Multilevel Intrusion Detection via Cross-Level Data Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intrusion detection systems for industrial automation and control systems are inadequate in detecting sophisticated cyber attacks, particularly those that manipulate process views or evade conventional signature-based malware detection methods, due to their reliance on assumptions about network traffic and inability to analyze measurements from multiple levels.
Innovation Solution
A multilevel intrusion detection system that utilizes software agents at different levels of the control network to collect and correlate data, transforming fieldbus protocols into more conducive communication protocols for analysis, enabling robust and efficient detection of cyber attacks by identifying anomalies through limit-based, change-based, and correlation-based methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If passive intrusion detection and deep-packet-inspection methods are used, then detection coverage is improved, but detection reliability deteriorates because these methods rely on assumptions that received traffic corresponds to actual observed traffic, which can be manipulated by attackers
Solution Approach 1:
The patent transitions from single-level network traffic analysis to multilevel analysis by collecting measurements from multiple control levels (fieldbus, controller, supervisory). This dimensional expansion allows the system to detect attacks that manipulate traffic at any single level by comparing consistency across levels, thereby resolving the contradiction between coverage and reliability.
Solution Approach 2:
The system implements feedback mechanisms where measurements from different control levels are continuously correlated and compared. When inconsistencies are detected between expected and actual measurements across levels, the system triggers alerts. This feedback loop enhances reliability by validating traffic authenticity through cross-level consistency checks.
2Ease of operation
If signature-based malware detection methods are used, then ease of operation is improved, but detection precision deteriorates because sophisticated attacks are camouflaged under normal network traffic and hidden inside legitimate systems
Solution Approach 1:
The patent segments the detection approach into multiple independent measurement collection points at different control levels. Each segment collects and analyzes measurements locally, then the results are correlated. This segmentation allows the system to maintain operational simplicity at each level while achieving high detection precision through collective analysis, overcoming the limitations of signature-based methods.
Solution Approach 2:
The patent introduces an intermediary correlation mechanism that compares measurements from multiple control levels. This intermediary layer analyzes consistency between levels without requiring complex signature databases, maintaining ease of operation while significantly improving detection precision by identifying anomalies that evade signature-based detection.
3Measurement precision
If data is collected from multiple control levels, then detection precision is improved, but device complexity increases due to the need for software agents at different levels and data transformation from fieldbus protocols
Solution Approach 1:
The patent employs universal software agents that can be deployed across different control levels and device types. These agents perform multiple functions: collecting measurements, transforming fieldbus protocols to standardized formats, and performing local analysis. This multi-functionality reduces overall system complexity by using a unified approach across diverse components while maintaining high detection precision.
Solution Approach 2:
The system uses standardized data representations and protocol transformations that create copyable, interoperable data formats across different control levels. By transforming fieldbus protocols into standardized formats, the system enables easy replication and correlation of measurements without dealing with protocol-specific complexities, thereby reducing device complexity while preserving detection precision.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method is disclosed for multilevel intrusion detection in an automation and control system. Two or more intrusion detection units are placed in the automation and control system at different control levels of the system, including a field bus control level and a direct control level. Control data associated with a field device of the automation and control system is collected by the intrusion detection units. The collected data is correlated, and an anomaly is detected based on the correlation. An intrusion detection may be identified in response to the detected anomaly.