SCADA Controller Data Validation for Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SCADA-managed industrial systems are vulnerable to cyber-attacks that can cause physical damage, with existing detection methods failing to differentiate between cyber-attacks and operational failures, leading to high rates of false alerts and inability to handle 'Zero-day' vulnerabilities.

Innovation Solution

A system and method that utilize dedicated industrial computerized devices to validate data flows from SCADA-connected controllers, generate operational models of industrial subsystems, define attack vectors, and monitor data for mismatches, issuing alerts only when data indicates a cyber-attack, thereby differentiating between cyber-attacks and operational failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly recognition and machine learning methods are used to detect cyber-attacks, then detection capability is improved, but false alert rates increase and Zero-day vulnerabilities cannot be detected

Engineering Contradiction:
Improvecyber-attack detection capabilityVSAvoidaccuracy in differentiating cyber-attacks from operational failures
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces a dedicated industrial computerized device as an intermediary between the SCADA system and the detection analysis. This device passively monitors data flows without intervening in normal operations, validating data authenticity and detecting cyber-attacks by comparing actual data flows against expected patterns defined in the operational model, thereby reducing false alerts while maintaining high detection accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by generating an operational model that defines expected data flows and relationships between physical parameters before attacks occur. This model is used to validate data authenticity and detect anomalies, enabling the system to identify both known attack patterns and previously unseen Zero-day vulnerabilities through physical inconsistency detection

Inventive Principle:
Principle #10Preliminary action

2Reliability

If controllers are designed for reliability and robust operation, then operational stability is improved, but security vulnerabilities increase due to lack of validation mechanisms

Engineering Contradiction:
Improvecontroller operational stabilityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the control system by introducing a dedicated industrial computerized device that operates independently from the main SCADA controllers. This segmentation allows the validation and detection functions to be performed separately without interfering with the controllers' primary function of maintaining operational stability, while simultaneously providing security validation to mitigate cyber-attack vulnerabilities

Inventive Principle:
Principle #1Segmentation

3Area of stationary object

If existing detection methods monitor network layer data, then detection coverage is improved, but ability to detect attacks in infected systems deteriorates

Engineering Contradiction:
Improvedetection coverage scopeVSAvoiddetection effectiveness in infected systems
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent replaces network-layer monitoring with a deeper validation approach that examines the physical consistency of data flows at the controller level. By substituting network monitoring with operational model-based validation that checks whether data flows match expected physical relationships, the system can detect cyber-attacks even when the network layer appears normal or when systems are already infected

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11093606B2System and method for detecting a cyber-attack at SCADA/ICS managed plants
Publication Date: 2021.08.17 RAFAEL ADVANCED DEFENSE SYST LTD
  • US11093606B2 patent drawing
  • US11093606B2 patent drawing
  • US11093606B2 patent drawing

AI summary

System for detecting a cyber-attack of a SCADA system managed plant. Each industrial computerized device of the system comprises a processor configured with a data validation module to determine whether data flow outputted from a SCADA-connected controller is authentic, and with an alert issuing mechanism activated following detection that the outputted data flow is indicative of a cyber-attack. The at least one dedicated industrial computerized device is operable to passively monitor in parallel data communicated between each of the controllers and the SCADA system including the outputted data at the nearest points of each of the controllers; seek mismatches between the plant state and the physical operation model; if a mismatch is detected, determine whether the mismatch is indicative of a cyber-attack perpetrated with respect to one of the controllers or an operational malfunction; and upon detecting a cyber-attack, activate the alert issuing mechanism to issue a security alert.