PLC Threat Detection Using a Deterministic Fictitious Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICSs) lack effective security measures at the Programmable Logic Controller (PLC) level, making them vulnerable to cyber attacks, which can lead to critical infrastructure damage and pose a risk to public health and safety, with existing solutions being costly, invasive, and focused on communication layers rather than hardware interfaces.

Innovation Solution

A threat detection system comprising a Deterministic Fictitious Programmable Logic Controller (DFPLC) and a monitoring unit that sends input signals and expects predetermined responses, alerting upon deviations, thereby monitoring and identifying cyber-attacks on ICSs with minimal infrastructure changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network level security using firewalls and packet diodes is implemented, then protection against unauthorized internet access is improved, but security at the PLC hardware interface level remains vulnerable

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security architecture by introducing a dedicated DFPLC component that operates independently from the main PLC system. This fictitious PLC is divided into specific functional modules (monitoring unit, signal generation unit, comparison unit) that work together to provide specialized security monitoring at the hardware interface level, complementing existing network-level security measures without requiring complex integration across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The DFPLC acts as an intermediary component between the monitoring system and the physical devices connected to the PLC. It receives copies of input signals from the monitoring unit, generates expected output signals based on predetermined logic, and compares these with actual PLC outputs. This intermediary approach enables security monitoring at the hardware level without directly interfering with or complicating the main PLC architecture or network security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing security measures are implemented, then protection against network attacks is improved, but cost and invasiveness increase while leaving PLC-level vulnerabilities unaddressed

Engineering Contradiction:
Improvesecurity protectionVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses copying by creating a fictitious PLC that replicates the essential input-output logic of the actual PLC system. The DFPLC is programmed with predetermined logic that mirrors the expected behavior of the physical devices it monitors. This copy enables security monitoring through comparison of expected versus actual signals without requiring expensive hardware modifications or invasive integration into the existing PLC infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The DFPLC is predetermined with pre-programmed logic that defines expected input-output relationships before deployment. The monitoring unit is pre-configured with the specific logic of the physical devices being monitored. This preliminary programming allows the system to immediately detect anomalies and potential cyber-attacks without requiring real-time analysis or complex decision-making, reducing implementation costs and simplifying deployment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security monitoring is implemented, then detection capability is improved, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidmonitoring infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing security monitoring resources on specific critical input-output points rather than attempting to monitor the entire PLC system comprehensively. The DFPLC is configured to monitor particular physical devices or I/O lines that are most vulnerable or critical to the operation. This localized approach provides effective threat detection capability at key points without requiring complex infrastructure to monitor every aspect of the PLC system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The monitoring unit implements partial action by monitoring only the specific input-output signals that are relevant to security concerns, rather than attempting to monitor all PLC operations. The DFPLC is programmed with predetermined logic for only the critical devices being monitored. This partial monitoring approach provides sufficient threat detection capability while keeping the monitoring infrastructure simple and cost-effective.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11378929B2Threat detection system for industrial controllers
Publication Date: 2022.07.05 SI GA DATA SECURITY 2014 LTD
  • US11378929B2 patent drawing
  • US11378929B2 patent drawing
  • US11378929B2 patent drawing

AI summary

A threat detection system for industrial controllers, comprising: at least one Programmable Logic Controller (PLC); at least one physical device connected with the PLC; a Deterministic Fictitious Programmable Logic Controller (DFPLC) deterministically programmed to respond with at least one predetermined signal to at least one input signal received; and a monitoring unit connected with the DFPLC; the DFPLC disguised as a PLC; and the monitoring unit configured to send at least one input signal to the DFPLC, receive at least one response from the DFPLC and communicate at least one alert upon the at least one response being other than an expected response according to the deterministic programming of the DFPLC.