OT Network Threat Intelligence via Telemetry Sanitization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Operational technology (OT) networks face significant security threats due to increased connectivity, leading to potential disruptions and high remediation costs, with existing solutions failing to effectively protect privacy and identity while sharing threat intelligence.
Innovation Solution
A community threat intelligence system that processes sanitized telemetry data from OT networks, removing sensitive information to protect participant identities, and generates collective threat intelligence for effective countermeasures, while maintaining privacy and reducing adversary dwell time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If threat intelligence data is shared across multiple OT networks, then collective defense capability and threat detection speed are improved, but participant privacy and identity protection are compromised
Solution Approach 1:
The patent extracts and removes personally identifiable information (PII) and sensitive data from telemetry streams before analysis. The system separates identifying characteristics from threat-relevant data, allowing threat intelligence to be shared while participant identities remain protected. This extraction process enables collective defense without compromising privacy.
Solution Approach 2:
The patent introduces an intermediary processing layer that acts as a mediator between raw telemetry data and threat intelligence analysis. This intermediary component sanitizes data by removing PII while preserving threat indicators, enabling safe sharing across networks. The intermediary ensures that collective defense capabilities are enhanced without direct exposure of participant identities.
2Measurement precision
If comprehensive telemetry data is collected from OT networks, then threat detection accuracy is improved, but data sensitivity and privacy risks increase
Solution Approach 1:
The system extracts only the necessary threat-relevant features from comprehensive telemetry data while removing sensitive PII. This selective extraction maintains threat detection accuracy by preserving critical security indicators while eliminating privacy risks associated with comprehensive data collection.
Solution Approach 2:
The patent applies different processing qualities to different portions of telemetry data. Sensitive fields undergo rigorous sanitization while threat-relevant fields maintain their detailed structure for accurate detection. This local quality differentiation allows comprehensive analysis where needed while protecting privacy where required.
3Loss of time
If real-time threat analysis is performed across multiple networks, then incident response time is reduced, but computational complexity and resource requirements increase
Solution Approach 1:
The patent segments the threat analysis process into distributed components across multiple networks rather than centralized processing. Each network performs local sanitization and preliminary analysis, reducing the computational burden on any single system and enabling faster real-time response while distributing complexity across the ecosystem.
Solution Approach 2:
The system performs preliminary data sanitization and preprocessing actions before main threat analysis. By pre-processing telemetry data to remove PII and structure threat indicators in advance, the system reduces computational complexity during critical real-time analysis phases, enabling faster incident response.
Data Source
AI summary
Techniques are provided for community threat intelligence for operational technology networks. For a plurality of OT networks, at least one monitoring device processes OT network traffic and collects telemetry data, and a telemetry sanitization system applies a sanitization process to the telemetry data to generate sanitized telemetry data that does not include sensitive data. A computer system receives sanitized telemetry data from the telemetry sanitization systems provided for the plurality of OT networks, maintains threat intelligence data generated based on the sanitized telemetry data, and provides access to at least one of the threat intelligence data and the sanitized telemetry data to a plurality of users.


