Computer-implemented method, computer system, and computer program product of visualizing unauthorized access tactics used to access machines located on industrial floor
Patent Information
- Application Number
- TW113126520
- Authority / Receiving Office
- TW · TW
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-07-25
- Filing Date
- 2024-07-16
- Publication Date
- 2026-08-11
- Estimated Expiration
- 2044-07-15
Smart Images

Figure TWG2TB001905365_001 
Figure TWG2TB001905365_002 
Figure TWG2TB001905365_003
Abstract
Description
Technical Field
[0001] The present disclosure relates generally to unauthorized access, and more particularly to unauthorized access or attempted access to machinery (e.g., robots, CNC machines, automated guided vehicles) located on industrial floors. Prior Art
[0002] Unauthorized access occurs when an individual gains access to a computer network, system, application software, data, or other resource without authorization. Any access to an information system or network that violates the security policies established by the owner or operator is considered unauthorized access. Unauthorized access also occurs when a legitimate user accesses resources they are not authorized to use.
[0003] In the context of the manufacturing industry, various machines (e.g., robots, CNC machines, automated guided vehicles, etc.) located on industrial floors (floors such as concrete used in industrial and commercial environments) are used to manufacture and produce components, goods, parts, etc., in workshops, factories, etc. For example, these machines may correspond to robots that weld and assemble parts. In another example, CNC machines cut metal parts to precise specifications. In another example, engine machining stations are used to create cylinder blocks.
[0004] Users (referred to as "security hackers") may attempt to gain unauthorized access to these machines located on industrial floors to steal sensitive data, cause damage, seize data as part of a ransomware attack, perform mischief, and so on. For example, a security hacker may attempt to gain unauthorized access to a CNC machine tool to manipulate the machine programming, causing it to create defective parts. If the machine operator fails to promptly notice the problem, these defective parts will enter the market. In another example, a security hacker may attempt to gain unauthorized access to a CNC machine tool to gain a competitive advantage by stealing confidential proprietary information.
[0005] Security hackers may use various methods to attempt to gain unauthorized access to machines located on industrial floors, such as exploiting software vulnerabilities. Other methods include social engineering tactics such as phishing, phishing SMS messages, spear phishing, and ransomware. Furthermore, security hackers may use malicious code (malware) to gain unauthorized access to machines located on industrial floors, including the information stored on these machines. Malware is software intentionally designed to gain unauthorized access to information or systems, such as machines located on industrial floors. Examples of this malware include computer viruses, worms, Trojan horses, ransomware, spyware, and rogue software.
[0006] Unfortunately, there is currently no effective means to notify machine operators, such as visually, of such attempts to gain unauthorized access to machines located on the industrial floor. These machine operators need to know which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, so that the machine operators can take corrective measures to address such attempts or successful unauthorized access to the machines on the industrial floor. Summary of the Invention
[0007] In one embodiment of the present disclosure, a computer-implemented method for visualizing unauthorized access or attempted unauthorized access to machines located on an industrial floor includes retrieving log files from a firewall that monitors traffic to and from the machines located on the industrial floor. The method further includes analyzing the log files from the firewall to identify behaviors used to access or attempt to access one or more of the machines located on the industrial floor. The method also includes analyzing a knowledge base for unauthorized access policies. Furthermore, the method includes creating an augmented reality visualization that, based on the analysis of the knowledge base, depicts the unauthorized access policy being enforced on the one or more machines located on the industrial floor in response to the identified behaviors being associated with the unauthorized access policy within a threshold degree of similarity.
[0008] Furthermore, in one embodiment of the present disclosure, the method further comprises analyzing log files from one or more machines located on the industrial floor to identify operating parameters.
[0009] Additionally, in one embodiment of the present disclosure, the method further includes creating an augmented reality visualization to depict an unauthorized access policy implemented on one or more machines located on the industrial floor using the identified operating parameters.
[0010] Furthermore, in one embodiment of the present disclosure, the method further includes creating one or more avatars of a security hacker and / or the detected malicious code. Furthermore, the method includes using the created one or more avatars to depict unauthorized access policies implemented on one or more machines located on the industrial floor in an augmented reality visualization.
[0011] Additionally, in one embodiment of the present disclosure, the method further includes identifying a corrective action for resolving an unauthorized access policy implemented on one or more machines located on the industrial floor using the knowledge base. Furthermore, the method includes depicting the identified corrective action for resolving the unauthorized access policy implemented on the one or more machines in an augmented reality visualization.
[0012] Furthermore, in one embodiment of the present disclosure, the method further includes receiving feedback regarding the augmented reality visualization. Additionally, the method includes updating a knowledge base of unauthorized access policies based on the feedback.
[0013] Additionally, in one embodiment of the present disclosure, augmented reality visualization is displayed on augmented reality smart glasses.
[0014] Other forms of embodiments of the computer-implemented method described above are in a system and a computer program product.
[0015] In this way, machine operators will now be effectively informed, such as through augmented reality visualization, of attempts to gain unauthorized access to machines located on the industrial floor. Consequently, machine operators will now understand which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, thereby allowing the machine operators to take corrective measures to address the attempted or successful unauthorized access to the machines.
[0016] The foregoing has generally outlined the features and technical advantages of one or more embodiments of the present disclosure so that the following detailed description of the present disclosure may be better understood. Additional features and advantages of the present disclosure will be described below, which may form the subject matter of the claims of the present disclosure. Simple diagram description
[0017] A better understanding of the present disclosure may be obtained when the following detailed description is considered in conjunction with the following drawings, in which:
[0018] Figure 1 illustrates an embodiment of a communication system for practicing the principles of the present disclosure;
[0019] FIG2 is a diagram of software components used by an unauthorized access detector for visualizing unauthorized access policies used to access or attempt to access a machine located on an industrial floor of an industrial facility, according to an embodiment of the present disclosure;
[0020] Figure 3 illustrates an embodiment of the hardware configuration of an unauthorized access detector for practicing the hardware environment of the present disclosure;
[0021] 4 is a flowchart of a method for visualizing unauthorized access or attempted unauthorized access to a machine located on an industrial floor of an industrial facility according to an embodiment of the present disclosure;
[0022] FIG5 is a flowchart of a method for creating an augmented reality visualization according to an embodiment of the present disclosure; and
[0023] FIG6 is a flowchart of a method for updating a knowledge base using received feedback regarding augmented reality visualization according to an embodiment of the present disclosure. Implementation Method
[0024] In one embodiment of the present disclosure, a computer-implemented method for visualizing unauthorized access or attempted unauthorized access to machines located on an industrial floor includes retrieving log files from a firewall that monitors traffic to and from the machines located on the industrial floor. The method further includes analyzing the log files from the firewall to identify behaviors used to access or attempt to access one or more of the machines located on the industrial floor. The method also includes analyzing a knowledge base for unauthorized access policies. Furthermore, the method includes creating an augmented reality visualization that, based on the analysis of the knowledge base, depicts the unauthorized access policy being enforced on the one or more machines located on the industrial floor in response to the identified behaviors being associated with the unauthorized access policy within a threshold degree of similarity.
[0025] In this way, machine operators will now be effectively informed, such as through augmented reality visualization, of attempts to gain unauthorized access to machines located on the industrial floor. Consequently, machine operators will now understand which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, thereby allowing the machine operators to take corrective measures to address the attempted or successful unauthorized access to the machines.
[0026] Furthermore, in one embodiment of the present disclosure, the method further comprises analyzing log files from one or more machines located on the industrial floor to identify operating parameters.
[0027] In this way, the operating parameters of the machines located on the industrial floor are identified by analyzing the log files from the machines.
[0028] Additionally, in one embodiment of the present disclosure, the method further includes creating an augmented reality visualization to depict an unauthorized access policy implemented on one or more machines located on the industrial floor using the identified operating parameters.
[0029] In this way, an augmented reality visualization is created that depicts the unauthorized access policy enforced on machines located on an industrial floor using the operating parameters of these machines.
[0030] Furthermore, in one embodiment of the present disclosure, the method further includes creating one or more avatars of a security hacker and / or the detected malicious code. Furthermore, the method includes using the created one or more avatars to depict unauthorized access policies implemented on one or more machines located on the industrial floor in an augmented reality visualization.
[0031] In this way, avatars of security hackers and / or detected malicious code are used to illustrate unauthorized access strategies to machines located on the industrial floor.
[0032] Additionally, in one embodiment of the present disclosure, the method further includes identifying a corrective action for resolving an unauthorized access policy implemented on one or more machines located on the industrial floor using the knowledge base. Furthermore, the method includes depicting the identified corrective action for resolving the unauthorized access policy implemented on the one or more machines in an augmented reality visualization.
[0033] In this way, corrective measures for addressing unauthorized access policies implemented on machines located on an industrial floor are depicted in an augmented reality visualization.
[0034] Furthermore, in one embodiment of the present disclosure, the method further includes receiving feedback regarding the augmented reality visualization. Additionally, the method includes updating a knowledge base of unauthorized access policies based on the feedback.
[0035] In this way, the knowledge base for unauthorized access policies is updated to improve the accuracy of unauthorized access policies stored in the knowledge base (such as those used by security hackers) and / or corrective measures used to address unauthorized access policies.
[0036] Additionally, in one embodiment of the present disclosure, augmented reality visualization is displayed on augmented reality smart glasses.
[0037] In this way, augmented reality visualization is displayed on the augmented reality smart glasses.
[0038] Other forms of embodiments of the computer-implemented method described above are in a system and a computer program product.
[0039] As mentioned above, in the context of the manufacturing industry, various machines (e.g., robots, CNC machines, automated guided vehicles, etc.) located on industrial floors (floors such as concrete used in industrial and commercial environments) are used to manufacture and produce components, goods, parts, etc., in workshops, factories, etc. For example, these machines may correspond to robots that weld and assemble parts. In another example, CNC machines cut metal parts to precise specifications. In another example, engine machining stations are used to create cylinder blocks.
[0040] Users (referred to as "security hackers") may attempt to gain unauthorized access to these machines located on industrial floors to steal sensitive data, cause damage, seize data as part of a ransomware attack, perform mischief, and so on. For example, a security hacker may attempt to gain unauthorized access to a CNC machine tool to manipulate the machine programming, causing it to create defective parts. If the machine operator fails to promptly notice the problem, these defective parts will enter the market. In another example, a security hacker may attempt to gain unauthorized access to a CNC machine tool to gain a competitive advantage by stealing confidential proprietary information.
[0041] Security hackers may use various methods to attempt to gain unauthorized access to machines located on industrial floors, such as exploiting software vulnerabilities. Other methods include social engineering tactics such as phishing, phishing SMS messages, spear phishing, and ransomware. Furthermore, security hackers may use malicious code (malware) to gain unauthorized access to machines located on industrial floors, including the information stored on these machines. Malware is software intentionally designed to gain unauthorized access to information or systems, such as machines located on industrial floors. Examples of this malware include computer viruses, worms, Trojan horses, ransomware, spyware, and rogue software.
[0042] Unfortunately, there is currently no effective means to notify machine operators, such as visually, of such attempts to gain unauthorized access to machines located on the industrial floor. These machine operators need to know which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, so that the machine operators can take corrective measures to address such attempts or successful unauthorized access to the machines on the industrial floor.
[0043] Embodiments of the present disclosure provide a means for effectively notifying machine operators of attempts to gain unauthorized access to machines located on an industrial floor. In one embodiment, an augmented reality visualization is created to depict unauthorized access policies enforced on machines located on the industrial floor, thereby notifying machine operators of such attempts. This augmented reality visualization is created by analyzing log files from a firewall that monitors traffic to and from machines located on the industrial floor. These log files can be analyzed to identify behaviors used to access or attempt to access machines located on the industrial floor. A knowledge base storing previously identified unauthorized access policies is then analyzed to determine whether the identified behaviors are within a threshold level of similarity to unauthorized access policies previously identified in the knowledge base. If the identified behaviors are within a threshold level of similarity to unauthorized access policies previously identified in the knowledge base, log files from machines located on the industrial floor that were accessed or attempted to access in an unauthorized manner (based on the identified behaviors) are analyzed to identify operating parameters (e.g., cutting speed, coolant temperature) of these machines. An augmented reality visualization is then created to depict unauthorized access policies enforced on machines located on an industrial floor using the identified operating parameters of these machines. Further discussion of these and other features is provided below.
[0044] In some embodiments of the present disclosure, the present disclosure includes a computer-implemented method, system, and computer program product for visualizing unauthorized access or attempted unauthorized access to machines located on an industrial floor. In one embodiment of the present disclosure, log files are retrieved from a firewall that monitors traffic to and from machines located on an industrial floor of an industrial facility. The retrieved log files are then analyzed to identify behaviors used to access or attempt to access one or more machines located on the industrial floor of the industrial facility. As used herein, "behavior" refers to actions performed by, for example, a security hacker, when accessing or attempting to access machines located on the industrial floor of the industrial facility. Furthermore, a knowledge base for unauthorized access policies is analyzed. As used herein, "knowledge base" refers to a collection of data containing information about unauthorized access policies previously used by, for example, security hackers to gain unauthorized access to machines located on the industrial floor of the industrial facility. If the identified behavior is within a threshold level of similarity to the unauthorized access policy learned from the knowledge base, an augmented reality visualization can then be created to depict the unauthorized access policy being executed on machines located on the industrial floor of the industrial facility. In this way, machine operators are effectively informed, such as through augmented reality visualization, of attempts to gain unauthorized access to machines located on the industrial floor. Consequently, machine operators will now understand which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, thereby allowing the machine operators to take corrective measures to resolve the attempted or successful unauthorized access to the machines.
[0045] In the following description, numerous specific details are set forth to provide a thorough understanding of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure can be practiced without these specific details. In other instances, well-known circuits have been shown in block diagram form to avoid obscuring the present disclosure with unnecessary detail. To the greatest extent possible, details regarding timing considerations and the like have been omitted as they are unnecessary for a complete understanding of the present disclosure and are within the skill of one of ordinary skill in the relevant art.
[0046] Referring now to the drawings in detail, FIG1 illustrates an embodiment of a communication system 100 for practicing the principles of the present disclosure. The communication system 100 includes an industrial facility 101 connected to an unauthorized access detector 102 via a network 103 and a firewall 108.
[0047] As used herein, "industrial facility" 101 refers to a complex (e.g., a manufacturing plant) that may consist of one or more buildings containing one or more machines 104 located on an industrial floor (a floor, such as concrete used in industrial and commercial environments) within industrial facility 101. These machines 104 are used to manufacture and produce components, goods, parts, etc. within industrial facility 101. Examples of these machines 104 include robots, CNC machine tools, and automated guided vehicles. For example, these machines may correspond to robots that weld and assemble components. In another example, a CNC machine cuts metal parts to precise specifications. In another example, an engine machining station is used to create cylinder blocks.
[0048] In one embodiment, each machine 104 is uniquely identified by a serial number stored in a data structure (e.g., a table) residing on a storage device of server 105 (discussed further below). In one embodiment, these serial numbers are associated with the type of machine (e.g., grinding machine) in such data structure (e.g., table). In one embodiment, such data structure is populated by an expert.
[0049] In the illustration of FIG. 1 , the industrial facility 101 is interconnected to the unauthorized access detector 102 via the network 103 and the firewall 108 via the server 105 .
[0050] In one embodiment, server 105 controls the operation of machine 104, such as via automation software. As used herein, "automation software" refers to applications designed to automate routine, repeatable tasks while minimizing the need for human input. For example, server 105 utilizes automation software to control machine 104 operations such as loading and unloading parts, material handling, transferring finished parts to post-processing, drilling, welding, painting, product inspection, pick and place, die casting, glass manufacturing, and grinding.
[0051] In one embodiment, data regarding operations performed by machine 104 is obtained from an Internet of Things (IoT) sensor 106. As used herein, IoT sensor 106 refers to a sensor that can be attached to machine 104 located on an industrial floor. Furthermore, IoT sensor 106 is configured to exchange data with other devices and systems via a network, such as network 103. In one embodiment, IoT sensor 106 is configured to monitor machine 104 located at industrial facility 101. For example, IoT sensor 106 can monitor operations of machine 104, such as loading and unloading parts, material handling, transferring finished parts to post-processing, drilling, welding, painting, product inspection, pick and place, die casting, glass manufacturing, grinding, and the like. In one embodiment, IoT sensor 106 captures operating parameters of machine 104 (e.g., shear speed, coolant temperature). This data can then be captured by IoT sensor 106 and transferred to server 105 for storage, such as on a storage device within server 105.
[0052] In one embodiment, the current location of machines 104 , including mobile ones, located on an industrial floor of an industrial facility 101 is determined based on location information (e.g., GPS (Global Positioning System) data) provided to a sensor 105 via an attached IoT sensor 106 .
[0053] In one embodiment, this data is stored in log files. As used herein, "logs" or "log files" refer to computer-generated data files that contain information about usage patterns, activities, and operations performed by machines 104. Log files indicate whether machines 104 are performing properly and optimally. In one embodiment, these log files indicate the operating parameters of machines 104 as captured by IoT sensors 106 attached to these machines 104. In one embodiment, these log files are generated by machines 104 based on data collected by IoT sensors 106 attached to these machines 104. In one embodiment, these log files are transferred to server 105 for storage, such as on a storage device on server 105.
[0054] In one embodiment, these log files from the machine 104 are obtained by the unauthorized access detector 102 via the network 103 , such as from a server 105 , and stored in a database 107 connected to the unauthorized access detector 102 .
[0055] In one embodiment, unauthorized access detector 102 is configured to detect unauthorized access to machines 104 in industrial facility 101. In one embodiment, unauthorized access detector 102 detects this unauthorized access by using firewall 108 connected between network 103 and industrial facility 101. Firewall 108, as used herein, refers to a network security device that monitors traffic to and from a network, such as network 103. In one embodiment, firewall 108 allows or blocks traffic based on a set of defined security rules.
[0056] In one embodiment, firewall 108 generates a log (log file) each time a firewall rule (security rule) is applied to traffic. In one embodiment, this logging is referred to as "firewall rule logging" and allows for auditing, verification, and analysis of the effectiveness of firewall rules. In one embodiment, firewall rule logging is an option for any firewall rule, regardless of the rule's action (allow or deny) or direction (inbound or outbound). In one embodiment, when logging is enabled for a firewall rule, an entry called a "connection record" is created each time a rule allows or denies traffic. In one embodiment, each connection record contains the source and destination Internet Protocol (IP) addresses, protocol and port, date and time, and a reference to the firewall rule that applied to the traffic. As used herein, an IP address refers to a unique address that identifies a device on the Internet or a local area network. Furthermore, each connection log includes actions performed by users, such as security hackers, in attempting to gain unauthorized access to machine 104, such as exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). As used herein, "security hacker" refers to one or more individuals intent on gaining unauthorized access to devices, such as machine 104. In one embodiment, these connection logs are used to form a log file.
[0057] In one embodiment, the unauthorized access detector 102 analyzes these log files from the firewall 108 to identify actions used to access or attempt to access one or more machines 104 located on the industrial floor of the industrial facility 101. As used herein, "actions" refer to actions performed by, for example, a security hacker, when accessing or attempting to access one or more machines 104 located on the industrial floor of the industrial facility 101. These actions are obtained from the connection records in the log files of the firewall 108 discussed above, including actions used to gain unauthorized access to the machines 104. Furthermore, in conjunction with these actions, the IP addresses of the devices used to gain access to the machines 104 are obtained from these connection records. In one embodiment, the unauthorized access detector 102 analyzes the log files to identify the IP addresses of the devices used by users to access the machines 104 located on the industrial floor of the industrial facility 101. In one embodiment, the IP address of the device identified by the user to access the machine 104 is compared to a list of known IP addresses of devices deemed trustworthy for secure communications with the machine 104. In one embodiment, such a list of known IP addresses of devices deemed trustworthy for secure communications with the machine 104 is stored in a data structure (e.g., a table) residing in the database 107. In one embodiment, such a list of known IP addresses is populated by an expert. When the IP address of the device identified by the user to access the machine 104 does not match one of the IP addresses in the list of known IP addresses, it can be inferred that potential unauthorized access to the machine 104 is being performed.
[0058] Furthermore, in one embodiment, the unauthorized access detector 102 is configured to analyze a knowledge base (or "knowledge corpus") 109 for unauthorized access strategies. As used herein, a "knowledge base" refers to a collection of data containing information about unauthorized access strategies previously used by, for example, security hackers to gain unauthorized access to machines 104. Examples of such strategies include exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and the use of malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). In one embodiment, such strategies include patterns of attempts to gain unauthorized access to specific machines 104 identified by serial numbers on industrial floors of the industrial facility 101. In one embodiment, such knowledge base 109 is populated by experts.
[0059] In one embodiment, the unauthorized access detector 102 is configured to determine whether identified behaviors for accessing or attempting to access one or more machines 104 (obtained from analyzing log files from the firewall 108) are within a threshold level of similarity to unauthorized access policies learned from the knowledge base 109. As used herein, "threshold level of similarity" means that the identified behaviors (obtained from analyzing log files from the firewall 108) and the unauthorized access policies learned from the knowledge base 109 share the same pattern within a threshold level of similarity. In one embodiment, such threshold level is user-specified.
[0060] If the identified behavior for accessing or attempting to access one or more machines 104 (obtained from analyzing log files from the firewall 108) is within a threshold level of similarity to the unauthorized access policy learned from the knowledge base 109, then in one embodiment, the unauthorized access detector 102 is configured to analyze log files from the machines 104 that were accessed or attempted to be accessed in an unauthorized manner on the industrial floors of the industrial facility 101 to identify operating parameters (e.g., cutting speed, coolant temperature) of these machines 104. As discussed above, in one embodiment, these log files are stored in the database 107.
[0061] In one embodiment, the unauthorized access detector 102 creates an augmented reality visualization to depict unauthorized access policies enforced on machines 104 located on the industrial floor of the industrial facility 101 using the identified operating parameters of these machines 104. As used herein, "augmented reality (AR)" refers to the overlaying of computer-generated imagery onto a user's view of the real world, thereby providing a composite view. In one embodiment, such augmented reality visualization is displayed on augmented reality (AR) smart glasses 110 worn by a user 111, such as a machine operator of a machine 104 located on the industrial floor of the industrial facility 101. In one embodiment, the AR smart glasses 110 correspond to a head-mounted device that includes a display that provides a graphical environment for virtual reality generation. The graphical environment includes graphical images and / or computer-generated sensory information. The display of the AR glasses 110 covers part or all of the user's field of view.
[0062] Exemplary embodiments of head-mounted components for augmented reality smart glasses 110 include visors, helmets, goggles, glasses, and other similar configurations. Examples of augmented reality glasses 110 may include, but are not limited to, Oculus Quest® 2, Microsoft® HoloLens® 2, Magic Leap One®, Google Glass® Enterprise Edition 2, and the like.
[0063] In one embodiment, such augmented reality visualization depicts how one or more machines 104 may be accessed or attempted to be accessed in an unauthorized manner, such as through the use of an avatar corresponding to a security hacker and / or detected malicious code that may be installed on the machine 104.
[0064] In one embodiment, such augmented reality visualization depicts corrective actions to address unauthorized access policies. In one embodiment, these corrective actions are identified from a knowledge base 109, which includes a list of corrective actions to be taken based on various unauthorized access policies implemented on various machines 104 located on the industrial floor of the industrial facility 101 (e.g., disabling the machine 104, reducing the cutting speed by 30%, etc.). In one embodiment, these corrective actions are populated in the knowledge base 109 by an expert.
[0065] The following description, in conjunction with FIG2 , provides a description of the software components of the unauthorized access detector 102 for visualizing unauthorized access strategies used to access or attempt to access machines 104 (e.g., robots, CNC machines, automated guided vehicles) located on an industrial floor of an industrial facility 101. The following description further provides a description of the hardware configuration of the unauthorized access detector 102 in conjunction with FIG3 .
[0066] The network 103 may be, for example, a local area network, a wide area network, a wireless wide area network, a circuit-switched telephone network, a Global System for Mobile Communications (GSM) network, a Wireless Application Protocol (WAP) network, a WiFi network, an IEEE 802.11 standard network, or various combinations thereof. Other networks (whose description is omitted here for the sake of brevity) may also be used in conjunction with the system 100 of FIG. 1 without departing from the scope of the present disclosure.
[0067] The scope of system 100 is not limited to any particular network architecture. System 100 may include any number of industrial facilities 101, unauthorized access detectors 102, networks 103, machines 104, servers 105, IoT sensors 106, databases 107, firewalls 108, knowledge bases 109, augmented reality (AR) glasses 110, and users 111 (e.g., machine operators).
[0068] 2 , a discussion is provided below regarding software components used by the unauthorized access detector 102 for visualizing unauthorized access strategies used to access or attempt to access machines 104 (e.g., robots, CNC machines, automated guided vehicles) located on an industrial floor of an industrial facility 101.
[0069] FIG2 is a diagram of software components used by the unauthorized access detector 102 to visualize unauthorized access strategies used to access or attempt to access a machine 104 (e.g., a robot, a CNC machine tool, an automated guided vehicle) located on an industrial floor of an industrial facility 101, according to an embodiment of the present disclosure.
[0070] 2 , in conjunction with FIG. 1 , the unauthorized access detector 102 includes an analysis engine 201 configured to retrieve and analyze log files from the firewall 108 to identify behaviors for accessing or attempting to access the machines 104 located on the industrial floor of the industrial facility 101 .
[0071] In one embodiment, the analysis engine 201 retrieves logs (log files) generated by the firewall 108 via the network 103 .
[0072] As discussed above, firewall 108, as used herein, refers to a network security device that monitors traffic to and from a network, such as network 103. In one embodiment, firewall 108 allows or blocks traffic based on a set of defined security rules.
[0073] In one embodiment, firewall 108 generates a log (log file) each time a firewall rule (security rule) is applied to traffic. In one embodiment, this logging is referred to as "firewall rule logging" and allows for auditing, verification, and analysis of the effectiveness of firewall rules. In one embodiment, firewall rule logging is an option for any firewall rule, regardless of the rule's action (allow or deny) or direction (inbound or outbound). In one embodiment, when logging is enabled for a firewall rule, an entry called a "connection record" is created each time a rule allows or denies traffic. In one embodiment, each connection record contains the source and destination Internet Protocol (IP) addresses, protocol and port, date and time, and a reference to the firewall rule that applied to the traffic. As used herein, an IP address refers to a unique address that identifies a device on the Internet or a local area network. Furthermore, each connection log includes actions performed by users, such as security hackers, in attempting to gain unauthorized access to machine 104, such as exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). As used herein, "security hacker" refers to one or more individuals intent on gaining unauthorized access to devices, such as machine 104. In one embodiment, these connection logs are used to form a log file.
[0074] In one embodiment, the analysis engine 201 analyzes these log files from the firewall 108 to identify actions used to access or attempt to access one or more machines 104 located on the industrial floor of the industrial facility 101. As used herein, "actions" refer to actions performed by, for example, a security hacker, when accessing or attempting to access one or more machines 104 located on the industrial floor of the industrial facility 101. These actions are obtained from the connection records in the log files of the firewall 108 discussed above, including actions used to gain unauthorized access to the machines 104. Furthermore, in conjunction with these actions, the IP addresses of the devices used to gain access to the machines 104 are obtained from these connection records. In one embodiment, the analysis engine 201 analyzes the log files to identify the IP addresses of the devices used by users to access the machines 104 located on the industrial floor of the industrial facility 101. In one embodiment, the IP address of the device identified by the user to access the machine 104 is compared to a list of known IP addresses of devices deemed trustworthy for secure communications with the machine 104. In one embodiment, such a list of known IP addresses of devices deemed trustworthy for secure communications with the machine 104 is stored in a data structure (e.g., a table) residing in the database 107. In one embodiment, such a list of known IP addresses is populated by an expert. When the IP address of the device identified by the user to access the machine 104 does not match one of the IP addresses in the list of known IP addresses, it can be inferred that potential unauthorized access to the machine 104 is being performed.
[0075] In one embodiment, the analysis engine 201 analyzes the log files generated by the firewall 108 using various software tools, which may include but are not limited to: SolarWinds® Security Event Manager, Papertrail, ManageEngine Event Log Analyzer, Loggly®, Sematext Log, Paessler® PRTG Network Monitor, Splunk, etc.
[0076] Furthermore, in one embodiment, analysis engine 201 analyzes a knowledge base (also referred to as a "knowledge corpus") 109 for unauthorized access strategies. As discussed above, "knowledge base" 109, as used herein, refers to a collection of data containing information regarding unauthorized access strategies previously used by, for example, security hackers to gain unauthorized access to machines 104. In one embodiment, knowledge base 109 is populated by experts. For example, these unauthorized access strategies include exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and exploiting malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). In one embodiment, these unauthorized access strategies include patterns of attempting to gain unauthorized access to specific machines 104 identified by serial number on an industrial floor of industrial facility 101. In one embodiment, these serial numbers are associated with machine types in a data structure (e.g., a table) stored in a storage device of server 105, which is accessible to analysis engine 201 of unauthorized access detector 102 via network 103. In one embodiment, such data structures are populated by experts.
[0077] In one embodiment, the analysis engine 201 analyzes the knowledge base 109 for unauthorized access policies using various software tools, which may include but are not limited to ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0078] The unauthorized access detector 102 further includes a similarity engine 202 configured to detect unauthorized access or attempted unauthorized access to one or more machines 104 located on an industrial floor of the industrial facility 101 based on identified behaviors associated with the unauthorized access policies of the knowledge base 109 within a threshold similarity level (behaviors identified by the analysis engine 201 analyzing log files from the firewall 108).
[0079] In one embodiment, similarity engine 202 is configured to determine whether identified behaviors for accessing or attempting to access one or more machines 104 (obtained from analyzing log files from firewall 108) are within a threshold level of similarity to unauthorized access policies learned from knowledge base 109. As used herein, "threshold level of similarity" means that identified behaviors (obtained from analyzing log files from firewall 108) and unauthorized access policies learned from knowledge base 109 share the same pattern within a threshold level of similarity. In one embodiment, such threshold level is user-specified.
[0080] For example, the similarity engine 202 obtains from the analysis engine 201 identified behaviors for accessing or attempting to access one or more machines 104, which may include the IP addresses of devices requesting access to the machines 104 and actions performed by such devices, such as a request to deploy known malicious code (e.g., Fireball, Emotet) to a specific machine 104 (e.g., a laser cutting tool identified by a serial number XYZ, where such serial number is related to the machine type). The similarity engine 202 may then determine whether the identified behavior (e.g., a request to deploy Fireball to a specific machine 104, such as a laser cutting tool identified by a serial number XYZ) matches the unauthorized access policy of the knowledge base 109 within a threshold similarity level. For example, the unauthorized access policy of knowledge base 109 requesting to deploy Fireball on machine 104 corresponding to a laser cutting tool located on an industrial floor of industrial facility 101 is considered to be within a threshold level of similarity to the identified behavior because both patterns involve requests to deploy the same malicious code on machine 104, both of which correspond to laser cutting tools.
[0081] In one embodiment, the similarity engine 202 utilizes pattern recognition software to determine whether the identified behavior for accessing or attempting to access one or more machines 104 is within a user-specified threshold similarity level to the unauthorized access policies learned from the knowledge base 109. Examples of such pattern recognition software may include, but are not limited to, HanAra®, Data Veil®, and the like.
[0082] In one embodiment, similarity engine 202 uses a machine learning algorithm to build and train a model (machine learning model) to determine whether an identified behavior for accessing or attempting to access one or more machines 104 is within a threshold level of similarity to unauthorized access policies learned from knowledge base 109. In one embodiment, similarity engine 202 builds and trains such a model (machine learning model) to perform such determinations using a sample dataset that includes behaviors that are believed to be within a threshold level of similarity to various unauthorized access policies from knowledge base 109. In one embodiment, such a sample dataset is compiled by an expert.
[0083] Furthermore, such sample data sets are referred to herein as "training data," which are used by a machine learning algorithm to make predictions or decisions about whether behaviors identified from log files (such as log files from firewall 108) are within a threshold level of similarity to the unauthorized access policies in knowledge base 109. The algorithm iteratively makes predictions about whether behaviors identified from log files (such as log files from firewall 108) are within a threshold level of similarity to the unauthorized access policies in knowledge base 109 until such predictions achieve a desired level of accuracy as determined by an expert. Examples of such learning algorithms include nearest neighbor methods, naive Bayes, decision trees, linear regression, support vector machines, and neural networks.
[0084] If the identified behavior for accessing or attempting to access one or more machines 104 (obtained from analyzing log files from firewall 108) is within a threshold level of similarity to the unauthorized access policy learned from knowledge base 109, analysis engine 201 analyzes log files from the machines 104 that were accessed or attempted to be accessed in an unauthorized manner on the industrial floors of industrial facility 101 to identify the operating parameters of these machines 104 (e.g., cutting speed, coolant temperature, operating steps, interactions with other machines 104). As discussed above, in one embodiment, these log files are stored in database 107. For example, in one embodiment, IoT sensors 106 capture the operating parameters of machines 104 (e.g., cutting speed, coolant temperature, operating steps, interactions with other machines 104). This data can then be transferred to server 105 for storage, such as on a storage device of server 105. In one embodiment, these log files are obtained by the unauthorized access detector 102 via the network 103 , such as from the server 105 , and stored in the database 107 .
[0085] Based on analyzing these log files, the analysis engine 201 can determine whether there are changes in operation, such as a sharp increase in the cutting speed of a CNC machine tool or a sharp drop in the coolant temperature. These changes can be reflected visually, such as through augmented reality visualization displayed on augmented reality glasses 110 worn by a user 111, such as a machine operator.
[0086] In one embodiment, the analysis engine 201 analyzes the log files generated by the machine 104 using various software tools, which may include but are not limited to: SolarWinds® Security Event Manager, Papertrail, ManageEngine Event Log Analyzer, Loggly®, Sematext Logs, Paessler® PRTG Network Monitor, Splunk, etc.
[0087] The unauthorized access detector 102 further includes a visualization engine 203 configured to create an augmented reality visualization to depict an unauthorized access policy implemented on one or more machines 104 located on an industrial floor of the industrial facility 101 using the identified operating parameters of such machines 104 .
[0088] As discussed above, the term "augmented reality (AR)" as used herein refers to the overlaying of computer-generated imagery onto a user's view of the real world, providing a composite view. In one embodiment, such AR visualization is displayed on AR smart glasses 110 worn by a user 111, such as a machine operator of a machine 104 located on an industrial floor of an industrial facility 101. In one embodiment, AR smart glasses 110 correspond to a head-mounted device that includes a display that provides a graphical environment for virtual reality generation. The graphical environment includes graphical images and / or computer-generated sensory information. The display of AR glasses 110 covers part or all of the user's field of view.
[0089] Exemplary embodiments of head-mounted components for augmented reality smart glasses 110 include visors, helmets, goggles, glasses, and other similar configurations. Examples of augmented reality glasses 110 may include, but are not limited to, Oculus Quest® 2, Microsoft® HoloLens® 2, Magic Leap One®, Google Glass® Enterprise Edition 2, and the like.
[0090] As discussed above, in one embodiment, an augmented reality visualization is created to depict the unauthorized access policy implemented on one or more machines 104 located on an industrial floor of the industrial facility 101 using the identified operating parameters of these machines 104. For example, based on these operating parameters, the augmented reality visualization may include visualizations of operating parameters such as coolant temperature, cutting speed, etc. Furthermore, these operating parameters may be used by the visualization engine 203 to visually depict the operating steps of the machine 104 (e.g., drilling, grinding, etc.) and its interactions with other machines 104 using augmented reality (e.g., a robotic handler placing a panel at a precise location so that a welding robot can perform all programmed welds).
[0091] In one embodiment, visualization engine 203 creates avatars of security hackers and / or detected unauthorized access strategies, such as malicious code that may be installed on machine 104. As used herein, "avatar" refers to a graphical representation of a user or object. As used herein, "security hacker" refers to one or more individuals intent on gaining unauthorized access to a device, such as machine 104.
[0092] In one embodiment, visualization engine 203 uses the created avatar in an augmented reality visualization to depict unauthorized access to one or more machines 104 located on an industrial floor of industrial facility 101. For example, an avatar of a security hacker and unauthorized access strategies (e.g., utilizing malicious code) can be displayed in the augmented reality visualization.
[0093] In one embodiment, the visualization engine 203 uses various software tools to create such augmented reality visualizations, which software tools may include but are not limited to Sketchfab®, Aryel®, SketchAR®, Threekit®, Zapworks®, etc.
[0094] The unauthorized access detector 102 further includes a remediation engine 204 configured to identify remediation measures to address unauthorized access policies using the knowledge base 109. In one embodiment, these remediation measures are identified from the knowledge base 109, which includes a list of remediation measures to be performed to address unauthorized access policies specified in the knowledge base 109 (e.g., disabling the machine 104, reducing the cutting speed by 30%, etc.). In one embodiment, these remediation measures are populated in the knowledge base 109 by an expert.
[0095] For example, in one embodiment, once the similarity engine 202 identifies an unauthorized access policy in the knowledge base 109 that is within a threshold similarity to the identified behavior for accessing or attempting to access a machine 104 located on an industrial floor of the industrial facility 101, the remediation engine 204 then searches the knowledge base 109 for any remediation measures to address such unauthorized access policy. In one embodiment, the remediation engine 204 uses various software tools to identify such remediation measures, such as, but not limited to, ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0096] Furthermore, in one embodiment, visualization engine 203 is configured to depict the identified corrective action to address the unauthorized access policy in an augmented reality visualization. For example, in one embodiment, visualization engine 203 depicts in the augmented reality visualization how to implement the identified corrective action (e.g., reducing the cutting speed of machine 104 by 30% and disabling machine 104) to address the unauthorized access policy. In one embodiment, visualization engine 203 depicts the corrective action to address the unauthorized access policy in the augmented reality visualization using various software tools, including but not limited to Sketchfab®, Aryel®, SketchAR®, Threekit®, Zapworks®, and the like.
[0097] In addition, the unauthorized access detector 102 includes a feedback engine 205 configured to update the knowledge base 109 based on feedback received from users (such as user 111) regarding the augmented reality visualization. For example, if the corrective action of reducing the cutting speed of the machine 104 by 30% does not fully resolve the unauthorized access policy, but instead requires reducing the cutting speed of the machine 104 by 50%, this information will be used to update the knowledge base 109. Therefore, when such an unauthorized access policy is identified in the future, a more appropriate corrective action will be recommended—recommending a 50% reduction in the cutting speed of the machine 104.
[0098] In one embodiment, feedback may be provided by the user in various ways, such as via a graphical user interface of the unauthorized access detector 102. In one embodiment, feedback is provided by the user (e.g., user 111) via electronic means, such as via email and text messaging.
[0099] The feedback engine 205 is configured to update the knowledge base 109 with the received feedback using various software tools, which may include but are not limited to ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0100] Further description of these and other features is provided below in conjunction with a discussion of methods for visualizing unauthorized access or attempted unauthorized access to machines 104 located on an industrial floor of an industrial facility 101 .
[0101] Before discussing a method for visualizing unauthorized access or attempted unauthorized access to a machine 104 located on an industrial floor of an industrial facility 101, a description of the hardware configuration of the unauthorized access detector 102 (FIG. 1) is provided below in conjunction with FIG. 3.
[0102] 3 , in conjunction with FIG. 1 , FIG. 3 illustrates an embodiment of the hardware configuration of the unauthorized access detector 102 of the present disclosure, representing a hardware environment for practicing the present disclosure.
[0103] Various aspects of the present disclosure are described using narrative text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in computer program product (CPP) embodiments. With respect to any flowchart, depending on the technology involved, the operations may be performed in an order different from that shown in a given flowchart. For example, two operations shown in successive flowchart blocks may be performed in reverse order, as a single integrated step, in parallel, or with at least partial overlap in time, also depending on the technology involved.
[0104] A computer program product embodiment ("CPP embodiment" or "CPP") is a term used in this disclosure to describe any one or more storage media (also referred to as "mediums") collectively comprised within a set of one or more storage devices that collectively contain machine-readable code corresponding to instructions and / or data for performing computer operations specified in a given CPP requirement. A "storage device" is any tangible device that can retain and store instructions for use by a computer processor. A computer-readable storage medium may be, without limitation, electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, mechanical storage media, or any suitable combination of the foregoing. Some known types of storage devices that include such media include: magnetic disks, hard drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanical encoding devices (such as punch cards or pits / pads formed in the major surface of an optical disc), or any suitable combination of the foregoing. The term computer-readable storage medium, as used in this disclosure, should not be construed as meaning storage in the form of transient signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides, light pulses transmitted through fiber-optic cables, electrical signals conveyed through wires, and / or other transmission media. As those skilled in the art will appreciate, data is typically moved at occasional points during normal operation of a storage device (such as during access, defragmentation, or garbage collection), but this does not render the storage device transient, as the data is not transient while it is stored.
[0105] Computing environment 300 contains an example of an environment for executing at least some of the computer program codes involved in executing the disclosed methods, such as visualizing unauthorized access or attempted unauthorized access to a machine 104 located on an industrial floor of an industrial facility 101, stored in block 301. In addition to block 301, computing environment 300 includes, for example, an unauthorized access detector 102, a network 103 (such as a wide area network (WAN)), an end-user device (EUD) 302, a remote server 303, a public cloud 304, and a private cloud 305. In this embodiment, the unauthorized access detector 102 includes a processor assembly 306 (including processing circuitry 307 and cache 308), a communication mesh 309, volatile memory 310, persistent storage 311 (including the operating system 312 and block 301 identified above), a peripheral device assembly 313 (including a user interface (UI) device assembly 314, storage 315, and an Internet of Things (IoT) sensor assembly 316), and a network module 317. The remote server 303 includes a remote database 318. The public cloud 304 includes a gateway 319, a cloud orchestration module 320, a host physical machine assembly 321, a virtual machine assembly 322, and a container assembly 323.
[0106] Unauthorized access detector 102 can take the form of a desktop computer, laptop computer, tablet computer, smartphone, smartwatch or other wearable computer, mainframe computer, quantum computer, or any other computer or mobile device now known or to be developed in the future that is capable of running programs, accessing a network, or querying a database (such as remote database 318). As is well understood in the computer arts, and depending on the technology, the performance of a computer-implemented method can be distributed among multiple computers and / or multiple locations. However, in this presentation of computing environment 300, the detailed discussion focuses on a single computer, specifically, unauthorized access detector 102, to keep the presentation as simple as possible. Unauthorized access detector 102 can be located in the cloud, even though it is not shown in the cloud in FIG. However, unauthorized access detector 102 need not be located in the cloud, except to the extent indicated.
[0107] Processor assembly 306 includes one or more computer processors of any type now known or to be developed in the future. Processing circuitry 307 may be distributed across multiple packages, such as multiple coordinated integrated circuit chips. Processing circuitry 307 may implement multiple processor threads and / or multiple processor cores. Cache memory 308 is memory located within the processor chip package and is typically used for data or code that should be quickly accessed by threads or cores running on processor assembly 306. Cache memory is typically organized into multiple levels depending on its relative proximity to the processing circuitry. Alternatively, some or all of the cache memory for the processor assembly may be located "off-chip." In some computing environments, processor assembly 306 may be designed to use qubits and perform quantum computations.
[0108] Computer-readable program instructions are typically loaded onto the unauthorized access detector 102 to cause the processor assembly 306 of the unauthorized access detector 102 to perform a series of operational steps and thereby affect a computer-implemented method, such that the instructions thus executed will instantiate the method specified in the flowcharts and / or narrative descriptions of the computer-implemented method included herein (collectively, the "disclosed method"). These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 308 and other storage media discussed below. The program instructions and associated data are accessed by the processor assembly 306 to control and direct the performance of the disclosed method. In the computing environment 300, at least some of the instructions for executing the disclosed method may be stored in block 301 in persistent storage 311.
[0109] The communication mesh 309 is a signal transmission path that allows the various components of the unauthorized access detector 102 to communicate with each other. Typically, this mesh is made up of switches and conductive paths, such as those that form buses, bridges, physical input / output ports, and the like. Other types of signal communication paths may be used, such as fiber optic communication paths and / or wireless communication paths.
[0110] Volatile memory 310 is any type of volatile memory, now known or to be developed in the future. Examples include dynamic random access memory (RAM) or static RAM. Typically, volatile memory is characterized by random access, but this is not required unless specifically indicated. In the unauthorized access detector 102, the volatile memory 310 is located in a single package and internal to the unauthorized access detector 102. Alternatively or additionally, the volatile memory may be distributed across multiple packages and / or located externally relative to the unauthorized access detector 102.
[0111] Persistent storage 311 is any form of non-volatile computer storage, now known or to be developed in the future. The non-volatility of this storage means that the stored data is maintained regardless of whether power is supplied to the unauthorized access detector 102 and / or directly to the persistent storage 311. Persistent storage 311 may be read-only memory (ROM), but typically at least a portion of the persistent storage allows data to be written, deleted, and rewritten. Some familiar forms of persistent storage include magnetic disks and solid-state storage devices. Operating system 312 can take several forms, such as various known proprietary operating systems or an open source portable operating system interface (POI) operating system using a kernel. The program code included in block 301 typically includes at least some of the computer program code involved in executing the disclosed method.
[0112] Peripheral device set 313 includes a collection of peripheral devices of unauthorized access detector 102. Data communication connections between peripheral devices and other components of unauthorized access detector 102 can be implemented in various ways, such as Bluetooth connections, near-field communication (NFC) connections, connections via cables (such as Universal Serial Bus (USB) cables), plug-in connections (e.g., secure digital (SD) cards), connections via local area communication networks, and even connections via wide area networks such as the Internet. In various embodiments, UI device set 314 may include components such as displays, speakers, microphones, wearable devices (such as goggles and smartwatches), keyboards, mice, printers, touchpads, game controllers, and touch-sensing devices. Storage 315 is external storage, such as an external hard drive or plug-in storage such as an SD card. Storage 315 can be permanent and / or volatile. In some embodiments, storage 315 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where the unauthorized access detector 102 requires a large amount of storage (e.g., where the unauthorized access detector 102 locally stores and manages a large database), this storage can then be provided by peripheral storage devices designed for storing large amounts of data, such as a storage area network (SAN) shared by multiple geographically distributed computers. The IoT sensor set 316 consists of sensors that can be used in IoT applications. For example, one sensor may be a thermometer and another sensor may be a motion detector.
[0113] Network module 317 is a collection of computer software, hardware, and firmware that allows unauthorized access detector 102 to communicate with other computers via WAN 103. Network module 317 may include hardware, such as a modem or Wi-Fi transceiver; software for packetizing and / or depacketizing data for transmission over a communications network; and / or web browser software for communicating data over the Internet. In some embodiments, the network control and network forwarding functions of network module 317 are executed on the same physical hardware device. In other embodiments (e.g., those utilizing software-defined networking (SDN)), the control and forwarding functions of network module 317 are executed on physically separate devices, allowing the control functions to manage several different network hardware devices. Computer-readable program instructions for executing the disclosed methods can typically be downloaded to unauthorized access detector 102 from an external computer or external storage device via a network adapter card or network interface included in network module 317.
[0114] WAN 103 is any wide area network (e.g., the Internet) capable of transmitting computer data over non-local distances using any technology now known or to be developed for transmitting computer data. In some embodiments, a WAN may be replaced and / or supplemented by a local area network (LAN), which is designed to transmit data between devices located in a local area, such as a Wi-Fi network. WANs and / or LANs typically include computer hardware such as copper transmission cables, optical fiber, wireless transmission, routers, firewalls, switches, gateway computers, and edge servers.
[0115] An end-user device (EUD) 302 is any computer system used and controlled by an end-user (e.g., a customer of the business operating the unauthorized access detector 102) and may take any of the forms discussed above with respect to the unauthorized access detector 102. The EUD 302 typically receives helpful and useful information from the operation of the unauthorized access detector 102. For example, if the unauthorized access detector 102 is designed to provide recommendations to the end-user, such recommendations would typically be communicated from the network module 317 of the unauthorized access detector 102 via the WAN 103 to the EUD 302. In this manner, the EUD 302 may display or otherwise present the recommendations to the end-user. In some embodiments, the EUD 302 may be a client device, such as a thin client, a fat client, a mainframe computer, a desktop computer, or the like.
[0116] Remote server 303 is any computer system that provides at least some data and / or functionality to Unauthorized Access Detector 102. Remote server 303 may be controlled and used by the same entity that operates Unauthorized Access Detector 102. Remote server 303 represents a machine that collects and stores helpful and useful data for use by other computers, such as Unauthorized Access Detector 102. For example, if Unauthorized Access Detector 102 is designed and programmed to provide recommendations based on historical data, this historical data may be provided to Unauthorized Access Detector 102 from Remote Database 318 on remote server 303.
[0117] Public cloud 304 is any computer system available to multiple entities, providing on-demand availability of computer system resources and / or other computer capabilities, particularly data storage (cloud storage) and computing power, without requiring direct and active management by users. Cloud computing typically leverages resource pooling to achieve coherence and economies of scale. Direct and active management of computing resources in public cloud 304 is performed by the computer hardware and / or software of cloud orchestration module 320. The computing resources provided by public cloud 304 are typically implemented using virtual computing environments (VCEs) running on various computers comprising a host physical machine set 321, which is the range of physical computers within and / or available to public cloud 304. Virtual computing environments (VCEs) typically take the form of virtual machines from virtual machine set 322 and / or containers from container set 323. It should be understood that these VCEs can be stored as images and transferred between and among various physical machine hosts, either as images or after instantiation of the VCEs. The cloud orchestration module 320 manages the transmission and storage of images, deploys new instances of VCE, and manages active instances of VCE deployments. The gateway 319 is a collection of computer software, hardware, and firmware that allows the public cloud 304 to communicate over the WAN 103.
[0118] The following provides some further explanation of virtualized computing environments (VCEs). A VCE can be stored as an "image." New VCE instances can be instantiated from an image. Two common types of VCEs are virtual machines and containers. Containers are VCEs that utilize operating system-level virtualization. This refers to an operating system feature where the kernel allows the existence of multiple isolated user space instances, called containers. From the perspective of the programs running within them, these isolated user space instances typically appear to be real computers. Computer programs running on a typical operating system can utilize all of the computer's resources, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capacity. However, programs running within a container can only use the container's contents and the devices assigned to it. This feature is known as containerization.
[0119] Private cloud 305 is similar to public cloud 304, except that its computing resources are only available to a single enterprise. While private cloud 305 is depicted as communicating with WAN 103, in other embodiments, the private cloud may be completely disconnected from the internet and accessible only via a local / private network. A hybrid cloud is a composite of multiple clouds of different types (e.g., private, corporate, or public), typically implemented by different vendors. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is bound together by standardized or proprietary technologies that enable orchestration, management, and / or data / application portability across the constituent clouds. In this embodiment, both public cloud 304 and private cloud 305 are part of a larger hybrid cloud.
[0120] Block 301 further includes the software components discussed above in conjunction with FIG. 2 for visualizing unauthorized access or attempted unauthorized access to machines 104 located on the industrial floor of industrial facility 101. In one embodiment, these components may be implemented in hardware. The functions discussed above performed by these components are not general-purpose computer functions. Therefore, unauthorized access detector 102 is a specialized machine that is the result of implementing specialized, non-general-purpose computer functions.
[0121] In one embodiment, the functionality of these software components of the unauthorized access detector 102 may be embodied in an application-specific integrated circuit, including functionality for visualizing unauthorized access or attempted unauthorized access to a machine 104 located on an industrial floor of the industrial facility 101.
[0122] As mentioned above, in the context of the manufacturing industry, various machines (e.g., robots, CNC machines, automated guided vehicles, etc.) located on industrial floors (floors such as those used in industrial and commercial environments) are used to manufacture and produce components, goods, parts, etc., in workshops, factories, etc. For example, these machines may correspond to robots that weld and assemble components. In another example, CNC machines cut metal parts to precise specifications. In another example, engine machining stations are used to create cylinder blocks. Users (referred to as "security hackers") may attempt to gain unauthorized access to these machines located on industrial floors in order to steal sensitive data, cause damage, seize data as part of a ransomware attack, perform pranks, etc. For example, a security hacker may attempt to gain unauthorized access to a CNC machine tool in order to manipulate the machine's programming, causing it to produce defective parts. If the machine operator fails to promptly notice the problem, the defective parts will enter the market. In another example, a security hacker may attempt to gain unauthorized access to a computer numerically controlled (CNC) machine tool to gain a competitive advantage by stealing confidential proprietary information. Security hackers may use various methods to attempt to gain unauthorized access to machines located on the industrial floor, such as exploiting software vulnerabilities. Other methods include social engineering tactics such as phishing, phishing text messages, spear phishing, and ransomware. Furthermore, security hackers may use malicious code (malware) to gain unauthorized access to machines located on the industrial floor, including the information stored on these machines. Malware is software intentionally designed to gain unauthorized access to information or systems, such as machines located on the industrial floor. Examples of such malware include computer viruses, worms, Trojan horses, ransomware, spyware, and rogue software. Unfortunately, there is currently no effective means of notifying machine operators, such as visually, of attempts to gain unauthorized access to machines located on the industrial floor. These machine operators need to know which machines on the industrial floor are being attempted to be accessed without authorization, or have actually been accessed without authorization, so that the machine operators can take corrective measures to resolve the attempted or successful unauthorized access to the machines on the industrial floor.
[0123] Embodiments of the present disclosure provide a means for effectively notifying machine operators of attempts to gain unauthorized access to machines located on an industrial floor by using augmented reality visualizations, discussed below in conjunction with Figures 4 through 6, to depict unauthorized access policies enforced on machines located on an industrial floor. Figure 4 is a flow chart of a method for visualizing unauthorized access or attempted unauthorized access to a machine 104 located on an industrial floor of an industrial facility 101. Figure 5 is a flow chart of a method for creating an augmented reality visualization. Figure 6 is a flow chart of a method for updating a knowledge base using feedback received regarding an augmented reality visualization.
[0124] As stated above, FIG. 4 is a flow chart of a method 400 for visualizing unauthorized access or attempted unauthorized access to a machine 104 located on an industrial floor of an industrial facility 101 according to an embodiment of the present disclosure.
[0125] 4 , in conjunction with FIG. 1 to FIG. 3 , in operation 401 , the analysis engine 201 of the unauthorized access detector 102 retrieves log files from the firewall 108 that monitors traffic to and from the machines 104 located on the industrial floors of the industrial facility 101 .
[0126] As discussed above, in one embodiment, the analysis engine 201 retrieves log files generated by the firewall 108 via the network 103 .
[0127] Furthermore, as discussed above, firewall 108 as used herein refers to a network security device that monitors traffic to and from a network, such as network 103. In one embodiment, firewall 108 allows or blocks traffic based on a set of defined security rules.
[0128] In one embodiment, firewall 108 generates a log file each time a firewall rule (security rule) is applied to traffic. In one embodiment, this logging is referred to as "firewall rule logging," which allows for auditing, verification, and analysis of the effectiveness of firewall rules. In one embodiment, firewall rule logging is an option for any firewall rule, regardless of the rule's action (allow or deny) or direction (inbound or outbound). In one embodiment, when logging is enabled for a firewall rule, an entry called a "connection record" is created each time a rule allows or denies traffic. In one embodiment, each connection record contains the source and destination Internet Protocol (IP) addresses, protocol and port, date and time, and a reference to the firewall rule that applied to the traffic. As used herein, an IP address refers to a unique address that identifies a device on the Internet or a local area network. Furthermore, each connection log includes actions performed by users, such as security hackers, in attempting to gain unauthorized access to machine 104, such as exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). As used herein, "security hacker" refers to one or more individuals focused on gaining unauthorized access to devices, such as machine 104. In one embodiment, these connection logs are used to form log files.
[0129] In operation 402 , the analysis engine 201 of the unauthorized access detector 102 analyzes log files retrieved from the firewall 108 to identify actions used to access or attempt to access one or more machines 104 located on an industrial floor of the industrial facility 101 .
[0130] As stated above, "behavior" as used herein refers to actions performed by, for example, a security hacker when accessing or attempting to access one or more machines 104 located on an industrial floor of industrial facility 101. These actions are obtained from connection records in the log files of firewall 108 discussed above, including actions used to gain unauthorized access to machines 104. Furthermore, in conjunction with these actions, the IP addresses of the devices used to gain access to machines 104 are obtained from these connection records. In one embodiment, analysis engine 201 analyzes the log files to identify the IP addresses of the devices used by users to access machines 104 located on an industrial floor of industrial facility 101. In one embodiment, the IP addresses of the identified devices used by users to access machines 104 are compared against a list of known IP addresses of devices deemed trustworthy for secure communications with machines 104. In one embodiment, such a list of known IP addresses of devices that are deemed trustworthy for secure communications with machine 104 is stored in a data structure (e.g., a table) residing in database 107. In one embodiment, such a list of known IP addresses is populated by an expert. When the IP address of a device utilized by a user to access machine 104 does not match one of the IP addresses in the list of known IP addresses, it can be inferred that potential unauthorized access to machine 104 is being performed.
[0131] In one embodiment, the analysis engine 201 analyzes the log files generated by the firewall 108 using various software tools, which may include but are not limited to: SolarWinds® Security Event Manager, Papertrail, ManageEngine Event Log Analyzer, Loggly®, Sematext Log, Paessler® PRTG Network Monitor, Splunk, etc.
[0132] In operation 403 , the analysis engine 201 of the unauthorized access detector 102 analyzes the knowledge base 109 for unauthorized access policies.
[0133] As discussed above, the term "knowledge base" 109 as used herein refers to a collection of data containing information regarding unauthorized access strategies previously used by, for example, security hackers to gain unauthorized access to machines 104. In one embodiment, the knowledge base 109 is populated by experts. Examples of such unauthorized access strategies include exploiting software vulnerabilities, social engineering tactics (e.g., phishing, phishing SMS, spear phishing, ransomware, etc.), and the use of malicious code (malware) (e.g., viruses, worms, Trojan horses, ransomware, spyware, rogue software, etc.). In one embodiment, such unauthorized access strategies include patterns of attempting to gain unauthorized access to specific machines 104 identified by serial number on an industrial floor of the industrial facility 101. In one embodiment, these serial numbers are associated with machine types in a data structure (e.g., a table) stored in a storage device of server 105, which is accessible to analysis engine 201 of unauthorized access detector 102 via network 103. In one embodiment, such data structures are populated by experts.
[0134] In one embodiment, the analysis engine 201 analyzes the knowledge base 109 for unauthorized access policies using various software tools, which may include but are not limited to ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0135] In operation 404, the similarity engine 202 of the unauthorized access detector 102 determines whether unauthorized access or attempted unauthorized access to one or more machines 104 located on an industrial floor of the industrial facility 101 is detected based on the identified behavior (identified in operation 402) being associated with the unauthorized access policy of the knowledge base 109 within a threshold similarity level.
[0136] As discussed above, in one embodiment, the similarity engine 202 is configured to determine whether the identified behavior for accessing or attempting to access one or more machines 104 (obtained from analyzing log files from the firewall 108) is within a threshold level of similarity to the unauthorized access policy learned from the knowledge base 109. As used herein, "threshold level of similarity" means that the identified behavior (obtained from analyzing log files from the firewall 108) and the unauthorized access policy learned from the knowledge base 109 have the same pattern within a threshold level of similarity. In one embodiment, such a threshold level is specified by the user.
[0137] For example, the similarity engine 202 obtains from the analysis engine 201 identified behaviors for accessing or attempting to access one or more machines 104, which may include the IP addresses of devices requesting access to the machines 104 and actions performed by such devices, such as a request to deploy known malicious code (e.g., Fireball, Emotet) to a specific machine 104 (e.g., a laser cutting tool identified by a serial number XYZ, where such serial number is related to the machine type). The similarity engine 202 may then determine whether the identified behavior (e.g., a request to deploy Fireball to a specific machine 104, such as a laser cutting tool identified by a serial number XYZ) matches the unauthorized access policy of the knowledge base 109 within a threshold similarity level. For example, the unauthorized access policy of knowledge base 109 requesting to deploy Fireball on machine 104 corresponding to a laser cutting tool located on an industrial floor of industrial facility 101 is considered to be within a threshold level of similarity to the identified behavior because both patterns involve requests to deploy the same malicious code on machine 104, both of which correspond to laser cutting tools.
[0138] In one embodiment, the similarity engine 202 utilizes pattern recognition software to determine whether the identified behavior for accessing or attempting to access one or more machines 104 is within a user-specified threshold similarity level to the unauthorized access policies learned from the knowledge base 109. Examples of such pattern recognition software may include, but are not limited to, HanAra®, Data Veil®, and the like.
[0139] In one embodiment, similarity engine 202 uses a machine learning algorithm to build and train a model (machine learning model) to determine whether an identified behavior for accessing or attempting to access one or more machines 104 is within a threshold level of similarity to unauthorized access policies learned from knowledge base 109. In one embodiment, similarity engine 202 builds and trains such a model (machine learning model) to perform such determinations using a sample dataset that includes behaviors that are believed to be within a threshold level of similarity to various unauthorized access policies from knowledge base 109. In one embodiment, such a sample dataset is compiled by an expert.
[0140] Furthermore, such sample data sets are referred to herein as "training data," which are used by a machine learning algorithm to make predictions or decisions about whether behaviors identified from log files (such as log files from firewall 108) are within a threshold level of similarity to the unauthorized access policies in knowledge base 109. The algorithm iteratively makes predictions about whether behaviors identified from log files (such as log files from firewall 108) are within a threshold level of similarity to the unauthorized access policies in knowledge base 109 until such predictions achieve a desired level of accuracy as determined by an expert. Examples of such learning algorithms include nearest neighbor methods, naive Bayes, decision trees, linear regression, support vector machines, and neural networks.
[0141] If the identified behavior for accessing or attempting to access one or more machines 104 (obtained from analyzing the log files from the firewall 108) is not within a threshold similarity level with the unauthorized access policy learned from the knowledge base 109, the analysis engine 201 continues to retrieve the log files generated by the firewall 108 via the network 103 in operation 401.
[0142] However, if the identified behavior for accessing or attempting to access one or more machines 104 (obtained from analyzing the log files from the firewall 108) is within a threshold similarity level with the unauthorized access policy learned from the knowledge base 109, then the analysis engine 201 of the unauthorized access detector 102 analyzes the log files from the machines 104 that were accessed or attempted to be accessed in an unauthorized manner on the industrial floor of the industrial facility 101 in operation 405 to identify the operating parameters of such machines 104 (e.g., cutting speed, coolant temperature, operating steps, interaction with other machines 104).
[0143] As discussed above, in one embodiment, these log files are stored in database 107. For example, in one embodiment, IoT sensor 106 captures operating parameters of machine 104 (e.g., cutting speed, coolant temperature, operating steps, interactions with other machines 104). This data can then be captured by IoT sensor 106 and transferred to server 105 for storage, such as on a storage device on server 105. In one embodiment, these log files are obtained by unauthorized access detector 102 via network 103, such as from server 105, and stored in database 107.
[0144] Based on analyzing these log files, the analysis engine 201 can determine whether there are changes in operation, such as a sharp increase in the cutting speed of a CNC machine tool or a sharp drop in the coolant temperature. These changes can be reflected visually, such as through augmented reality visualization displayed on augmented reality glasses 110 worn by a user 111, such as a machine operator.
[0145] In one embodiment, the analysis engine 201 analyzes the log files generated by the machine 104 using various software tools, which may include but are not limited to: SolarWinds® Security Event Manager, Papertrail, ManageEngine Event Log Analyzer, Loggly®, Sematext Logs, Paessler® PRTG Network Monitor, Splunk, etc.
[0146] In operation 406 , the visualization engine 203 of the unauthorized access detector 102 creates an augmented reality visualization to depict the unauthorized access policy implemented on one or more machines 104 located on the industrial floor of the industrial facility 101 using the identified operating parameters of these machines 104 .
[0147] As discussed above, the term "augmented reality (AR)" as used herein refers to the overlaying of computer-generated imagery onto a user's view of the real world, providing a composite view. In one embodiment, such AR visualization is displayed on AR smart glasses 110 worn by a user 111, such as a machine operator of a machine 104 located on an industrial floor of an industrial facility 101. In one embodiment, AR smart glasses 110 correspond to a head-mounted device that includes a display that provides a graphical environment for virtual reality generation. The graphical environment includes graphical images and / or computer-generated sensory information. The display of AR glasses 110 covers part or all of the user's field of view.
[0148] Exemplary embodiments of head-mounted components for augmented reality smart glasses 110 include visors, helmets, goggles, glasses, and other similar configurations. Examples of augmented reality glasses 110 may include, but are not limited to, Oculus Quest® 2, Microsoft® HoloLens® 2, Magic Leap One®, Google Glass® Enterprise Edition 2, and the like.
[0149] As discussed above, in one embodiment, an augmented reality visualization is created to depict the unauthorized access policy implemented on one or more machines 104 located on an industrial floor of the industrial facility 101 using the identified operating parameters of these machines 104. For example, based on these operating parameters, the augmented reality visualization may include visualizations of operating parameters such as coolant temperature, cutting speed, etc. Furthermore, these operating parameters may be used by the visualization engine 203 to visually depict the operating steps of the machine 104 (e.g., drilling, grinding, etc.) and its interactions with other machines 104 using augmented reality (e.g., a robotic handler placing a panel at a precise location so that a welding robot can perform all programmed welds).
[0150] Further discussion on creating such augmented reality visualizations is provided below in conjunction with FIG. 5 .
[0151] FIG5 is a flowchart of a method 500 for creating an augmented reality visualization according to an embodiment of the present disclosure.
[0152] Referring to FIG. 5 , in conjunction with FIG. 1 through FIG. 4 , in operation 501, the visualization engine 203 of the unauthorized access detector 102 creates an avatar of a security hacker and / or detected unauthorized access policy, such as malicious code that may be installed on the machine 104. As used herein, "avatar" refers to a graphical representation of a user or object. As used herein, "security hacker" refers to one or more individuals intent on gaining unauthorized access to a device, such as the machine 104.
[0153] In operation 502, the visualization engine 203 of the unauthorized access detector 102 uses the created avatar to depict unauthorized access to one or more machines 104 located on an industrial floor of the industrial facility 101 in an augmented reality visualization. For example, an avatar of a security hacker and unauthorized access strategies (e.g., malicious code) may be displayed in the augmented reality visualization.
[0154] As stated above, in one embodiment, the visualization engine 203 uses various software tools to create such augmented reality visualizations, which software tools may include but are not limited to Sketchfab®, Aryel®, SketchAR®, Threekit®, Zapworks®, etc.
[0155] In operation 503 , the remediation engine 204 of the unauthorized access detector 102 identifies remediation measures to resolve the unauthorized access policy using the knowledge base 109 .
[0156] As discussed above, in one embodiment, these corrective actions are identified from the knowledge base 109, which includes a list of corrective actions (e.g., disabling the machine 104, reducing the cutting speed by 30%, etc.) to be performed to resolve the unauthorized access policy specified in the knowledge base 109. In one embodiment, these corrective actions are populated in the knowledge base 109 by an expert.
[0157] For example, in one embodiment, once the similarity engine 202 identifies an unauthorized access policy in the knowledge base 109 that is within a threshold similarity to the identified behavior for accessing or attempting to access a machine 104 located on an industrial floor of the industrial facility 101, the remediation engine 204 then searches the knowledge base 109 for any remediation measures to address such unauthorized access policy. In one embodiment, the remediation engine 204 uses various software tools to identify such remediation measures, such as, but not limited to, ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0158] In operation 504 , the visualization engine 203 of the unauthorized access detector 102 depicts the identified corrective measures to address the unauthorized access policy in an augmented reality visualization.
[0159] For example, in one embodiment, the visualization engine 203 depicts in an augmented reality visualization how to implement the identified corrective action (e.g., reducing the cutting speed of the machine 104 by 30% and disabling the machine 104) to resolve the unauthorized access policy. In one embodiment, the visualization engine 203 depicts in an augmented reality visualization the corrective action to resolve the unauthorized access policy using various software tools, including but not limited to Sketchfab®, Aryel®, SketchAR®, Threekit®, Zapworks®, etc.
[0160] Furthermore, feedback regarding the accuracy of augmented reality visualizations, such as from machine users (e.g., user 111), can be provided. This feedback can be used to update knowledge base 109 to improve the accuracy of unauthorized access policies (such as those used by security hackers) and / or corrective measures used to address unauthorized access policies stored in knowledge base 109. A discussion of updating knowledge base 109 based on this feedback is provided below in conjunction with FIG. 6 .
[0161] FIG. 6 is a flow chart of a method 600 for updating the knowledge base 109 using received feedback regarding augmented reality visualization according to an embodiment of the present disclosure.
[0162] 6 , in combination with FIG. 1 to FIG. 5 , in operation 601, the feedback engine 205 of the unauthorized access detector 102 determines whether feedback regarding an augmented reality visualization, such as the augmented reality visualization displayed on the augmented reality glasses 110 , is received, such as from a user 111 (e.g., a machine operator).
[0163] If the feedback engine 205 does not receive such feedback, then in operation 601, the feedback engine 205 of the unauthorized access detector 102 continues to determine whether feedback is received, such as from the user 111 (e.g., a machine operator), regarding the augmented reality visualization, such as the augmented reality visualization displayed on the augmented reality glasses 110.
[0164] However, if feedback is received, such as from a user 111 (e.g., a machine operator) regarding an augmented reality visualization, such as the augmented reality visualization displayed on the augmented reality glasses 110, then in operation 602, the feedback engine 205 of the unauthorized access detector 102 updates the knowledge base 109 based on the feedback received from the user (e.g., user 111) regarding the augmented reality visualization.
[0165] In one embodiment, feedback may be provided by the user in various ways, such as via a graphical user interface of the unauthorized access detector 102. In one embodiment, feedback is provided by the user (e.g., user 111) via electronic means, such as via email and text messaging.
[0166] For example, if the corrective action does not completely resolve the unauthorized access policy by reducing the cutting speed of machine 104 by 30%, but instead requires reducing the cutting speed of machine 104 by 50%, this information will be used to update knowledge base 109. Therefore, when such an unauthorized access policy is identified in the future, a more appropriate corrective action will be recommended, namely reducing the cutting speed of machine 104 by 50%.
[0167] The feedback engine 205 is configured to update the knowledge base 109 with the received feedback using various software tools, which may include but are not limited to ClickUp®, ProProfs® Knowledge Base, Freshdesk®, Confluence®, etc.
[0168] In this way, machine operators will now be effectively informed of attempts to gain unauthorized access to machines located on the industrial floor. For example, these machine operators will now be able to visualize this unauthorized access or attempted unauthorized access to machines located on the industrial floor, such as via augmented reality visualizations displayed on augmented reality glasses worn by the machine operators. Furthermore, such augmented reality visualizations may include possible corrective measures to be taken to address the unauthorized access or attempted unauthorized access to machines located on the industrial floor. As a result of the foregoing, machine operators will now understand which machines located on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, thereby allowing them to take corrective measures to address the attempted or successful unauthorized access to the machines.
[0169] Furthermore, the principles of the present disclosure improve techniques or technical fields involving unauthorized access. As described above, in the context of the manufacturing industry, various machines (e.g., robots, CNC machines, automated guided vehicles, etc.) located on industrial floors (such as concrete floors used in industrial and commercial environments) are used to manufacture and produce components, goods, parts, etc., in workshops, factories, etc. For example, these machines may correspond to robots that weld and assemble components. In another example, CNC machines cut metal parts to precise specifications. In another example, engine machining stations are used to create cylinder blocks. Users (referred to as "security hackers") may attempt to gain unauthorized access to these machines located on industrial floors to steal sensitive data, cause damage, seize data as part of a ransomware attack, perform pranks, etc. For example, a security hacker may attempt to gain unauthorized access to a CNC machine tool to manipulate the machine programming, causing it to produce defective parts. If the machine operator does not promptly notice the problem, the defective parts will enter the market. In another example, a security hacker may attempt to gain unauthorized access to a computer numerically controlled (CNC) machine tool to gain a competitive advantage by stealing confidential proprietary information. Security hackers may use various methods to attempt to gain unauthorized access to machines located on the industrial floor, such as exploiting software vulnerabilities. Other methods include social engineering tactics such as phishing, phishing text messages, spear phishing, and ransomware. Furthermore, security hackers may use malicious code (malware) to gain unauthorized access to machines located on the industrial floor, including the information stored on these machines. Malware is software intentionally designed to gain unauthorized access to information or systems, such as machines located on the industrial floor. Examples of such malware include computer viruses, worms, Trojan horses, ransomware, spyware, and rogue software. Unfortunately, there is currently no effective means of notifying machine operators, such as visually, of attempts to gain unauthorized access to machines located on the industrial floor. These machine operators need to know which machines on the industrial floor are being attempted to be accessed without authorization, or have actually been accessed without authorization, so that the machine operators can take corrective measures to resolve the attempted or successful unauthorized access to the machines on the industrial floor.
[0170] Embodiments of the present disclosure improve upon this technique by capturing log files from a firewall that monitors traffic to and from machines located on an industrial floor of an industrial facility. The captured log files are then analyzed to identify behaviors used to access or attempt to access one or more machines located on the industrial floor of the industrial facility. As used herein, "behavior" refers to actions performed by, for example, a security hacker, when accessing or attempting to access a machine located on the industrial floor of the industrial facility. Furthermore, a knowledge base for unauthorized access policies is analyzed. As used herein, "knowledge base" refers to a collection of data containing information about unauthorized access policies previously used by, for example, security hackers to gain unauthorized access to machines located on the industrial floor of the industrial facility. If the identified behavior matches an unauthorized access policy learned from the knowledge base within a threshold level of similarity, an augmented reality visualization can be created to depict the unauthorized access policy being enforced on the machines located on the industrial floor of the industrial facility. In this way, machine operators can now be effectively informed, such as through augmented reality visualization, of attempts to gain unauthorized access to machines located on an industrial floor. Consequently, machine operators will now understand which machines on the industrial floor are being attempted to access without authorization, or have actually been accessed without authorization, thereby allowing them to take corrective measures to address the attempted or successful unauthorized access to the machines. Furthermore, this approach provides improvements in the field of technology related to unauthorized access.
[0171] The technical solutions provided by the present disclosure cannot be performed in the human mind or by a human using pen and paper. That is, the technical solutions provided by the present disclosure cannot be implemented in the human mind or by a human using pen and paper in any reasonable amount of time and with any reasonable expected accuracy without the use of a computer.
[0172] The description of various embodiments of the present disclosure has been presented for illustrative purposes and is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical application, or technical improvements over commercially available technologies, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein.
[0173] 100: Communication System 101: Industrial Facilities 102: Unauthorized access to the detector 103: Internet 104: Machine 105: Server 106: Internet of Things (IoT) Sensors 107: Database 108: Firewall 109: Knowledge Base / Knowledge Corpus 110: Augmented Reality (AR) Smart Glasses 111: User 201:Analysis Engine 202: Similarity Engine 203:Visualization Engine 204: Correction Engine 205: Feedback Engine 300: Computing Environment 301: Block 302: End User Device (EUD) 303: Remote Server 304: Public Cloud 305:Private Cloud 306: Processor Collection 307: Processing circuit system 308: Cache memory 309: Communication Mesh Architecture 310: Volatile memory 311: Permanent Storage 312: Operating System 313: Peripheral device collection 314: User Interface (UI) Device Collection 315: Storage 316: Internet of Things (IoT) sensor collection 317: Network Module 318: Remote Database 319: Gateway 320: Cloud Orchestration Module 321:Host entity machine collection 322: Virtual Machine Collection 323:Container Collection 400:Method 401: Operation 402: Operation 403: Operation 404: Operation 405: Operation 406: Operation 500:Method 501: Operation 502: Operation 503: Operation 504: Operation 600:Method 601: Operation 602: Operation
Claims
1. A method for visualizing unauthorized access or attempted unauthorized access by a computer to machines located on an industrial floor, the method comprising: retrieving log files from a firewall that monitors traffic to and from the machines located on the industrial floor; analyzing the log files from the firewall to identify an action for accessing or attempting to access one or more of the machines located on the industrial floor; analyzing a knowledge base for unauthorized access policies; analyzing log files from the one or more machines located on the industrial floor to identify operational parameters; and creating an augmented reality visualization to plot an unauthorized access policy executed on the one or more machines located on the industrial floor based on the analysis of the knowledge base, in response to the identified action being associated with the unauthorized access policy within a contiguous similarity level, wherein the augmented reality visualization plots the unauthorized access policy using the identified operational parameters, and wherein the augmented reality visualization includes a visualization of the identified operational parameters.
2. The method of claim 1, further comprising: creating one or more avatars of a security hacker and / or a detected malicious code; and using the created one or more avatars in the augmented reality visualization to depict the unauthorized access policy executed on the one or more machines located on the industrial floor.
3. The method of claim 2, further comprising: identifying a corrective measure for using the knowledge base to address one or more unauthorized access policies implemented on the one or more machines located on the industrial floor; and plotting the identified corrective measure for addressing the unauthorized access policies implemented on the one or more machines in the augmented reality visualization.
4. The method of request item 1, further comprising: receiving feedback on the augmented reality visualization; and updating the knowledge base against unauthorized access policies based on the feedback.
5. The method of claim 1, wherein the augmented reality visualization is displayed on augmented reality smart glasses.
6. A computer program product for visualizing unauthorized access to or attempted unauthorized access to machines located on an industrial floor, the computer program product comprising one or more computer-readable storage media having program code embodied therewith, the program code containing programmed instructions for performing the following operations: retrieving log files from a firewall that monitors traffic to and from the machines located on the industrial floor; analyzing the log files from the firewall to identify an action for accessing or attempting to access one or more of the machines located on the industrial floor; and analyzing a knowledge base for unauthorized access policies. Analyze log files from one or more machines located on the industrial floor to identify operating parameters; and create an augmented reality visualization to plot an unauthorized access policy executed on one or more machines located on the industrial floor based on the analysis of the knowledge base, in response to the identified behavior being associated with the unauthorized access policy within a certain degree of contiguous similarity, wherein the augmented reality visualization plots the unauthorized access policy using the identified operating parameters, and wherein the augmented reality visualization includes a visualization of the identified operating parameters.
7. The computer program product of claim 6, wherein the program code further includes programmatic instructions for performing the following operations: creating one or more avatars of a security hacker and / or a detected malicious program code; and using the created one or more avatars in the augmented reality visualization to depict the unauthorized access policy executed on the one or more machines located on the industrial floor.
8. The computer program product of claim 7, wherein the program code further includes programmable instructions for performing the following operations: identifying corrective measures for using the knowledge base to resolve one or more unauthorized access policies implemented on the one or more machines located on the industrial floor; and plotting the identified corrective measures for resolving the unauthorized access policies implemented on the one or more machines in the augmented reality visualization.
9. The computer program product of claim 6, wherein the program code further includes programmable instructions for performing the following operations: receiving feedback on the augmented reality visualization; and updating the knowledge base against unauthorized access policies based on the feedback.
10. The computer program product as claimed in claim 6, wherein the augmented reality visualization is displayed on augmented reality smart glasses.
11. A computer system comprising: a memory for storing a computer program for visualizing unauthorized access to or attempted unauthorized access to machines located on an industrial floor; and a processor connected to the memory, wherein the processor is configured to execute program instructions of the computer program, the program instructions including: retrieving log files from a firewall that monitors traffic to and from the machines located on the industrial floor; analyzing the log files from the firewall to identify an action for accessing or attempting to access one or more of the machines located on the industrial floor; and analyzing a knowledge base for unauthorized access policies. Analyze log files from one or more machines located on the industrial floor to identify operating parameters; and create an augmented reality visualization to plot an unauthorized access policy executed on one or more machines located on the industrial floor based on the analysis of the knowledge base, in response to the identified behavior being associated with the unauthorized access policy within a certain degree of contiguous similarity, wherein the augmented reality visualization plots the unauthorized access policy using the identified operating parameters, and wherein the augmented reality visualization includes a visualization of the identified operating parameters.
12. The system of claim 11, wherein the program instructions of the computer program further include: creating the augmented reality visualization to plot the unauthorized access policy executed on the one or more machines located on the industrial floor using the identified operating parameters.
13. The system of claim 11, wherein the program instructions of the computer program further include: creating one or more avatars of a security hacker and / or a detected malicious code; and using the created one or more avatars in the augmented reality visualization to depict the unauthorized access policy executed on the one or more machines located on the industrial floor.
14. The system of claim 13, wherein the program instructions of the computer program further include: identifying a corrective measure for using the knowledge base to address one or more unauthorized access policies implemented on the one or more machines located on the industrial floor; and plotting the identified corrective measure for addressing the unauthorized access policies implemented on the one or more machines in the augmented reality visualization.
15. The system of request 11, wherein the program instructions of the computer program further include: receiving feedback on the augmented reality visualization; and updating the knowledge base against unauthorized access policies based on the feedback.
Citation Information
Patent Citations
Dynamic monitoring and securing of factory processes, equipment and automated systems
TW202122946A
A system and method for providing one or more services using an augmented reality display
US20210322877A1
Detection of anomalies associated with fraudulent access to a service platform
US20220210172A1
Network security threat detection by user / user-entity behavioral analysis
US9516053B1