Attacker Localization via Anomaly Propagation Tracking in TSN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In time-sensitive networking environments, attackers can disrupt time synchronization by delaying messages and modifying residence times on switch nodes, leading to desynchronization of follower nodes and remaining undetected.
Innovation Solution
The solution involves tracking anomaly propagation in time-sensitive networking environments by using a monitor node to detect non-compliant nodes based on remote performance measurements and keyed hash values, and identifying malicious nodes by analyzing their positions in the network topography.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If time synchronization protocol is implemented in TSN environment, then time synchronization is achieved, but attacker can disrupt synchronization by delaying messages and modifying residence times
Solution Approach 1:
The patent implements a feedback mechanism where the monitor node continuously observes performance measurements (residence times, frame ingress times) from follower nodes and switch nodes. When anomalies are detected that indicate desynchronization attacks, the system generates alerts and can trigger resynchronization protocols. This closed-loop feedback enables the TSN network to detect and respond to synchronization disruptions, resolving the vulnerability while maintaining synchronization reliability.
Solution Approach 2:
The patent introduces a monitor node as an intermediary between the leader node and follower nodes. This intermediary continuously collects performance measurements, analyzes them for anomalies, and identifies potential attack sources by comparing expected versus actual residence times. The monitor node acts as a security layer that protects the time synchronization protocol from attacks without requiring changes to the core synchronization mechanism.
2Object-generated harmful factors
If attacker delays messages and modifies residence times, then desynchronization occurs, but attacker remains undetected in compromised node
Solution Approach 1:
The patent replaces traditional security mechanisms (which would require complex authentication and encryption at each node) with a measurement-based detection system. By substituting security verification with performance measurement analysis (comparing expected versus actual residence times), the system can detect attackers through their behavioral impact on message timing rather than requiring direct security credentials at each node.
Solution Approach 2:
The monitor node serves as an intermediary that aggregates and analyzes performance measurements from multiple nodes. By collecting data from the leader node, follower nodes, and switch nodes, the monitor can triangulate the source of desynchronization attacks. This intermediary approach makes detection feasible by centralizing the analysis of timing anomalies that would be difficult to detect at individual nodes.
3Measurement precision
If monitor node tracks anomaly propagation using performance measurements, then malicious nodes are localized, but system complexity increases
Solution Approach 1:
The patent segments the monitoring function into distinct components: the monitor node that collects and analyzes data, the leader node that generates synchronization messages, follower nodes that provide performance measurements, and switch nodes that report residence times. This segmentation allows each component to perform a specific function with relatively simple logic, while the overall system achieves sophisticated attacker localization through the coordinated interaction of these segmented parts.
Data Source
AI summary
Systems, apparatuses and methods may provide for technology that detects one or more non-compliant nodes with respect to a timing schedule, detects one or more compliant nodes with respect to the timing schedule, and identifies a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography. The non-compliant node(s) and the compliant node(s) may be detected based on post-synchronization messages, historical attribute data and/or plane diversity data.


