Industrial Plant Network Security via Protocol Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation and control systems, increasingly interconnected with enterprise networks, face heightened security threats due to their exposure to malware and other cyber risks, which can lead to significant downtime and liability in modern automated industrial plants.
Innovation Solution
A multi-service packet switch with an embedded application-aware engine (AWE) that recognizes and processes data packets across various industrial protocols, converting them into a common format for security inspection at any OSI layer, and optionally blocking or transmitting packets based on threat assessment, supported by a distributed firewall configuration across the plant network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If industrial plants adopt standard network software and protocols (Ethernet, TCP/IP, HTTP, Windows) to increase flexibility and responsiveness, then adaptability and productivity are improved, but exposure to security threats (malware, viruses, worms, unauthorized access) increases
Solution Approach 1:
The patent introduces an intermediary security system that sits between the industrial control systems and the enterprise network. This intermediary monitors, filters, and controls data packets flowing through the network, blocking malicious traffic while allowing legitimate communication. The system acts as a buffer that protects the industrial plant from external threats while maintaining network connectivity and standard protocols.
2Reliability
If firewalls and security devices are deployed to protect against malware, then security is improved, but device complexity and potential downtime increase
Solution Approach 1:
The patent segments the security system into multiple functional components distributed across the network infrastructure. Rather than a single complex firewall, the security functionality is divided into packet inspection engines, protocol translators, and filtering mechanisms that operate at different network layers. This segmentation reduces the complexity of any single device while maintaining comprehensive security coverage.
3Measurement precision
If comprehensive security inspection at all OSI layers is performed, then measurement precision of security threats is improved, but processing time and productivity are reduced
Solution Approach 1:
The patent implements a layered inspection approach where not all packets undergo full multi-layer inspection. Instead, the system performs basic filtering at lower layers (L2-L3) for all packets, and only subjects suspicious or specific types of traffic to deeper application-layer inspection (L7). This partial action approach maintains high detection accuracy for threats while preserving overall network throughput and minimizing processing delays for legitimate traffic.
Data Source
AI summary
An embodiment of the disclosure provides a communication network having a plurality of end devices protected by multilayer switches that receive data packets in different formats for transmission to the end devices, translate received data packets to a common data format for inspection to determine if they pose a security threat, and if they do not pose a threat, forward the data packets to their end device destinations.


