Telemetry Analytics for Industrial Control Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face challenges in detecting and responding to cybersecurity threats due to the unique characteristics of IT and OT domains, leading to inefficiencies in situational awareness and threat detection, particularly in power grid networks, where existing security solutions often fail to provide timely and accurate alerts and may generate high false positive rates.

Innovation Solution

The ESTATION system integrates the ESCAN framework for effective security control assignment, the SINOPTEC telemetry analytics system for physical process anomaly detection, and the ECHO event management system for correlating events across IT and OT domains, utilizing machine learning and domain-specific context to enhance situational awareness and reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security solutions are deployed in ICS environments, then security monitoring is provided, but detection accuracy is reduced due to high false positive rates

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system segments security monitoring into two distinct domains: IT domain monitoring (using traditional security appliances like IDS/IPS, firewalls) and OT domain monitoring (using telemetry analytics for physical process analysis). Each domain has specialized components optimized for its unique characteristics, allowing accurate detection in both domains without cross-contamination of false positives.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an event correlation system as an intermediary that receives events from both IT and OT domains, correlates them using domain-specific knowledge, and produces unified security alerts. This intermediary layer reconciles the different event formats and detection methodologies, eliminating false positives that arise from applying IT-domain solutions to OT-domain problems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security controls are deployed throughout the network, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security controls into domain-specific segments: IT-domain security appliances (firewalls, IDS/IPS, antivirus) and OT-domain telemetry analytics engines. Each segment processes only the types of events it is designed for, reducing overall system complexity while maintaining comprehensive coverage across both domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The event correlation system serves as a universal platform that handles events from multiple domains (IT and OT) through a single interface. It provides multi-functional capabilities including event normalization, correlation, enrichment with domain-specific knowledge, and unified alert generation, replacing the need for separate complex systems in each domain.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional security appliances are used for monitoring, then security events are detected, but detection latency increases due to lack of visibility into process-level attacks

Engineering Contradiction:
Improvesecurity event detectionVSAvoiddetection latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system adds a new dimension to security monitoring by incorporating OT telemetry data (physical process parameters) alongside traditional IT security events. This dimensional expansion enables detection of process-level attacks that are invisible to conventional network-based security appliances, reducing detection latency for attacks that manifest primarily in the physical domain.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3206368B1Telemetry analysis system for physical process anomaly detection
Publication Date: 2020.08.05 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP3206368B1 patent drawingFigure 1
  • EP3206368B1 patent drawingFigure 2
  • EP3206368B1 patent drawingFigure 3

AI summary

Systems, methods, and apparatus, including computer programs encoded on computer storage media, for analyzing telemetry data from physical process sensors to detect anomalies within the physical process. A telemetry analytics system is disclosed as a process level anomaly detection system based on operational telemetrics and domain-specific knowledge that protects cyber physical system (CPS) devices against zero-day exploits not detectable through traditional system log or network packet inspection. The telemetry analytics system operates as a security component comparable to intrusion detection or anti-virus/anti-malware that generates alerts upon detecting anomalies in the sensor and/or activity data ingested from system or network data sources.