METHOD AND SYSTEM FOR CONDUCTING AN IT SECURITY TEST
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2023-02-13
- Publication Date
- 2026-05-21
AI Technical Summary
Existing IT security tests face reliability issues due to devices becoming unresponsive and failing to provide expected data feedback, which compromises the integrity of the testing process.
An IT security test method that combines data feedback analysis with optical and acoustic detection of device states, using cameras and microphones to infer device conditions, and employs actuators to manage device states, ensuring continued testing even in the absence of data feedback.
Enhances the reliability of IT security tests by providing additional information on device states, allowing for safer operation and potential recovery of unresponsive devices, thus maintaining the integrity of the testing process.
Description
[0001] The invention relates to a method and a system for performing an IT security test.
[0002] Procedures and systems for data collection in industrial environments are disclosed in US 2019 / 258805 A1 and US 2020 / 103894 A1. US 2019141074 discloses IT security tests.
[0003] It is common practice to subject devices to IT security testing using test platforms. Typically, the devices are connected to a test platform via a data connection to perform the IT security test. While the device usually remains accessible via the data connection, in certain cases it may become unresponsive and not react as expected. In these instances, the reliability of the IT security tests may be reduced.
[0004] It is therefore an object of the invention to provide a method for carrying out an IT security test, by means of which IT security tests of devices can be improved, and in particular made more reliable. Furthermore, it is an object of the invention to provide a system for carrying out an IT security test, by means of which the improved method for carrying out an IT security test can be implemented.
[0005] This object of the invention is achieved by a method for performing an IT security test with the features specified in claim 1, by a system for performing an IT security test with the features specified in claim 6, and by a manufacturing plant and / or maintenance plant and / or logistics plant with the features specified in claim 11. Preferred embodiments of the invention are specified in the dependent claims, the following description, and the drawing.
[0006] In the inventive method for performing an IT security test of a device using a data connection, in particular a network connection, the IT security test of the device is carried out, and during the execution of the IT security test, data feedback from the device is acquired via the data connection. Additionally, the device's state is optically and / or acoustically recorded, and the data feedback is evaluated taking the acquired device state into account. By means of the optical and / or acoustic recording of the device's state, additional information about the device's state is available beyond the data connection, so that in cases where data feedback is absent or occurs differently than expected, the device state can be used.By using the additional device status, it is possible to determine, even without data feedback, whether the device is still operational or whether it is in a malfunctioning state. If the device is in a malfunctioning state during the IT security test, this information can be included in the IT security test evaluation as an additional test result.
[0007] In the method according to the invention, detection is preferably performed optically and / or acoustically using at least one detection means, in particular using at least one camera and / or at least one microphone. Particularly preferably, one or more user interfaces of the device are detected by the detection means. Thus, the device's state can be easily inferred from the detection of the device's user interfaces. Preferably, in the method according to the invention, a graphical user interface or acoustic signals for users can be detected. For example, messages, in particular warning signals, alerts, or alarms, can be displayed via graphical user interfaces and can be easily detected by the detection means. Acoustic warning signals or alerts, such as alarm tones, especially alarm buzzers, can also be easily detected.Such graphic or acoustic warning signals allow a reliable conclusion to be drawn about an unintended device condition.
[0008] In the method according to the invention, the data feedback comprises feedback data and / or information on whether feedback data is received or whether no feedback data or less feedback data is received than expected. Thus, data feedback can, on the one hand, include feedback data from the device that the device outputs in response to input data forming test data. On the other hand, data feedback can also mean the absence of feedback data, particularly in situations where feedback data is expected. Even in such situations, the absence of feedback data can constitute feedback information from the device.
[0009] In the method according to the invention, the detected device state is preferably used to derive safety information from the data feedback as a function of the device state. Safety information can be obtained much more reliably from the combination of the device state with the data feedback than from the data feedback alone. In particular, a device state can be related to a simultaneous or preceding data feedback, thus taking into account any influence or correlation between the data feedback and the device state.
[0010] In the method according to the invention, the detected device state is advantageously used to operate the device depending on its state, in particular to reset the device. If a faulty device state is inferred from the detected device state, the device can be reset using this further development of the method according to the invention. Advantageously, an actuator is used for this purpose, which initiates a reset process, in particular by operating a reset button or by using a reset field on a touchscreen, or by interrupting an electrical supply or by causing an electrical short circuit.
[0011] Preferably, in a preferred embodiment of the inventive method, the detected device state is used to put the device into a safe operating mode and / or to subject it to a software update and / or to take it out of service and / or to switch it off or put it into a sleep state.
[0012] In the method according to the invention, the device state is suitably detected by acquiring an acoustic signal from the device, in particular an alarm signal, and / or an optical signal from the device, in particular a display. Advantageously, optical and / or acoustic signals can be used to detect the device state in an easily classifiable manner and correlated with a device state.
[0013] Particularly preferably, the device state forms or comprises a fault state of the device, wherein the device state is detected by means of an error message, in particular an optical notification signal, preferably a notification window, and / or an acoustic signal, of the device and / or an operating system of the device and / or software of the device.
[0014] The system according to the invention for performing an IT security test of a device for carrying out a method as described above has a communication interface for a data connection with the device and has a test device for carrying out the IT security test, which is configured to acquire data feedback from the device and has at least one acquisition means for optical and / or acoustic acquisition of the device state and an evaluation device, which is configured to evaluate the data feedback taking into account the acquired device state. The system according to the invention is configured for carrying out a method according to the invention as described above and accordingly has the advantages already explained for the method according to the invention.
[0015] The system according to the invention is designed for performing an IT security test of a device with a graphical and / or optical and / or acoustic user interface, wherein the at least one detection means is designed for capturing the user interface. In particular, optical and / or acoustic user interfaces can be easily detected with detection means designed for optical or acoustic detection.
[0016] In the system according to the invention, the at least one detection means comprises at least one camera and / or at least one microphone.
[0017] The system according to the invention comprises at least one actuator configured for operating the device depending on the device state. Preferably, such an actuator is configured for operating a reset button or a reset field on a touchscreen.
[0018] The system according to the invention is designed to perform an IT security test of a device with at least one user interface, wherein the actuator is configured to operate the at least one user interface of the device.
[0019] The production plant and / or maintenance plant and / or logistics plant according to the invention comprises a system according to the invention as described above. Advantageously, the production plant and / or maintenance plant and / or logistics plant according to the invention also includes the device, which is preferably a control unit and / or a production device and / or a maintenance device and / or a logistics device, advantageously a production tool and / or production robot and / or a maintenance tool and / or a maintenance robot and / or a logistics tool and / or a logistics robot and / or a logistics vehicle.
[0020] Advantageously, the method according to the invention, or at least parts of the method according to the invention, are implemented by computer.
[0021] The invention is explained in more detail below with reference to an embodiment illustrated in the drawing. The single figure 1 shows a schematic flowchart of a method according to the invention for performing an IT security test of a device.
[0022] The in Fig. 1 The flowchart shown illustrates the process of an IT security test of a device DEV in the form of a manufacturing device, such as a programmable milling cutter, in a MAN manufacturing plant networked via an IoT network. Alternatively, the device could also be a logistics device, such as a mobile warehouse robot, in a logistics plant networked via an IoT network, or a maintenance device, such as a maintenance robot, in a maintenance plant networked via an IoT network.
[0023] The DEV device has a communication interface KOM for data connection, by means of which the DEV device can be programmed to be controlled.
[0024] The DEV device also has a user interface USE, which allows a user to identify an operating mode, for example a production mode in which the DEV device is controlled programmatically via the KOM communication interface for the production of a product, a maintenance mode in which a software update of the DEV device can take place, and a sleep state in which the device is not accessible via the KOM communication interface.
[0025] During an IT security test, the DEV device is fed a series of fuzzing input data by a test platform SIE via the KOM communication interface, and the data feedback from the DEV device is monitored. In safe, normal operation, the DEV device uses the KOM communication interface to issue acknowledgment data upon receipt of the input data and transmits documentation data about its operation at regular intervals. Therefore, in the normal state of the DEV device, the data feedback consists of this acknowledgment data and documentation data.
[0026] The SIE test platform receives and evaluates this data feedback. It then compares this feedback with the fuzzing input data transmitted to the device, and deviations from normal operation can be checked for IT security vulnerabilities using the SIE test platform.
[0027] However, if the fuzzing input data causes the DEV device to switch from normal operation to a faulty state, the DEV device, in the illustrated embodiment, ceases its data feedback. Consequently, no further feedback data is received from the SIE test platform via the KOM communication interface. The data feedback is thus characterized by a lack of feedback data.
[0028] However, the SIE test platform not only has a communication interface KOM, but also recording equipment in the form of a video camera VID and a microphone MIK.
[0029] The user interface (USE) of the device DEV is filmed using the video camera VID. When the device DEV stops transmitting data, the image of the user interface captured by the video camera VID is evaluated. The user interface may have a display showing an error message in the form of a notification window from the device DEV's operating system. The video camera VID transmits the image of the display with the notification window to the test platform SIE via a video signal connection VIDSIG.
[0030] A classification system, CLASS, on the SIE test platform is trained to evaluate and classify the display images containing the notification window. The notification window might contain an error message indicating a device DEV error state, such as "Device is not responding. Continued operation requires a restart." The CLASS classification system is trained to recognize these notification windows and capture their text content. To accomplish this, the classification system uses a neural network that has undergone appropriate training in a standard, well-known manner.
[0031] The classification device CLASS now transmits the image signals classified on the basis of the captured text content, i.e. a class assigned to the captured image signals, to a status determination device DET, which assigns the captured text content of the notification windows to a device state of the device DEV.
[0032] Analogous to the video camera's images, the microphone MIK records audio signals from the user interface USE of the device DEV. The user interface USE of the device DEV emits a warning tone when the device DEV stops providing data feedback. The microphone MIK also transmits this audio signal to the test platform SIE via the video signal connection VIDSIG. The classification unit CLASS additionally classifies the audio signals and transmits the classification of the audio signal—that is, a class assigned to the captured audio signals—to the state detection unit DET. The state detection unit DET maintains an assignment rule in internal memory that assigns the classified audio and video signals—i.e., the classes of the audio and video signals—to an internal device state of the device DEV. The data feedback and the fuzzing input data are analyzed based on the assigned device state.For example, the SIE test platform can be used to deduce, in a known manner, which fuzzing input data leads to the device state determined by the DET condition monitoring device, and which data feedback typically precedes such a device state with no feedback data. These test results (RES), which are deduced using the SIE test platform, are transmitted to a results database (DB), which stores and documents the test results (RES).
[0033] Additionally, the device state determined in this way is used to continue the test. For example, the fuzzing input data that led to the faulty device state can be modified so that such a faulty device state can be avoided in subsequent test runs. In further embodiments, the fuzzing input data can also be varied in such a way that it is possible to abstract which type of fuzzing input data leads to a faulty device state.
[0034] Furthermore, in an embodiment not shown, the test platform SIE can be signal-connected to an actuator in the form of a robotic finger, which can press a reset button on the user interface USE of the device DEV. Alternatively, in other embodiments, the user interface can have a touchscreen, and the actuator can operate a reset field on the touchscreen. In further embodiments, the actuator can be a circuit breaker that interrupts a circuit of the device DEV and / or a short-circuiting element that causes a short circuit in the device DEV. Thus, in cases where a faulty device state occurs with a lack of feedback data, the test platform SIE can transmit a reset signal to the robotic finger, which then presses the reset button of the user interface USE.This allows the DEV device to be restarted and the IT security test to be continued with the SIE test platform.
Claims
1. Method for carrying out an IT security test on a device (DEV) by means of a data connection (KOM), in particular a network connection, in which - the IT security test on the device (DEV) is carried out, - a data feedback of the device is acquired by means of the data connection (KOM) as the IT security test is carried out, - a device status of the device (DEV) is additionally optically and / or acoustically acquired, - the data feedback is evaluated in consideration of the acquired device status, and in which the acquisition is performed optically and / or acoustically by means of at least one acquisition means (MIK, VID) and the device status forms or comprises an error status of the device, the device status being acquired on the basis of an error message, an optical notification signal and / or an acoustic signal, of the device and / or an operating system of the device and / or software of the device, the acquired device status being used to operate the device (DEV) according to the device status, and in which the acquired device status is used to put the device (DEV) into a safe operating mode and / or to subject it to a software update and / or to take it out of operation and / or to switch it off or to put it into an idle state.
2. Method according to the preceding claim, in which the acquisition means (MIK, VID) forms at least one camera (VID) and / or at least one microphone (MIK) and / or the optical notification signal is a notification window.
3. Method according to either of the preceding claims, in which the data feedback comprises feedback data and / or the information regarding whether feedback data are received or whether no or fewer feedback data than expected are received.
4. Method according to the preceding claim, in which the acquired device status is used to derive safety information from the data feedback according to the device status.
5. Method according to one of the preceding claims, in which the device status is acquired by acquiring an acoustic signal of the device (DEV), in particular an alarm signal of the device (DEV), and / or an optical signal of the device (DEV), in particular a display on the device (DEV).
6. System for carrying out an IT security test on a device (DEV) for carrying out a method according to one of the preceding claims, having a communication interface (KOM) for a data connection to the device (DE), having a test unit for carrying out the IT security test, which is designed to acquire a data feedback of the device (DE), having at least one acquisition means (MIK, VID) for the optical and / or acoustic acquisition of the device status, having an evaluation unit (DET), which is designed to evaluate the data feedback in consideration of the acquired device status.
7. System according to the preceding claim, which is designed to carry out an IT security test on a device (DE) having a graphical and / or acoustic user interface, the at least one acquisition means being designed to acquire the user interface.
8. System according to the preceding claim, in which the at least one acquisition means has at least one camera (VID) and / or at least one microphone (MIK).
9. System according to one of the preceding claims, having at least one actuator designed to operate the device (DE) according to the device status.
10. System according to one of the preceding claims, which is designed to carry out an IT security test on a device (DEV) having at least one user interface, the actuator being configured to operate the at least one user interface of the device (DEV).
11. Manufacturing facility and / or maintenance facility and / or logistics facility having a system according to one of the preceding claims.