Aspect Modeling for Process Variable Anomaly Detection
Ryan Heartfield
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
In the complex and rapidly evolving landscape of Industrial Control Systems (ICS) and Operational Technology (OT), the distinction between traditional engineering challenges and cybersecurity threats has become increasingly blurred. Ryan Heartfield's talk at S4 addresses a critical gap in current OT security strategies: the lack of comprehensive cyber-physical situation awareness. While engineering teams meticulously monitor process variables for operational integrity and performance, and cybersecurity teams focus on network-level anomalies, these two vital perspectives often remain siloed. This segmentation leads to a significant challenge in anomaly detection, where events are either misinterpreted due to insufficient context or missed entirely because they occur beyond the network perimeter, directly within the physical process.

Key moments
- 0:00 Introduction: Siloed teams, context gap in OT security.
- 2:00 Visibility vs. Context: The bigger challenge for process data.
- 4:00 Why process variables lack context: Subjective naming.
- 4:30 Guide to symbols for different anomaly detection approaches.
- 5:00 What is Aspect Modeling? A hierarchical approach.
- 5:40 Level 1 Aspect Model: Dynamic, generic data anomaly detection.
- 6:00 Benefits: Explainable situations for OT and cyber security.
Aspect Modeling for Process Variable Anomaly Detection
Speakers: Ryan Heartfield
Conference: S4
YouTube: https://www.youtube.com/watch?v=gATyNfyisBI
Overview
In the complex and rapidly evolving landscape of Industrial Control Systems (ICS) and Operational Technology (OT), the distinction between traditional engineering challenges and cybersecurity threats has become increasingly blurred. Ryan Heartfield's talk at S4 addresses a critical gap in current OT security strategies: the lack of comprehensive cyber-physical situation awareness. While engineering teams meticulously monitor process variables for operational integrity and performance, and cybersecurity teams focus on network-level anomalies, these two vital perspectives often remain siloed. This segmentation leads to a significant challenge in anomaly detection, where events are either misinterpreted due to insufficient context or missed entirely because they occur beyond the network perimeter, directly within the physical process.
Heartfield introduces Aspect Modeling as an innovative, hierarchical approach designed to bridge this divide. The core premise is to derive meaningful context from raw process variable data, enabling both engineering and cybersecurity teams to understand and respond to anomalies more effectively. By moving beyond network-centric monitoring to incorporate deep insights from process variables, organizations can achieve faster, more accurate detection and root cause analysis, thereby significantly enhancing resilience against a spectrum of incidents ranging from cyberattacks to equipment failures and configuration errors. This methodology is particularly pertinent as increased connectivity and automation magnify the complexity and breadth of threats in industrial environments.
The talk highlights that while collecting process data is achievable, the real challenge lies in contextualizing it. Process variables often have subjective, inconsistent naming conventions, making it difficult to discern their operational meaning or significance without expert knowledge. Aspect Modeling seeks to automate the generation of this crucial context, allowing for autonomous identification of anomalies and their classification as potentially cyber-related or purely operational. This integrated approach promises to accelerate incident response by providing both OT engineers and cybersecurity analysts with a unified, actionable understanding of the operational environment, fostering unprecedented collaboration in safeguarding critical infrastructure.
Background
▶ Watch: Introduction: Siloed teams, context gap in OT security. (0:00)
The convergence of Information Technology (IT) and Operational Technology (OT) has introduced unprecedented efficiencies and capabilities within industrial environments, but it has simultaneously expanded the attack surface and amplified the complexity of threats. Traditional OT security approaches have largely mirrored IT security, focusing heavily on network traffic analysis and endpoint security within the enterprise and industrial demilitarized zones (IDMZs). However, a significant portion of critical operational activity, particularly at the field bus and actuation/sensing levels, may never traverse the IT network. This creates a blind spot for cybersecurity teams relying solely on network-based monitoring, leaving industrial processes vulnerable to attacks or failures that manifest as changes in process variables (PVs).
Control system engineers, on the other hand, have decades of experience collecting and analyzing process variable data for operational monitoring, performance optimization, and predictive maintenance. They understand the intricate relationships between temperature, pressure, flow rates, motor RPMs, and other physical parameters that define the health and integrity of an industrial process. However, their primary focus is operational continuity, and they typically lack the cybersecurity context to identify malicious intent behind anomalous process behaviors. This results in two distinct teams—engineering and cybersecurity—with siloed views, often struggling to collaborate effectively during incidents because they "speak different languages" and lack a shared understanding of the root cause, whether it's a system fault, equipment failure, configuration error, or a sophisticated cyberattack.
A critical hurdle in leveraging process variable data for cybersecurity is the sheer lack of context. While device-level data (e.g., firmware versions, operating modes) often has a structured schema, process variables are highly programmatic and subjective. Their naming conventions can be inconsistent, varying widely across different systems, vendors, and even within the same plant. Common prefixes like I_ (input) or O_ (output) offer minimal insight into the variable's true meaning or its role within the larger operational context. Without this context, an anomalous reading from a sensor or an unexpected change in a motor's speed appears as an isolated data point, making it incredibly difficult for a cybersecurity analyst to determine if it signifies a cyber intrusion or a benign operational fluctuation. The challenge, therefore, is not merely collecting the data—which engineers are already doing—but transforming this raw, context-poor data into actionable intelligence that can answer the fundamental question: "Is this process anomaly cyber-related or not?"
Key Findings
▶ Watch: Why process variables lack context: Subjective naming. (4:00)
Ryan Heartfield's presentation introduces Aspect Modeling as a novel and crucial framework for addressing the context problem in process variable anomaly detection within industrial control systems. The central finding is that by adopting a hierarchical modeling approach, organizations can autonomously derive meaningful context from raw process variable data, thereby enabling more effective and explainable anomaly detection for both engineering and cybersecurity teams.
The core contribution of Aspect Modeling is its multi-layered structure designed to progressively enrich the understanding of process data:
- Level 1 Model (Dynamic & Generic Anomaly Detection): This foundational layer treats all incoming process variable data as generic, regardless of its specific physical or cyber nature. The focus here is on identifying the lowest-level anomalies within individual data streams. This could involve detecting unusual deviations in physical parameters like temperature, vibration, or water level, as well as anomalies in cyber-related variables such as operating modes or program sequence executions. The key characteristic of this level is its dynamism and autonomy; it learns normal behavior without requiring prior, deep contextual knowledge of each variable.
- Level 2 Model (Contextualization and Relationship Modeling): Although not explicitly detailed in the transcript, the hierarchical nature implies that this intermediate layer builds upon the Level 1 detections. Its purpose would be to identify relationships and correlations between different process variables, understanding how they interact under normal operating conditions. For example, linking a change in pump speed to a corresponding change in flow rate. This layer starts to build a more comprehensive understanding of the process state by integrating individual anomalies into a broader picture, moving towards understanding why an anomaly might be occurring.
- Level 3 Model (Root Cause Analysis and Actionable Intelligence): This top layer focuses on applying root cause analysis to the detected anomalies, aiming to answer the critical question: "Is this anomaly cyber-related or not?" It translates low-level anomalies and contextualized relationships into explainable situations that are actionable by both industrial engineering and cybersecurity teams. For cybersecurity, this means mapping process behaviors to known Tactics, Techniques, and Procedures (TTPs), while for engineering, it means identifying specific operational deviations that require attention. This level transforms raw data and initial anomaly detections into practical insights, accelerating incident response by providing clear, context-rich information to the appropriate stakeholders.
Another significant finding is that data collection for process variables does not need to be disruptive or complex. Heartfield emphasizes leveraging existing infrastructure and protocols like OPC UA. Rather than implementing disruptive methods such as injecting code onto PLCs or installing physical taps on serial cables, organizations can connect to existing SCADA systems, Human-Machine Interfaces (HMIs), or data historians that are already publishing this data. OPC UA, being a publish-subscribe protocol, allows for non-intrusive data collection by simply subscribing to existing data streams, mirroring how control system engineers already operate. This finding streamlines the initial data acquisition phase, allowing resources to be focused on the more challenging task of contextualization.
In essence, Aspect Modeling provides a structured pathway to achieve cyber-physical situation awareness, enabling organizations to detect more anomalies, detect them faster, and improve the accuracy of root cause analysis by providing the necessary context to both operational and security personnel.
Technical Deep Dive
▶ Watch: Guide to symbols for different anomaly detection approaches. (4:30)
The technical foundation of Aspect Modeling for Process Variable Anomaly Detection hinges on a multi-tiered, autonomous learning framework designed to extract context from inherently unstructured or poorly understood process data. The core challenge, as identified by Heartfield, is not merely data visibility—which is readily achievable—but the profound lack of context surrounding process variables. Unlike well-structured device data (e.g., firmware, operating mode), process variables are often "programmatic variables" with subjective naming conventions, making their meaning opaque without expert knowledge.
The proposed solution is a hierarchical modeling approach:
- Level 1 Model: Dynamic, Generic Anomaly Detection
This initial layer focuses on identifying fundamental deviations in individual process variable data streams. The premise is to treat all data generically, regardless of whether it represents a physical measurement (e.g., temperature, pressure, flow) or a cyber-related state (e.g., program sequence, operating mode). The goal here is to learn the "normal" behavior of each variable and detect any statistically significant departures. Heartfield indicates that this level can leverage various analytical approaches:
- Mathematical Algorithms (π symbol): These could involve statistical process control (SPC) techniques, time-series analysis, or other quantitative methods to identify outliers, trends, or shifts in data distribution. For example, detecting a sudden spike in temperature outside of a learned operating range.
- Heuristics (Tree symbol): Rule-of-thumb approaches or domain-specific guidelines can be applied to identify anomalies based on predefined conditions or known operational constraints.
- Statistical Distributions (Curly line symbol): Learning the probability distribution of a variable's values over time allows for the detection of events that fall outside expected statistical norms. This could involve identifying data points that are multiple standard deviations away from the mean.
- Machine Learning (Brain symbol): Algorithms such as clustering, classification, or regression models can be trained on historical data to identify novel patterns or behaviors that deviate from the learned baseline. This is particularly useful for detecting subtle, evolving anomalies that might not be caught by static rules.
- Rules (Clipboard symbol): Explicitly defined rules, perhaps derived from engineering specifications or safety limits, can trigger alerts when variable values exceed or fall below predetermined thresholds.
The emphasis at Level 1 is on identifying the lowest-level anomalies autonomously, without requiring upfront, deep contextual understanding of what each specific process variable represents. This makes the approach scalable and less reliant on manual configuration by subject matter experts.
- Level 2 Model: Contextualization and Inter-Variable Relationships
While the transcript doesn't detail Level 2 as extensively as Level 1 and Level 3, its role within a hierarchical model is to build context by understanding the relationships between process variables. After individual anomalies are detected at Level 1, Level 2 would correlate these anomalies and identify interdependencies. For instance, if a pump's motor speed (PV1) increases, a corresponding increase in liquid flow rate (PV2) might be expected. An anomaly at Level 1 in PV1, without a corresponding expected change in PV2, would become a more significant contextual anomaly at Level 2. This layer could employ:
- Correlation Analysis: Identifying statistical relationships between different process variables.
- Process Graph Modeling: Representing the industrial process as a graph where nodes are components/variables and edges are their interactions, allowing for anomaly propagation analysis.
- State Machine Modeling: Defining expected sequences of operations and identifying deviations from these sequences.
The output of Level 2 would be a richer understanding of the process state, where individual anomalies are understood in the context of the larger system, moving towards identifying situations rather than just isolated events.
- Level 3 Model: Root Cause Analysis and Actionable Intelligence
This highest layer is where the accumulated context is leveraged for root cause analysis and to generate explainable situations for both OT engineering and cybersecurity teams. The primary objective is to determine if a detected anomaly or contextual situation is cyber-related. This involves:
- Mapping to TTPs: For cybersecurity, Level 3 transforms process anomalies into indicators of compromise or attack behaviors that align with known Tactics, Techniques, and Procedures (TTPs), similar to those defined by frameworks like MITRE ATT&CK for ICS. For example, an unexpected change in a control loop's setpoint combined with unusual network traffic patterns could indicate a cyberattack attempting to manipulate the process.
- Actionable Behaviors for Engineering: For the engineering team, Level 3 provides clear diagnostics regarding operational deviations, equipment health, or configuration errors. An anomaly might indicate a failing sensor, a valve stuck open, or an unexpected change in process parameters requiring operational adjustment.
- Automated Response Support: By providing enriched context, Level 3 facilitates more autonomous and rapid incident response. It helps answer why an anomaly occurred, allowing teams to differentiate between operational faults and malicious activities, and to prioritize their response accordingly.
Data Collection Strategy:
Heartfield emphasizes that the initial step of data collection should be non-disruptive and leverage existing infrastructure. Instead of "putting code on PLCs" or "putting a tap or box in the middle of an electrical cable," which are often difficult to scale and disruptive, the recommended approach is to connect to existing data sources that control system engineers already utilize.
The preferred protocol highlighted is OPC UA. This is a modern, secure, and robust industrial interoperability standard that supports a publish-subscribe communication model. By connecting to existing SCADA systems, Human-Machine Interfaces (HMIs), or data historians—or even directly to PLCs if they support OPC UA natively—an anomaly detection system can subscribe to data streams without imposing additional load or requiring modifications to the operational environment. This mirrors how these systems already communicate, ensuring minimal impact on process integrity and performance. The data collected via OPC UA can also be TLS encrypted if configured correctly, addressing security concerns during transmission.
In summary, the technical deep dive reveals a sophisticated approach to process variable anomaly detection that systematically builds context from raw data, enabling a more intelligent and unified response to incidents across the cyber-physical spectrum.
Demo / Proof of Concept
▶ Watch: Level 1 Aspect Model: Dynamic, generic data anomaly detection. (5:40)
The transcript for Ryan Heartfield's talk "Aspect Modeling for Process Variable Anomaly Detection" does not include a description of a specific live demonstration or a detailed proof of concept. The speaker primarily focuses on explaining the theoretical framework of Aspect Modeling, its hierarchical structure, and the underlying principles for data collection and contextualization. While the talk outlines the conceptual approach and the types of anomalies that could be detected, it does not present a practical walkthrough of the system in action or its results from a specific implementation.
Defensive Implications
▶ Watch: Benefits: Explainable situations for OT and cyber security. (6:00)
The implications of Aspect Modeling for industrial defenders are profound, offering a pathway to significantly enhance cyber-physical situation awareness and incident response capabilities. The primary defensive strategy derived from this talk is to shift beyond purely network-centric security monitoring and integrate deep analysis of process variable data into the security operations workflow.
- Embrace Process Variable Monitoring: Defenders must recognize that critical operational activity often occurs below the network layer, directly at the actuation and sensing level. Implementing systems that monitor process variables is no longer a luxury but a necessity for comprehensive OT security. This allows for the detection of anomalies that may indicate a cyberattack, system fault, equipment failure, or configuration error, which would otherwise be invisible to traditional network intrusion detection systems.
- Leverage Existing Operational Data Sources: The talk strongly advocates for a non-disruptive approach to data collection. Instead of deploying new, intrusive sensors or modifying PLC code, defenders should work with engineering teams to tap into existing OPC UA data streams from SCADA systems, HMIs, and data historians. This strategy minimizes operational risk, reduces deployment costs, and leverages data that is already being collected and validated by operational personnel. Utilizing OPC UA's publish-subscribe model ensures that data collection does not negatively impact PLC performance or network bandwidth.
- Prioritize Contextualization: Raw process variable data is of limited use to cybersecurity teams due to its lack of context. Defensive strategies must incorporate methodologies, such as Aspect Modeling, that can autonomously derive meaning from these variables. This involves building models that understand normal operational baselines (Level 1), the interdependencies between variables (Level 2), and how deviations translate into actionable intelligence related to cyber threats or operational issues (Level 3). Without this contextualization, alerts generated from process data will be "muffins that look like Chihuahuas"—meaningless and overwhelming.
- Foster IT/OT Collaboration: Aspect Modeling inherently promotes collaboration by providing a common language and contextualized insights for both engineering and cybersecurity teams. Defenders should actively work to break down organizational silos, sharing insights derived from process variable monitoring with their OT engineering counterparts. This shared understanding accelerates root cause analysis and improves the efficiency of incident response, as both teams can contribute their unique expertise to address a unified view of the incident. The goal is not to merge teams into a "hybrid control room" immediately, but to create an "umbilical cord" of shared data and intelligence.
- Enable Explainable Detections: Security alerts must be explainable and actionable. Aspect Modeling's Level 3 aims to translate technical anomalies into clear implications, such as mapping behaviors to TTPs for cyber teams or identifying specific operational deviations for engineers. Defenders should seek or develop solutions that provide this level of detail, moving beyond simple alerts to provide rich context that aids in rapid decision-making and response.
By integrating process variable anomaly detection with robust contextualization, leveraging existing OT data infrastructure, and fostering cross-functional collaboration, industrial defenders can move towards a truly cyber-physical security posture, capable of detecting, analyzing, and responding to the full spectrum of threats facing modern industrial control systems.
Key Takeaways
- Cyber-physical situation awareness is critical: Traditional network-centric security in OT is insufficient; monitoring process variables is crucial for detecting threats and operational issues beyond the network.
- Context is the biggest challenge: Collecting process data is straightforward, but understanding the subjective, often inconsistently named process variables is the primary hurdle for effective anomaly detection.
- Aspect Modeling offers a hierarchical solution: This framework (Level 1, 2, 3 models) autonomously builds context from raw process data, moving from generic anomaly detection to root cause analysis and actionable intelligence.
- Leverage existing OPC UA infrastructure: Data collection should be non-disruptive, utilizing existing SCADA, HMI, and data historian systems via OPC UA's publish-subscribe model, avoiding costly and risky new deployments.
- Bridge the IT/OT divide: Aspect Modeling provides a shared context, enabling both industrial engineering and cybersecurity teams to understand anomalies, accelerate incident response, and improve collaboration, even while operating in their respective specialized roles.
- Focus on explainable and actionable detections: The goal is to provide clear insights, differentiating between cyber-related incidents and operational faults, and mapping them to TTPs for security teams or specific operational deviations for engineers.
About the Speaker(s)
Ryan Heartfield is a speaker at the S4 conference, where he presented his work on "Aspect Modeling for Process Variable Anomaly Detection." Based on the content of his talk, he is an expert in industrial control system security, with a focus on innovative methods for enhancing cyber-physical situation awareness and bridging the gap between operational technology engineering and cybersecurity disciplines. His research and insights are geared towards developing practical, scalable solutions for anomaly detection in complex industrial environments.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Heartfield's Aspect Modeling presents a highly relevant and technically sound framework for bridging the critical gap in cyber-physical situation awareness within OT environments. By systematically addressing the 'context problem' of process variable data through a hierarchical model, the talk outlines a practical and non-disruptive approach to anomaly detection that promises significant impact for industrial defenders. While the lack of a live demo in the transcript is a missed opportunity to see the framework in action, the conceptual depth and actionable defensive implications make this a strong contribution to ICS security.
Heather Calloway (CISO) — STRONG ACCEPT
Ryan Heartfield's talk on Aspect Modeling presents a crucial framework for gaining cyber-physical situation awareness in OT environments, directly addressing the systemic challenge of siloed IT/OT perspectives and the lack of context in process variable data. By proposing a hierarchical approach to autonomously contextualize raw operational data, the model offers a credible path for organizations to accelerate anomaly detection, improve root cause analysis, and enhance institutional resilience against both cyberattacks and operational failures, making it highly relevant for security leaders grappling with industrial risk.