PLC Network Traffic Analysis for Deviant Engineering Modifications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation control networks are vulnerable to malicious threats that can disrupt operations and compromise the integrity of programmable logic controllers, with existing solutions failing to effectively detect deviant engineering modifications through network traffic analysis.

Innovation Solution

A network security system that collects and compares network traffic data from engineering stations using a network traffic collection device, storage module, comparison module, abnormality detection module, and alarming/correction module to identify deviant modifications by analyzing traffic content and timing patterns against benchmarks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network traffic analysis is implemented to detect deviant engineering modifications, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The network security system is divided into distinct functional modules: a network traffic collection device for capturing traffic data, a comparison module for analyzing traffic patterns, and an alarming module for generating alerts. This segmentation allows each module to perform its specific function efficiently while maintaining overall system manageability despite the increased complexity of network traffic analysis.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive network traffic data collection is performed, then detection accuracy is improved, but data processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-establishes a database of normal network traffic patterns and communication protocols specific to programmable logic controllers during the engineering phase. By having baseline data ready before actual monitoring begins, the comparison module can quickly evaluate current traffic against known good patterns without requiring extensive analysis time, thus maintaining both accuracy and speed.

Inventive Principle:
Principle #10Preliminary action

3Speed

If real-time monitoring of network traffic is implemented, then response time to threats is improved, but computational load increases

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational load
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system employs lightweight traffic analysis that focuses on key identifying features and timing patterns rather than deep inspection of every packet. By analyzing only the most critical aspects of network traffic that indicate deviant modifications, the system achieves real-time detection with reduced computational overhead, effectively using minimal processing resources for each traffic unit.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11140186B2Identification of deviant engineering modifications to programmable logic controllers
Publication Date: 2021.10.05 SIEMENS INDUSTRY INC
  • US11140186B2 patent drawing
  • US11140186B2 patent drawing
  • US11140186B2 patent drawing

AI summary

Embodiments include methods, network security computer systems, and computer program products for identifying deviant engineering modifications to programmable logic controllers. Aspects include: collecting, by a network traffic collection device of the network security computer, network traffic data from one or more engineering stations, and storing, by a network traffic data storage device, the network traffic data collected. Each of the engineering stations may include one or more programmable logic controllers. The method also may include: comparing, by a network traffic comparison module, the network traffic data collected, detecting, by an abnormality detection module, any deviant engineering modifications to the programmable logic controllers in the engineering stations; and generating, by an alarming and correction module, one or more reports for the deviant engineering modifications to programmable logic controllers. The alarming and correction module may generate one or more alarms and block any network traffic associated with the deviant engineering modifications.