Anomaly Detection in PLC Systems via Virtual Copying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technological systems face challenges in detecting anomalies due to the use of obsolete equipment and unprotected information transmission protocols, which can lead to vulnerabilities and potential catastrophic consequences.
Innovation Solution
A method and system for detecting anomalies in technological systems that require minimal a priori knowledge about Programmable Logic Controllers (PLCs), using a duplicator and monitor to intercept and compare data packets, ensuring detection of unauthorized interventions even with unprotected protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic analysis is performed to detect anomalies in technological systems, then anomaly detection capability is improved, but the method requires large volume of a priori information about PLC protocols and parameter values
Solution Approach 1:
The patent creates a virtual copy of the PLC controller within the automated control system. This virtual PLC replicates the communication protocols and behavior of the physical PLC, allowing the monitoring system to analyze traffic patterns without requiring extensive knowledge of specific PLC protocols. The virtual PLC serves as a reference model against which actual PLC communications can be compared, eliminating the need for large volumes of a priori information about protocol details and parameter values.
2Duration of action of stationary object
If obsolete equipment with unprotected information transmission protocols is used in technological systems, then equipment longevity and operational continuity are maintained, but vulnerabilities to malicious actions and computer attacks increase
Solution Approach 1:
The patent introduces a duplicator component that acts as an intermediary between the SCADA system and the obsolete PLC. The duplicator intercepts and monitors all data packets exchanged between these components, creating a layer of security observation without requiring modification of the obsolete PLC's unprotected protocols. This intermediary enables detection of malicious actions and anomalies while allowing the legacy equipment to continue operating with its original communication protocols intact.
Solution Approach 2:
The system performs preliminary monitoring and analysis of data packets before they reach the obsolete PLC or SCADA system. By establishing the duplicator in advance to capture and analyze communications, the system can detect potential security threats and anomalies before they cause harm. This preliminary action enables proactive security monitoring of vulnerable obsolete equipment without requiring retroactive modifications to the equipment itself.
3Reliability
If updating of PLC firmware is performed to address security vulnerabilities, then security protection is improved, but the process requires involvement of equipment maker and is extremely hard to solve
Solution Approach 1:
The duplicator serves as an intermediary security layer that provides protection without requiring firmware updates to the obsolete PLC. By monitoring and analyzing communications at the network level, the duplicator enables security improvements while avoiding the complex and costly process of obtaining and installing updated firmware from equipment manufacturers.
4Measurement precision
If anomaly detection methods requiring extensive a priori information are used, then detection accuracy is improved, but the methods produce errors such as type I and type II errors (false positives and false negatives)
Solution Approach 1:
The virtual PLC creates an accurate reference model of normal PLC communication behavior. By comparing actual PLC communications against this virtual copy, the system can detect anomalies with high precision without relying on extensive a priori information about specific protocol parameters. This copying approach reduces false positives and false negatives by providing a dynamic baseline for comparison rather than relying on static threshold values or extensive protocol knowledge.
Data Source
Figure 1a
Figure 1b
Figure 2
AI summary
Disclosed herein are systems and methods for detecting anomalies in a technological system. In one example, a method comprises, intercepting, by a duplicator running on an upper-level element of the technological system at least one outgoing data packet addressed to a middle-level element of the technological system, sending, by the duplicator, information about the intercepted at least one outgoing data packet to a monitor using a secure connection, the monitor running on the middle-level element, intercepting, by the monitor, at least one incoming data packet, comparing, by the monitor, the information received from the duplicator with the intercepted at least one incoming data packet, and detecting, by the monitor, an anomaly in the technological system when the intercepted at least one incoming data packet does not conform to the information received from the duplicator.