Packet-Correlation Anomaly Inspection for Industrial Control Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial control systems are vulnerable to malicious attacks, such as those launched by hackers or viruses, which send spoofed reporting messages to misguide controllers and field apparatuses, leading to incorrect operations and data manipulation.

Innovation Solution

An anomaly inspection appliance that monitors correlations between packets transmitted through different communication channels using a first and second communication protocol, performs field breakdown on these packets, and matches fields to determine if correlations match expected types, issuing an alarm for anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication monitoring is used without correlation analysis, then the system operates with simple packet transmission, but the system cannot detect spoofed messages and remains vulnerable to malicious attacks

Engineering Contradiction:
Improvesystem securityVSAvoidinspection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an anomaly inspection appliance as an intermediary device that monitors communication between controllers and field apparatuses. This appliance captures packets from communication channels, performs correlation analysis on packet fields, and detects anomalies without disrupting normal system operation. The intermediary approach enables security monitoring while maintaining system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the inspection process into distinct functional modules: packet capture module, field breakdown module, correlation computation module, and anomaly detection module. This segmentation allows each module to perform its specific function independently, making the complex inspection system manageable and maintainable while providing comprehensive security monitoring.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If correlation analysis is performed on all packet fields, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by focusing correlation analysis on specific critical packet fields rather than uniformly analyzing all fields. The system identifies and prioritizes fields that are most indicative of spoofing attempts (such as message identifiers, data values, and control instructions) while applying less intensive analysis to other fields, thereby balancing detection accuracy with processing efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by performing correlation analysis on a selected subset of packet fields that are most relevant for detecting spoofed messages. Rather than exhaustively analyzing every field in every packet, the system applies intelligent filtering to focus computational resources on the most suspicious or critical fields, achieving effective anomaly detection with reduced processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If the system monitors multiple communication channels with different protocols, then coverage of malicious attacks improves, but the complexity of field matching and correlation computation increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidfield matching complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a correlation database and field matching mechanism that can handle multiple communication protocols (such as Modbus, Profibus, and other industrial protocols). The system maintains a unified approach to packet capture and analysis that adapts to different protocols, allowing the same inspection appliance to monitor diverse communication channels without requiring protocol-specific hardware or complex separate analysis paths.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413609B2Anomaly inspection appliance and anomaly inspection method based on correlations of packets
Publication Date: 2025.09.09 TXONE NETWORKS INC
  • US12413609B2 patent drawing
  • US12413609B2 patent drawing
  • US12413609B2 patent drawing

AI summary

A method and an appliance for anomaly inspection based on correlations of packets are provided. The appliance has a processing unit, a first communication channel, and a second communication channel. The first communication channel transmits a first packet under a first communication protocol and the second communication channel transmits a second packet under a second communication protocol. The processing unit performs a field breakdown procedure to the first packet and the second packet to respectively obtain multiple packet fields of the two packets, matching relevant fields of the two packets based on a correlation database and computing the correlation of the relevant fields.