Network Analysis for Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security configurations and monitoring tools fail to leverage the deterministic characteristics of industrial control systems, leading to inefficiencies in setting up and maintaining security measures, particularly in detecting new or modified attacks and missing traffic patterns.

Innovation Solution

A method and system that automatically generate a model of expected communication in control system networks based on available system information, configure security measures, and monitor for the absence of expected traffic, using explicit and implicit data extraction from system description data to determine security parameters for firewalls, intrusion detection, and missing traffic detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based IDS is used to detect known attacks, then detection accuracy for known attacks is improved, but the system cannot detect new or modified attacks and produces false negatives for unknown threats

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by automatically generating a communication model during system commissioning, before actual operation begins. This model captures all expected communication patterns, protocols, and data flows, enabling the security system to detect deviations from normal behavior without requiring pre-existing signatures for every possible attack scenario

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of detecting attacks by matching known attack signatures (traditional approach), the patent inverts the approach by first establishing what normal communication looks like through automated modeling, then detecting any deviation from this modeled normal behavior as potential attacks. This allows detection of both known and unknown attacks without relying on pre-existing attack signatures

Inventive Principle:
Principle #13The other way round (Inversion)

2Adaptability or versatility

If statistical modeling is used to detect deviations from normal behavior, then new attacks can be detected, but the system produces too many false alarms when rare legitimate events occur

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by automatically generating a communication model during system commissioning, before actual operation begins. This model captures all expected communication patterns, protocols, and data flows, enabling the security system to detect deviations from normal behavior without requiring pre-existing signatures for every possible attack scenario

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses self-service by automatically generating its own communication model from system design information without requiring manual input or learning phases. The automated model generation process captures rare legitimate events during the modeling phase, ensuring they are recognized as normal behavior and do not trigger false alarms during operation

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If manual configuration of security measures is performed, then security policies can be customized, but the workload for commissioning engineers and operators increases significantly

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoidcommissioning efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system uses self-service by automatically generating security configuration data from system design information. The automated process extracts communication patterns, identifies security requirements, and generates configuration files for firewalls and IDS without requiring manual security expert intervention, thereby maintaining customization while dramatically reducing commissioning workload

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary automated tool that acts as a mediator between system design information and security configuration requirements. This tool translates technical system specifications into security configuration data, eliminating the need for manual translation by security experts while ensuring accurate and consistent security policies

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If firewalls and IDS are configured with comprehensive rules to cover all attack scenarios, then security coverage is improved, but the complexity of configuration and maintenance increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies taking out by extracting the complexity of security configuration from manual processes and embedding it automatically into the system commissioning workflow. The automated model generation and configuration generation processes handle the complex analysis and rule creation, leaving operators with simple validation and approval tasks while maintaining comprehensive security coverage

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2366241B1Network analysis
Publication Date: 2018.07.25 ABB RES LTD
  • EP2366241B1 patent drawingFigure 1
  • EP2366241B1 patent drawingFigure 2
  • EP2366241B1 patent drawingFigure 3

AI summary

A technique for automatic analysis of a network, in which network specification information (11) is converted into a single intermediate representation (13) of the network. The intermediate representation can then be used to determine security parameters (21), and expected data traffic parameters (31).