Multilevel Intrusion Detection via Cross-Level Data Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems for industrial automation and control systems are inadequate in detecting sophisticated cyber attacks, particularly those that manipulate process views or evade conventional signature-based malware detection methods, due to their reliance on assumptions about network traffic and inability to analyze measurements from multiple levels.

Innovation Solution

A multilevel intrusion detection system that utilizes software agents at different levels of the control network to collect and correlate data, transforming fieldbus protocols into more conducive communication protocols for analysis, enabling robust and efficient detection of cyber attacks by identifying anomalies through limit-based, change-based, and correlation-based methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If passive intrusion detection and deep-packet-inspection methods are used, then detection coverage is improved, but detection reliability deteriorates because these methods rely on assumptions that received traffic corresponds to actual observed traffic, which can be manipulated by attackers

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transitions from single-level network traffic analysis to multilevel analysis by collecting measurements from multiple control levels (fieldbus, controller, supervisory). This dimensional expansion allows the system to detect attacks that manipulate traffic at any single level by comparing consistency across levels, thereby resolving the contradiction between coverage and reliability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system implements feedback mechanisms where measurements from different control levels are continuously correlated and compared. When inconsistencies are detected between expected and actual measurements across levels, the system triggers alerts. This feedback loop enhances reliability by validating traffic authenticity through cross-level consistency checks.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If signature-based malware detection methods are used, then ease of operation is improved, but detection precision deteriorates because sophisticated attacks are camouflaged under normal network traffic and hidden inside legitimate systems

Engineering Contradiction:
Improvedetection simplicityVSAvoidattack detection precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the detection approach into multiple independent measurement collection points at different control levels. Each segment collects and analyzes measurements locally, then the results are correlated. This segmentation allows the system to maintain operational simplicity at each level while achieving high detection precision through collective analysis, overcoming the limitations of signature-based methods.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary correlation mechanism that compares measurements from multiple control levels. This intermediary layer analyzes consistency between levels without requiring complex signature databases, maintaining ease of operation while significantly improving detection precision by identifying anomalies that evade signature-based detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If data is collected from multiple control levels, then detection precision is improved, but device complexity increases due to the need for software agents at different levels and data transformation from fieldbus protocols

Engineering Contradiction:
Improveattack detection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs universal software agents that can be deployed across different control levels and device types. These agents perform multiple functions: collecting measurements, transforming fieldbus protocols to standardized formats, and performing local analysis. This multi-functionality reduces overall system complexity by using a unified approach across diverse components while maintaining high detection precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses standardized data representations and protocol transformations that create copyable, interoperable data formats across different control levels. By transforming fieldbus protocols into standardized formats, the system enables easy replication and correlation of measurements without dealing with protocol-specific complexities, thereby reducing device complexity while preserving detection precision.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3607484B1Multilevel intrusion detection in automation and control systems
Publication Date: 2021.06.30 SIEMENS MOBILITY GMBH
  • EP3607484B1 patent drawingFigure 1
  • EP3607484B1 patent drawingFigure 2
  • EP3607484B1 patent drawingFigure 3

AI summary

A system and method is disclosed for multilevel intrusion detection in an automation and control system. Two or more intrusion detection units are placed in the automation and control system at different control levels of the system, including a field bus control level and a direct control level. Control data associated with a field device of the automation and control system is collected by the intrusion detection units. The collected data is correlated, and an anomaly is detected based on the correlation. An intrusion detection may be identified in response to the detected anomaly.