Telemetry Analytics for Industrial Control Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICS) face challenges in detecting and responding to cybersecurity threats due to the unique characteristics of IT and OT domains, leading to inefficiencies in situational awareness and threat detection, particularly in power grid networks, where existing security solutions often fail to provide timely and accurate alerts and may generate high false positive rates.
Innovation Solution
The ESTATION system integrates the ESCAN framework for effective security control assignment, the SINOPTEC telemetry analytics system for physical process anomaly detection, and the ECHO event management system for correlating events across IT and OT domains, utilizing machine learning and domain-specific context to enhance situational awareness and reduce false positives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security solutions are deployed in ICS environments, then security monitoring is provided, but detection accuracy is reduced due to high false positive rates
Solution Approach 1:
The system segments security monitoring into two distinct domains: IT domain monitoring (using traditional security appliances like IDS/IPS, firewalls) and OT domain monitoring (using telemetry analytics for physical process analysis). Each domain has specialized components optimized for its unique characteristics, allowing accurate detection in both domains without cross-contamination of false positives.
Solution Approach 2:
The system introduces an event correlation system as an intermediary that receives events from both IT and OT domains, correlates them using domain-specific knowledge, and produces unified security alerts. This intermediary layer reconciles the different event formats and detection methodologies, eliminating false positives that arise from applying IT-domain solutions to OT-domain problems.
2Reliability
If security controls are deployed throughout the network, then security coverage is improved, but system complexity increases
Solution Approach 1:
The system divides security controls into domain-specific segments: IT-domain security appliances (firewalls, IDS/IPS, antivirus) and OT-domain telemetry analytics engines. Each segment processes only the types of events it is designed for, reducing overall system complexity while maintaining comprehensive coverage across both domains.
Solution Approach 2:
The event correlation system serves as a universal platform that handles events from multiple domains (IT and OT) through a single interface. It provides multi-functional capabilities including event normalization, correlation, enrichment with domain-specific knowledge, and unified alert generation, replacing the need for separate complex systems in each domain.
3Reliability
If traditional security appliances are used for monitoring, then security events are detected, but detection latency increases due to lack of visibility into process-level attacks
Solution Approach 1:
The system adds a new dimension to security monitoring by incorporating OT telemetry data (physical process parameters) alongside traditional IT security events. This dimensional expansion enables detection of process-level attacks that are invisible to conventional network-based security appliances, reducing detection latency for attacks that manifest primarily in the physical domain.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, and apparatus, including computer programs encoded on computer storage media, for analyzing telemetry data from physical process sensors to detect anomalies within the physical process. A telemetry analytics system is disclosed as a process level anomaly detection system based on operational telemetrics and domain-specific knowledge that protects cyber physical system (CPS) devices against zero-day exploits not detectable through traditional system log or network packet inspection. The telemetry analytics system operates as a security component comparable to intrusion detection or anti-virus/anti-malware that generates alerts upon detecting anomalies in the sensor and/or activity data ingested from system or network data sources.