Behavioral Modeling for Anomaly Detection in Utility Automation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Power utility automation networks face challenges in detecting new, unknown malware forms due to the reliance on signature-based cybersecurity approaches, which require prior knowledge of malware behavior and are ineffective against zero-day attacks.

Innovation Solution

A behavioral modeling approach is introduced, utilizing System Configuration Description Language (SCL) files and traffic data to train a model that identifies anomalous traffic behavior in power utility automation networks, enabling early detection of cybersecurity threats, including zero-day attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based cybersecurity mechanisms are used to detect malware, then known malware can be effectively detected, but new forms of malware (zero-day attacks) cannot be detected because their signatures are unknown

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcapability to detect new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing network traffic data before deploying the behavioral model. It trains the model in advance using historical traffic data to establish a baseline of normal network behavior, enabling the system to detect deviations caused by new malware without requiring pre-existing signatures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the detection parameter from static malware signatures to dynamic behavioral patterns. Instead of matching known malware characteristics, the system monitors deviations from established normal behavior parameters, allowing it to detect new malware forms that exhibit anomalous behavioral patterns rather than matching known signatures

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional network security mechanisms (firewalls, signature-based IPS/IDS) are deployed to inspect traffic, then Layer-2 and Layer-3 traffic can be protected, but these mechanisms are ineffective against malware that does not match known signatures

Engineering Contradiction:
Improvenetwork security protectionVSAvoidnew malware infiltration risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system replaces mechanical signature-matching mechanisms with a machine learning-based behavioral analysis system. Instead of using rigid firewall rules and signature databases, the system employs trained models that automatically learn and adapt to normal network behavior patterns, substituting static mechanical security checks with dynamic intelligent analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The behavioral model performs self-service by automatically training on network traffic data and continuously improving its detection capabilities. The system autonomously identifies normal behavior patterns and detects anomalies without requiring manual signature updates or configuration changes, enabling it to adapt to new threats independently

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11941710B2Behavioral modeling for power utility automation networks
Publication Date: 2024.03.26 CISCO TECHNOLOGY INC
  • US11941710B2 patent drawing
  • US11941710B2 patent drawing
  • US11941710B2 patent drawing

AI summary

According to one or more embodiments of the disclosure, a device obtains one or more System Configuration Description Language files regarding a power utility automation network. The device also obtains traffic data regarding traffic in the power utility automation network. The device trains, using the one or more System Configuration Description Language files and the traffic data, a behavioral model for the power utility automation network that models traffic in the power utility automation network. The device initiates use of the behavioral model in the power utility automation network to identify anomalous traffic behavior in the power utility automation network.