State Machine Network Anomaly Detection for ICS Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICS) are vulnerable to cyber attacks due to their insecure design, which can disrupt critical infrastructure and pose risks to facilities, services, the environment, and human life, with existing solutions failing to effectively detect and mitigate various threats such as viruses, code injection, protocol exploitation, and unauthorized user activities.
Innovation Solution
A method and system that establish a baseline of acceptable network behavior using state machines to detect anomalies by analyzing packet sequences and transition probabilities, allowing for real-time detection and response to potential cyber security compromises, including alerting and blocking malicious activities without impacting critical infrastructure operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures are implemented on ICS, then security protection is improved, but system operation and performance deteriorate due to air gap requirements and protocol restrictions
Solution Approach 1:
The patent introduces a protocol analyzer and state machine model as an intermediary component that monitors and analyzes traffic between ICS devices without disrupting normal operations. This intermediary enables security detection while maintaining the operational integrity and performance of the control system, resolving the contradiction between security protection and system productivity
2Measurement precision
If comprehensive traffic monitoring is implemented to detect all attack types, then detection accuracy is improved, but system complexity and computational overhead increase
Solution Approach 1:
The patent transforms the monitoring approach by changing parameters from comprehensive deep packet inspection to state machine-based protocol state validation. This parameter change enables accurate detection of protocol violations and attacks while reducing computational overhead and system complexity, as the state machine efficiently tracks legitimate protocol states without requiring exhaustive analysis of all traffic
Data Source
AI summary
Methods and systems for detecting a potential compromise of cyber security in an industrial network are disclosed. These methods and systems comprise elements of hardware and software for generating and analyzing vectors indicative of network behavioral states to establish thresholds for anomalous behavior in the industrial network.


