Parallel Command Validation for Industrial Control Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial asset control systems are vulnerable to cyber threats, particularly unauthorized commands that can cause rapid instability or catastrophic damage, as existing threat detection methods are inadequate in addressing simultaneous faults and quick-acting malicious attacks.
Innovation Solution
A validation platform that interprets data packets to identify control commands, introduces them into a parallel industrial asset simulation, validates the simulated results, and only allows validated commands to be executed, while discarding potentially harmful commands and triggering threat alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cyber-threat detection techniques are used, then the system can detect some threats, but it cannot detect quick-acting malicious attacks that cause severe damage within milliseconds
Solution Approach 1:
The validation platform performs preliminary validation of control commands by introducing them into a parallel industrial asset simulation before execution. This preliminary action allows the system to assess potential threats and validate command safety in advance, enabling detection of malicious attacks before they cause damage to the actual industrial asset.
Solution Approach 2:
The system creates a virtual copy of the industrial asset through parallel simulation. This copy receives and processes control commands identical to those sent to the actual asset, allowing threat detection without affecting real operations. The simulation model serves as a digital twin for validating command safety.
2Reliability
If FDIA approaches are used to analyze sensor data, then naturally occurring faults can be detected, but simultaneous multiple faults from malicious attacks cannot be addressed
Solution Approach 1:
The validation platform performs multiple functions simultaneously: it validates control commands, detects malicious attacks, identifies simultaneous multiple faults, and prevents catastrophic damage. By introducing commands into parallel simulation and analyzing simulated results, the system handles diverse threat scenarios including coordinated attacks on multiple sensors and actuators.
Solution Approach 2:
The parallel industrial asset simulation acts as an intermediary between the control command source and the actual industrial asset. This intermediary layer analyzes command effects in a virtual environment, allowing detection of multiple simultaneous faults and malicious attacks before they affect the real system.
3Productivity
If control commands are executed directly without validation, then the system operates in real-time, but unauthorized commands can cause catastrophic damage
Solution Approach 1:
Control commands are validated in advance by introducing them into parallel simulation before execution on the actual industrial asset. This preliminary validation assesses command safety without delaying real-time operations, as the simulation runs concurrently with the control system.
Solution Approach 2:
A virtual copy of the industrial asset is maintained through parallel simulation to test control commands. This copy receives and processes commands that would otherwise be executed on the real asset, allowing safety validation without impacting actual production or operation speed.
Data Source
AI summary
According to some embodiments, a validation platform computer may interpret at least one received data packet to identify a control command for a controller of an industrial asset control system. The at least data packet being might be received, for example, from a network associated with a current operation of the industrial asset control system. The control command may then be introduced into an industrial asset simulation executing in parallel with the industrial asset control system. A simulated result of the control command from the industrial asset simulation may be validated, and, upon validation of the simulated result, it may be arranged for the control command to be provided to the controller of the industrial asset control system. Additionally, in some embodiments failed validation of a simulated result will prompt a threat-alert signal as well as prevent the command (e.g., data packet) from continuing to the controller.


