Overlay Cyber Security Network for Process Control Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Process Control Networks (PCNs) face challenges in detecting and responding to cyber threats due to insufficient logging capabilities, particularly at Level 0 and 1, which hampers forensic analysis and security measures, and lacks a standardized log structure, leading to operational blind spots and inadequate security layers.
Innovation Solution
An overlay cyber security network system that monitors, detects, and corrects anomalies by capturing and storing log information from physical-level signals, transforming them into standardized formats, and providing a defense-in-depth security architecture, integrating with existing PCNs to enhance forensic analysis and security functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional PCN logging capabilities are used, then system operation is maintained, but forensic analysis capability is insufficient due to lack of standardized log structure and Level 0 data collection
Solution Approach 1:
The patent segments the logging system into multiple hierarchical levels (Level 0 through Level 4), with each level collecting and storing log data in standardized formats. Level 0 captures physical device signals, Level 1 captures controller data, and higher levels capture network and forensic data. This segmentation allows comprehensive information collection while maintaining manageable complexity through modular architecture.
Solution Approach 2:
The patent adds a new dimensional layer to the logging system by introducing an overlay cyber security network that operates parallel to the conventional PCN. This overlay network collects log data from all levels simultaneously and stores it in standardized formats, enabling forensic analysis without disrupting the original system operation.
2Reliability
If overlay cyber security network is implemented, then forensic analysis capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary overlay cyber security network that mediates between the conventional PCN and forensic analysis systems. This overlay network acts as a buffer layer that collects, standardizes, and stores log data from multiple sources, thereby improving security detection capability while isolating the complexity of forensic requirements from the operational PCN.
3Loss of information
If standardized log formats are enforced across all levels, then forensic analysis is improved, but ease of operation decreases due to stricter conformance requirements
Solution Approach 1:
The patent implements a universal standardized log format that serves multiple functions simultaneously: it enables forensic analysis, maintains system operation records, and provides security monitoring. The same log structure is used across all levels (0-4), allowing a single system to handle diverse logging requirements without requiring separate management procedures for each level.
Data Source
AI summary
An overlay cyber security networked system and method that includes one or more devices configured to monitor physical-level signal information to determine a cyber security threat or breach event based on activity occurring with physical signals present at one or more components of a Process Control Network (PCN), enabling forensic analysis. The overlay cyber security networked system also provides information needed for real-time incident management by capturing logs of relevant events at various points in the network hierarchy starting at the analog signaling from the sensors to detect unauthorized variances in operational parameters, thereby providing a defense in depth security architecture for PCN-based systems.


