PLC Threat Detection Using a Deterministic Fictitious Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICSs) lack effective security measures at the Programmable Logic Controller (PLC) level, making them vulnerable to cyber attacks, which can lead to critical infrastructure damage and pose a risk to public health and safety, with existing solutions being costly, invasive, and focused on communication layers rather than hardware interfaces.
Innovation Solution
A threat detection system comprising a Deterministic Fictitious Programmable Logic Controller (DFPLC) and a monitoring unit that sends input signals and expects predetermined responses, alerting upon deviations, thereby monitoring and identifying cyber-attacks on ICSs with minimal infrastructure changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network level security using firewalls and packet diodes is implemented, then protection against unauthorized internet access is improved, but security at the PLC hardware interface level remains vulnerable
Solution Approach 1:
The patent segments the security architecture by introducing a dedicated DFPLC component that operates independently from the main PLC system. This fictitious PLC is divided into specific functional modules (monitoring unit, signal generation unit, comparison unit) that work together to provide specialized security monitoring at the hardware interface level, complementing existing network-level security measures without requiring complex integration across the entire system.
Solution Approach 2:
The DFPLC acts as an intermediary component between the monitoring system and the physical devices connected to the PLC. It receives copies of input signals from the monitoring unit, generates expected output signals based on predetermined logic, and compares these with actual PLC outputs. This intermediary approach enables security monitoring at the hardware level without directly interfering with or complicating the main PLC architecture or network security infrastructure.
2Reliability
If existing security measures are implemented, then protection against network attacks is improved, but cost and invasiveness increase while leaving PLC-level vulnerabilities unaddressed
Solution Approach 1:
The patent uses copying by creating a fictitious PLC that replicates the essential input-output logic of the actual PLC system. The DFPLC is programmed with predetermined logic that mirrors the expected behavior of the physical devices it monitors. This copy enables security monitoring through comparison of expected versus actual signals without requiring expensive hardware modifications or invasive integration into the existing PLC infrastructure.
Solution Approach 2:
The DFPLC is predetermined with pre-programmed logic that defines expected input-output relationships before deployment. The monitoring unit is pre-configured with the specific logic of the physical devices being monitored. This preliminary programming allows the system to immediately detect anomalies and potential cyber-attacks without requiring real-time analysis or complex decision-making, reducing implementation costs and simplifying deployment.
3Reliability
If comprehensive security monitoring is implemented, then detection capability is improved, but system complexity and infrastructure requirements increase
Solution Approach 1:
The patent applies local quality by focusing security monitoring resources on specific critical input-output points rather than attempting to monitor the entire PLC system comprehensively. The DFPLC is configured to monitor particular physical devices or I/O lines that are most vulnerable or critical to the operation. This localized approach provides effective threat detection capability at key points without requiring complex infrastructure to monitor every aspect of the PLC system.
Solution Approach 2:
The monitoring unit implements partial action by monitoring only the specific input-output signals that are relevant to security concerns, rather than attempting to monitor all PLC operations. The DFPLC is programmed with predetermined logic for only the critical devices being monitored. This partial monitoring approach provides sufficient threat detection capability while keeping the monitoring infrastructure simple and cost-effective.
Data Source
AI summary
A threat detection system for industrial controllers, comprising: at least one Programmable Logic Controller (PLC); at least one physical device connected with the PLC; a Deterministic Fictitious Programmable Logic Controller (DFPLC) deterministically programmed to respond with at least one predetermined signal to at least one input signal received; and a monitoring unit connected with the DFPLC; the DFPLC disguised as a PLC; and the monitoring unit configured to send at least one input signal to the DFPLC, receive at least one response from the DFPLC and communicate at least one alert upon the at least one response being other than an expected response according to the deterministic programming of the DFPLC.


