OT-IT Gateway Filtering for Industrial Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial systems face security breaches and inadequate intrusion detection when connecting operational technology (OT) networks to information technology (IT) networks, as existing gateways provide full access to OT equipment, making it difficult to prevent malicious actions and detect anomalies effectively.

Innovation Solution

An industrial system with a gateway that connects OT and IT networks, equipped with a processor and analyzer to collect operational data, detect anomalies, assess risks, and provide alerts, while implementing authentication and data filtering to restrict access and monitor information exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a gateway is used to connect OT network to IT network, then remote access capability is improved, but security vulnerability increases due to full access to OT equipment

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway segments network traffic into multiple categories (operational traffic, maintenance traffic, administrative traffic) and applies different filtering rules to each segment. This allows selective access control where different types of traffic are handled differently, preventing full unrestricted access while maintaining necessary remote operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway acts as an intermediary device between IT and OT networks, implementing authentication mechanisms and traffic filtering. It mediates all communications by verifying credentials, classifying traffic types, and applying appropriate access controls, thus preventing direct unfiltered access from IT to OT equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication mechanisms are implemented, then security is improved, but access complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication mechanism dynamically adapts based on traffic classification. Different authentication levels are applied to different traffic types: operational traffic may use simplified authentication, while maintenance and administrative traffic require stronger authentication. This dynamic approach maintains security without uniformly increasing complexity for all access types.

Inventive Principle:
Principle #15Dynamics

3Reliability

If traffic filtering is implemented, then security is improved, but information exchange efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidinformation exchange efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The filtering mechanism applies different levels of inspection and control to different types of traffic. Operational traffic (critical for production) receives minimal filtering to maintain efficiency, while maintenance and administrative traffic undergo more rigorous filtering. This local differentiation of filtering intensity maintains security while preserving information exchange efficiency for critical operations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11711341B2System for securing a cyber-physical method
Publication Date: 2023.07.25 UNIVERSITE GRENOBLE ALPES
  • US11711341B2 patent drawing
  • US11711341B2 patent drawing
  • US11711341B2 patent drawing

AI summary

The invention relates to an industrial system comprising machines, systems for controlling machines connected by a first communication network, and a gateway intended to connect the first communication network to a second communication network. The gateway comprises a memory and comprises a processor configured to copy to the memory first data transmitted over the second communication network and relating to the operation of the machines.