PLC Backplane Analyzer for Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems, particularly those involving programmable logic controllers (PLCs), are vulnerable to malicious attacks like the STUXNET worm, which can compromise PLC integrity by subverting traditional verification methods such as firmware read-back and network traffic analysis.
Innovation Solution
An analyzer system is configured to capture and compare operational data with baseline data across a backplane, detecting anomalies by replicating control data and forwarding it to an analyzer system for comparison, thereby identifying unexpected or malicious activity between components communicatively coupled across the backplane.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If firmware read-back or network traffic analysis is used to verify PLC integrity, then remote verification capability is improved, but the verification can be subverted by malicious attacks
Solution Approach 1:
The patent introduces a backplane as an intermediary monitoring point between the PLC controller and its components. By capturing and analyzing traffic flowing through the backplane, the system achieves verification of PLC integrity without relying on potentially subverted firmware read-back or external network traffic analysis. The backplane acts as a trusted intermediary that provides direct observation of internal controller communications.
2Measurement precision
If backplane traffic capture is implemented for intrusion detection, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The analyzer system creates copies of backplane traffic for analysis while allowing the original traffic to continue flowing uninterrupted between controller components. This copying approach enables comprehensive monitoring and anomaly detection without altering the normal operation of the PLC system or requiring complex modifications to the controller architecture.
Solution Approach 2:
The system segments the monitoring function from the control function by placing the analyzer as a separate component that independently captures and analyzes backplane traffic. This segmentation allows the analyzer to focus solely on detection tasks while the controller continues its control operations, reducing overall system complexity.
3Speed
If real-time backplane monitoring is performed, then intrusion detection speed is improved, but processing overhead increases
Solution Approach 1:
The analyzer implements partial monitoring by focusing on specific backplane traffic patterns and protocols that are most indicative of intrusions. Rather than analyzing every single byte of backplane traffic, the system selectively monitors critical communication channels and data types, reducing processing overhead while maintaining effective detection speed.
Data Source
AI summary
The various technologies presented herein relate to the determination of unexpected and/or malicious activity occurring between components communicatively coupled across a backplane. Control data, etc., can be intercepted at a backplane where the backplane facilitates communication between a controller and at least one device in an automation process. During interception of the control data, etc., a copy of the control data can be made, e.g., the original control data can be replicated to generate a copy of the original control data. The original control data can continue on to its destination, while the control data copy can be forwarded to an analyzer system to determine whether the control data contains a data anomaly. The content of the copy of the control data can be compared with a previously captured baseline data content, where the baseline data can be captured for a same operational state as the subsequently captured control data.


