Infrastructure Anomaly Detection via Packet-Based Virtual Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SCADA systems for industrial infrastructure face high management costs and inefficiencies due to the need for frequent polling of RTUs, especially in systems with small or infrequent variations, leading to exorbitant costs and computational demands, and are unable to effectively prevent anomalous situations caused by unwanted intrusions or random failures.

Innovation Solution

A method and apparatus that analyze data packets exchanged in a telecommunication system to generate virtual representations of the infrastructure, comparing these representations to identify critical states and anomalies, using a 'push' logic that minimizes computational costs by only analyzing data packets when exchanged, and defining allowed protocols and thresholds to detect non-allowable communication sequences and frequencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If frequent polling of RTUs is performed to monitor infrastructure in real-time, then detection precision of anomalies is improved, but management costs and computational demands increase exorbitantly

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system performs polling only periodically when necessary, rather than continuously. The monitoring is triggered by events or changes in the infrastructure, allowing the system to maintain anomaly detection precision while significantly reducing computational energy consumption by avoiding redundant polling cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The infrastructure components themselves generate and transmit data when changes occur, eliminating the need for active polling. RTUs and sensors autonomously report their state when anomalies or changes are detected, reducing the computational burden on the central SCADA system while maintaining detection precision.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If RTUs are provided for each component to enable detailed monitoring, then control capability is improved, but device complexity and management costs increase

Engineering Contradiction:
Improvecontrol capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system uses a universal monitoring approach where a single SCADA infrastructure can monitor multiple components with different levels of detail. Not every component requires a dedicated RTU; instead, components are monitored based on their importance and change frequency, reducing device complexity while maintaining control capability for critical elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Different monitoring strategies are applied to different parts of the infrastructure based on their specific needs. Critical components receive detailed monitoring with dedicated RTUs, while less critical components use simpler monitoring methods, optimizing the balance between control capability and system complexity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the SCADA system architecture is changed to accommodate infrastructure modifications, then adaptability is improved, but management costs and system disruption increase

Engineering Contradiction:
Improvearchitecture adaptabilityVSAvoidmanagement cost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The SCADA system architecture is designed to be dynamic and flexible, allowing components to be added, removed, or modified without requiring complete system reconfiguration. The system can dynamically adjust monitoring parameters and polling frequencies based on infrastructure changes, maintaining adaptability while minimizing management costs and system disruption.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If polling frequency is increased to detect small variations, then measurement precision is improved, but productivity of the monitoring system deteriorates

Engineering Contradiction:
Improvedetection precision for small variationsVSAvoidmonitoring system efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system dynamically changes polling parameters based on the specific monitoring needs and infrastructure state. For components requiring detection of small variations, higher polling frequencies are applied selectively, while other components use lower frequencies, thereby maintaining measurement precision for critical parameters without deteriorating overall system productivity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3674823B1Method and apparatus for detecting the anomalies of an infrastructure
Publication Date: 2022.03.30 NOZOMI NETWORKS SAGL
  • EP3674823B1 patent drawingFigure 1~2
  • EP3674823B1 patent drawingFigure 3
  • EP3674823B1 patent drawingFigure 4

AI summary

The present invention relates to a method for detecting anomalies in an infrastructure comprising the step of analyzing each of the data packets (PD) exchanged in the telecommunication system; identifying for each of the analysed data packets (PD) all the network protocols used and at least one field of each of the protocols; generating a virtual representation of the infrastructure (1) for each of the exchanged data packets (PD) and on the basis of the identified protocols and fields; storing the virtual representation generated for each of the exchanged data packets (PD); comparing the virtual representation stored with at least one comparison element, identifying at least one critical state of the infrastructure from the differences and/or similarities between the stored virtual representation and the comparison elements; signaling, by means of the computerized data processing means, an anomaly of the infrastructure when at least one of the critical states is identified in the virtual representation.