OT Network Security Analysis Using Cross-System Threat Coefficients

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing the security of industrial control systems in OT networks fail to accurately consider the inter-influence between different industrial control systems, leading to incomplete and inaccurate security assessments.

Innovation Solution

The proposed method involves collecting communication data packets from industrial control systems within an OT network, extracting network identifiable information, and determining if this information is present in a pre-created event database. If it is, the data packet is identified as malicious, and threat coefficients are calculated for each affected industrial control system based on security policies and network identifiable information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analysis is performed based on communication data packets collected from a single industrial control system, then the analysis process is simple and fast, but the security assessment is inaccurate because inter-influence between different industrial control systems is not considered

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidanalysis process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges security analysis across multiple industrial control systems by collecting communication data packets from all systems in the OT network, not just individual systems. This combines data from diverse sources to enable comprehensive threat assessment that captures inter-system influences, thereby improving security assessment accuracy while managing complexity through unified analysis architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security analysis mechanism that handles multiple industrial control systems simultaneously through a single analysis platform. The system performs multiple functions: collecting packets from various systems, identifying malicious packets, calculating threat coefficients for different systems, and assessing overall network security, thereby improving accuracy without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If threat coefficients are calculated for multiple industrial control systems based on security policies, then the security analysis becomes comprehensive and accurate, but the computational complexity and time consumption increase

Engineering Contradiction:
Improvesecurity analysis reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing security policies for each industrial control system before actual security analysis occurs. These security policies, including protection levels and threat response rules, are configured in advance, allowing the system to quickly calculate threat coefficients during real-time analysis without performing complex policy evaluations from scratch, thus improving reliability while reducing analysis time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex manual security assessment processes with automated computational mechanisms. The system uses algorithmic threat coefficient calculations based on predefined security policies, automatically processing communication data packets and assessing multiple industrial control systems simultaneously, thereby achieving comprehensive and accurate analysis while minimizing time loss through automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4135281B1Industrial control system safety analysis method and apparatus, and computer-readable medium
Publication Date: 2025.03.05 SIEMENS (CHINA) CO LTD
  • EP4135281B1 patent drawingFigure 1
  • EP4135281B1 patent drawingFigure 2
  • EP4135281B1 patent drawingFigure 3

AI summary

Provided are an industrial control system safety analysis method and apparatus, and a computer-readable medium. The industrial control system safety analysis method comprises: collecting a communication data packet from a first industrial control system, an operation technology (OT) network comprising the first industrial control system and at least one second industrial control system connected to one another, the communication data packet being interactive data transmitted between control devices in the first industrial control system; extracting network identifiable information from the communication data packet; determining whether the network identifiable information is located in a pre-created event database; and if the network identifiable information is located in the event database, then determining that the communication data packet is a malicious data packet, acquiring security policies of the first industrial control system and each second industrial control system, and determining a threat coefficient of the communication data packet for each second industrial control system according to the network identifiable information and each security policy. The present solution can analyze the safety of an industrial control system more accurately.