Detection of cyber threats in devices
An automated method for detecting cyber threats in digital machine components addresses the unreliability and incompleteness of existing systems by integrating diverse data sources and secure information exchange, achieving comprehensive and confidential threat detection.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- SYNAMIC TECHNOLOGIES UG (HAFTUNGSBESCHRÄNKT)
- Filing Date
- 2024-11-04
- Publication Date
- 2026-05-07
AI Technical Summary
Current methods for detecting cyber threats in digital machine components are unreliable, incomplete, and lack automation, particularly failing to consider hardware components and their vulnerabilities, and do not facilitate confidential information exchange among manufacturers.
A method for automated detection of cyber threats using an inventory database that integrates data from multiple sources, applies machine learning for data standardization, and employs a situational awareness database for secure information sharing among stakeholders.
Enables reliable, real-time, and collaborative detection of cyber threats across complex devices, ensuring confidentiality and completeness of threat assessment.
Smart Images

Figure 00000007_0000 
Figure 00000008_0000
Abstract
Description
Field of invention
[0001] The invention relates to the field of cybersecurity and improves the possibilities for preventing cyberattacks by detecting cyber threats before an attack or damage occurs. State of the art
[0002] The detection of cyber threats in digital machine components is currently not systematic. While machine-readable information on cyber threats is available, the data quality and completeness are insufficient for comprehensive processing. Inventory data is often scattered across various data sources and cannot be analyzed holistically.
[0003] Therefore, mapping a given inventory using known methods is unreliable and prone to errors, and is thus rarely practiced. In particular, identifying affected components poses significant challenges.
[0004] Procedures for the confidential exchange of information on product- and component-related cyber threats do not exist, particularly not in machine-readable form. Specifically, no procedures exist that allow this information to be linked to rules for its disclosure. Current technology only provides for publication in public vulnerability databases. This precludes sharing vulnerability information with directly affected partners before publication.
[0005] Existing solutions for detecting cyber threats are limited to identifying known software vulnerabilities. Hardware components are not considered. The attribution of the vulnerability to a specific device must be done manually. Furthermore, no automatic assessment of the vulnerabilities regarding their potential impact is possible. This is particularly true when the source of the cyber threat lies within a component of the device.
[0006] Currently, no reliable, sufficiently complete, and automated detection of cyber threats to a device is possible. Because cyber threat information is exchanged via public platforms, attackers have the opportunity to plan their attacks in this way. Task
[0007] The object of the invention is to identify cyber threats to complex devices. The method must be able to handle incomplete, inconsistent, and time-varying data.
[0008] It is therefore necessary to create a solution that considers the complex supply chains of devices holistically, and in particular takes into account that devices can contain a multitude of digital components. These components are often sourced from different manufacturers. The detection of cyber threats in this environment must be automated, reliable, and rapid.
[0009] This also requires a means for the confidential exchange of vulnerabilities between the various manufacturers. The invention restricts access to this information to the directly involved parties. Solution
[0010] Methods for the automatic detection of cyber threats to devices. Survey of the inventory of digital elements
[0011] The method enables device operators and manufacturers to automatically detect and assess cyber threats. A graphical representation of the method can be found in Fig. 1.
[0012] The first step involves recording the inventory of the machine's digital elements (referred to as components). Information is gathered from various sources (operator, manufacturer, third parties) and compiled. Data sources and inventory database
[0013] The following data sources, among others, can be used for compiling the inventory database: - Active component self-identification: Components actively contact a system and transmit their identity, for example via an electronic bus system or as telemetry. This periodic transmission allows for an up-to-date inventory at any given time. Active component self-identification is a machine function. - Passive component self-identification: Components provide an interface through which their identity can be queried, for example, via an electronic bus system. Alternatively, an agent on or off the machine can identify the components based on characteristic communication features. The querying of passive component self-identification can be automated. Periodic querying ensures an up-to-date inventory at all times. Passive component self-identification is a machine function. - Inventory at the time of production: As part of the production process, the identity of the integrated components is recorded and stored. This information is typically obtained from the ERP (Enterprise Resource Planning) systems of the machine manufacturer. - Inventory at the time of development: As part of the development process, the identity of the intended component is recorded and stored. This information is typically obtained from the machine manufacturer's design, planning, or development systems.
[0014] The described methods can be used individually or in any combination; at least one is required. The data obtained is evaluated and used according to its reliability, with the most reliable data source taking precedence. The collected data is transferred to a structured, common data format and stored. This data includes the hardware, software, and firmware of the component.
[0015] The data format includes at least the manufacturer, the product name, and the version. For components that themselves contain further subcomponents, the list of subcomponents can also be transmitted and stored. The same procedures are used to identify the subcomponents as for recording the component inventory. A component entry is also created in the inventory database for each subcomponent. The components are linked to their contained subcomponents in the database. This creates a tree-like representation of the contained hardware and software components.
[0016] Optionally, attributes can be included that describe the type of function of the component in the machine and how the component is important for the functional safety of the machine.
[0017] The collected inventory data is processed to standardize alternative product names and duplicate entries from different channels. Identical components recorded under different identities are grouped together. Machine learning methods are used for this grouping.
[0018] The inventory database is capable of receiving this information from various data sources. This includes the provision of inventory data by the machine operator, the manufacturer, or third parties (for example, from customer service).
[0019] The inventory data is stored and merged in the inventory database. Taxonomy
[0020] The collected inventory is mapped to external taxonomies for product identification and cyber threat identification. These taxonomies are then applied to the machine itself and its components and sub-components. This process establishes a mapping between the inventory entries and the product taxonomie entries. The procedure assigns a reliability score to the mapping, describing the strength of the assignment. Similarity metrics, such as the Hamming distance, are used to determine the reliability score.
[0021] The taxonomy includes, among other things, information about the manufacturer, product names and versions, as well as other unique keys that serve to identify the products.
[0022] For products for which no assignment with a sufficient reliability score can be generated, additional entries are created in a separate product taxonomy.
[0023] The references to the entries in the external product taxonomies are stored in the inventory database together with the reliability score. Structure of the location database
[0024] The cybersecurity situational picture is derived from cybersecurity information. It serves to identify cyber threats and vulnerabilities to the machine.
[0025] Cybersecurity information is obtained from third parties and stored in the information database. Different attributes are assigned to this cybersecurity information: - Type of information (for example, a vulnerability that enables an attack, a successfully executed attack, or an observed attack attempt) - Source of information - Date of information gathering and last update - Components affected or vulnerable by the weakness. - Severity of potential impacts, describing the technical effects on the affected component. The description of the potential impacts is carried out using a scoring procedure. - Textual description of the information - Rules for sharing information and permissible participants - Additional metadata
[0026] Cybersecurity information is gathered from various sources. These sources can be publicly accessible, such as vulnerability databases or warnings from CERTs and public authorities. Industry standards and taxonomies describing attack techniques, vulnerability types, countermeasures, and attackers are also incorporated into the situational awareness database, thus enabling the analysis of the information within its context.
[0027] Incoming information is stored in the situational awareness database. The system employs a mechanism that regularly queries the stored sources and incorporates new cybersecurity information into the database. This ensures a constantly up-to-date situational awareness picture.
[0028] Incoming information is stored as it is received and time-stamped. Information can be structured and follow a defined data format, or it can be unstructured as free text.
[0029] Sources can be private or confidential. Incoming information is marked with a characteristic that describes the rules for its disclosure. Different levels of restriction differentiate whether information is intended for confidential processing by the recipient, whether disclosure within the entire recipient organization is permitted, whether disclosure to any third party is allowed, or whether publication of the information is also permitted. In the case of restricted disclosure, it can be specified to which participants in the process disclosure is permitted. Different levels of restriction can be selected for different participants.
[0030] The components affected by the vulnerabilities or susceptible to attack are linked to the corresponding entries in the product taxonomy. Machine learning methods are used for this purpose. The mapping between the cybersecurity information and the product taxonomy entries is characterized by a reliability score. The reliability score is stored along with the mapping to the product taxonomy entries. For product references where a mapping with a sufficient reliability score cannot be generated, additional entries are created in a separate product taxonomy. Creation of the threat register
[0031] The identification of vulnerabilities and cyber threats to the machine is performed by a threat assessment algorithm that links the machine's inventory from the inventory database with the situational awareness database. The threat assessment algorithm identifies which cybersecurity information from the situational awareness database pertains to the machine and, based on this, creates a threat register for the machine. To do this, the threats to the machine's components and sub-components are identified, evaluated within the machine's context, and summarized. Only cybersecurity information from the situational awareness database is included where the rules for its distribution permit its application to the machine.
[0032] The cybersecurity information is described as cyber threats and, according to the rules for disclosure defined by the user, is included in the situational awareness database and marked accordingly.
[0033] Entries in the threat register are assessed with regard to the risk associated with a threat. The assessment takes into account the severity of the cyber threat as well as the attributes that describe the component's function.
[0034] Furthermore, a reliability score for the threat is determined based on the reliability scores of the inventory database and the location database.
[0035] The threat register creates a rule for each threat to be forwarded. Detected threats, along with this rule, are added to the situational awareness database. Purpose and Application
[0036] The described method has various application scenarios that can be mapped by building a multiple threat registers and inventory databases.
[0037] The described procedure for labeling cybersecurity information and threats with rules for sharing enables cross-organizational collaboration while ensuring confidentiality.
[0038] The end user always interacts with their own threat register and inventory database. For complex queries, access can be provided via the AI assistant. The confidentiality of information is ensured through the situational awareness database and the rules governing information sharing. The end user can define the sharing rules for information from their threat register. In this way, they can restrict access to the information to the necessary group of participants.
[0039] The solution enables the following application scenarios: - Scenario 1: Use by the machine operator (Operator 1). The machine operator can use the procedure to detect cyber threats to the machines they operate. To do this, they access the cybersecurity information from Manufacturer 1's threat register via the situational awareness database. By registering all machines, the procedure can be extended to multiple manufacturers, entire production processes, or production facilities. Scenario 2: Relationship between machine manufacturer (Manufacturer 1) and component supplier (Manufacturer 2). This method can be used by a machine manufacturer who maintains an inventory of the digital components of their machine. The digital elements of the machine are recorded. Manufacturer 1 then accesses the cybersecurity information from Manufacturer 2's threat register via the location database. Scenario 3: Operator-to-operator relationship. Where a machine is used to provide an outsourced service, the procedure enables the customer to detect cyber threats on the machine. The service provider stores the machine data in the inventory database for this purpose.
[0040] A graphical representation of the system's structure can be found in Fig. 1.
[0041] A graphical representation of the usage scenarios can be found in Fig. 2.
[0042] In all scenarios, information is exchanged via the shared situational awareness database. All information there is marked with the rules governing information sharing. The situational awareness database ensures that the connected systems only receive information for which a rule permits its release.
[0043] This system, networked via the situational database, enables all participants to reliably assess their threat level. Each participant has access to the information they are permitted to share, in accordance with the established rules. Solution advantages
[0044] The presented method enables the fully automated, real-time detection of cyber threats against devices. Furthermore, it allows manufacturers and operators to approach threat detection as a collaborative task. This improves the reliability and completeness of the detection. Glossary of Cybersecurity Information.
[0045] Cybersecurity information describes a) actual observed unlawful acts (“incidents” / cybersecurity incidents) as well as vulnerabilities in digital components of a device that enable unlawful acts. Cyber threat.
[0046] Cyber threats describe how cybersecurity information indicates that components or devices are at risk of a successful cyberattack. Digital component.
[0047] A digital component is a component that has the ability to run software or firmware. Hardware.
[0048] The physical components of a component, usually CPU and active digital components, RAM, storage, and interfaces. Firmware.
[0049] Firmware consists of programs required for the operation of the digital component, usually the operating system, driver software, and resource management. Software.
[0050] Programs that enable the digital component to perform its function within the device.
Claims
[1] System for checking a device for cyber threats, comprising: 1.
1. an inventory database 1.1.
1. wherein the inventory database records the device and its digital components (hardware, software, firmware); 1.1.
2. wherein at least the following information is stored for the device and its digital components: designation, manufacturer, version; 1.1.
3. where this information is obtained from at least one source; 1.
2. at least one taxonomy; 1.2.
1. wherein the taxonomy provides authoritative designations for devices and digital components; 1.2.
2. where a link is established between the entries in the inventory database and the entries in the taxonomy; 1.
3. a location database; 1.3.
1. wherein the situation database records cybersecurity information relating to devices and / or digital components; 1.3.
2. where this information is obtained from at least one source; 1.3.
3. where a link is established between the entries in the location database and the entries in the taxonomy; 1.
4. Means of detecting a cyber threat to the device; 1.4.
1. where the inventory database and the situation database are accessed to detect the cyber threat; 1.4.
2. where, in order to detect the cyber threat, the links between the inventory database and the location database to the taxonomy are also used; 1.4.
3. wherein the means are in place to search for matches in the device or its digital components in the inventory database and the location database; 1.
5. a threat register; 1.5.
1. wherein the identified cyber threats are recorded in the threat register; 1.5.
2. wherein a risk assessment is stored in the threat register for each detected cyber threat. [2] Method for checking a device for cyber threats using the system according to claim 1, comprising the following steps: 2.
1. Recording the device and its digital components in the inventory database; 2.
2. Linking the entries in the inventory database with the entries in the taxonomy, whereby inaccurate matches are described by a reliability score; 2.
3. Recording cybersecurity information relating to devices and / or digital components in the situational awareness database; 2.
4. Linking the entries in the location database with the entries in the taxonomy; 2.
5. where the entries recorded in the databases are continuously updated; 2.
6. Detection of cyber threats to the device; 2.6.
1. where, in order to detect cyber threats, links between the inventory database and the location database with the same entry in the taxonomy are searched; 2.
7. Storing detected cyber threats in the threat register; 2.
8. Determine a risk assessment for each identified cyber threat; 2.8.
1. Saving the risk assessment in the threat register. [3] Method according to the immediately preceding claim, characterized by , - that the situational awareness database stores rules regarding permission to disclose each piece of cybersecurity information; and - that when detecting cyber threats, the device only considers entries from the location database for which permission to disclose the data has been given. [4] Method according to one of the two immediately preceding claims, characterized by , - that a detected cyber threat is included in the situational awareness database as new cybersecurity information. [5] Means of individual risk assessment of a cyber threat to a device and / or a digital component, characterized by , - that information from the inventory and the location database is combined for the risk assessment.