Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP

Mars Cheng (Senior Researcher · TX1 Networks), Jr Wei-Huang (Senior Researcher)

DEF CON 33 · Day 1 · Main Stage

Overview

In this DEF CON talk, Mars Cheng and Jr Wei-Huang (Jay Jong) from TX1 Networks presented a groundbreaking approach to enhance Operational Technology (OT) security by leveraging Artificial Intelligence (AI) and Natural Language Processing (NLP) to autonomously generate Application Security Rules (ASR) for detecting OT-specific attacks. The presentation, titled "Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP," addresses the unique and pressing challenges of securing critical industrial control systems (ICS) and OT environments, which often cannot adopt traditional IT security paradigms.

Watch on YouTube

Visual summary for Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP by Mars Cheng, Jr Wei-Huang
Visual summary for Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP by Mars Cheng, Jr Wei-Huang

Key moments

  1. 0:00 Introduction to speakers and talk topic
  2. 2:00 Why OT detection differs from IT security
  3. 3:20 Combining AI and OT attributes for effective detection
  4. 4:00 Analyzing past AI research and its OT limitations
  5. 6:15 The critical role of process relationships in OT
  6. 6:45 Real-world OT attack: Sandworm's 'leaf of land'
  7. 8:00 Examples of malicious process chain indicators

Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP

Speakers: Mars Cheng (Senior Researcher, TX1 Networks); Jr Wei-Huang (Senior Researcher)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=MJV5FQztfi4

Overview

In this DEF CON talk, Mars Cheng and Jr Wei-Huang (Jay Jong) from TX1 Networks presented a groundbreaking approach to enhance Operational Technology (OT) security by leveraging Artificial Intelligence (AI) and Natural Language Processing (NLP) to autonomously generate Application Security Rules (ASR) for detecting OT-specific attacks. The presentation, titled "Let AI Autogenerate Neural ASR Rules for OT Attacks via NLP," addresses the unique and pressing challenges of securing critical industrial control systems (ICS) and OT environments, which often cannot adopt traditional IT security paradigms.

The core of their research lies in developing a novel machine learning model designed to learn baseline normal behaviors within OT environments, identify subtle deviations indicative of attacks, and subsequently block malicious activities. This is particularly vital given the high stakes of OT security, where successful cyberattacks can lead to physical damage, operational disruptions, and even loss of life. By focusing on behavioral analysis and the critical role of process relationships, the speakers propose a lightweight, robust, and explainable detection solution tailored specifically for the nuances of industrial systems.

This work matters significantly because it offers a practical pathway to overcome the limitations of human-defined rules and the impracticality of frequent signature updates in OT. It promises earlier, more accurate, and context-aware threat detection, enabling defenders to prevent attacks more effectively and improve incident response in diverse OT verticals like manufacturing, critical infrastructure, and automotive industries. The presented methodology aims to bridge the gap between advanced AI capabilities and the specialized requirements of OT security, moving beyond generic IT solutions that often generate excessive false positives or miss critical OT-specific threats.

Background

▶ Watch: Introduction to speakers and talk topic (0:00)

Securing Operational Technology (OT) environments presents a fundamentally different set of challenges compared to conventional IT systems. Unlike their IT counterparts, OT systems are often legacy, difficult to patch, and challenging to update without risking operational disruptions. Traditional antivirus solutions, with their reliance on frequent signature updates and large signature databases, are typically impractical in these sensitive environments, frequently causing performance issues or instability. Yet, factories and critical infrastructure demand robust protection, leading to a critical question: how can OT environments effectively adapt to evolving threats while minimizing false alarms and leveraging OT-specific features that IT-centric solutions often overlook?

The speakers highlighted that while AI advancements offer promising avenues for malware detection, previous research, primarily focused on IT, often falls short in the OT context. For instance, a 2020 study on dynamic analysis techniques using graph learning successfully detected over 96% of unseen malware by transforming API usage into numerical vectors. However, it required extensive human expertise to define "sensitive APIs," making it unsuitable for the unique and diverse landscape of OT/ICS attacks. Similarly, a 2024 paper leveraging dark-to-vector and Google Robot (a transformer model utilizing self-attention mechanisms) demonstrated robust NLP technology for learning from expert rules, but still did not specifically address OT challenges. Another 2021 approach transformed individual process behaviors into graph-based Directed Acyclic Graphs (DAGs), achieving 94% detection accuracy across five dimensions (registry, network, process, DNS, file), but suffered from performance limitations and, critically, lacked the ability to model process parent-child relationships.

The absence of robust parent-child process relationship analysis was identified as a major limitation in these prior works when applied to OT. The speakers underscored the critical role of these relationships in semantic detection, citing real-world examples. The Sandworm group's disruptive attacks on the Ukrainian grid involving living-off-the-land (LOTL) techniques, often difficult to flag as malicious by IT EDRs, demonstrate the necessity of understanding process lineage. Scenarios like explorer.exe launching wscript.exe, followed by cmd.exe and then calc.exe, or Adobe Reader/Microsoft Office triggering PowerShell, are strong indicators of malicious behavior when their parent-child context is considered. In OT, many benign activities can continuously trigger false alarms from generic IT EDRs, as the overlap between benign OT actions and real threats, such as LOTL binaries, is frequent. This necessitates a defensive strategy that can discern true threats from normal operational noise.

The ultimate goal for OT security, therefore, is to move beyond simply detecting malicious intent at the very end of an attack chain. The speakers emphasized the need for earlier detection and warning events, capable of identifying abnormal or suspicious behavior in otherwise benign software. Current detection methods heavily rely on signature-based or attack surface reduction (ASR) rules, such as those found in Microsoft Defender. However, the human resource required to continuously define and update these expert rules for the myriad of OT-specific scenarios is prohibitive. This gap led to the central hypothesis of their research: can AI help autogenerate these ASR rules for OT-specific attacks, leveraging NLP to effectively combine AI technology with unique OT attributes for more accurate and effective detection solutions? This forms the foundational problem their novel machine learning model aims to solve.

Key Findings

▶ Watch: Combining AI and OT attributes for effective detection (3:20)

The research introduced a novel machine learning model specifically designed to overcome the unique detection challenges within OT and ICS environments. The core innovation lies in its ability to learn baseline normal behaviors from real-world OT data, identify subtle deviations, and then classify them as suspicious or malicious, offering an early warning system that traditional IT-centric solutions often miss.

A critical finding was the necessity for the model to be lightweight and robust. OT environments typically have resource constraints, and any security solution must operate efficiently without impacting operational performance. The model achieves this by effectively learning suspicious behavior from intensely real-world OT datasets, which are inherently different in scope and process behavior compared to IT. Large-scale, data-driven AI ensures that diverse OT behaviors are converted into discrete vector expressions, achieving robust semantic representations.

The architecture of their model involves several key steps:

  1. Data Collection: Gathering diverse behavioral data at a fundamental level from OT environments.
  2. Filtering: Applying human-defined expert ASR rules to isolate suspicious telemetry data. This initial filtering step is crucial because, in OT, it's often more practical to first identify "suspicious" activity rather than immediately classifying something as "malicious" due to the diverse and often unique nature of industrial processes.
  3. Model Input: These filtered data points, representing sequences of suspicious behavior, serve as input to their custom model, dubbed "suspicious to AI to vector."
  4. Learning and Recognition: The model learns to recognize and identify malicious behavior by analyzing these sequences.

The model builds upon adjustments from the IE SMP 2019 "as-to-vector" model, which utilizes actor representations to quantify discrete risk states within process trends. It determines suspiciousness by predicting central commands based on contextual behaviors, modeling both temporal sequences and immediate suspicious activities.

Extensive experiments were conducted using a comprehensive dataset:

  • Over 550 human-defined ASR rules for suspicious and malicious behaviors.
  • 2 million telemetry records spanning benign, suspicious, and malicious activities.
  • Data sourced from over 50,000 real OT binaries across various factory environments.

A significant achievement was the successful identification of 12 distinct malware threats from this dataset of over 50,000 samples, all originating from real OT environments. The model not only detects threats but also provides explainable and traceable detections. By leveraging the initial suspicious rules, the model can articulate why a behavior is considered malicious, providing clear and relevant information for incident response teams. For example, it can identify specific actions like "registering itself as a boot service" or "setting itself as a default network proxy."

Furthermore, the model demonstrated the ability to categorize malware into different variant groups (e.g., virus, worm, trojan, backdoor) based on shared behavioral features, even if the binary itself has changed or is previously unseen. This is crucial for protecting against polymorphic malware and zero-day threats in OT, where signature updates are impractical. The overlap in behavioral features between different malware cases forms the core basis for the model's recognition and categorization capabilities.

The overall finding is that this experimental model shows significant promise for lightweight, long-term malware detection in OT environments. It offers a robust protection mechanism by being pre-trained once and then deployed, maintaining a high detection rate in real-world scenarios. Its adaptability allows for the design of specific models tailored to different attack vectors and industrial verticals, such as financial sectors, manufacturing, car industries, and semiconductors, delivering more accurate and robust protection.

Technical Deep Dive

▶ Watch: Analyzing past AI research and its OT limitations (4:00)

The core of the proposed solution is the "suspicious to AI to vector" machine learning model, designed to address the unique challenges of OT and ICS detection. This model represents a significant departure from traditional signature-based methods by focusing on behavioral analytics and leveraging the power of Natural Language Processing (NLP) concepts.

The model’s architecture is an evolution of the IE SMP 2019 "as-to-vector" model. This foundational model is adapted to quantify discrete risk states within a sequence of process trends. Instead of treating individual events in isolation, the "suspicious to AI to vector" model processes behavioral data as a continuous "sentence" or "document," much like NLP models analyze human language. This approach allows it to understand the context and sequence of actions, which is critical for identifying sophisticated, multi-stage attacks prevalent in OT environments.

The process begins with dynamic behavior analysis. Selected malware samples and suspicious behavior trends are fed into the "suspicious to AI to vector" model. The key is to convert these complex, dynamic behaviors into a format that the AI can understand and process effectively. This is achieved by transforming the raw telemetry data into discrete vector expressions. Each vector semantically represents a specific set of behaviors or a sequence of actions. This conversion is vital for achieving robust semantic representations of OT system activities, allowing the model to find similarities and differences between behaviors that might appear disparate at a superficial level.

Central to the model's functionality is its ability to model both temporal sequences and immediate suspicious activity. It doesn't just look for a single malicious event but analyzes the order and context in which events occur. For example, the model predicts "central commands" based on the observed contextual behaviors. This means it can infer the likely intent or next step of a process by analyzing its preceding actions and the environment it operates within. This is crucial for detecting living-off-the-land (LOTL) attacks, where legitimate system tools are misused for malicious purposes, as their maliciousness often only becomes apparent when viewed in sequence.

The model relies on a comprehensive dataset of 550 human-defined ASR rules. These rules act as a baseline for what constitutes "suspicious" behavior in an OT context. They are not static signatures but rather behavioral patterns that guide the initial filtering of telemetry data. For instance, a rule might identify a legitimate industrial control application attempting to access network resources in an unusual way, or a seemingly benign process spawning a command shell. This initial human expert input is critical for training the model to distinguish between normal OT operations and potentially harmful deviations.

The model’s inference process is designed to be lightweight. Once trained, it can take a new suspicious behavior sample and immediately classify it. This involves:

  1. Dynamic Behavior Analysis: Observing and collecting behavioral data from a running process or system.
  2. Suspicious Trend Identification: Comparing observed behaviors against the learned patterns of suspicious activity.
  3. Vector Conversion: Transforming the observed behavioral sequence into a vector representation.
  4. Risk Semantic Classification: The model then performs a judgment, classifying the behavior based on its risk semantic, which could range from benign to highly malicious. This classification is informed by the model's training on the extensive dataset of 2 million telemetry records from over 50,000 OT binaries.

The emphasis on parent-child process relationships is technically integrated into the model's contextual understanding. By tracking the lineage of processes, the model can build a more accurate picture of an application's behavior. For instance, if a legitimate PDF reader (parent process) spawns powershell.exe (child process), this relationship is a strong indicator of suspicious activity that would likely be missed by a model that only examines individual process actions. The "suspicious to AI to vector" model integrates this relational data into its vector representations, allowing it to "understand" the significance of such chains of events.

The ultimate technical goal is to provide explainable and traceable detections. When the model identifies a threat, it doesn't just output a "malicious" flag. Instead, it can link the detected behavior back to the specific suspicious rules it triggered and articulate the sequence of actions that led to the classification. This level of detail, such as "registering itself as a Buddha service" or "setting itself as a default network proxy," is invaluable for incident responders, allowing them to quickly understand the nature of the threat and take targeted remediation actions. This transparency is a key differentiator, moving beyond opaque "black box" AI detections to provide actionable intelligence in critical OT environments.

Demo / Proof of Concept

▶ Watch: Real-world OT attack: Sandworm's 'leaf of land' (6:45)

While the talk did not feature a live, interactive demonstration, the speakers effectively illustrated the model's capabilities through two detailed case studies, serving as concrete proof-of-concept examples of how their "suspicious to AI to vector" model identifies and explains OT-specific malware. These cases highlight the model's ability to categorize threats, identify their specific behaviors, and provide actionable intelligence.

Case 1: Identifying a "Warm Matu" Malware Variant

The first case involved a specific, unnamed malware variant that the model categorized as a "warm matu" (likely referring to a type of worm or similar highly infectious malware). The detection process was as follows:

  • Rule Triggering: The malware variant triggered four of the human-defined suspicious ASR rules. These rules represent specific behavioral patterns deemed anomalous or potentially malicious in an OT context.
  • Behavioral Concatenation: The model then concatenated these observed behaviors into a "mo better" representation – essentially, its internal vector-based understanding of the malware's actions. This allows the model to categorize even variants that are not present in a static pattern database, focusing on their shared behavioral features.
  • Explainable Behaviors: Crucially, the model could explain why it flagged this malware. It identified that the malware was:
  1. Attending persistence by registering itself as a boot service. This is a common technique for malware to ensure it restarts with the system.
  2. Setting itself as a default network proxy to capture local network traffic. This indicates an attempt at network reconnaissance or data exfiltration.
  3. Cleaning the default proxy cache of the Internet Explorer to ensure continuous traffic monitoring. This action aims to maintain its covert monitoring capabilities.
  • Incident Response Value: For an incident response team in an OT environment, this level of detail is invaluable. Instead of just a generic "malware detected" alert, they receive a clear breakdown of the malware's actions, enabling them to understand the attack's impact and formulate targeted remediation steps.

Case 2: Identifying another Malware Type with Five Suspicious Behaviors

The second case presented another distinct malware, which the model categorized as "model m type one gam rule" (likely an internal classification for a specific malware family or type). This example further underscored the model's explainability and traceability:

  • Sequential Detection: The model detected a sequence of five suspicious behaviors consistent with this malware type. The emphasis on sequence is vital, as individual behaviors might be benign, but their order and context reveal malicious intent.
  • Vector Sequencing for Analysis: The use of vector sequencing allowed these behaviors to be grouped and analyzed effectively, providing a comprehensive view of the threat.
  • Specific Actions Identified: The model identified the following key malicious behaviors:
  1. Disguising itself as a hidden distance file. This suggests an attempt at evasion or camouflage within the system.
  2. Establishing persistence by registering as a boot service. Similar to Case 1, this ensures continued operation.
  3. Clearing the default Internet Explorer proxy cache to maintain effective traffic monitoring. Again, this highlights network monitoring or manipulation.
  • Support for Remediation: These detailed behavioral insights significantly support subsequent response and remediation efforts, allowing defenders to pinpoint the exact mechanisms the malware uses for persistence, communication, and evasion.

Beyond these specific cases, the speakers highlighted the model's broader capability to identify different variant groups (e.g., virus, worm, trojan, backdoor) because they possess shared behavioral features that trigger the underlying rules. Even if the binary changes (polymorphic or metamorphic variants), the core behavioral "feature" remains, allowing the model to detect and classify them. The overlap in behaviors between different malware cases forms the core basis for the model's ability to recognize and categorize threats, making it resilient against novel or mutated attacks. This demonstrate that the model, despite being experimental, offers a promising, lightweight, and long-term detection solution for OT environments.

Defensive Implications

▶ Watch: Examples of malicious process chain indicators (8:00)

The "suspicious to AI to vector" model presented by Mars Cheng and Jr Wei-Huang introduces several critical defensive implications for Operational Technology environments, moving beyond the limitations of traditional IT security solutions.

Firstly, the most significant implication is a paradigm shift from signature-based detection to behavioral and semantic analysis in OT. Given that OT systems cannot be easily patched or frequently updated, relying on static signatures is inherently ineffective against novel or polymorphic threats. This AI-driven approach offers robust protection against previously unseen malware and zero-day exploits by focusing on how an application behaves rather than what its binary signature is. Defenders can gain a proactive stance against evolving threats.

Secondly, the model provides crucial early warning capabilities. By focusing on identifying "suspicious" activities rather than waiting for definitive "malicious" intent at the end of an attack chain, the system can alert defenders much sooner. Detecting abnormal behaviors in even benign software, such as an industrial HMI process attempting unusual network connections or spawning an unexpected child process, can indicate a potential compromise before significant damage occurs. This early detection allows for timely intervention, potentially preventing the full execution of an attack.

Thirdly, the approach promises a significant reduction in false positives compared to generic IT EDRs deployed in OT. Traditional EDRs often struggle with the unique and often unusual (by IT standards) benign behaviors found in OT, leading to alert fatigue. By training on extensive, real-world OT datasets and leveraging human-defined suspicious rules specific to industrial processes, the model can more accurately distinguish between legitimate operational anomalies and actual threats, improving the signal-to-noise ratio for security teams.

Fourthly, the model's design allows for customizable and targeted protection for specific OT verticals. The speakers mentioned the ability to design different models for financial sectors, manufacturing, automotive industries, and semiconductors. This means that security solutions can be highly tuned to the unique operational contexts, protocols, and common attack vectors of each industry, leading to more accurate and relevant threat detection. This vertical-specific tailoring is a major advantage over one-size-fits-all security products.

Fifthly, the explainable and traceable detections offered by the model significantly enhance incident response (IR) capabilities. When an alert is triggered, IR teams receive not just a warning, but also a detailed breakdown of the specific behaviors that led to the detection (e.g., "registered as a boot service," "set itself as a default network proxy"). This actionable intelligence allows responders to quickly understand the nature of the threat, its persistence mechanisms, and its potential impact, enabling faster and more effective containment, eradication, and recovery efforts. It transforms a black-box alert into a clear forensic trail.

Finally, the lightweight and pre-trainable nature of the model makes it practical for deployment in resource-constrained OT environments. Once trained, the model can be deployed without requiring continuous, heavy computational resources for retraining or constant signature updates. This ensures that the security solution itself does not become an operational burden, a critical consideration in sensitive industrial settings.

Key Takeaways

  • OT Security Requires Specialized Detection: Traditional IT security solutions, particularly signature-based antivirus and EDRs, are often impractical and ineffective in OT environments due to unique operational constraints, legacy systems, and the critical need for process stability.
  • AI and NLP for Rule Generation: Leveraging AI and Natural Language Processing (NLP) allows for the autonomous generation of Application Security Rules (ASR) tailored for OT-specific attacks, overcoming the significant human resource limitations involved in manually defining and maintaining such rules.
  • Behavioral Detection with Context: The "suspicious to AI to vector" model focuses on behavioral analysis, incorporating critical factors like parent-child process relationships and temporal sequences, to detect subtle deviations from normal OT operations that indicate malicious activity.
  • Explainable and Traceable Threats: The model provides detailed, explainable insights into detected threats, outlining specific malicious behaviors (e.g., persistence mechanisms, network proxy manipulation) which are crucial for effective incident response and remediation.
  • Early Warning and Reduced False Positives: By identifying "suspicious" rather than solely "malicious" activities and being trained on real-world OT data, the model offers earlier detection capabilities and significantly reduces false positives, improving the efficiency of security teams.
  • Customizable and Lightweight for OT: The architecture is designed to be lightweight and robust, allowing for pre-training and deployment in resource-constrained OT environments, with the flexibility to develop tailored models for specific industrial verticals (e.g., manufacturing, automotive, semiconductors).

About the Speaker(s)

Mars Cheng is a Senior Researcher at TX1 Networks, a startup specializing in OT security solutions. His work primarily focuses on insert search OT security and enterprise security, with a strong emphasis on research that supports product development and highlights critical OT vertical security issues. Mars Cheng is an experienced speaker, having presented at over 60 conferences globally, including prestigious events like Black Hat USA, Black Hat Europe, RSA Conference, and DEF CON's "Crisis Stage" multiple times. Beyond his research, he has served as a cybersecurity auditor for OT crypto infrastructure within the Taiwan government and holds an executive director position for the Association of Hacks in Taiwan (known as HITCON), where he also organizes the HITCON CISO Summit, one of the largest CISO events in the Asia Pacific region.

Jr Wei-Huang, also known as Jay Jong, is a Senior Researcher at TX1 Networks. His expertise lies in threat hunting, detection engineering, and malware analysis. Prior to his current role, Jay Jong worked as an EDR product developer and a detection strategist researcher. Recently, his research has focused on uncovering interesting aspects of OT security and developing effective detection strategies for these unique environments. He is also slated to present his work at an upcoming conference in Europe.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate OT security research with a real problem statement and genuine dataset — 50K OT binaries and 2M telemetry records is not nothing. The core contribution is a word2vec-style behavioral embedding applied to OT process telemetry with explicit parent-child relationship modeling, which is a reasonable engineering advance over generic IT EDR approaches, even if the underlying ML technique isn't novel.

Heather Calloway (CISO) — WEAK

Technically earnest OT detection research with a legitimate problem statement — the gap between IT-centric EDRs and OT behavioral reality is real and underserved. But the jump from 'experimental model' to deployable defender capability is never bridged, and the governance and operational accountability questions that any OT security leader actually needs answered are completely absent.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33