OT-IT Gateway Packet Filtering for Industrial Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial systems face security breaches and inadequate intrusion detection when connecting OT and IT networks, as existing gateways provide complete access to OT networks, making it difficult to prevent malicious actions from corrupted remote workstations and lacking sufficient reliability for detecting anomalies.

Innovation Solution

An industrial system with a gateway that filters data packets, traces information exchange, and detects anomalies by analyzing operational variables, determining impact severity, and calculating an overall risk level, while implementing authentication and intrusion detection methods to prevent unauthorized access and malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a gateway is used to connect OT network to IT network, then remote access to OT network is enabled, but complete access to authorized equipment is granted making it vulnerable to malicious actions

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system between the IT network and OT network that acts as a mediator. This intermediary captures data packets from the gateway, analyzes them against established behavioral models, and selectively blocks malicious traffic while allowing legitimate traffic to pass. The intermediary does not directly connect to either network but processes traffic through the gateway, providing security without preventing remote access functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network traffic analysis function from the gateway itself. Instead of embedding security functions within the gateway, the system separates the data capture, analysis, and decision-making processes into distinct components. The gateway handles traffic routing while the intermediary handles security analysis, allowing each component to specialize in its function without compromising the other.

Inventive Principle:
Principle #1Segmentation

2Productivity

If direct connection between IT and OT networks is established, then data exchange is enabled, but filtering and tracing of data packets becomes difficult

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidpacket filtering complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The intermediary system serves as a mediator that captures all data packets passing through the gateway without disrupting the direct connection between IT and OT networks. By positioning the analysis function in this intermediary layer, the system can filter and trace packets without adding complexity to the core data exchange path, maintaining efficiency while enabling comprehensive security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3785158B1System for securing a cyber-physical method
Publication Date: 2022.01.19 UNIVERSITE GRENOBLE ALPES
  • EP3785158B1 patent drawingFigure 1~2
  • EP3785158B1 patent drawingFigure 3~4
  • EP3785158B1 patent drawingFigure 5~6

AI summary

The invention relates to an industrial system comprising machines (14), systems (22) for controlling machines connected by a first communication network (26), and a gateway (20) intended to connect the first communication network (26) to a second communication network (30). The gateway (20) comprises a memory (36) and a processor (34) configured to copy to the memory first data transmitted over the second communication network relating to the operation of the machines.