OT Network Threat Intelligence via Telemetry Sanitization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operational technology (OT) networks face significant security threats due to increased connectivity, leading to potential disruptions and high remediation costs, with existing solutions failing to effectively protect privacy and identity while sharing threat intelligence.

Innovation Solution

A community threat intelligence system that processes sanitized telemetry data from OT networks, removing sensitive information to protect participant identities, and generates collective threat intelligence for effective countermeasures, while maintaining privacy and reducing adversary dwell time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat intelligence data is shared across multiple OT networks, then collective defense capability and threat detection speed are improved, but participant privacy and identity protection are compromised

Engineering Contradiction:
Improvecollective defense capabilityVSAvoidparticipant privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts and removes personally identifiable information (PII) and sensitive data from telemetry streams before analysis. The system separates identifying characteristics from threat-relevant data, allowing threat intelligence to be shared while participant identities remain protected. This extraction process enables collective defense without compromising privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between raw telemetry data and threat intelligence analysis. This intermediary component sanitizes data by removing PII while preserving threat indicators, enabling safe sharing across networks. The intermediary ensures that collective defense capabilities are enhanced without direct exposure of participant identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive telemetry data is collected from OT networks, then threat detection accuracy is improved, but data sensitivity and privacy risks increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprivacy risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the necessary threat-relevant features from comprehensive telemetry data while removing sensitive PII. This selective extraction maintains threat detection accuracy by preserving critical security indicators while eliminating privacy risks associated with comprehensive data collection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different processing qualities to different portions of telemetry data. Sensitive fields undergo rigorous sanitization while threat-relevant fields maintain their detailed structure for accurate detection. This local quality differentiation allows comprehensive analysis where needed while protecting privacy where required.

Inventive Principle:
Principle #3Local quality

3Loss of time

If real-time threat analysis is performed across multiple networks, then incident response time is reduced, but computational complexity and resource requirements increase

Engineering Contradiction:
Improveincident response timeVSAvoidcomputational complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the threat analysis process into distributed components across multiple networks rather than centralized processing. Each network performs local sanitization and preliminary analysis, reducing the computational burden on any single system and enabling faster real-time response while distributing complexity across the ecosystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary data sanitization and preprocessing actions before main threat analysis. By pre-processing telemetry data to remove PII and structure threat indicators in advance, the system reduces computational complexity during critical real-time analysis phases, enabling faster incident response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11677771B2Community threat intelligence and visibility for operational technology networks
Publication Date: 2023.06.13 DRAGOS INC
  • US11677771B2 patent drawing
  • US11677771B2 patent drawing
  • US11677771B2 patent drawing

AI summary

Techniques are provided for community threat intelligence for operational technology networks. For a plurality of OT networks, at least one monitoring device processes OT network traffic and collects telemetry data, and a telemetry sanitization system applies a sanitization process to the telemetry data to generate sanitized telemetry data that does not include sensitive data. A computer system receives sanitized telemetry data from the telemetry sanitization systems provided for the plurality of OT networks, maintains threat intelligence data generated based on the sanitized telemetry data, and provides access to at least one of the threat intelligence data and the sanitized telemetry data to a plurality of users.