Cybersecurity Simulator for OT Network Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems in operational technology (OT) environments face vulnerabilities due to gaps in network security systems, which can allow cyberattacks to go undetected, especially as hacking techniques evolve.

Innovation Solution

A cybersecurity simulator is used to create a virtual network security system within an OT environment, allowing for the simulation of cyberattacks. This simulator receives configuration data from the actual network security system, configures a virtual network, and deploys simulated cyberattacks to identify any undetected threats, generating notifications for un detected attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network security system is deployed to monitor network activity in an OT environment, then security monitoring capability is improved, but the system may still have gaps that allow undetected cyberattacks

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidundetected cyberattacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtual network environment that is a copy of the actual OT network, including virtual replicas of network security systems, endpoints, and infrastructure. This virtual copy allows simulated cyberattacks to be deployed without affecting the real network, enabling comprehensive testing of detection capabilities while maintaining security monitoring in the production environment.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary actions by simulating cyberattacks in the virtual network environment before they occur in the actual OT network. This allows the network security system to be tested and tuned in advance, identifying gaps in detection capabilities proactively rather than reacting to real attacks after they occur.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If simulated cyberattacks are deployed on a virtual network to test security systems, then detection of vulnerabilities is improved, but system complexity increases

Engineering Contradiction:
Improvevulnerability detectionVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

By creating a virtual copy of the OT network environment, the patent isolates the complexity of attack simulation from the production network. The virtual network contains virtual replicas of endpoints, network infrastructure, and security systems, allowing comprehensive vulnerability testing without adding complexity to the actual OT operations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system segments the network into virtual and physical domains. The virtual network environment handles all simulation and testing activities, while the actual OT network remains separate and operational. This segmentation allows complex attack simulation to be contained in the virtual environment without affecting the simplicity and stability of the production network.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the network security system uses detection rules to classify network activity, then false positives may occur, but adding more detection rules increases system complexity

Engineering Contradiction:
Improvecyberattack classification accuracyVSAvoiddetection rule complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The virtual network environment allows the creation and testing of multiple detection rules in isolation before implementing them in the production system. Virtual replicas of network traffic and attack patterns can be used to validate detection rule effectiveness, enabling more precise classification without immediately increasing production system complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements feedback mechanisms where simulated cyberattacks provide test results that feed back into the detection rule development process. By analyzing which simulated attacks were detected and which were not, the system can iteratively refine detection rules to improve classification accuracy while managing complexity through controlled experimentation in the virtual environment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250039216A1Systems and methods of simulating cyberattacks
Publication Date: 2025.01.30 ROCKWELL AUTOMATION TECH INC
  • US20250039216A1 patent drawing
  • US20250039216A1 patent drawing
  • US20250039216A1 patent drawing

AI summary

A non-transitory computer readable medium stores instructions that, when executed by a processor, cause the processor to receive configuration data representative of one or more operational parameters of the network security system, execute a virtual network including a virtual network security system configured based on the configuration data, deploy simulated cyberattacks on the virtual network, identify one or more of the simulated cyberattacks that were not detected by the virtual network security system, and generate a notification identifying the one or more of the simulated cyberattacks that were not detected by the virtual network security system.