OT Network Security Analysis Using Cross-System Threat Coefficients
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for analyzing the security of industrial control systems in OT networks fail to accurately consider the inter-influence between different industrial control systems, leading to incomplete and inaccurate security assessments.
Innovation Solution
The proposed method involves collecting communication data packets from industrial control systems within an OT network, extracting network identifiable information, and determining if this information is present in a pre-created event database. If it is, the data packet is identified as malicious, and threat coefficients are calculated for each affected industrial control system based on security policies and network identifiable information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security analysis is performed based on communication data packets collected from a single industrial control system, then the analysis process is simple and fast, but the security assessment is inaccurate because inter-influence between different industrial control systems is not considered
Solution Approach 1:
The patent merges security analysis across multiple industrial control systems by collecting communication data packets from all systems in the OT network, not just individual systems. This combines data from diverse sources to enable comprehensive threat assessment that captures inter-system influences, thereby improving security assessment accuracy while managing complexity through unified analysis architecture
Solution Approach 2:
The patent creates a universal security analysis mechanism that handles multiple industrial control systems simultaneously through a single analysis platform. The system performs multiple functions: collecting packets from various systems, identifying malicious packets, calculating threat coefficients for different systems, and assessing overall network security, thereby improving accuracy without proportionally increasing complexity
2Reliability
If threat coefficients are calculated for multiple industrial control systems based on security policies, then the security analysis becomes comprehensive and accurate, but the computational complexity and time consumption increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing security policies for each industrial control system before actual security analysis occurs. These security policies, including protection levels and threat response rules, are configured in advance, allowing the system to quickly calculate threat coefficients during real-time analysis without performing complex policy evaluations from scratch, thus improving reliability while reducing analysis time
Solution Approach 2:
The patent replaces complex manual security assessment processes with automated computational mechanisms. The system uses algorithmic threat coefficient calculations based on predefined security policies, automatically processing communication data packets and assessing multiple industrial control systems simultaneously, thereby achieving comprehensive and accurate analysis while minimizing time loss through automation
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided are an industrial control system safety analysis method and apparatus, and a computer-readable medium. The industrial control system safety analysis method comprises: collecting a communication data packet from a first industrial control system, an operation technology (OT) network comprising the first industrial control system and at least one second industrial control system connected to one another, the communication data packet being interactive data transmitted between control devices in the first industrial control system; extracting network identifiable information from the communication data packet; determining whether the network identifiable information is located in a pre-created event database; and if the network identifiable information is located in the event database, then determining that the communication data packet is a malicious data packet, acquiring security policies of the first industrial control system and each second industrial control system, and determining a threat coefficient of the communication data packet for each second industrial control system according to the network identifiable information and each security policy. The present solution can analyze the safety of an industrial control system more accurately.