi-dimensional parameter approach transforms security monitoring from IT-only to a combined IT-OT framework, improving alert accuracy.
2Reliability
If cybersecurity systems monitor only IT network communications, then network security is protected, but cyber-physical impact on industrial processes cannot be detected
Solution Approach 1:
The patent combines IT network monitoring capabilities with OT process monitoring into a single security system. The system simultaneously processes network communication events and physical process conditions, correlating them to detect security issues that have cyber-physical impact while maintaining a unified architecture.
Solution Approach 2:
The security system acts as an intermediary that correlates and integrates data from IT and OT domains. It mediates between network security events and operational technology events, using correlation logic to connect disparate data sources and provide comprehensive security intelligence without requiring complete system restructuring.
3Reliability
If security systems generate multiple security alerts for potential threats, then threat detection coverage is improved, but resource consumption increases and response efficiency decreases
Solution Approach 1:
The system changes alert generation parameters by incorporating OT operational context into the alerting logic. Instead of generating alerts based solely on IT security events, the system evaluates multiple parameters including physical process conditions, operational state, and correlated event patterns, generating alerts only when genuine threats are identified.
Solution Approach 2:
The security system implements feedback mechanisms where alert generation is influenced by correlated data from both IT and OT domains. The system continuously monitors and adjusts alert generation based on the correlation between network events and operational conditions, reducing false positives and improving response efficiency through intelligent filtering.
Data Source
AI summary
A device may receive historical operational technology data and historical information technology data associated with historical systems and may train a machine learning model with the historical operational technology data and the historical information technology data to generate a trained machine learning model. The device may receive real-time operational technology data and real-time information technology data associated with a system and may process the real-time operational technology data and the real-time information technology data, with the trained machine learning model, to determine a trust score and a risk score for an event or set of events associated with the real-time operational technology data and the real-time information technology data. The device may perform one or more actions based on the trust score and the risk score.


