SCADA Intrusion Detection Using Auto-Generated ICS Whitelists

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IDS implementations in SCADA systems face complexity and challenges in keeping configuration up-to-date, especially when devices connected to the ICS network change, leading to administrative burdens and delayed response times to intrusion attempts.

Innovation Solution

A SCADA system with an integrated intrusion detection component that automatically generates and updates a whitelist based on SCADA configuration information, including device information, to identify authorized communications and respond to unauthorized activity, thereby reducing manual intervention and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IDS implementations use dedicated appliances or separate servers to store configuration information, then the IDS can detect unauthorized traffic, but the configuration becomes complex and difficult to keep updated when devices change

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the IDS configuration storage function with the SCADA system's existing configuration database. Instead of using separate dedicated appliances or servers, the IDS component utilizes the SCADA system's internal configuration information to automatically generate and update authorized communication whitelists, thereby reducing overall system complexity while maintaining detection capability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The IDS component automatically generates authorized communication information from SCADA configuration data without requiring manual configuration updates. When device information changes in the SCADA system, the IDS self-updates its whitelist by reading the modified configuration, eliminating the need for administrators to manually maintain IDS configuration

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration updates are performed for each device change in the SCADA system, then the IDS can maintain accurate whitelists, but administrative burden increases and response time to intrusion attempts delays

Engineering Contradiction:
Improvewhitelist accuracyVSAvoidconfiguration update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The IDS component establishes a feedback mechanism with the SCADA configuration system. When configuration changes occur in the SCADA system (such as device additions, removals, or modifications), the IDS automatically detects these changes through configuration monitoring and regenerates the authorized communication whitelist accordingly, ensuring continuous accuracy without manual intervention

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The IDS pre-generates the authorized communication whitelist from SCADA configuration information before intrusion detection begins. This preliminary action ensures that the whitelist is ready and accurate from the start, and subsequent updates are automatically triggered by configuration changes, eliminating delays in response to new devices or intrusion attempts

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3002648B1Scada intrusion detection systems
Publication Date: 2021.06.16 SCHNEIDER ELECTRIC USA INC
  • EP3002648B1 patent drawingFigure 1
  • EP3002648B1 patent drawingFigure 2
  • EP3002648B1 patent drawingFigure 3

AI summary

According to one aspect, a SCADA system is provided. The SCADA system includes a network interface configured to communicate data with a plurality of industrial control devices via an industrial control system (ICS) network. The SCADA system further includes a memory storing SCADA configuration information including ICS network configuration information and device information descriptive of each industrial control device of the plurality of industrial control devices and at least one processor in data communication with the memory and the network interface. The SCADA system also includes an intrusion detection component executable by the at least one processor and configured to read the SCADA configuration information, generate, from the SCADA configuration information, authorized communication information descriptive of one or more expected communication types of communications authorized for transmission via the ICS network.