OT Security Zone Mapping for Covert Path Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OT networks are vulnerable to covert paths across different security zones, which are unknown to network management systems, posing significant security risks due to connections like IoT devices and servers with multiple network interface cards.

Innovation Solution

A central OT security monitoring server receives IP configuration data from data collectors, identifies subnets, determines security zones, and discovers covert paths by analyzing network connections, using predefined thresholds or predefined security zone relationships to recognize and block unauthorized paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security devices isolate OT network from IT network using security zones, then network security is improved, but covert paths may still exist across different security zones

Engineering Contradiction:
Improvenetwork securityVSAvoidcovert path risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors network traffic and collects IP configuration data from data collectors, creating a feedback loop that detects covert paths and provides information for security policy adjustments. The central server receives ongoing data about network connections and dynamically identifies covert paths that bypass security zones.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A central OT security monitoring server acts as an intermediary between security devices and network traffic. It collects data from multiple sources including data collectors, security device logs, and IP configuration information, then analyzes this data to identify covert paths that traditional security devices may have missed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple network interface cards are deployed on border servers, then network functionality is improved, but covert paths from IT network to OT network are created

Engineering Contradiction:
Improvenetwork functionalityVSAvoidunauthorized access path
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system monitors IP configuration data from servers with multiple network interface cards, tracking which interfaces connect to which networks. By continuously collecting and analyzing this configuration information alongside traffic data, the system identifies when multi-homed servers create covert paths between IT and OT networks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The central security monitoring server intermediates between the multi-homed servers and the security policy enforcement mechanisms. It collects IP configuration data from these servers, analyzes their network connections across security zones, and identifies covert paths that result from their multi-network connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If IoT devices are used for data collecting, then data gathering capability is improved, but covert paths across production control systems and monitoring systems are created

Engineering Contradiction:
Improvedata gathering capabilityVSAvoidcovert path between control and monitoring systems
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system collects IP configuration data from IoT devices deployed in the OT network and monitors their network connections. By continuously gathering data about IoT device configurations and their communication patterns, the system identifies covert paths that these devices create between production control systems and IT monitoring systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The central security monitoring server acts as an intermediary that collects information about IoT devices from data collectors and analyzes their network behavior. It identifies covert paths created by IoT devices by comparing their IP configurations and network connections against security zone boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If physical isolation is applied to disrupt threats, then network security is improved, but covert paths may still bypass the isolation

Engineering Contradiction:
Improvenetwork securityVSAvoidcovert path detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system continuously monitors network traffic and collects IP configuration data to create feedback about actual network connections. This ongoing monitoring detects covert paths that bypass physical isolation by providing real-time information about unauthorized connections between security zones.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The central security monitoring server serves as an intermediary detection layer that operates independently of physical isolation measures. It collects data from multiple sources including security device logs and data collectors, then analyzes this information to identify covert paths that traditional isolation mechanisms have failed to prevent.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250258911A1Method And Systems For Covert Path Discovering
Publication Date: 2025.08.14 SIEMENS AG
  • US20250258911A1 patent drawing
  • US20250258911A1 patent drawing
  • US20250258911A1 patent drawing

AI summary

Various embodiments of the teachings herein include a method for covert path discovering in OT security monitoring. An example includes: receiving IP configuration data of network connections among the OT network and an IT network connected to the OT network from a data collector connected to the OT network; identifying subnets among the OT network and the IT network based on the IP configuration data; determining different security zones among the OT network and the IT network based on the identified subnets; and discovering a covert path across a first identified subnet and a second identified subnet, wherein the first identified subnet belongs to a first determined security zone, and the second identified subnet belongs to a second determined security zone.