Redundant SIEM Architecture for Automation Network Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation networks face challenges in reliably detecting and evaluating security-relevant events due to potential message loss or manipulation during transmission, which can lead to false alarms and compromised security monitoring.

Innovation Solution

A redundant SIEM system architecture with a reliability and trustability verifier module is implemented, where two software tools work in tandem to check message generation and transmission, simulating scenarios to verify correct preconfiguration and detect deviations, ensuring tamperproof and reliable event reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single SIEM system is used to monitor security events, then the system structure is simple, but the reliability of security monitoring is compromised due to potential message loss or manipulation

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing different functional qualities in different parts of the system. The first SIEM system performs primary security monitoring with message evaluation, while the second SIEM system provides specialized verification of message generation and transmission. Each component has a specific quality optimized for its function, with the verification system focusing on reliability checking rather than general security analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The second SIEM system acts as an intermediary verification layer between the data processing devices and the first SIEM system. It mediates the security monitoring process by independently verifying message generation and transmission, then providing feedback to confirm system reliability without disrupting the primary monitoring function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundant SIEM systems are implemented to verify message transmission, then security monitoring reliability is improved, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvemessage transmission reliabilityVSAvoidredundant system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary verification actions by having the second SIEM system check message generation and transmission before the first SIEM system processes them for security analysis. This preliminary action ensures that only verified, reliable messages enter the primary monitoring system, preventing message loss or manipulation from compromising security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The second SIEM system creates a verification copy of the message transmission path, independently checking message generation and transmission without interfering with the primary monitoring flow. This copying approach allows reliability verification to occur in parallel, adding redundancy without significantly increasing processing complexity.

Inventive Principle:
Principle #26Copying

3Measurement precision

If the SIEM system evaluates all messages to detect security attacks, then detection capability is improved, but false alarms increase due to message loss or manipulation

Engineering Contradiction:
Improveattack detection precisionVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The second SIEM system provides feedback verification by independently checking message generation and transmission, then confirming reliability to the first SIEM system. This feedback mechanism allows the primary system to distinguish between genuine security events and false alarms caused by message loss or manipulation, improving detection precision while reducing false positive rates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10574671B2Method for monitoring security in an automation network, and automation network
Publication Date: 2020.02.25 SIEMENS AG
  • US10574671B2 patent drawing
  • US10574671B2 patent drawing
  • US10574671B2 patent drawing

AI summary

An automation network includes a plurality of data processing devices that are connected to one another for data communication. At least one data processing device in a first state, from the plurality of data processing devices, is preconfigured such that it generates corresponding messages upon identifying one or more security-relevant events. The messages are transmitted to at least one first software tool configured to record and evaluate the messages to determine whether there is a security-relevant attack on the automation network. The messages are transmitted to a second software tool configured to record and evaluate the messages and to determine whether the corresponding messages are generated by the at least one data processing device.