Replica PLC Accelerated Simulation for Malware Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial and energy control systems face challenges in rapidly characterizing the impact of sophisticated malware attacks, as existing methods are costly, time-consuming, and limited in scalability, and require deep knowledge to manage the complexity of these systems.

Innovation Solution

A threat impact characterization system using a replica programmable logic controller (PLC) operating at accelerated speeds, simulating the production system to determine potential threats by comparing malware-infected and non-infected firmware impacts, facilitating quick translation of low-level forensics data into high-level impact characterization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional malware analysis methods are used on production systems, then thorough threat characterization can be achieved, but the process becomes time-consuming and costly

Engineering Contradiction:
Improvethreat characterization accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates a replica PLC that copies the functional and operational characteristics of the production PLC. This replica serves as a testbed for malware analysis, allowing thorough threat characterization without impacting the actual production system. The replica can be safely infected with malware and analyzed in detail while the production system remains operational and unaffected.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system separates the analysis function from the production function by creating distinct replica PLCs for different analysis purposes. One replica can be used for static analysis while another is used for dynamic analysis, allowing parallel processing and reducing overall analysis time without compromising thoroughness.

Inventive Principle:
Principle #1Segmentation

2Reliability

If static analysis alone is used, then system safety is maintained, but the analysis is incomplete and time-consuming

Engineering Contradiction:
Improvesystem safetyVSAvoidanalysis throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the analysis approach by first performing static analysis to identify potential threats, then selectively applying dynamic analysis to specific malware samples that require deeper investigation. This dynamic approach maintains safety through controlled execution while improving productivity by avoiding unnecessary dynamic analysis of all samples.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Static analysis is performed as a preliminary step before dynamic analysis. This preliminary action identifies suspicious code patterns and potential threats, allowing the system to prioritize which malware samples require dynamic analysis. This reduces the overall number of dynamic analyses needed while maintaining thoroughness for high-risk samples.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If dynamic analysis is performed on production PLCs, then comprehensive threat detection is achieved, but the production system becomes vulnerable and at risk

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The replica PLC serves as a safe copy for dynamic malware analysis. The malware is executed and analyzed on the replica rather than the production PLC, eliminating the vulnerability risk to the production system. The replica can be isolated in a controlled environment, ensuring that even if the malware causes damage, the production system remains protected.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The replica PLC acts as an intermediary between the malware and the production system. All dynamic analysis is conducted through this intermediate layer, which buffers and protects the production system from direct exposure to malicious code. The replica absorbs the harmful effects while providing the necessary data for threat characterization.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If multiple replica PLCs are used for parallel analysis, then analysis speed increases, but system complexity increases

Engineering Contradiction:
Improveanalysis speedVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The multiple replica PLCs are designed with universal functionality, where each replica can perform both static and dynamic analysis tasks. This multi-functionality reduces the need for specialized hardware for each analysis type, simplifying the overall system architecture while maintaining high productivity through parallel processing capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3475774B1System and method for threat impact determination
Publication Date: 2023.07.12 SIEMENS AG
  • EP3475774B1 patent drawingFigure 1
  • EP3475774B1 patent drawingFigure 2
  • EP3475774B1 patent drawingFigure 3

AI summary

A system (100) and method is provided that facilitates threat impact characterization. The system may include a replica programmable logic controller (PLC) (102) that corresponds to a production PLC (122) in a production system (120) and that may be configured to operate at an accelerated processing speed that is at least two times faster than a processing speed of the production PLC. The system may also include a data processing system (132) configured to communicate with the replica PLC when executing malware infected PLC firmware (112) and generate a simulation (146) of the production system based on a virtual model (142) of the production system operating at an accelerated processing speed that is at least two times faster than a processing speed of the physical production system. The simulation may include accelerated simulation of the production PLC based on communication with the replica PLC using the malware infected PLC firmware. The data processing system may also monitor: outputs from the replica PLC and the simulation of the production system to determine a possible threat to a hardware component (124) of the production system caused by the production PLC executing the infected PLC firmware rather than a non-infected PLC firmware; and output data indicative of the possible threat thorough a display device (152).