Packet-Correlation Anomaly Inspection for Industrial Control Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial control systems are vulnerable to malicious attacks, such as those launched by hackers or viruses, which send spoofed reporting messages to misguide controllers and field apparatuses, leading to incorrect operations and data manipulation.
Innovation Solution
An anomaly inspection appliance that monitors correlations between packets transmitted through different communication channels using a first and second communication protocol, performs field breakdown on these packets, and matches fields to determine if correlations match expected types, issuing an alarm for anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional communication monitoring is used without correlation analysis, then the system operates with simple packet transmission, but the system cannot detect spoofed messages and remains vulnerable to malicious attacks
Solution Approach 1:
The patent introduces an anomaly inspection appliance as an intermediary device that monitors communication between controllers and field apparatuses. This appliance captures packets from communication channels, performs correlation analysis on packet fields, and detects anomalies without disrupting normal system operation. The intermediary approach enables security monitoring while maintaining system functionality.
Solution Approach 2:
The patent segments the inspection process into distinct functional modules: packet capture module, field breakdown module, correlation computation module, and anomaly detection module. This segmentation allows each module to perform its specific function independently, making the complex inspection system manageable and maintainable while providing comprehensive security monitoring.
2Measurement precision
If correlation analysis is performed on all packet fields, then detection accuracy improves, but processing time and computational resources increase
Solution Approach 1:
The patent applies local quality by focusing correlation analysis on specific critical packet fields rather than uniformly analyzing all fields. The system identifies and prioritizes fields that are most indicative of spoofing attempts (such as message identifiers, data values, and control instructions) while applying less intensive analysis to other fields, thereby balancing detection accuracy with processing efficiency.
Solution Approach 2:
The patent implements partial action by performing correlation analysis on a selected subset of packet fields that are most relevant for detecting spoofed messages. Rather than exhaustively analyzing every field in every packet, the system applies intelligent filtering to focus computational resources on the most suspicious or critical fields, achieving effective anomaly detection with reduced processing overhead.
3Adaptability or versatility
If the system monitors multiple communication channels with different protocols, then coverage of malicious attacks improves, but the complexity of field matching and correlation computation increases
Solution Approach 1:
The patent implements universality by designing a correlation database and field matching mechanism that can handle multiple communication protocols (such as Modbus, Profibus, and other industrial protocols). The system maintains a unified approach to packet capture and analysis that adapts to different protocols, allowing the same inspection appliance to monitor diverse communication channels without requiring protocol-specific hardware or complex separate analysis paths.
Data Source
AI summary
A method and an appliance for anomaly inspection based on correlations of packets are provided. The appliance has a processing unit, a first communication channel, and a second communication channel. The first communication channel transmits a first packet under a first communication protocol and the second communication channel transmits a second packet under a second communication protocol. The processing unit performs a field breakdown procedure to the first packet and the second packet to respectively obtain multiple packet fields of the two packets, matching relevant fields of the two packets based on a correlation database and computing the correlation of the relevant fields.


