Network Security Agent Payload Compression for ICS Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICSs) in modern industrial plants are increasingly exposed to security threats due to their integration with enterprise network systems, leading to potential significant downtime and liability, as malware damage can amplify across interconnected manufacturing components.
Innovation Solution
A network agent, referred to as the Octopus agent, is configured to evaluate and compress 'surprise-free' payload fields in industrial protocol packets, reducing unnecessary traffic to Intrusion Detection Systems (IDS) hubs, using a packet payload compressor and field compression category set to identify and compress expected field values, thereby minimizing network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all ICS network traffic is mirrored to the IDS hub for security monitoring, then malware detection capability is improved, but network traffic volume and processing overhead increase significantly
Solution Approach 1:
The patent extracts only the essential payload fields from IndProt packets that are necessary for malware detection, rather than mirroring complete packet traffic. The network agent identifies and extracts specific payload fields based on evaluation criteria, sending only these extracted fields to the IDS hub for analysis, thereby reducing traffic volume while maintaining detection effectiveness.
Solution Approach 2:
The patent segments the packet payload into evaluated fields and non-evaluated fields. Only the evaluated fields that meet specific criteria are extracted and transmitted to the IDS hub, while other fields are filtered out. This segmentation approach allows selective transmission of critical data elements, reducing overall traffic volume.
2Measurement precision
If conventional network agents transmit complete packet payloads to IDS hubs, then detection accuracy is maintained, but network bandwidth consumption and processing load increase
Solution Approach 1:
The patent applies local quality by evaluating different payload fields according to their specific characteristics and detection requirements. Each field is assessed against criteria such as whether it contains expected values or shows signs of malware. Only fields that meet the evaluation criteria are extracted and transmitted, ensuring that detection accuracy is maintained for critical fields while reducing bandwidth consumption by filtering out non-essential fields.
3Quantity of substance
If the network agent evaluates and compresses surprise-free payload fields, then network traffic volume is reduced, but agent complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-defining evaluation criteria and field extraction rules in the network agent. The agent is configured with predetermined conditions for identifying surprise-free fields and rules for extracting specific payload fields. This preliminary configuration enables automated evaluation and compression without requiring complex real-time decision-making, reducing agent complexity while achieving traffic volume reduction.
Data Source
AI summary
A network apparatus comprising: a packet payload compressor (PPC) operable to: receive a packet copied from a network, the packet comprising a source, destination, and a payload; extract a value of a field comprised in the payload; provide a computed value of the field based on the source and destination of the packet; compare the extracted value and the computed value; and compress the field if the extracted value is the same as the computed value, and a traffic shaper operable to transmit a compressed packet comprising the compressed field.


