Network Security Agent Payload Compression for ICS Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICSs) in modern industrial plants are increasingly exposed to security threats due to their integration with enterprise network systems, leading to potential significant downtime and liability, as malware damage can amplify across interconnected manufacturing components.

Innovation Solution

A network agent, referred to as the Octopus agent, is configured to evaluate and compress 'surprise-free' payload fields in industrial protocol packets, reducing unnecessary traffic to Intrusion Detection Systems (IDS) hubs, using a packet payload compressor and field compression category set to identify and compress expected field values, thereby minimizing network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all ICS network traffic is mirrored to the IDS hub for security monitoring, then malware detection capability is improved, but network traffic volume and processing overhead increase significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidnetwork traffic volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential payload fields from IndProt packets that are necessary for malware detection, rather than mirroring complete packet traffic. The network agent identifies and extracts specific payload fields based on evaluation criteria, sending only these extracted fields to the IDS hub for analysis, thereby reducing traffic volume while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the packet payload into evaluated fields and non-evaluated fields. Only the evaluated fields that meet specific criteria are extracted and transmitted to the IDS hub, while other fields are filtered out. This segmentation approach allows selective transmission of critical data elements, reducing overall traffic volume.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If conventional network agents transmit complete packet payloads to IDS hubs, then detection accuracy is maintained, but network bandwidth consumption and processing load increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by evaluating different payload fields according to their specific characteristics and detection requirements. Each field is assessed against criteria such as whether it contains expected values or shows signs of malware. Only fields that meet the evaluation criteria are extracted and transmitted, ensuring that detection accuracy is maintained for critical fields while reducing bandwidth consumption by filtering out non-essential fields.

Inventive Principle:
Principle #3Local quality

3Quantity of substance

If the network agent evaluates and compresses surprise-free payload fields, then network traffic volume is reduced, but agent complexity increases

Engineering Contradiction:
Improvenetwork traffic volumeVSAvoidagent complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining evaluation criteria and field extraction rules in the network agent. The agent is configured with predetermined conditions for identifying surprise-free fields and rules for extracting specific payload fields. This preliminary configuration enables automated evaluation and compression without requiring complex real-time decision-making, reducing agent complexity while achieving traffic volume reduction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9854069B2Network security agent
Publication Date: 2017.12.26 RADIFLOW
  • US9854069B2 patent drawing
  • US9854069B2 patent drawing
  • US9854069B2 patent drawing

AI summary

A network apparatus comprising: a packet payload compressor (PPC) operable to: receive a packet copied from a network, the packet comprising a source, destination, and a payload; extract a value of a field comprised in the payload; provide a computed value of the field based on the source and destination of the packet; compare the extracted value and the computed value; and compress the field if the extracted value is the same as the computed value, and a traffic shaper operable to transmit a compressed packet comprising the compressed field.