Why OT Detection Differs from IT

▶ Watch (2:08)

OT systems cannot be patched easily or updated frequently. Traditional virus signature databases grow large and slow down factory systems, risking operational disruption. IT-focused EDR tools miss OT-specific attacks like live-off-the-land binaries. The overlap between benign OT actions and real threats is high. Mars Cheng asked: can AI help OT environments adopt detection without triggering false alarms?

Process Relationships: Key to Early Detection

▶ Watch (7:24)

A Russian Sandworm attack on Ukrainian grids used live-off-the-land methods invisible to IT EDR. Analyzing parent-child process relationships proved essential during incident response. For example, explorer.exe launching wscript.exe then cscript.exe signals a LOLBins attack. Another case: Adobe Reader or Office triggering PowerShell. These patterns reveal malicious intent before the final payload executes. Early warning in OT requires tracking these behavioral chains.

The Model: Suspicious-to-Vector with Expert Rules

▶ Watch (13:27)

The team built a model that collects behavioral data at the process level. It filters telemetry through 550 human-defined ASR rules to isolate suspicious sequences. The dataset includes 2 million records from 50,000 binaries, all from real OT environments. Each behavior sequence is converted into a vector using an adapted AS2V architecture. The model predicts central commands based on context, balancing temporal sequence and immediate activity.

Results: 12 Malware Families Found in 50,000 Binaries

▶ Watch (16:14)

The model identified 12 distinct malware families from real factory data. For each detection, it maps back to the specific suspicious rules triggered. One case involved a worm that registered itself as a service and cleared Internet Explorer proxy cache. Another variant group showed five overlapping behavior sequences. Even if the binary changes, the behavior features remain, allowing the model to catch variants without signature updates.

Notable Quotes

“the model must be lightweighted and robust effectively learning suspicious behavior from intensively real world OT data set” Mars Cheng · ▶ 12:47

“So using this model we successfully identified um 12 distinct malware thread from the data set in over 50 um 50 um thousands samples” Mars Cheng · ▶ 16:14

“Why is a process relationship so critical for semantic detachments?” Mars Cheng · ▶ 7:19

Key Takeaways

  • OT detection needs process-relationship analysis to catch live-off-the-land attacks.
  • The model uses 550 expert rules to filter suspicious behavior chains.
  • Early detection of behavioral sequences can prevent attacks before malicious payloads execute.

About the Speaker(s)

Mars Cheng is the Head of Cyber Threat & Product Defense Center at TXOne Networks Inc., responsible for leading three subgroups within the center: PSIRT, Advanced Threat Research Group, and Threat Operation Group. Additionally, he serves as the Executive Director of the Association of Hackers in Taiwan (HIT/HITCON) and General Coordinator of HITCON CISO Summit 2025; he plays a pivotal role in fostering collaboration between enterprises and government entities to strengthen cybersecurity. His expertise encompasses ICS/SCADA systems, malware analysis, threat intelligence and hunting, blue team, and enterprise security. A seasoned speaker, Mars has delivered over 60 presentations at international cybersecurity conferences, including Black Hat USA, Europe, and MEA, RSA Conference, DEF CON, CODE BLUE, FIRST, HITB, HITCON, Troopers, NOHAT, SecTor, S4, SINCON, and ROOTCON, among others. He has successfully organized several notable HITCON events, including the HITCON CISO Summit in 2023 and 2024, HITCON PEACE 2022, and HITCON 2021 and 2020.

Jr-Wei Huang is a Senior Threat Researcher of Cyber Threat & Product Defense Center at TXOne Networks Inc., specializing in threat hunting, detection engineering, and malware analysis. He has 3 years hands-on experience in developing EDR product features and designing effective detection strategies. Jr-Wei Huang has spoken at conferences such as HITCON, JASEC, and CYBERSEC Taiwan, covering topics including Windows and macOS security, blue team operations, and detection engineering. He has also delivered lectures and training sessions for universities and private companies across Taiwan.