Industrial Network Switch Packet Classification for ICS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face security breaches and inefficiencies due to invalid or malicious communication packets, which can disrupt or damage the systems.

Innovation Solution

A network switch configured to enforce protocol constraints and use models to classify communication packets, intelligently routing them based on process behavioral analysis, and generating control actions to mitigate potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network switches are used in industrial control systems, then basic packet forwarding is achieved, but security vulnerabilities and system reliability deteriorate due to inability to identify malicious packets

Engineering Contradiction:
Improvesystem reliabilityVSAvoidmalicious packet impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces protocol constraint rules and process behavioral models as intermediary mechanisms between network packets and the industrial control system. These intermediaries analyze packet characteristics against predefined constraints and behavioral patterns to identify malicious packets before they reach the control system, thereby protecting system reliability without requiring changes to the control devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network switch performs preliminary analysis of communication packets by comparing packet characteristics against protocol constraints and process behavioral models before forwarding them to destination devices. This preliminary action identifies and blocks malicious packets in advance, preventing them from causing harm to the industrial control system while maintaining normal communication flow for valid packets.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If protocol constraints and behavioral models are enforced at the network switch, then security against malicious packets is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork switch complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security analysis function into distinct components: protocol constraint rules for syntax validation, process behavioral models for pattern recognition, and packet characteristic extraction. This segmentation allows the network switch to implement complex security checks through modular, manageable components rather than a monolithic complex system, facilitating easier configuration and maintenance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network switch implements feedback mechanisms where packet analysis results are used to dynamically adjust filtering decisions. The switch continuously monitors packet flows, compares characteristics against constraints and models, and adjusts its behavior based on the analysis outcomes. This feedback-driven approach enables sophisticated security enforcement while maintaining operational simplicity through automated adaptation.

Inventive Principle:
Principle #23Feedback

3Reliability

If all communication packets are analyzed and routed through security checks, then security coverage is improved, but communication efficiency deteriorates due to increased processing time

Engineering Contradiction:
Improvesecurity coverageVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by focusing security analysis on specific packet characteristics that are most indicative of malicious behavior, rather than examining every aspect of each packet. The system extracts and analyzes only the most relevant features against constraints and models, providing sufficient security coverage while minimizing processing overhead and maintaining communication efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The network switch changes parameters by transforming packet data into specific characteristic representations suitable for constraint matching and model comparison. This parameter transformation optimizes the analysis process by converting raw packet data into features that can be efficiently evaluated against security criteria, reducing processing time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4149079B1Configurable network switch for industrial control systems including deterministic networks
Publication Date: 2026.03.25 GE AVIATION SYST LTD
  • EP4149079B1 patent drawingFigure 1
  • EP4149079B1 patent drawingFigure 2
  • EP4149079B1 patent drawingFigure 3

AI summary

A network switch 350 includes a first port 352 configured for communication with a first electric device and a second port 353 configured for communication with a second electric device in a deterministic network. The network switch includes one or more processors configured to receive at the first port a communication packet 355 associated with the first electric device and the second electric device, determine if the communication packet 355 satisfies a plurality of protocol constraints 364, and in response to the communication packet satisfying the plurality of protocol constraints 364, input one or more message characteristics from the communication packet 355 into a model 368 associated with a first industrial process. The model 368 is configured to output a process behavioral classification based on the one or more message characteristics. The one or more processors receive a process behavioral classification for the communication packet, and selectively generate a control action 372 for the ICS based on the process behavioral classification.