Industrial Zero-Trust Architecture Using Entropy-Based Malware Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial IoT networks face significant security challenges due to the presence of legacy devices lacking authentication methods and system patching, making it difficult to define adequate security policies, and malware can falsify data to avoid detection by operating within normal parameters, posing risks to industrial equipment and processes.

Innovation Solution

A zero-trust architecture is introduced that utilizes entropy testing and machine learning to verify the integrity of industrial equipment by adding entropy to control commands and analyzing sensor data for inconsistencies, employing data verification, entropy analysis, and closed-loop observation to detect and mitigate potential malware threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (e.g., 802.1x) are implemented in industrial IoT networks, then security policy enforcement is improved, but compatibility with legacy devices deteriorates because these devices lack authentication support

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidlegacy device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that does not require direct 802.1x support on legacy devices. Instead, it uses observable behavior patterns and entropy analysis of device operations to infer authentication status, acting as a mediator between modern security requirements and legacy device capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the authentication parameters from traditional credential-based authentication to behavior-based authentication. By monitoring operational parameters, timing patterns, and entropy characteristics of device behavior, the system can authenticate legacy devices without requiring them to support standard authentication protocols

Inventive Principle:
Principle #35Parameter changes

2Difficulty of detecting and measuring

If comprehensive security monitoring is implemented to detect malware, then detection capability is improved, but false negatives increase because malware can falsify data to operate within normal parameters

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system introduces entropy analysis as a form of behavioral vibration detection. By analyzing the randomness and unpredictability patterns in device operations, it can detect subtle anomalies that indicate malware presence, even when malware attempts to maintain normal operational parameters

Inventive Principle:
Principle #18Mechanical vibration

Solution Approach 2:

The system implements continuous feedback loops that monitor device behavior over time, comparing actual operational patterns against expected patterns. This feedback mechanism allows the system to adapt to changing malware tactics and maintain high detection accuracy by identifying deviations from normal behavior patterns

Inventive Principle:
Principle #23Feedback

3Reliability

If entropy testing is added to control commands for malware detection, then security verification is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The entropy testing mechanism is designed to be self-service, where the system automatically generates and analyzes entropy patterns in control commands without requiring manual configuration or intervention. The complexity is managed through automated algorithms that compute entropy metrics and compare them against baseline patterns

Inventive Principle:
Principle #25Self-service

4Measurement precision

If machine learning models are used to analyze sensor data for inconsistencies, then malware detection accuracy is improved, but processing requirements and computational load increase

Engineering Contradiction:
Improvesensor data verification accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The machine learning model implements partial action by focusing only on the most critical entropy metrics and behavioral patterns rather than analyzing all possible sensor data dimensions. This selective approach maintains high detection accuracy while reducing computational energy consumption by processing only the most informative features

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11392115B2Zero-trust architecture for industrial automation
Publication Date: 2022.07.19 CISCO TECHNOLOGY INC
  • US11392115B2 patent drawing
  • US11392115B2 patent drawing
  • US11392115B2 patent drawing

AI summary

According to one or more embodiments of the disclosure, a device in a network obtains parameters for entropy testing of industrial equipment that controls a physical process. Entropy is added to commands sent to the industrial equipment during the entropy testing. The device receives packets that were generated during the entropy testing of the industrial equipment and include sensor data regarding the physical process. The device determines whether the sensor data is inconsistent by analyzing the sensor data using a machine learning model that models the physical process. The device initiates a corrective measure, when the sensor data is determined to be inconsistent.