State Machine Network Anomaly Detection for ICS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) are vulnerable to cyber attacks due to their insecure design, which can disrupt critical infrastructure and pose risks to facilities, services, the environment, and human life, with existing solutions failing to effectively detect and mitigate various threats such as viruses, code injection, protocol exploitation, and unauthorized user activities.

Innovation Solution

A method and system that establish a baseline of acceptable network behavior using state machines to detect anomalies by analyzing packet sequences and transition probabilities, allowing for real-time detection and response to potential cyber security compromises, including alerting and blocking malicious activities without impacting critical infrastructure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented on ICS, then security protection is improved, but system operation and performance deteriorate due to air gap requirements and protocol restrictions

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem operation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a protocol analyzer and state machine model as an intermediary component that monitors and analyzes traffic between ICS devices without disrupting normal operations. This intermediary enables security detection while maintaining the operational integrity and performance of the control system, resolving the contradiction between security protection and system productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive traffic monitoring is implemented to detect all attack types, then detection accuracy is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the monitoring approach by changing parameters from comprehensive deep packet inspection to state machine-based protocol state validation. This parameter change enables accurate detection of protocol violations and attacks while reducing computational overhead and system complexity, as the state machine efficiently tracks legitimate protocol states without requiring exhaustive analysis of all traffic

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10681079B2Method for mitigation of cyber attacks on industrial control systems
Publication Date: 2020.06.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10681079B2 patent drawing
  • US10681079B2 patent drawing
  • US10681079B2 patent drawing

AI summary

Methods and systems for detecting a potential compromise of cyber security in an industrial network are disclosed. These methods and systems comprise elements of hardware and software for generating and analyzing vectors indicative of network behavioral states to establish thresholds for anomalous behavior in the industrial network.