OT Network Replication for Safe Attack Path Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OT network security assessments are time-consuming, provide only historical snapshots, and pose risks to critical industrial systems, making it difficult to assess and mitigate vulnerabilities effectively.

Innovation Solution

A threat analysis system generates a network replica of an OT environment, applies an attack simulation model to simulate threats, and provides real-time risk reduction recommendations based on simulated attack data, allowing for continuous assessment without disrupting live networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional penetration testing and live network testing are used to assess vulnerability, then assessment accuracy is improved, but system safety deteriorates due to risks to critical industrial systems

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidrisk to critical industrial systems
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent creates a digital replica (graph database) of the OT network that mirrors the actual network structure, assets, and relationships. This copy allows penetration testing and vulnerability assessment to be performed on the replica instead of the live system, maintaining assessment accuracy while eliminating risks to critical industrial systems

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The graph database replica serves as an intermediary between the vulnerability assessment process and the actual OT network. All testing, simulation, and analysis operations are conducted through this intermediary layer, allowing accurate assessment without direct interaction with or potential harm to the critical industrial systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If point-in-time vulnerability assessments are conducted, then historical risk snapshot is obtained, but continuous monitoring capability is lost

Engineering Contradiction:
Improveassessment time efficiencyVSAvoidcontinuous risk assessment capability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system enables continuous vulnerability assessment by maintaining an updated graph database replica that reflects current network state. The attack simulation model can be repeatedly applied to this replica over time, providing continuous monitoring and real-time risk assessment without interrupting live operations

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary actions by continuously maintaining an up-to-date replica of the network topology, assets, and relationships. This preliminary preparation allows rapid, continuous assessment to be conducted at any time without needing to interrupt operations or start lengthy assessment processes

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250274475A1Operational technology network replication and attack path simulation
Publication Date: 2025.08.28 FRENOS INC
  • US20250274475A1 patent drawing
  • US20250274475A1 patent drawing
  • US20250274475A1 patent drawing

AI summary

Techniques are provided for operational technology (OT) network replication and attack path simulation. OT environment data describing a plurality of assets belonging to an OT network environment is received. A network replica of the OT network environment is generated based on the network data and the asset data. The network replica comprises a structured representation of the plurality of assets, communication pathways between the plurality of assets, security controls implemented in the OT network environment, and vulnerabilities. An attack simulation model is applied to the network replica and a threat database comprising threat data describing a plurality of threats. The attack simulation model simulates attacks by the plurality of threats on the network replica and generate simulated attack data describing a set of simulated attack paths corresponding to one or more threats. One or more risk reduction recommendations are provided based on the simulated attack data.