Anomaly Detection in PLC Networks via Packet Duplication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial technological systems face challenges in securing automated control systems due to obsolete equipment and unprotected information transmission protocols, leading to vulnerabilities that can result in malicious interventions disrupting critical processes.

Innovation Solution

A method and system for detecting anomalies in technological systems by intercepting and comparing data packets between upper and middle-level elements using a duplicator and monitor, establishing secure connections, and detecting deviations to identify unauthorized interventions without requiring extensive a priori knowledge about the PLCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If obsolete equipment with unprotected information transmission protocols is used in technological systems, then the service life of equipment is extended and replacement costs are reduced, but security vulnerabilities appear in the control systems enabling malicious actions

Engineering Contradiction:
Improveequipment service lifeVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a monitoring system as an intermediary component that sits between the obsolete PLC and the network. This monitor intercepts and analyzes data packets transmitted by the PLC, detecting anomalies without requiring modification of the obsolete equipment itself. The duplicator on the upper level and monitor on the middle level create a security layer that protects the vulnerable PLC while maintaining its operational continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the control system into multiple hierarchical levels (upper level with duplicator, middle level with monitor, lower level with PLC) and segments the security function from the operational function. This segmentation allows the obsolete PLC to continue operating while the monitoring infrastructure provides security independently, resolving the contradiction between maintaining legacy equipment and ensuring security.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traffic analysis is performed to detect anomalies in the data transmission network, then security monitoring is achieved, but a large volume of a priori information about the PLC is required and detection errors occur

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoida priori information requirements
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the duplicator on the upper level sends information about outgoing data packets to the monitor on the middle level via a secure connection. The monitor compares incoming packets against this reference information, enabling anomaly detection based on deviations from expected behavior rather than requiring extensive prior knowledge of PLC protocols and parameters.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Instead of analyzing incoming traffic against known PLC protocols (the conventional approach requiring a priori knowledge), the patent inverts the approach by having the upper level provide reference information about expected traffic patterns to the monitor. The monitor then detects anomalies by comparing actual traffic against this reference, eliminating the need for extensive PLC-specific knowledge.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11425154B2System and method of detecting anomalies in a technological system
Publication Date: 2022.08.23 AO KASPERSKY LAB
  • US11425154B2 patent drawing
  • US11425154B2 patent drawing
  • US11425154B2 patent drawing

AI summary

Disclosed herein are systems and methods for detecting anomalies in a technological system. In one aspect, an exemplary method comprises, intercepting, by a duplicator running on an upper-level element of the technological system at least one outgoing data packet addressed to a middle-level element of the technological system, sending, by the duplicator, information about the intercepted at least one outgoing data packet to a monitor using a secure connection, the monitor running on the middle-level element, intercepting, by the monitor, at least one incoming data packet, comparing, by the monitor, the information received from the duplicator with the intercepted at least one incoming data packet, and detecting, by the monitor, an anomaly in the technological system when the intercepted at least one incoming data packet does not conform to the information received from the duplicator.