Overlay Cyber Security Network for Process Control Forensics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Process Control Networks (PCNs) face challenges in detecting and responding to cyber threats due to insufficient logging capabilities, particularly at Level 0 and 1, which hampers forensic analysis and security measures, and lacks a standardized log structure, leading to operational blind spots and inadequate security layers.

Innovation Solution

An overlay cyber security network system that monitors, detects, and corrects anomalies by capturing and storing log information from physical-level signals, transforming them into standardized formats, and providing a defense-in-depth security architecture, integrating with existing PCNs to enhance forensic analysis and security functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional PCN logging capabilities are used, then system operation is maintained, but forensic analysis capability is insufficient due to lack of standardized log structure and Level 0 data collection

Engineering Contradiction:
Improvelog informationVSAvoidlogging system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the logging system into multiple hierarchical levels (Level 0 through Level 4), with each level collecting and storing log data in standardized formats. Level 0 captures physical device signals, Level 1 captures controller data, and higher levels capture network and forensic data. This segmentation allows comprehensive information collection while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimensional layer to the logging system by introducing an overlay cyber security network that operates parallel to the conventional PCN. This overlay network collects log data from all levels simultaneously and stores it in standardized formats, enabling forensic analysis without disrupting the original system operation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If overlay cyber security network is implemented, then forensic analysis capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary overlay cyber security network that mediates between the conventional PCN and forensic analysis systems. This overlay network acts as a buffer layer that collects, standardizes, and stores log data from multiple sources, thereby improving security detection capability while isolating the complexity of forensic requirements from the operational PCN.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If standardized log formats are enforced across all levels, then forensic analysis is improved, but ease of operation decreases due to stricter conformance requirements

Engineering Contradiction:
Improveforensic information qualityVSAvoidlog management ease
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements a universal standardized log format that serves multiple functions simultaneously: it enables forensic analysis, maintains system operation records, and provides security monitoring. The same log structure is used across all levels (0-4), allowing a single system to handle diverse logging requirements without requiring separate management procedures for each level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10250619B1Overlay cyber security networked system and method
Publication Date: 2019.04.02 SERVICENOW INC
  • US10250619B1 patent drawing
  • US10250619B1 patent drawing
  • US10250619B1 patent drawing

AI summary

An overlay cyber security networked system and method that includes one or more devices configured to monitor physical-level signal information to determine a cyber security threat or breach event based on activity occurring with physical signals present at one or more components of a Process Control Network (PCN), enabling forensic analysis. The overlay cyber security networked system also provides information needed for real-time incident management by capturing logs of relevant events at various points in the network hierarchy starting at the analog signaling from the sensors to detect unauthorized variances in operational parameters, thereby providing a defense in depth security architecture for PCN-based systems.