Loading…
The Rosetta stone of CPS: Claroty’s AI-powered library
Ben Hazan, Anton Berlinsky, Ohad Avni, Itay Wagner, Guy Zalcman, Dor Bdolach, Ravid Ariely, Gal Sberro
- Source
- Databricks
- Published
- Added to Yomu
Summary
CPS asset identification is difficult because 88% of CPS assets do not transmit an exact product code and 76% use product codes that differ from the vendor's official records. Claroty's AI-Powered CPS Library addresses this entity-resolution problem with a hybrid architecture that combines classic matching, statistical inference, generative AI, NLP, reasoning agents, and human-in-the-loop review to reconcile protocol data, vendor records, manuals, and vulnerability information. Its Databricks-based lakehouse uses Delta Lake, Unity Catalog, Spark pipelines, Model Serving, MLflow evaluations, Lakebase, and Databricks Apps to maintain governed, auditable mappings across a catalog of more than 17 million assets. The post reports 25% improved vulnerability-attribution accuracy and says early tests gave 56% of analyzed devices new or updated recommendations for outdated firmware, while low-confidence mappings remain subject to expert review.
Context
CPS and OT security teams often lack reliable device identities because assets may report incomplete or inconsistent product codes. The post says this makes vulnerability management difficult and forces teams to manually reconcile vendor catalogs, advisories, and vulnerability databases.
Approach / What changed
Claroty built an AI-Powered CPS Library as a hybrid entity-resolution system. It combines classic matching and statistical methods with generative AI, NLP and reasoning agents, governed Databricks lakehouse pipelines, Delta Lake, Unity Catalog, Lakebase, MLflow evaluation, Databricks Apps, and human review of low-confidence mappings.
Takeaways
- Team82 found that 88% of CPS assets do not transmit an exact product code, while 76% use codes that differ from vendors' official records.
- The library uses NLP agents, reasoning agents with confidence scoring, and human-in-the-loop review to resolve identities and feed corrections back into the system.
- The post reports 25% higher vulnerability-attribution accuracy and new or updated outdated-firmware recommendations for 56% of analyzed devices in early tests.