Method for monitoring a control program of at least one functional unit of a machine installation, computer program product, computer-readable storage medium and electronic computing device

EP4555434A1Pending Publication Date: 2025-05-21SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023768149
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-30
Filing Date
2023-08-22
Publication Date
2025-05-21

AI Technical Summary

Technical Problem

Current methods for monitoring and updating control programs in machine systems require manual processing of changes, leading to inefficiencies and potential machine downtime, especially in production chains where vulnerabilities need to be assessed and addressed.

Method used

An automated method using an electronic computing device for categorizing and remediating vulnerabilities in control programs, employing machine learning algorithms to identify, categorize, and suggest corrective measures, such as patches, to prevent machine standstill and reduce manual effort.

Benefits of technology

This approach simplifies the monitoring and updating process, reduces downtime, and saves resources by automating vulnerability assessment and remediation, allowing for efficient handling of multiple vulnerabilities through intelligent patching and policy reuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a method for monitoring a control program (12) of at least one functional unit (14) of a machine installation (16) by means of an electronic computing device (10), comprising the steps of: - detecting a vulnerability (18) within the control program (12); (S1) - categorising the detected vulnerability (18) on the basis of vulnerabilities already analysed in the past; (S2.1, S2.2, S2.3) and - proposing a rectification measure for the vulnerability (18) depending on the categorisation. (S3) The invention also relates to a computer program product, a computer-readable storage medium and an electronic computing device (10).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Method for monitoring a control program of at least one functional unit of a machine system, computer program product, computer-readable storage medium and electronic computing device

[0003] The invention relates to a method for monitoring a control program of at least one functional unit of a machine system by means of an electronic computing device according to the applicable patent claim 1. Furthermore, the invention relates to a computer-readable storage medium, a computer program product and an electronic computing device.

[0004] It is already known that, for example, software or control programs or so-called firmware in machinery in production chains can have vulnerabilities. It is therefore important that the software or firmware can be updated. This involves installing a so-called patch or a new version of the software or firmware. The customer currently has the problem that they have to process each change individually. Vulnerabilities can be categorized as follows: For example, a vulnerability can be categorized as open or as resolved. It can also be determined whether the software or firmware is not affected by the vulnerability in question. Accordingly, the category of the vulnerability is currently assessed manually and assigned accordingly.

[0005] It is also known that information on vulnerabilities is provided in a structured manner so that it can be recorded and processed automatically. This is known under the term CVE (common vulnerabilities and exposures). A vulnerability is identified by a unique identifier, the affected hardware or software components are specified and the severity is assessed using a CVSS score (common vulnerabilities scoring system). Information on vulnerabilities is provided via corresponding CVE databases. A so-called SCAD (security content automation protocol) is used to define data formats in order to automate security management.

[0006] The object of the present invention is to provide a method, a computer program product, a computer-readable storage medium and an electronic computing device by means of which a control program can be monitored in a simplified manner.

[0007] This object is achieved by a method, a computer program product, a computer-readable storage medium, and an electronic computing device according to the independent patent claims. Advantageous embodiments are specified in the subclaims.

[0008] One aspect of the invention relates to a method for monitoring a control program of at least one functional unit of a machine system by means of an electronic computing device. A vulnerability is detected within the control program. The detected vulnerability is categorized based on vulnerabilities already analyzed in the past. A remedy for the vulnerability is proposed depending on the categorization.

[0009] In particular, the concept of the invention is based on the automated categorization or grouping of reported vulnerabilities and the measures derived from them in a specific environment. For this purpose, the vulnerability reports are analyzed to determine which actions are derived from them in the specific case. Within this analysis, for example, a vulnerability is assessed, whether it is open, has been resolved, or whether this control program is not affected by the vulnerability.

[0010] In the next step, for example, a program-supported automatic assignment of the vulnerability to one of the listed or named categories takes place, into which, for example, similar vulnerabilities have previously been categorized.

[0011] In particular, a search function for similar vulnerabilities and their handling can be suggested. This has the advantage of essentially eliminating manual effort for searching and handling and significantly increasing user-friendliness. By tailoring the search as specifically as possible, the search options can be meaningfully expanded and the customer or provider can be shown all suitable solutions, for example, finding and implementing the appropriate patch for their vulnerability.

[0012] It should be noted at this point that the term "patch" is to be understood broadly. It generally refers to an update of software and / or firmware or the control program. In particular, it can represent an update for industrial IoT (Internet of Things) devices or a control unit. It can also represent an update for a virtual automation function or a virtual control unit of the IoT devices.

[0013] In particular, the invention provides for a complete update and thus a standstill of the machine to be prevented by carrying out an appropriate rectification measure which does not bring the machine to a standstill. The machine itself has at least one functional unit, in particular a plurality of functional units. A functional unit can then in turn be assigned to a plurality of control programs. It is therefore the object of the invention to prevent a standstill of the machine on the basis of a simple check of the control programs and corresponding recommendations for action or rectification measures, whereby a longer outage can be prevented, particularly for example in series process plants, whereby massive effort and money can be saved.

[0014] According to an advantageous embodiment, the vulnerability is categorized into at least two, in particular at least three, categories. In particular, a first category designates the vulnerability as open, a second category designates the vulnerability as closed, and a third category designates the vulnerability as not relevant to the functional unit. This allows for a simple categorization that describes the vulnerabilities accordingly and suggests appropriate remediation measures, for example, in the case of only open vulnerabilities.

[0015] Furthermore, it can be provided that the categorization is carried out based on a vulnerability characteristic of the vulnerability. In particular, the similarity of the vulnerabilities is defined in such a way that a specific "policy" is established for the vulnerability characteristic. In this case, it can be provided, for example, that a type and / or a manufacturer of the affected functional unit and / or a location of the affected functional unit is described using the vulnerability characteristic.For example, the type and manufacturer of the affected component or functional unit, the location, in particular physical and / or topological, of the affected functional unit, the type of vulnerability, for example remote code execution, buffer overflow, deny of service, availability of an update or workaround, can be defined, whereby a corresponding search request can be started which, based on the specified parameters, goes through the previous vulnerability assessment, compares it and, based on the appropriate criteria, issues a grouping suggestion or categorization.

[0016] Furthermore, it may be provided that an update of the control program is proposed as a remedial measure. In particular, the categorization or grouping forms the basis for further action, for example, defining and implementing a suitable way to remedy this vulnerability using an appropriate patch. It may also turn out that the vulnerability has already been remedied or is assessed as non-critical or not affected. It is also possible that further countermeasures, such as disconnecting a subnetwork, blocking a port with a firewall, stopping a machine, shutting down an automation system, or the like, are taken.

[0017] Furthermore, it can be provided that within the categorization the vulnerability is compared with other vulnerabilities and if the vulnerability is similar to at least one other closed vulnerability, the remediation measure for the other vulnerability that has already been closed is proposed for the vulnerability. In other words, the systematics of the specific policy can also be supplemented by a comparison of the aforementioned action measures that could mean reuse in a similar case or vulnerability. For this purpose, for example, the electronic computing device is made available as a machine learning algorithm and is taught which actions were taken by a security administrator in response to a specific vulnerability report. These actions are recorded as a template or as an example.In the case of a similar vulnerability report, one or more templates can then be suggested automatically. The recommended action can specify what needs to be done and the boundary conditions of the technical system or the automation component under which these measures are to be implemented. A further advantageous embodiment provides for the detection of the vulnerability and / or the categorization of the vulnerability and / or the suggestion of remedial measures to be carried out using a machine learning algorithm in the electronic computing device. For example, the machine learning algorithm can be provided as artificial intelligence, for example in the form of a neural network. In particular, this will make it possible to detect, categorize and / or suggest remedial measures more quickly and easily in the future.Furthermore, it can also be provided that, for example, the repair itself is carried out automatically using the neural network.

[0018] Furthermore, it has proven advantageous to analyze the categorized vulnerability and consider it for the detection, categorization, and / or remediation of future vulnerabilities. This allows the electronic computing device to learn and, in the future, utilize uncategorized vulnerabilities to identify future vulnerabilities. This creates a learning system that can be easily verified.

[0019] It has also proven advantageous to check whether the effect of the fix for the vulnerability on another detected vulnerability is affected. For example, it may be intended that several functional units are affected by a vulnerability. This vulnerability can then be closed because, for example, a firewall setting was incorrect or the firewall setting was changed by blocking a port. Based on this measure, the corresponding policy, particularly as a parent program, can indicate that this type of change would also be suitable for the other vulnerability or for yet another vulnerability and could therefore be implemented there in the same way. In this way, several vulnerabilities can be fixed at the same time by changing a port or configuration. In addition, a so-called patch can fix several vulnerabilities and be applicable to several components.

[0020] Furthermore, it has proven advantageous if the electronic computing device is provided as a central electronic computing device external to the machine. For example, the electronic computing device can then be connected to a network in order to be able to provide appropriate patches. Furthermore, the electronic computing device can be coupled to a large number of machines, so that corresponding remediation measures on one machine can possibly also be relevant for another machine. In this way, a closed system can be created, whereby the checking of vulnerabilities can again advantageously be carried out on the basis of the electronic computing device.

[0021] According to a further advantageous embodiment, the corrective action is carried out automatically by means of the electronic computing device. In particular, it can be provided that the electronic computing device is provided with the suggestion for the corrective action, with the electronic computing device, in turn, automatically implementing the corrective action based on the suggestion. Alternatively, it can be provided that the suggestion is proposed, for example, to a user of the electronic computing device, who can then manually carry out the corresponding corrective action.

[0022] The proposed method is, in particular, a computer-implemented method. Therefore, a further aspect of the invention relates to a computer program product with program code means which, when the program code means are processed by the electronic computing device, cause an electronic computing device to carry out a method according to the preceding aspect. The computer program product can also be referred to as a computer program.

[0023] Furthermore, the invention also relates to a computer-readable storage medium containing the computer program product.

[0024] A further aspect of the invention relates to the electronic computing device for monitoring a control program of at least one functional unit of a machine system, wherein the electronic computing device is designed to carry out a method according to the preceding aspect. In particular, the method is carried out by means of the electronic computing device.

[0025] The electronic computing device comprises, for example, electronic components, such as processors, circuits, in particular integrated circuits, as well as other electronic components in order to be able to carry out corresponding process steps.

[0026] Advantageous embodiments of the method are to be regarded as advantageous embodiments of the computer program product, the computer-readable storage medium, and the electronic computing device. The electronic computing device, in particular, has physical features enabling the corresponding method steps to be carried out.

[0027] For use cases or application situations that may arise during the method and which are not explicitly described here, it may be provided that, in accordance with the method, an error message and / or a request to enter user feedback is issued and / or a standard setting and / or a predetermined initial state is set.

[0028] The invention will now be explained in more detail with reference to exemplary embodiments in the drawings. In this connection: Fig. 1 shows a schematic flow diagram according to an embodiment of the method; and

[0029] FIG. 2 is a schematic block diagram of an electronic computing device according to an embodiment.

[0030] In the figures, identical or functionally identical elements are provided with the same reference numerals.

[0031] FIG. 1 shows a schematic flow diagram according to one embodiment of the method. In particular, FIG. 1 shows a method for monitoring a control program 12 (FIG.

[0032] 2) at least one functional unit 14 (FIG. 2) of a machine system 16 (FIG. 2) by means of an electronic computing device 10 (FIG. 2).

[0033] In a first step S1, a vulnerability 18 (FIG. 2) is detected within the control program 12. In a second step S2.1, S2.2, S2.3, the detected vulnerability 18 is categorized based on previously analyzed vulnerabilities. In a third step S3, a remediation measure for the vulnerability 18 is then proposed based on the categorization.

[0034] In particular, FIG. 1 shows that the vulnerability 18 is categorized into at least two, in particular at least three, categories. In particular, a first category can designate the vulnerability 18 as open, which is represented here by step S2.1. Furthermore, a second category can designate the vulnerability 18 as closed, which is represented here by the second step S2.2. Furthermore, the vulnerability 18 can be designated as not relevant for the functional unit 14, which is represented here by the second step S2.3. The categorization can be carried out in particular on the basis of a vulnerability characteristic of the vulnerability 18. In particular, a type and / or a manufacturer of the affected functional unit 14 and / or a location of the affected functional unit 14 can be described by means of the vulnerability characteristic.As a corrective measure, for example, an update of the control program 12 may be suggested.

[0035] Furthermore, it can be provided that within the categorization the vulnerability 18 is compared with other vulnerabilities and if the vulnerability 18 is similar to at least one other closed vulnerability, the remedy measure of the already closed further vulnerability is proposed for the vulnerability 18.

[0036] Furthermore, it can be provided that the categorized vulnerability 18 is analyzed and taken into account for the detection and / or categorization and / or remediation of a future vulnerability. Furthermore, the impact of the remediation of the vulnerability 18 on other detected vulnerabilities can be examined.

[0037] FIG. 2 shows a schematic block diagram according to an embodiment of the electronic computing device 10. FIG. 2 shows in particular that in a block 20 an assignment of new vulnerabilities to the functional unit 14, for example the vulnerability 18, is carried out. In a block 22 the status or the category of the vulnerability 18 is assessed by a machine learning algorithm, in particular an artificial intelligence, for example as a neural network. It is then assessed whether the vulnerability 18 is open. If this is the case, the vulnerability 18 is closed by a user in block 24. In block 26 the machine learning algorithm then again suggests assigning this to similar components, in particular based on so-called tags. In block 28, on the basis of block 22 or block 24, it is decided that the vulnerability 18 is closed.In block 30, corresponding tags can then be added based on the same changes. In block 32, the tags can be added to components or functional units 14 based on the machine learning algorithm. If, for example, new components or functional units 14 are to be added, this is done in block 34. The corresponding tags can then be added to the new functional unit 14 in block 36.

[0038] In particular, FIG. 2 shows a sequence of what is known as a security / vulnerability use case, wherein in FIG. 2 this is proposed as being tool-based. The corresponding functional units 14 are imported, for example, in the Industrial Security Vulnerability Manager (IVM), which corresponds in particular to the tool for software identification, monitoring and update provision for security issues and is represented here by the electronic computing device 10. The prerequisite for this is that the corresponding tags are added; the information is provided automatically in order to increase user-friendliness. The tags are assigned statically, for example depending on the functional unit, part of the plant, IP network or configuration. All known information is used. A user can also add their own tags or attributes.These can be derived, for example, from the project planning of an automation system, for example by designating automation components, for example a machine or a machine type, an automation cell, an automation zone, a production line, a location, or these are assigned. It is also possible to take current operating data, for example a current operating mode of a machine, status data of the physical, technical system, into account. Furthermore, further tags can be assigned. For this purpose, a machine learning algorithm, in particular AI-based, can also be used as program support as additional assistance in order to increase the scope of the assignment. In addition to the criteria to be checked, the machine learning algorithm checks how similar cases were handled in the past, or it acts here to reduce effort.The tags or attributes are to be evaluated, clustered, and suggestions for improvement are presented. The prerequisite is that all vulnerabilities 18 of this type can be found and modified by the electronic computing device 10. Based on these changes, the machine learning algorithm learns and makes suggestions for further changes.

[0039] In this case, tags refer to properties of a component or a vulnerability 18 that can be assigned manually or automatically and are machine-readable. They can therefore be further processed and compared by a program or a machine learning algorithm, for example artificial intelligence. Examples include hardware / firmware / software version, IP address, network range, open ports, physical location, affiliation to a specific part of the system / production line, group within which vulnerabilities were treated the same way in the past, etc. A component or functional unit 14 can have any number of tags.

Claims

Patent claims 1. A method for monitoring a control program (12) of at least one functional unit (14) of a machine system (16) by means of an electronic computing device (10), comprising the steps of: - detecting a vulnerability (18) within the control program (12); (Sl) - Categorizing the detected vulnerability (18) based on vulnerabilities already analyzed in the past (S2.1, S2.2, S2.3) and - Proposals for a remediation measure for the vulnerability (18) depending on the categorization. (S3) 2. Method according to claim 1, characterized in that the weak point (18) is categorized into at least two, in particular into at least three, categories.

3. Method according to claim 2, characterized in that a first category designates the vulnerability (18) as open (S2.1), a second category designates the vulnerability (18) as closed (S2.2) and a third category designates the vulnerability (18) as not relevant for the functional unit (14) (S2.3).

4. Method according to one of the preceding claims, characterized in that the categorization is carried out on the basis of a vulnerability characteristic of the vulnerability (18).

5. The method according to claim 4, characterized in that a type and / or a manufacturer of the affected functional unit (14) and / or a location of the affected functional unit (14) is described by means of the vulnerability characteristic.

6. Method according to one of the preceding claims, characterized in that an update of the control program (12) is proposed as a remedial measure.

7. Method according to one of the preceding claims, characterized in that within the categorization the vulnerability (18) is compared with further vulnerabilities and if the vulnerability (18) is similar to at least one further closed vulnerability, the remedy measure of the already closed, further vulnerability is proposed for the vulnerability (18).

8. Method according to one of the preceding claims, characterized in that the detection of the vulnerability (18) and / or the categorization of the vulnerability (18) and / or the suggestion of the remedy measure is carried out by means of a machine learning algorithm of the electronic computing device (10).

9. Method according to one of the preceding claims, characterized in that the categorized vulnerability (18) is analyzed and taken into account for a detection and / or categorization and / or elimination of a future vulnerability.

10. Method according to one of the preceding claims, characterized in that an effect of the remedy for the vulnerability (18) on a further detected vulnerability is checked.

11. Method according to one of the preceding claims, characterized in that the electronic computing device (10) is provided as a machine-external, central electronic computing device (10).

12. Method according to one of the preceding claims, characterized in that the implementation of the remedial measure is carried out automatically by means of the electronic computing device (10).

13. Computer program product with program code means which cause an electronic computing device (10) to carry out a method according to one of claims 1 to 12 when the program code means are processed by the electronic computing device (10).

14. A computer-readable storage medium comprising at least one computer program product according to claim 13.

15. Electronic computing device (10) for monitoring a control program (12) of at least one functional unit (14) of a machine system (16), wherein the electronic computing device (10) is designed to carry out a method according to one of claims 1 to 12.