Monitoring Control Apparatus for Cyberattack Detection Without State Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyberattack detection systems require the introduction of a state notification packet, making them difficult to implement as they necessitate additions or modifications to the entire system, which can be cumbersome.

Innovation Solution

A monitoring control system generates a state model based on control values and measurement values, allowing for cyberattack detection without receiving a state notification, thereby enabling detection without modifying the existing system infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a state notification packet function is incorporated into the server device and controller to detect cyberattacks, then attack detection capability is improved, but device complexity and ease of manufacture deteriorate due to required system modifications

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem modification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a monitoring control apparatus as an intermediary component that detects cyberattacks by monitoring communication data between the server device and controller, rather than requiring modifications to these core components. The monitoring apparatus generates state models based on normal communication patterns and detects deviations, serving as a separate detection layer that preserves the original system architecture while enabling attack detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the attack detection function from the core control system by implementing it as a separate monitoring control apparatus. This segmentation allows the detection function to be added independently without modifying the server device or controller, reducing the complexity burden on the main system while maintaining detection capability

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If existing attack detection functions with fixed detection rules are used, then ease of operation is improved, but adaptability deteriorates when facing new attack patterns

Engineering Contradiction:
Improvedetection rule simplicityVSAvoidattack pattern recognition flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic detection rules that automatically adapt to new attack patterns. The monitoring control apparatus generates state models based on observed communication data and updates detection rules dynamically. When new attack patterns emerge, the system learns from the communication data and adjusts its detection criteria, transitioning from static fixed rules to dynamic adaptive rules that evolve with the threat landscape

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the monitoring control apparatus continuously analyzes communication data, compares it against state models, and refines its detection rules based on observed patterns. The system uses feedback from detected anomalies and normal operations to continuously improve its detection capability, allowing it to adapt to new attack patterns while maintaining operational simplicity

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3731122B1Attack detection apparatus, attack detection method, and attack detection program
Publication Date: 2021.09.01 MITSUBISHI ELECTRIC CORP
  • EP3731122B1 patent drawingFigure 1
  • EP3731122B1 patent drawingFigure 2
  • EP3731122B1 patent drawingFigure 3

AI summary

A model generation unit (112) generates a state model that indicates a measurement value in each state of a monitoring target, based on a plurality of measurement values obtained by measuring the monitoring target. An integration unit (114) generates a detection rule that indicates communication information in each state of the monitoring target, based on pieces of communication data communicated by the monitoring target in a time period during which the plurality of measurement values are obtained. An attack detection unit (115) determines whether new communication data is attack data, using the state model and the detection rule.