
With Industrial Anomaly Detection from Siemens, security-relevant incidents such as unauthorized intrusion or malware can be detected and countermeasures taken on this basis. The software is pre-installed on an industrial PC and is easy to integrate into industrial environments. Alternatively, it will also be available on network components from Siemens, such as the 'Ruggedcom RX1500' multi-service platform with 'Rugged-com APE'. Anomaly detection is particularly suitable for companies in the automotive production, aerospace, chemical, pharmaceutical, food and beverage and water/wastewater sectors. In the first step, 'Industrial Anomaly Detection' creates transparency about the devices integrated in industrial networks, such as controllers or operating devices and the software installed on them. On this basis, vulnerabilities of network devices are identified in the second step by examining the devices for known security gaps (Common Vulnerabilities and Exposures/CVE). At the same time, other security vulnerabilities caused by insecure configuration are identified and rectified. In the third step, the communication behavior of the devices can be continuously monitored. The system records the data passively and therefore has no influence on production. It supports the products of all common automation manufacturers and their protocols. If the solution detects deviations that indicate unauthorized intrusion or misconfigurations, for example, it automatically sends an alarm message to the user. Artificial intelligence is also used for anomaly detection. The configuration of the system is self-learning: the solution automatically analyzes the data traffic in the network in a 'learning phase' in order to later detect anomalies that indicate intrusion or data theft by hackers, for example.
