Virtual OT Network Simulation for Cybersecurity Rule Gaps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face vulnerabilities due to gaps in network security systems that allow cyberattacks to go undetected, as attackers adapt their techniques and the configuration of the OT environment changes.

Innovation Solution

A cybersecurity simulator is used to create a virtual network security system based on the configuration of the real network, simulating cyberattacks to identify and expose vulnerabilities in the network security system, generating reports on undetected threats and providing recommendations for improvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network security system is deployed to monitor OT network activity, then security detection capability is improved, but unidentified gaps in the system render the OT network vulnerable to attack

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidvulnerability to attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security testing by deploying simulated cyberattacks against the OT network security system before actual attacks can occur. The cybersecurity simulator proactively identifies gaps and vulnerabilities through advance testing, allowing security teams to remediate issues before they can be exploited by real attackers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the potential harm of simulated cyberattacks into a benefit by using these simulated attacks as a testing mechanism. The simulated malicious activity, which could be harmful if real, is instead used to identify security gaps and improve the overall security posture of the OT network.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Measurement precision

If simulated cyberattacks are deployed to test the network security system, then security gaps are identified, but the complexity of the testing system increases

Engineering Contradiction:
Improvesecurity gap identification accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system creates a virtual copy of the OT network environment with a virtual network security system that mirrors the real system's configuration. This copy is used for testing purposes, allowing comprehensive security testing without affecting the actual OT network. The virtual environment can be freely manipulated and tested with various simulated attacks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The cybersecurity simulator acts as an intermediary between the test administrator and the network security system. It manages the deployment of simulated cyberattacks, coordinates the testing process, and consolidates results into comprehensive reports, simplifying the overall testing workflow despite the complexity of the underlying test infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If the virtual network security system is configured based on real system configuration data, then test results are accurate, but the configuration process becomes more complex

Engineering Contradiction:
Improvetest result accuracyVSAvoidconfiguration process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system creates a virtual copy of the real network security system by importing its configuration data. This copy accurately replicates the real system's security rules, policies, and settings, ensuring that test results reflect the actual system's performance. The virtual configuration can be updated to match any changes in the real system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system provides feedback mechanisms that allow administrators to verify the accuracy of the virtual configuration against the real system. Test results from the virtual environment feed back into understanding the real system's security posture, and discrepancies can be identified and corrected to improve configuration accuracy over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12574401B2Operational technology cyber defense cloud services platform
Publication Date: 2026.03.10 ROCKWELL AUTOMATION TECH INC
  • US12574401B2 patent drawing
  • US12574401B2 patent drawing
  • US12574401B2 patent drawing

AI summary

A non-transitory computer readable medium stores instructions that, when executed by a processor, cause the processor to receive data associated with a plurality of simulated cyberattacks on a virtual operational technology (OT) network, wherein the virtual OT network comprises a virtualized representation of an OT network based on configuration data of the OT network, identify, based on the received data, one or more cybersecurity vulnerabilities of the OT network, identify one or more modifications to a set of cybersecurity rules implemented in the OT network to address the one or more cybersecurity vulnerabilities of the OT network, provide an indication of the one or more modifications to a computing device associated with the OT network for approval; and update, via a third-party network security service utilized by an operator of the OT network, the set of cybersecurity rules to implement the one or more identified modifications.