OPC UA Malicious Activity Detection via Communication Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems in IIoT ecosystems, particularly those using OPC UA transport protocols, are unable to effectively analyze malicious packets, posing a significant threat to industrial process control and automation systems due to the lack of capability to identify malicious activity among thousands of connected nodes.

Innovation Solution

A method and apparatus for detecting malicious activity in IIoT nodes using historical communication data clustering and pattern identification, where current communication data is matched against identified patterns to determine malicious activity, employing a hybrid machine-learning process combining unsupervised clustering and supervised classification algorithms within an intelligent security agent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection systems are used in IIoT ecosystems, then general security monitoring is provided, but they cannot analyze malicious packets using OPC UA transport protocols

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprotocol analysis capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between the OPC UA protocol and intrusion detection systems. This intermediary translates or adapts the protocol-specific packets into a format that can be analyzed by security systems, enabling both protocol-specific analysis and general security monitoring without requiring complete redesign of existing IDS infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms the analysis parameters by converting protocol-specific OPC UA packet structures into standardized security analysis parameters. This parameter transformation enables conventional intrusion detection systems to analyze IIoT traffic effectively by changing the representation format while preserving the essential security-relevant features.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If third party security vendor IDS or application firewall is deployed, then basic security filtering is provided, but they lack the ability to analyze malicious packets with UA transport protocols

Engineering Contradiction:
Improvemalicious packet protectionVSAvoidprotocol-specific threat detection
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the security analysis function into two parts: a protocol-aware analysis component that understands OPC UA specifics and a general intrusion detection component. This segmentation allows the system to handle protocol-specific threats with specialized knowledge while maintaining the capabilities of conventional IDS for general security monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis of OPC UA packets using protocol-specific knowledge before passing them to conventional intrusion detection systems. This preliminary action pre-processes and flags suspicious patterns that are specific to the OPC UA protocol, enabling more effective detection by downstream security components.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive monitoring of thousands of connected IIoT nodes is implemented, then security coverage is improved, but analysis complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal analysis framework that can handle multiple IIoT node types and communication patterns through a single standardized interface. This multi-functional approach allows the system to scale to thousands of nodes without proportionally increasing complexity, as the same core analysis mechanisms apply across different node types and protocol variations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10432647B2Malicious industrial internet of things node activity detection for connected plants
Publication Date: 2019.10.01 HONEYWELL INTERNATIONAL INC
  • US10432647B2 patent drawing
  • US10432647B2 patent drawing
  • US10432647B2 patent drawing

AI summary

A method and apparatus for identifying malicious activity. At least one memory is configured to store historical communication data. At least one processor is configured to retrieve the historical communication data related to communications between a server and a plurality of clients in a system. The processor is further configured to cluster the historical communication data to group communications of the historical communication data. The processor is further configured to identify a plurality of patterns that indicate malicious activity based on the grouped communications. The processor is further configured to receive current communication data. The processor is further configured to determine whether the current communication data matches the one of the plurality of patterns. The processor is further configured to, responsive to a grouped element of the grouped communications matching the pattern, identifying a group of communications between the server and the plurality of clients as the malicious activity.