Method and system of prediction of vulnerability attacks on automation system
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2024-07-26
- Publication Date
- 2026-04-29
Smart Images

Figure EP2024071237_06022025_PF_FP_ABST
Abstract
Description
[0001] METHOD AND SYSTEM OF PREDICTION OF VULNERABILITY ATTACKS ON
[0002] AUTOMATION SYSTEM
[0003] Description
[0004] The present invention relates to a f ield of cybersecurity, and more particularly relates to a method and system for predicting a vulnerability attack on an automation system .
[0005] An automation system such as an industrial control systems ( ICS ) and a supervisory control and data acquisition ( SCADA) systems , is conf igured to manage and control a plurality of industrial processes . However , the automation system is sus ceptible to a plurality of vulnerability attacks by malicious persons such as computer hackers . The plurality of vulnerability attacks can disrupt operations , and compromise sensi tive data stored in the automation system . The plurality of vulnerability attacks pose signif icant risks to safety, security, and productivity of the automation system .
[0006] The automation system may be connected the Internet . Thus , conventionally, the automation system may be exposed to a large variety of threats of the plurality of vulnerability attacks . Traditional security measures such as f irewalls , intrusion detection systems ( IDS ) , and antivirus software alone are often insuf f icient to defend against sophisticated and evolving vulnerability attack threats .
[0007] Conventionally, the plurality of vulnerability attacks are neutralized by one or more reactive measures , such as patching one or more vulnerabilities , implementing security controls , and responding to incidents after the plurality of vulnerability attacks occur . Thus , traditional approaches lack a capability of anticipating and preventing the plurali ty of vulnerability attacks before a plurality of vulnerabil ities of the automation systems are exploited . Predictive techniques in the context of the plurality of vulnerability attacks on the automation systems are relatively underdevel oped, leaving critical infrastructures exposed to the risk of zero-day exploits and emerging attack vectors .
[0008] In light of above , there exists a need for an ef f icient method and system for predicting vulnerability attacks on an automation system .
[0009] The obj ect of the invention is achieved by an ef f icient method for predicting vulnerability attacks on an automation sys tem . Advantageously, the proposed method for predicting vul nerability attacks on an automation system of fers a proactive and preventive approach to system security . The proposed method utilizes historical system data , real - time monitoring , and threat intelligence feeds to generate predictive models capable of identifying emerging attack patterns and indicators of compromise .
[0010] The method presents several key advantages over existing solutions . Firstly, it enables organizations to shift from a reactive security posture to a proactive posture by antici pating vulnerabilities and potential attacks . Secondly, it enhances the overall resilience of automation systems by identifying weak points and enabling timely remediation actions . Thirdly, the method reduces the likelihood of success ful attacks , minimizing the associated f inancial losses , operational disruptions , and reputational damages . Lastly, by facilitating early detection, the proposed method allows security teams to prioritize and allocate resources ef fectively for incident response and recovery ef forts .
[0011] In conclusion, the proposed method for predicting vulnerabil ity attacks on an automation system represents a signif icant advancement in the f ield of automation system security . By providing industrial plants with a proactive defense mechanism, the proposed method empowers the industrial plants to stay ahead of cyber threats and safeguard critical infrastructures . The proposed method has an ability to predict at tacks and vulnerabilities before the vulnerabilities of the automation system can be exploited . Thus , the proposed method holds a potential to revolutionize a way in which automation systems are protected and secured .
[0012] The method of predicting the vulnerability attack is implemented on the automation system of an industrial plant . The industrial plant , also known as an industrial facility or industrial complex, is a physical location where a plurality of industrial operations and processes take place . In one example , the industrial plant refers to a facility or site where raw materials are transformed or processed into f inished goods or intermediate products through at least one of a manufacturing operation, a production operation, or an assembly operation .
[0013] The industrial plant can vary in size and complexity, ranging from small - scale facilities to large industrial complexes . The automation system in the industrial plant refers to a combination of hardware and software components designed to control and monitor industrial processes , machinery, and equipment inside the industrial plant . The automation system is a technology-driven system that aims to enhance operational ef f iciency, productivity, and safety in manufacturing and industrial environments . The vulnerability attack on the automation system of the industrial plant refers to an exploi tation of security weaknesses or vulnerabilities in a soft ware of the automation system . The vulnerabi lity attack aims to compromise an integrity, availability, or conf identiality of the automation system, potentially leading to operational disruptions , equipment damage , or unauthorized access to sensitive data .
[0014] In a preferred embodiment , the method comprises receiving , by a processing unit , a plurality of engineering data obj ects associated with the automation system . The method further comprises receiving by the processing unit , information associated with a plurality of past vulnerability attacks on the automation system . In one example , the plurality of engineering data obj ects and the information associated with the plurality of past vulnerability attacks are received from a server . In another example , the plurality of engineering data obj ects and the information associated with the plurality of past vulnerability attacks are received from a user via a us er input device such a document scanner , an optical character recognition device such as a mobile phone , or a computer keyboard .
[0015] The plurality of engineering data obj ects comprises information associated with a plurality of software components and a plurality of hardware components of the automation system . Examples of the plurality of software components comprises a plurality of code segments which when executed by the processing unit , controls at least one of a Supervisory Control and Data Acquisition system, a Programmable Logic Controller , a Human-Machine Interface , a Manufacturing Execution System, and distributed Control System in the industrial plant . The plurality of hardware components of the automation system comprises a plurality of Sensors , a plurlaity of Actuators , a plurality of Industrial Communication Networks , and a plural ity of Industrial PCs and Servers of the automation system . The plurality of software components further comprises clas ses , functions , loops , and conditional statements in the plurality of code segments . The information associated with the plurality of past vulner- ability attacks comprises information about one or more vul nerability attacks which have occured on the automation sys tem in the past . In one example , the plurality of past vul nerabilities attacks may have be detected by one or more security consultants in a course of one or more vulnerability snif f ing operations conducted by the one or more security consultants on the automation system . The security consultant may be a cyber security expert tasked with identifying one or more vulnerabilities in the automation system .
[0016] Each vulnerability attack of the plurality of past vulnerability attack is mounted on a weakness or f law in a design, an implementation, or a conf iguration of at least one of the plurality of software components and the plurality of hardware components of the automation system . In one example , each vulnerability attack of the plurality of past vulnerability attack is mounted on an erroneous code segment in the plurality of code segments of the plurality of software components . In otherwords , the plurality of past vulnerability attacks are mounted on one or more vulnerabilities of a plurality of vulnerabilities of the automation system . Each vul nerability of the plurality of vulnerabilites is weak- ness / f law in the automation system . The vulnerabi lity can be a potential entry point through which an attacker can compromise a security, an integrity, or an availability of the automation system . In one example , each vulnerability of the plurality of vulnerabilities is indicative of an erroneous hardware conf iguration in the plurality of hardware components . Each of the plurality of vulnerabilities is potential ly susceptible to a vulnerability attack by a hacker .
[0017] In one example , the plurality of vulnerabilities comprises programming errors , misconf igurations , design f laws , or a presence of insecure features in the plurality of software components or the plurality of hardware components. The plurality of vulnerabilities exist in various parts of the auto- mation system, including operating systems, applications, network devices, databases, or firmware.
[0018] Examples of information of the plurality of past vulnerability attack includes information associated with each vulnerability of the plurality of vulnerabilities. For example, information associated with each vulnerability includes a vulnerability ID, a Vulnerability Description, a list of Components affected by the vulnerability, a Vulnerability Type, a Severity of the vulnerability, an Exploitability of the vulnerability, a Mitigation Measures deployed to nullify the vulnerability, and a Date at which the vulnerability was exploited. The vulnerability ID is a unique identifier assigned to a specific vulnerability, often using a naming convention like Common Vulnerabilities and Exposures ID. The vulnerability description is a detailed explanation of the vulnerability, including a nature, an impact, and one or more potential risks of the specific vulnerability.
[0019] The list of components affected by the vulnerability comprises one or more software components and one or more hardware components of the plurality of software components and of the plurality of hardware component, which were affected by a vulnerability attack mounted on the vulnerability. The vulnerability type of the vulnerability is a categorization of the vulnerability based on one or more characteristics of the vulnerability. For example, the vulnerability type could be a buffer overflow type vulnerability, an SQL injection vulnerability, a cross-site scripting (XSS) vulnerability, or a privilege escalation vulnerability. The severity of the vulnerability is an assessment of the severity or criticality of the vulnerability. The severity is represented using scoring systems like CVSS (Common Vulnerability Scoring System) with ratings such as low, medium, high, or critical . The exploitability of the vulnerability comprises information on whether known exploits or attack vectors are available for the vul nerability .
[0020] The mitigation measures of the vulnerability comprises recommendations or guidelines provided by a security consultant on how to mitigate or address the vulnerability . Examples of the mitigation measures may include patches , software updates , conf iguration changes , or workarounds . The dates of the vul nerability comprises timestamps indicating when the vulnerability is discovered, disclosed, or patched by the one or more security consultants . The information of the plurality of past vulnerability attacks further comprises a business impact and an ef fect of each of the plurality of past vulnerability attacks . In one example , information about the plurality of past vulnerability attacks is received by the processing unit in the form of text f iles which comprise information associated the plurality of vulnerabilities .
[0021] In one example , the plurality of engineering data obj ects comprises one or more textual documents which comprise information associated the plurality of software components and the plurality of hardware components . Examples of the plural ity of engineering data obj ects comprises one or more textual documents comprising a technical documentation, a sourcecode , a manual , and a specif ication of the automation system from the industrial plant . Such textual documents comprises information about the plurality of software components and the plurality of hardware components , and one or more functional ities of the plurality of software components and the plural ity of hardware components . Such textual documents further comprise information of a manner of connection and communication of the plurality of software components and the plurali ty of hardware components with each other . Advantageously, the one or more security consultants is saved from a task of manually reading through the plurality of engineering data obj ects , thus saving labour and time .
[0022] In other words , the plurality of engineering data obj ects comprise information associated with the plurality of soft ware components and the plurality of hardware components of the automation system . In another example , the plurality of engineering data obj ects comprises text f iles , binary f iles and images scans of physical technical documents . The plural ity of engineering data obj ects comprises information about the plurality of software components such as tags , User def ined datatypes (UDTs ) , blocks , libraries , and their interconnections with other sub systems like Human machine interfaces (HMI ) , OPC UA and other web servers and one or more connections of the plurality of software components to the plurality of hardware components . The plurality of engineering data obj ects further comprises information about behavior of the plurality of software components and the plurality of hardware components at a normal operation of the automation system . The normal operation of the automation system is indicative of a state of operation of the automation system when no vulnerabilities are present in the automation system .
[0023] The plurality of engineering data obj ects further comprises details about instruction set used by the plurality of hardware components . The plurality of engineering data further comprises behavior of the plurality of hardware components such as a maximum, a minimum and an optimum scan cycle used by the plurality of hardware components to execute the plurality of software components . The plurality of engineering data obj ects comprises information about behavioral modality of trio namely the plurality of software components , the plurality of hardware components , and the plurality of connections between the plurality of software components and the plurality of hardware components . Advantageously, the behaviour of the plurality of software components and the plurali ty of software components are automatically analyzed by the processing unit . Thus , labour and ef fort required to manually analyze the plurality of engineering data obj ects is eradi cated .
[0024] In one example , information about the behavior of the plural ity of software components and the plurality of hardware components comprises information about a plurality of dependencies between a plurality of input parameters and a plurality of output parameters associated with the plurality of hardware components and the plurality of software components . The plurality of dependencies between the plurality of input parameters and the plurality of output parameters is indicative of a ratio between at least one input parameter of the plurality of input parameters to at least one output parameter of the plurality of output parameters .
[0025] The plurality of input parameters comprise data received by the plurality of software components and the plurality of hardware components under the normal operation of the automation systems . The plurality of output parameters comprise data output by the the plurality of software components and the plurality of hardware components under the normal operation of the automation systems .
[0026] In one example , the plurality of input parameters comprises information about a telemetry data , a user input , a sensor input , and a user conf iguration received by the plurality of software components and the plurality of hardware components . The plurality of input parameters further comprises information about a code segment executed by the plurality of software components and the plurality of hardware components . In another example , the plurality of output parameters com- prises information about a processing speed, a memory usage , an output signal , and a list of system errors generated by the plurality of software components and the plurality of hardware components .
[0027] In another example , the plurality of input parameter comprise information associated with a plurality of inputs received by the automation system . Examples of plurality of input parameters include information about a Network Traf f ic , a User Input , a System Call , a File Operation and an API Call received by the plurality of software components and the plurality of hardware components . In another example , the plurality of output parameters are indicative of a plurality of outputs of the automation system . Examples of plurality of output parameters include information about a Log File , a Network Connection, a Process Information, a File Integrity and an API Call associated with the plurality of software components and the plurality of hardware components .
[0028] The method further comprises analysing , by the processing unit , the plurality of engineering data obj ects and the information about the plurality of past vulnerability attacks by application of a natural language processing algorithm on the plurality of engineering data obj ects and the information on the plurality of past vulnerability attacks on the automation system . The natural language processing algorithm is a computational method or technique designed to process and analyze human language . The NLP algorithm is conf igured to enable computers to understand, interpret , and generate natural language text or speech . The NLP algorithm employ a plurality of techniques from linguistic rules to statistical models and machine learning . Examples of the natural language processing algorithm include but is not limited to a Stanford Parser al gorithm, a Spacy algorithm, a CoreNLP algorithm, an OpenNLP algorithm, a Gensim algorithm, a Hugging Face Transformers algorithm, and a Stanford Part-of -Speech Tagger (POS) algorithm .
[0029] The method further comprises generating, by the processing unit, a first set of tokens from the plurality of engineering data objects based on the analysis. Each token of the first set of tokens comprises information associated with a specific data object of the plurality of engineering data objects. The processing unit is configured to generate the first set of tokens by application of a tokenization algorithm on the analysed plurality of engineering data objects. The tokenization algorithm is a computational method which splits a text present in the plurality of engineering data objects, into individual words, phrases, or sentences, known as tokens. The tokenization algorithm comprises a plurality of rules and patterns to segment the text effectively. Examples of the tokenization algorithm comprises a Rule-based tokenization algorithm, a white space tokenization algorithm, a Regular expression tokenization algorithm, a Statistical tokenization algorithm, a Maximum entropy tokenization algorithms, and a Neural network-based tokenization algorithms.
[0030] The method further comprises applying, by the processing unit, a dependency parsing algorithm on the first set of tokens to analyze a syntactic structure of interdependencies between one or more tokens of the first set of tokens. In another example, the dependency parsing algorithm is applied on the text comprised within the plurality of engineering data objects. The dependency parsing algorithm is configured to identify a plurality of grammatical relationships between two or more tokens of the first set of tokens and the grammatical relationships are represented by the dependency parsing algorithm as a dependency tree. Thus, the processing unit is configured to generate a plurality of dependency trees. Each dependency tree of the plurality of dependency trees is repre- sentative of the plurality of grammatical relationships between two or more tokens of the f irst set of tokens . It is noted that each token of the f irst set of tokens is indicative of information about the plurality of software components and the plurality of hardware components . Thus , the plurality of grammatical relationships between the f irst set of tokens is indicative of the plurality of dependencies between two or more components in the plurality of software components and the plurality of hardware components . Since the plurality of engineering data obj ects comprise information about the plurality of input parameters and the plurality of output parameters , the plurality of grammatical relationships between the f irst set of tokens is further indicative of the plurality of dependencies between the plurality of input parameters and the plurality of output parameters .
[0031] The method further comprises extracting , by the processing unit , information associated with the plurality of software components and the plurality of hardware components of the automation system from the f irst set of tokens . In one example , the processing unit is conf igured to f ilter the f irst set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of the plurality of software components and the plurality of hardware components in the plurality of tokens .
[0032] The method further comprises analyzing , by the processing unit , the plurality of dependencies in the plurality of dependency trees and the identif ied mentions of the plurality of software components and the plurality of hardware components by application of a semantic role labelling algorithm on the f irst set of tokens . The semantic role labelling algorithm is conf igured to assign semantic roles to the identi f ied mentions of the plurality of hardware components and the plurality of software components based on the plurality of dependency trees . The semantic roles of each component of the plurality of hardware components and the plurality of soft ware components is indicative of a relationship of each component with other components of the plurality of hardware components and the plurality of software components . Examples of the semantic role labelling algorithms include , but is not limited to AllenNLP Algorithm or PropBank proj ect algorithm .
[0033] The method further comprises analyzing , by the processing unit , the plurality of grammatic relationships and the plurality of assigned semantic roles to determine a plurality of interconnections between tokens in the f irst set of tokens . The plurality of interconnections between tokens among the f irst set of tokens is indicative of a plurality of interdependencies between behaviour of the plurality of software components and the plurality of hardware components . For example , the plurality of interdependencies are indicative of the plurality of dependencies between the plurality of input parameters and the plural ity of output parameters associated with the plurality of software components and the plurality of hardware components .
[0034] For example , a dependency between an input parameter and an output parameter of at least one software component or hardware component in at least one dependency tree of the plural ity of dependency trees , is indicative of a interdependency between the software component and the hardware component . In other words , the method comprises generating , by the processing unit , a f irst map between the generated f irst set of tokens based on an analysis of the generated f irst set of tokens . The f irst map comprises the generated plurality of interconnections between two or more tokens of the f irst set of tokens . In one example , the f irst map is stored as a plurali ty of knowledge graph triples . The method further comprises generating , by the processing unit , a f irst knowledge graph to represent the determined plurality of interconnections between two or more tokens of the f irst set of tokens . In other words , the generated f irst knowledge graph comprises information about the plurality of interdependencies between the plurality of hardware components and the plurality of software components .
[0035] In one example , the generated f irst knowledge graph comprises a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with at least one of a specif ic hardware component or a specif ic software component of the plurality of software components and the plurality of hardware components . In one example , a plurality of graph database technologies or graph representation formats like such as SPARQL and Resource Description Framework is used to store data in and manage the generated f irst knowledge graph . The generated f irst knowledge graph is an engineering behaviour ontological schema . In other words , the method further comprises generating the engineering behavior ontological schema based on an analysis of the plural ity of engineering data obj ects and the information associat ed with the plurality of past vulnerability attacks .
[0036] In one example , the plurality of software components compris es a plurality of code segments in a PLC code and the information about the plurality of hardware components comprises information associated with a performance of the plurality of hardware components when each hardware component executes the plurality of code segments . In such a case , the engineering behaviour ontological schema is a knowledge graph representation comprising information associated with a plurality of interconnections and dependencies between a plurality of code segments in the PLC code , and a performance of the plurality of hardware obj ects associated with the plurality of code segments . In another example , the plurality of engineering data obj ects comprises information associated with the plurality of input parameters and the plurality of output parameters associated with each of the plurality of software components and the plurality of hardware components of the automation system . In such a case , the engineering behaviour ontological schema comprises information associated with the plurality of dependencies between the plurality of input parameters and the plurality of output parameters , when during a state of the automation system in which a vulnerability is not present in the automation system . Advantageously, the processing unit is conf igured to automatically generate the engineering behaviour ontological schema which comprises information about a behaviour of the plurality of hardware components and the plurality of software components under the normal operation of the automation system .
[0037] The method further comprises analyzing , by the processing unit , the plurality of engineering data obj ects and the information about the plurality of past vulnerability attacks by application of the NLP algorithm on the information associated with the plurality of past vulnerability attacks . The method further comprises generating , by the processing unit a second set of tokens from the information associated with the plurality of past vulnerability attacks based on analysis of information associated with the plurality of past vulnerabil ity attacks . Each token of the second set of tokens comprises information associated with a specif ic past vulnerability at tack of the plurality of past vulnerability attacks . The processing unit is conf igured to generate the second set of tokens by application of the tokenization algorithm on the analysed plurality of engineering data obj ects and the information associated with the plurality of past vulnerability attacks . The method further comprises applying , by the processing unit , a dependency parsing algorithm on the second set of tokens to analyze a syntactic structure of one or more tokens of the second set of tokens . The dependency parsing algorithm is conf igured to identify a plurality of grammatical relationships between two of more tokens of the second set of tokens and the grammatical relationships are represented by the dependency parsing algorithm as a dependency tree . Thus , the processing unit is conf igured to generate a plurality of dependency trees . Each dependency tree of the plurality of dependency trees is representative of the plurality of grammat ical relationships between two or more tokens of the second set of tokens . It is noted that each token of the second set of tokens is indicative of information about one or more past vulnerability attacks of the plurality of vulnerability at tacks .
[0038] The method further comprises extracting , by the processing unit , information associated with the plurality of past vul nerability attacks . In one example , the processing unit is conf igured to f ilter the second set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of each vulnerability attack of the plurality of past vulnerability attacks . In one example , the identif ied mentions of each vulnerability attack comprises the vulnerability ID of the vulnerability attack .
[0039] The method further comprises analyzing , by the processing unit , a plurality of dependencies in the plurality of dependency trees and the identif ied mentions of the plurality of past vulnerability attacks by application of a semantic role labelling algorithm . The semantic role labelling algorithm is conf igured to assign semantic roles to the identif ied mentions of the plurality of past vulnerability attacks based on the plurality of dependency trees . The semantic roles of each component of the plurality of past vulnerability attacks is indicative of an ef fect of plurality of past vulnerability attacks on the plurality of hardware components and the plurality of software components .
[0040] The method further comprises analyzing , by the processing unit , the plurality of grammatic relationships and the plurality of assigned semantic roles to determine a plurality of interconnections between two or more tokens in the f irst set of tokens and the second set of tokens . The plurality of interconnections between one or more tokens among the second set of tokens is indicative of a plurality of interdependencies between behaviour of the plurality of software components and the plurality of hardware components and the plurality of past vulnerability attacks . For example , the plurality of interdependencies are indicative of the plurality of interdependencies between the plurality of past vulnerability attacks with a behaviour of the plurality of software components and the plurality of hardware components . For example , the plurality of interdependencies are indicative of variations in the plurality of input parameters and the plurality of output parameters in the event of at least one vul nerability attack of the plurality of past vulnerability at tacks .
[0041] In another example , the plurality of interdependencies are indicative of a ratio between the plurality of input parameters and the plurality of output parameters in the event of at least one vulnerability attack of the plurality of past vulnerability attacks . In yet another example , the plurality of interdependencies comprises information about a plurality of anomalies in the plurality of input parameters and the plurality of output parameters during each of the plurality of past vulnerability attacks . The method further comprises generating , by the processing unit , a second knowledge graph to represent the determined plurality of interconnections between two or more tokens of the f irst set of tokens and the second set of tokens . It is noted that the second set of tokens comprises information about the plurality of past vulnerability attacks . In other words , the generated second knowledge graph comprises information about the plurality of interdependencies between the plurality of hardware components and the plurality of soft ware components during each of the plurality of past vulnerability attacks .
[0042] Furthermore , the generated second knowledge graph comprises information associated with the plurality of anomalies in values of the plurality of input parameters and the plurality of output parameters of the automation system . The second knowledge graph further comprises information associated with a mapping between the plurality of anomalies , the plurality of input parameters , and the plurality of output parameters . In other words , the method comprises generating , by the processing unit , a second map between the generated second set of tokens based on an analysis of the generated second set of tokens .
[0043] In one example , the second generated knowledge graph compris es a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with a specif ic vulnerability attack of the plurality of vul nerability attacks or a specif ic component of the plurality of software components and the plurality of hardware components . In one example , a plurality of graph database technol ogies or graph representation formats like such as SPARQL and Resource Description Framework is used to store data in and manage the generated knowledge graph . The generated second knowledge graph is a vulnerability ontological schema . In other words , the method further comprises generating the vul nerability ontological schema based an analysis of the plurality of engineering data ob- j ects and information associat ed with the plurality of past vulnerability attacks .
[0044] In one example , the vulnerability ontological schema compris es information associated with the plurality of anomalies as sociated with the plurality of past vulnerability attacks . Examples of the plurality of anomalies associated each of the plurality of past vulnerability attacks includes one or more anomalies in the plurality of input parameters and the plurality of output parameters of the automation system during each vulnerability attack of the plurality of past vulnerability attacks . An anomaly is indicative of a variation of the plurality of input parameters and the plurality of output parameters from one or more parameter values indicated by the engineering behaviour ontological schema . The vulnerability ontological schema comprises information about a plurality of dependencies between the plurality of anomalies and the plurality of past vulnerability attacks . Thus , each anomaly of the plurality of anomalies is mapped by the vulnerability ontological schema to a specif ic past vulnerability attacks of the plurality of past vulnerability attacks .
[0045] The method further comprises analyzing the second set of tokens , by the processing unit , to extract information associ ated with an ef fect of each vulnerability attack of the plurality of past vulnerability attacks on the automation sys tem . The method further comprises generating , a third knowledge graph comprising information associated with an ef fect of each vulnerability attack , of the plurality of past vulnerability attacks , on the plurality of software components and the plurality of hardware components . In one example , the third knowledge graph comprises information associ ated ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components and the plu- rality of software components .
[0046] In one example , the information associated with ef fect of each of the plurality of past vulnerability attacks comprises information associated with at least one of a stoppage , a slowness , a crash, a malfunction, a data theft , and a code replication, a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system caused by the vulnerability attack , a change in process of the automation system by the vulnerability attack , a change in processing power of the automation system which has occurred on the automation system as a result of each of the plurality of past vulnerability attacks . It is noted that , the ef fect of each of the plurality of past vulnerabil ity attacks is manually recorded by the security consultant during the one or more vulnerability snif f ing operations conducted by the security consultant on the automation system .
[0047] In one example , the third generated knowledge graph comprises a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with an ef fect of a specif ic vulnerability attack of the plurality of vulnerability attacks on a specif ic component of the plurality of software components and the plurality of hardware components . In one example , the third knowledge graph comprises information associated each of the plurality of past vulnerability attacks . The ef fect of the plurality of past vulnerability attacks include , but is not limited to a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system caused by the vulnerability attack , a change in process of the automation system by the vulnerability attack , a change in processing power of the automation system caused by the vulnerability attack . Advantageously, the processing unit is conf ig- ured to automatically generate the attack ef fect ontological schema which comprises information about an ef fect of each of the plurality of past vulnerability attacks .
[0048] The generated third knowledge graph is an attack ef fect ontological schema . In other words , the method further comprises generating , by the processing unit , the attack ef fect ontological schema . In one example , the attack ef fect ontological schema comprises information associated with an ef fect of each of the plurality of past vulnerability attacks on the plurality of software components and the plurality of hardware components . For example , information stored in the at tack ef fect ontological schema comprises but is not limited to a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system caused by the vulnerability attack , a change in process of the automation system by the vulnerability attack , a change in processing power of the automation system caused by the vulnerability attack . Furthermore , the attack ef fect ontological schema comprises information associated with a plurality of interdependencies between the ef fect of each vul nerability attack of the plurality of past vulnerability at tacks on the plurality of software components and the plural ity of hardware components . In other words , the attack ef fect ontological schema comprises information associated with the ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components and the plurality of software components .
[0049] The method further comprises receiving , by the processing unit , a set of input parameters and a f irst set of output parameters from the automation system . The set of input parameters comprises a plurality of inputs received by the plurali ty of software components and the plurality of hardware components . Examples of the set of input parameters include , but is not limited to a sensor input , a user input , a workf low detail , a plurality of scan cycle parameters associated with the plurality of software components and the plurality of hardware components . The f irst set of output parameters comprises information about memory usage of the plurality of software components and the plurality of hardware components . The f irst set of output parameters further comprises a data output , a processing power consumption data , and information about a processing speed of the plurality of software components and the plurality of hardware components .
[0050] The method further comprises applying , by the processing unit , the engineering behaviour ontological schema on the received set of input parameters and the f irst set of output parameters . In one example , to apply the engineering behavior ontological schema on the received set of input parameters and the received f irst set of output parameters , the processing unit is conf igured to query the engineering behavior ontological schema based on the received set of input parameters . It is noted that the engineering behaviour ontological schema comprises information associated with the plurality of dependencies between the plurality of input parameters and the plurality of output parameters of the automation system under a normal operation of the automation system . The normal operation of the automation system is a circumstance at which the automation system is not subj ect to an potential vulnerability attack by a malicious entity such as a hacker . Thus , by querying the engineering behaviour ontological schema , the processing unit is conf igured to generate a second set of output parameters based on the set of input parameters . The second set of output parameters are indicative of one or more output parameters which are generated by the automation sys tem, when the automation system processes the set of input parameters in a normal operation of the automation system . The normal operation of the automation system is indicative of an absence of any potential vulnerability attack on the automation system . Advantageously, the processing unit is enabled to compare the f irst set of output parameters with the second set of output parameters to detect one or more anomalies in the f irst set of output parameters and thereby detect an potential vulnerability attack on the automation system .
[0051] The processing unit is further conf igured to generate the second set of output parameters by querying the engineering behavior ontological schema using the received set of input parameters . The method further comprises comparing , by the processing unit , the f irst set of output parameters with the second set of output parameters . The processing unit is conf igured to compare the f irst set of output parameters and the second set of output parameters by application of a compari son algorithm on the f irst set of output parameters and the second set of output parameters . Examples of the comparison algorithm comprises , but is not limited to mean absolute error based algorithm, Root Mean Squared Error based algorithm, and a cosine similarity algorithm .
[0052] The method further comprises determining , by the processing unit , at least one anomaly in the f irst set of output parameters based on the comparison . The at least one anomaly is indicative of a dif ference between the f irst and the second set of output parameters . In other words , the determined at least one anomaly is indicative of a deviation of a behaviour of the automation system from a behaviour expressed in the engi neering behaviour ontological schema . Thus , the detected at least one anomaly is an indication of an potential vulnerability attack on the automation system .
[0053] The method further comprises comparing , by the processing unit , the determined at least one anomaly with the plurality of anomalies depicted in the vulnerability ontological sche- ma . It is noted that each anomaly of the plurality of anoma- lies is associated with a specif ic vulnerability attack of the plurality of past vulnerability attacks . Furthermore , each node of the plurality of nodes of the vulnerability ontology schema is representative of a specif ic vulnerability attack of the plurality of past vulnerability attacks . In one example , the determined at least one anomaly is compared with the plurality of anomalies by application of a similarity al gorithm on the determined at least one anomaly and the plurality of anomalies . Examples of the similarity algorithm includes a cosine similarity algorithm and a Jaccard similarity algorithm . The similarity algorithm is conf igured to determine a similarity of the at least one anomaly to a set of anomalies stored in the vulnerability ontology schema . In a case where the at least one anomaly is similar to the set of anomalies , the similarity algorithm is conf igured to match the at least one anomaly to the set of anomalies .
[0054] The method further comprises matching , by the processing unit , the determined at least one anomaly with at least one node of the plurality of nodes of the vulnerability ontology schema . The at least one node of the plurality of nodes comprises information associated with the set of anomalies which are similar to the determined at least one anomaly . Furthermore , the at least one node of the plurality of nodes comprises information associated with a set of past vulnerabil ity attacks which caused the set of anomalies in the past . The method further comprises detecting , by the processing unit , an potential vulnerability attack on the automation system based on the detected at least one node of the plural ity of nodes . In other words , the method further comprises detecting an potential vulnerability attack on the automation system based on the detected at least one anomaly in the automation system . The method further comprises comparing , by the processing unit , the detected at least one node of the vulnerability ontological schema with each node of the attack ef fect ontological schema based on an analysis of the detected potential vulnerability attack and the vulnerability ontological schema . In one example , the detected at least one node of the vulnerability ontological schema is compared with each node of the attack ef fect ontological schema by application of a similarity algorithm on the detected at least one node of the vulnerability ontological schema and each node of the attack ef fect ontological schema . Examples of the similarity algorithm includes a cosine similarity algorithm and a Jaccard similarity algorithm .
[0055] The method further comprises detecting at least one node of the attack ef fect ontology schema based on the comparison . The detected at least one node of the attack ef fect ontology schema is indicative of information associated with a list of ef fects caused by the determined set of past vulnerability attacks on the automation system in the past . In other words , the processing unit is conf igured to detect a list of ef fects caused by the determined set of past vulnerability attacks on the automation system . Since the detected potential vulnerability attack is similar to the determined set of past vul nerability attacks , the list of ef fect caused by the the determined set of past vulnerability attacks is indicative of a set of possible ef fects of the potential vulnerability at tack . The method further comprises determining the set of possible ef fects of the potential vulnerability attack based on an analysis of the at least one node of the attack ef fect ontology schema . In other words , the method further comprises detecting , by the processing unit ( 202 ) , a vulnerability at tack and a set of possible ef fects of the vulnerability at - tack based on the determined at least one anomaly . In one example , the information associated with the set of possible ef fects caused by the potential vulnerability attack comprises information associated with at least one of a stoppage , a slowness , a crash, a malfunction, a data theft , and a code replication, a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system which may be caused by the potential vulnerability attack , a change in process of the automation system by the potential vulnerability attack , a change in processing power of the automation system which has occurred on the automation system as a result of the potential vulnerability attack . Furthermore , the information associated with the set of possible ef fects of the potential vulnerability attack comprises a list of components of the plurality of software components and the plurality of hardware components af fected by each of the potential vulnerability attack . Advantageously, the processing unit is conf igured to generate a list of possible ef fects of the potential vulnerability at tack on the automation system . Thus , a security consultant is enabled to take appropriate steps to neutralize the ongoign vulnerability attack .
[0056] The method further comprises initiating , by the processing unit , a vulnerability snif f ing operation on the automation system based on the detection of the potential vulnerability attack and the detected set of possible ef fects of the potential vulnerability attack . The vulnerability snif f ing operation refers to a process of actively scanning the automation system to identify vulnerabilities or weaknesses that could potentially be exploited by malicious actors . Examples of the vulnerability snif f ing operation includes , but is not limited to Port Scanning based vulnerability snif f ing operation, Vul nerability Scanners based vulnerability snif f ing operation, Network Mapping based vulnerability snif f ing operation, and Web Application Scanning based vulnerability snif f ing opera- tion . The vulnerability snif f ing operation is executed to validate a presence of the potential vulnerability attack on the automation system .
[0057] The method further comprises validating , by the processing unit , the detected vulnerability attack based on a result of the vulnerability snif f ing operation . In one example , the result of the vulnerability snif f ing operation indicates a presence of a vulnerability in the automation system . In such a case , the detected potential vulnerability attack is vali dated by the processing unit . Advantageously, the processing unit initiates the vulnerability snif f ing operation based on the detection of the potential vulnerability attack on the automation system .
[0058] The method further comprises generating , by the processing unit , a user alert based on the validation of the detected potential vulnerability attack on the automation system . In one example , the user alert is at least one of a voice based, a image based or a text based user alert . The method further comprises outputting , by the processing unit , the generated user alert comprising information about the detected vulnerability attack and the detected set of possible ef fects of the detected potential vulnerability attack to a user . In one example , the generated user alert is output by the processing unit via an output device such as a computer monitor .
[0059] In one example , the generated user alert comprises information associated with the predicted potential vulnerability attack . For example , the information associated with the detected potential vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerabil ity Description, the list of Components af fected by the vul - nerability, the Vulnerability Type , the Severity of the vul nerability, the Exploitability of the vulnerability, the Mit igation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulberability attack of the plurality of past vulnerability attacks . In other words , the method further comprises outputting at least one mitigation measure deployed by the
[0060] In one example , the generated user alert comprises information associated with the detected vulnerability attack . For example , the information associated with the detected vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerability Description, the list of Components af fected by the vulnerability, the Vulnerability Type , the Severity of the vulnerability, the Exploitability of the vulnerability, the Mitigation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulnerability attack of the plurality of past vulnerability attacks .
[0061] The obj ect of the present invention is also achieved by an automation system conf igured to detect vulnerability attacks on the automation system . The automation system comprises a processing unit and a memory coupled to the processor . The memory comprises a vulnerability intelligence module stored in the form of machine- readable instructions executable by the processor . The vulnerability intelligence module is conf igured for performing the method as described above .
[0062] The obj ect of the present invention is also achieved by a computer-program product having machine- readable instructions stored therein, that when executed by one or more proces sor ( s ) , cause the one or more processor ( s ) to perform method steps as described above .
[0063] The above-mentioned and other features of the invention will now be addressed with reference to the accompanying drawings of the present invention . The illustrated embodiments are intended to illustrate , but not limit the invention .
[0064] The present invention is further described hereinafter with reference to illustrated embodiments shown in the accompanying drawings , in which :
[0065] FIG 1 is a block diagram of an industrial environment capable of predicting vulnerability attacks on an automation system, according to an embodiment of the present invention ;
[0066] FIG 2 is a block diagram of an automation system, such as those shown in FIG . 1 , in which an embodiment of the present invention can be implemented ;
[0067] FIG 3 is a block diagram of an vulnerability intelligence module , such as those shown in FIG 2 , in which an embodiment of the present invention can be implemented ;
[0068] FIG 4A- F is a process f lowchart illustrating an exemplary method of automatically predicting vulnerability attacks on the automation system, according to an embodiment of the present invention ; and
[0069] FIG 5 is a schematic representation of an exemplary pro- cess of predicting an potential vulnerability at- tack on an automation system, according to an em- bodiment of the present invention .
[0070] Various embodiments are described with reference to the drawings , wherein like reference numerals are used to refer the drawings , wherein like reference numerals are used to refer to like elements throughout . In the following description, for the purpose of explanation, numerous specif ic details are set forth in order to provide thorough understanding of one or more embodiments . It may be evident that such embodiments may be practiced without these specif ic details .
[0071] FIG 1 is a block diagram of an industrial environment 100 capable of automatic prediction of vulnerability attacks on an industrial plant 106 , according to an embodiment of the present invention . In FIG 1 , the industrial environment 100 includes an automation system 102 , and one or more client devices 120A-N . As used herein, "industrial environment" refers to a processing environment comprising conf igurable computing physical and logical resources , for example , networks , servers , storage , applications , services , etc . , and data distributed over a platform, such as cloud computing platform . The industrial environment 100 provides on-demand network access to a shared pool of the conf igurable computing physical and logical resources . The automation system 102 is communicatively connected to the industrial plant 106 via the network 104 ( such as Local Area Network (LAN) , Wide Area Network (WAN) , Wi - Fi , Internet , any short range or wide range communication) . Examples of the industrial plant 106 includes , a power plant , a manufacturing plant , and a water treatment plant . The automation system 102 is also connected to the one or more client devices 120A-N via the network 104 . The one or more client devices 120A-N may be a desktop computer , laptop computer , tablet , smart phone and the like . Each of the one or more client devices 120A-N is provided with a user interface 122A-N . For example , the one or more client devices 120A-N can access the engineering system 102 for inputting information about a plurality of past vulnerability attacks to the database 118 . The one or more client devices 120A-N can access cloud applications . Throughout the specif ication, the terms "client device" and "user device" are used interchangeably .
[0072] The automation system 102 may be a standalone server deployed at a control station or may be a remote server on a cloud computing platform . In a preferred embodiment , the automation system 102 may be a cloud-based automation system . The engi neering system 102 may comprise a platform 110 ( such as a cloud computing platform) , an vulnerability intelligence module 112 , a server 114 including hardware resources and an operating system (OS ) , a network interface 116 and the database 118 . The network interface 116 enables communication between the automation system 102 , the industrial plant 106 , and the one or more client device ( s ) 120A-N . The server 114 may include one or more servers on which the OS is installed . The servers 114 may comprise one or more processors , one or more storage devices , such as , memory units , for storing data and machine- readable instructions for example , applications and application programming interfaces (APIs ) , and other peripherals required for providing computing ( such as cloud computing) functionality . In one example , the server 114 stores a plurality of engineering data obj ects and information associ ated with a plurality of past vulnerability attacks on the automation system .
[0073] The platform 110 enables functionalities such as data reception, data processing , data rendering , data communication, etc . using the hardware resources and the OS of the servers 114 and delivers the aforementioned services using the appli cation programming interfaces deployed therein . The platform 110 may comprise a combination of dedicated hardware and software built on top of the hardware and the OS . The plat form 110 may further comprise a vulnerability intelligence module 112 conf igured for automatically detecting a vulnerability attack on the automation system 102 . Details of the vulnerability intelligence module 112 is explained in FIG . 3 .
[0074] The industrial plant 106 , also known as an industrial facili ty or industrial complex, is a physical location where a plurality of industrial operations and processes are executed . In one example , the industrial plant 106 refers to a facility or site where raw materials are transformed or processed into f inished goods or intermediate products through at least one of a manufacturing operation, a production operation, or an assembly operation .
[0075] The industrial plant 106 can vary in size and complexity, ranging from small - scale facilities to large industrial complexes . The automation system 102 of the industrial plant 106 refers to a combination of the plurality of hardware components 108A-N and the plurality of software components 109A-N designed to control and monitor industrial processes , machinery, and equipment inside the industrial plant . The automation system is a technology-driven system that aims to enhance operational ef f iciency, productivity, and safety in manufacturing and industrial environments . The vulnerability attack on the automation system 102 of the industrial plant 106 refers to an exploitation of security weaknesses or vul nerabilities in a software of the automation system 102 . The vulnerability attack aims to compromise an integrity, availability, or conf identiality of the automation system, potentially leading to operational disruptions , equipment damage , or unauthorized access to sensitive data . FIG . 1 further depicts a plurality of hardware components 108A-N and a plural ity of software components 109A-N of the industrial plant 106 .
[0076] Examples of the plurality of software components 109A-N comprises a plurality of code segments which when executed by a processing unit , controls at least one of a Supervisory Control and Data Acquisition system, a Programmable Logic Controller , a Human-Machine Interface , a Manufacturing Execution System, and distributed Control System . The plurality of hardware components 108A-N of the automation system comprises a plurality of Sensors , a plurlaity of Actuators , a network gate , a router device , a mobile phone , a plurality of Indus trial Communication Networks , and a plurality of Industrial PCs and Servers . The plurality of software components further comprises classes , functions , loops , and conditional statements in the plurality of code segments .
[0077] The database 118 stores the information relating to the technical installation and the one or more client device ( s ) 120A- N . The database 118 is , for example , a structured query language ( SQL) data store or a not only SQL (NoSQL) data store . In an exemplary embodiment , the database 118 may be conf igured as cloud-based database implemented in the industrial environment 100 , where computing resources are delivered as a service over the platform 110 . The database 118 , according to another embodiment of the present invention, is a location on a f ile system directly accessible by the vulnerability in- tellgence module 112 . The database 118 is conf igured to store the plurality of engineering data obj ects associated with the plurality of hardware components 108A-N, the plurality of software components 109A-N and the like . FIG 2 is a block diagram of an automation system 102, such as those shown in FIG 1, in which an embodiment of the present invention can be implemented. In FIG 2, the automation system 102 includes a processing unit 202, an accessible memory 204, a storage unit 206, a communication interface 208, an inputoutput unit 210, a network interface 212 and a bus 214.
[0078] The processing unit 202, as used herein, means any type of computational circuit, such as, but not limited to, a microprocessor unit, microcontroller, complex instruction set computing microprocessor unit, reduced instruction set computing microprocessor unit, very long instruction word microprocessor unit, explicitly parallel instruction computing microprocessor unit, graphics processing unit, digital signal processing unit, or any other type of processing circuit. The processing unit 202 may also include embedded controllers, such as generic or programmable logic devices or arrays, application specific integrated circuits, single-chip computers, and the like.
[0079] The memory 204 may be non- transitory volatile memory and nonvolatile memory. The memory 204 may be coupled for communication with the processing unit 202, such as being a computer- readable storage medium. The processing unit 202 may execute machine-readable instructions and / or source code stored in the memory 204. A variety of machine-readable instructions may be stored in and accessed from the memory 204. The memory 204 may include any suitable elements for storing data and machine-readable instructions, such as read only memory, random access memory, erasable programmable read only memory, electrically erasable programmable read only memory, a hard drive, a removable media drive for handling compact disks, digital video disks, diskettes, magnetic tape cartridges, memory cards, and the like. In the present embodiment, the memory 204 includes an integrated development environment ( IDE) 216 . The IDE 216 includes the remodeller module 112 stored in the form of machine- readable instructions on any of the above-mentioned storage media and may be in communication with and executed by the processor ( s ) 202 .
[0080] When executed by the processing unit 202 , the vulnerability intelligence module 112 causes the processing unit 202 to receive a plurality of engineering data obj ects associated with the automation system 102 . The vulnerability intelligence module 112 further causes the processing unit 202 to receive information associated with a plurality of past vulnerability attacks on the automation system 106 . In one example , the plurality of engineering data obj ects and the information as sociated with the plurality of past vulnerability attacks are received from the server 114 . In another example , the plural ity of engineering data obj ects and the information associat ed with the plurality of past vulnerability attacks are received from a user via a user input device such as the one or more client devices 120A-N .
[0081] The plurality of engineering data obj ects comprises information associated with the plurality of software components 109A-N and the plurality of hardware components 108A-N of the automation system 102 .
[0082] The information associated with the plurality of past vulnerability attacks comprises information about one or more vul nerability attacks on a plurality of vulnerabilities in the automation system . In one example , the plurality of vulnerabilities may be detected by one or more security consultants in a course of one or more vulnerability snif f ing operations conducted by the one or more security consultants on the automation system . The security consultant may be a cyber security expert tasked with identifying one or more vulnerabili ties in the automation system . Each vulnerability of the plurality of vulnerabilities is indicative of a weakness or f law in a design, an implementation, or a conf iguration of at least one of the plurality of software components and the plurality of hardware components of the automation system . In one example , each vulnerability of the plurality of vulnerabilities is indicative of an erroneous code segment in the plurality of code segments of the plurality of software components . In another example , each vulnerability of the plurality of vulnerabil ities is indicative of an erroneous hardware conf iguration in the plurality of hardware components . Each of the plurality of vulnerabili ties is potentially susceptible to a vulnerability attack by a hacker . Thus , a vulnerability is a potential entry point through which an attacker can compromise a security, an integrity, or an availability of the automation system .
[0083] In one example , the plurality of vulnerabilities comprises programming errors , misconf igurations , design f laws , or a presence of insecure features in the plurality of software components or the plurality of hardware components . The plurality of vulnerabilities exist in various parts of the automation system, including operating systems , applications , network devices , databases , or f irmware .
[0084] Examples of information of the plurality of past vulnerabil ity attack includes information associated with each vulnerability of the plurality of vulnerabilities . For example , information associated with each vulnerability includes a vul nerability ID , a Vulnerability Description, a list of Components af fected by the vulnerability, a Vulnerabil ity Type , a Severity of the vulnerability, an Exploitability of the vul nerability, a Mitigation Measure deployed to nullify the vul nerability, and a Date at which the vulnerability was exploited . The vulnerability ID is a unique identif ier assigned to a specif ic vulnerability, often using a naming convention like Common Vulnerabilities and Exposures ID . The vulnerabil ity description is a detailed explanation of the vulnerabil ity, including a nature , an impact , and one or more potential risks of the specif ic vulnerability .
[0085] The list of components af fected by the vulnerability compris es one or more software components and one or more hardware components of the plurality of software components and of the plurality of hardware component , which were af fected by a vulnerability attack mounted on the vulnerability . The vul nerability type of the vulnerability is a categorization of the vulnerability based on one or more characteristics of the vulnerability . For example , the vulnerability type could be a buf fer overf low type vulnerability, an SQL inj ection vulnerability, a cross - site scripting (XSS ) vulnerability, or a privilege escalation vulnerability . The severity of the vul nerability is an assessment of the severity or criticality of the vulnerability . The severity is represented using scoring systems like CVSS (Common Vulnerability Scoring System) with ratings such as low, medium, high, or critical . The exploitability of the vulnerability comprises information on whether known exploits or attack vectors are available for the vul nerability .
[0086] The mitigation measures of the vulnerability comprises recommendations or guidelines provided by a security consultant on how to mitigate or address the vulnerability . Examples of the mitigation measures may include patches , software updates , conf iguration changes , or workarounds . The dates of the vul nerability comprises timestamps indicating when the vulnerability is discovered, disclosed, or patched by the one or more security consultants . The information of the plurality of past vulnerability attacks further comprises a business impact and an ef fect of each of the plurality of past vulner- ability attacks . In one example , information about the plurality of past vulnerability attacks is received by the processing unit in the form of text f iles which comprise information associated the plurality of vulnerabilities .
[0087] In one example , the plurality of engineering data obj ects comprises one or more textual documents which comprise information associated the plurality of software components 109A-N and the plurality of hardware components 108A-N . Examples of the plurality of engineering data obj ects comprises one or more textual documents comprising a technical documentation, a sourcecode , a manual , and a specif ication of the automation system from the industrial plant . Such textual documents comprises information about the plurality of software components and the plurality of hardware components , and one or more functionalities of the plurality of software components and the plurality of hardware components . Such textual documents further comprise information of a manner of connection and communication of the plurality of software components 109A-N and the plurality of hardware components 108A-N with each other . Advantageously, the one or more security consultants is saved from a task of manually reading through the plurali ty of engineering data obj ects , thus saving labour and time .
[0088] In other words , the plurality of engineering data obj ects comprise information associated with the plurality of soft ware components 109A-N and the plurality of hardware components 108A-N of the automation system 102 . In another example , the plurality of engineering data obj ects comprises text f iles , binary f iles and images scans of physical technical documents . The plurality of engineering data obj ects compris es information about the plurality of software components 109A-N such as tags , User def ined datatypes (UDTs ) , blocks , libraries , and their interconnections with other sub systems like Human machine interfaces (HMI ) , OPC UA and other web servers and one or more connections of the plurality of soft ware components 109A-N to the plurality of hardware components 108A-N . The plurality of engineering data obj ects further comprises information about behavior of the plurality of software components 109A-N and the plurality of hardware components 108A-N at a normal operation of the automation sys tem . The normal operation of the automation system is indicative of a state of operation of the automation system 102 when no vulnerability attacks are potential on the automation system .
[0089] The plurality of engineering data obj ects further comprises details about instruction set used by the plurality of hardware components 108A-N . The plurality of engineering data further comprises behavior of the plural ity of hardware components 108A-N such as a maximum, a minimum and an optimum scan cycle used by the plurality of hardware components 108A- N to execute the plurality of software components 109A-N . The plurality of engineering data obj ects comprises information about behavioral modality of trio namely the plurality of software components 109A-N, the plurality of hardware components 108A-N, and the plurality of connections between the plurality of software components 109A-N and the plurality of hardware components 108A-N . Advantageously, the behaviour of the plurality of software components 109A-N and the plurality of software components 109A-N are automatically analyzed by the processing unit 202 . Thus , labour and ef fort required to manually analyze the plurality of engineering data obj ects is eradicated .
[0090] In one example , information about the behavior of the plural ity of software components 109A-N and the plurality of hardware components 108A-N comprises information about a plurali ty of dependencies between a plurality of input parameters and a plurality of output parameters associated with the plu- rality of hardware components 108A-N and the plurality of software components 109A-N . The plurality of input parameters comprise data received by the plurality of software components 109A-N and the plurality of hardware components 108A-N under the normal operation of the automation systems . The normal operation of the automation system is indicative of a time period in which the automation system 102 is not subj ect to an potential vulnerability attack . The plurality of output parameters comprise data output by the the plurality of soft ware components 109A-N and the plurality of hardware components 108A-N under the normal operation of the automation systems .
[0091] In one example , the plurality of input parameters comprises information about a telemetry data , a user input , a sensor input , and a user conf iguration received by the plurality of software components 109A-N and the plurality of hardware components 108A-N . The plurality of input parameters further comprises information about a code segment executed by the plurality of software components 109A-N and the plurality of hardware components 108A-N . In another example , the plurality of output parameters comprises information about a processing speed, a memory usage , an output signal , and a list of system errors generated by the plurality of software components 109A-N and the plurality of hardware components 108A-N .
[0092] The plurality of dependencies between the plurality of input parameters and the plurality of output parameters is indicative of a ratio between at least one input parameters of the plurality of input parameters to at least one output parameter of the plurality of output parameters . In another example , the plurality of input parameter comprise information associated with a plurality of inputs received by the automation system . Examples of plurality of input parameters include information about a Network Traf f ic , a User Input , a System Call , a File Operation and an API Call received by the plurality of software components and the plurality of hardware components . In another example , the plurality of output parameters are indicative of a plurality of outputs of the automation system . Examples of plurality of output parameters include information about a Log File , a Network Connection, a Process Information, a File Integrity and an API Call associ ated with the plurality of software components 109A-N and the plurality of hardware components 108A-N .
[0093] When executed by the processing unit 202 , the vulnerability intelligence module 112 further causes the processing unit 202 to analyze the plurality of engineering data obj ects and the information about the plurality of past vulnerability at tacks by application of a natural language processing algorithm on the plurality of engineering data obj ects and the information on the plurality of past vulnerability attacks on the automation system . The natural language processing algorithm is a computational method or technique designed to process and analyze human language . The NLP algorithm is conf igured to enable computers to understand, interpret , and generate natural language text or speech . The NLP algorithm employ a plurality of techniques from linguistic rules to statisti cal models and machine learning . Examples of the natural language processing algorithm include but is not limited to a Stanford Parser algorithm, a Spacy algorithm, a CoreNLP algorithm, an OpenNLP algorithm, a Gensim algorithm, a Hugging Face Transformers algorithm, and a Stanford Part -of - Speech Tagger ( POS ) algorithm .
[0094] The vulnerability intelligence module 112 further causes the processing unit 202 to generate a f irst set of tokens from the plurality of engineering data obj ects based on the analysis . Each token of the f irst set of tokens comprises information associated with a specif ic data obj ect of the plurali - ty of engineering data obj ects . The processing unit 202 is conf igured to generate the f irst set of tokens by application of a tokenization algorithm on the analysed plurality of engineering data obj ects . The tokenization algorithm is a computational method which splits a text present in the plurali ty of engineering data obj ects , into individual words , phrases , or sentences , known as tokens . The tokenization al gorithm comprises a plurality of rules and patterns to segment the text ef fectively . Examples of the tokenization algorithm comprises a Rule-based tokenization algorithm, a white space tokenization algorithm, a Regular expression tokenization algorithm, a Statistical tokenization algorithm, a Maxi mum entropy tokenization algorithms , and a Neural networkbased tokenization algorithms .
[0095] The vulnerability intelligence module 112 further causes the processing unit 202 to apply a dependency parsing algorithm on the f irst set of tokens to analyze a syntactic structure of interdependencies between one or more tokens of the f irst set of tokens . In another example , the dependency parsing algorithm is applied on the text comprised within the plural ity of engineering data obj ects . The dependency parsing algorithm is conf igured to identify a plurality of grammatical relationships between two or more tokens of the f irst set of tokens and the grammatical relationships are represented by the dependency parsing algorithm as a dependency tree . Thus , the processing unit is conf igured to generate a plurality of dependency trees .
[0096] Each dependency tree of the plurality of dependency trees is representative of the plurality of grammatical relationships between two or more tokens of the f irst set of tokens . It is noted that each token of the f irst set of tokens is indicative of information about the plurality of software components and the plurality of hardware components . Thus , the plurality of grammatical relationships between the f irst set of tokens is indicative of the plurality of dependencies between two or more components in the plurality of software components and the plurality of hardware components .
[0097] Since the plurality of engineering data obj ects comprise information about the plurality of input parameters and the plurality of output parameters , the plurality of grammatical relationships between the f irst set of tokens is further indicative of the plurality of dependencies between the plural ity of input parameters and the plurality of output parameters .
[0098] The vulnerability intelligence module 112 further causes the processing unit 202 to extract information associated with the plurality of software components 109A-N and the plurality of hardware components 108A-N of the automation system 102 from the f irst set of tokens . In one example , the processing unit 202 is conf igured to f ilter the f irst set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of the plurality of software components 109A-N and the plurality of hardware components 108A-N in the f irst set of tokens .
[0099] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze a plurality of dependencies in the plurality of dependency trees and the identif ied mentions of the plurality of software components 109A-N and the plurality of hardware components 108A-N by application of a semantic role labelling algorithm on the f irst set of tokens . The semantic role labelling algorithm is conf igured to assign semantic roles to the identif ied mentions of the plurality of hardware components 108A-N and the plurality of software components 109A-N based on the plurality of dependency trees . The semantic roles of each component of the plurality of hardware components 108A-N and the plurality of software components 109A-N is indicative of a relationship of each component with other components of the plurality of hardware components 108A-N and the plurality of software components 109A- N . Examples of the semantic role labelling algorithms include , but is not limited to AllenNLP Algorithm or PropBank proj ect algorithm .
[0100] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze the plurality of grammatic relationships and the plurality of assigned semantic roles to determine a plurality of interconnections between tokens in the f irst set of tokens . The plurality of interconnections between tokens among the f irst set of tokens is indicative of a plurality of interdependencies between behaviour of the plurality of software components and the plurality of hardware components . For example , the plurality of interdependencies are indicative of the plurality of dependencies between the plurality of input parameters and the plurality of output parameters associated with the plurality of software components 109A-N and the plurality of hardware components 108A-N .
[0101] For example , a dependency between an input parameter and an output parameter of at least one software component or hardware component in at least one dependency tree of the plural ity of dependency trees , is indicative of a interdependency between the software component and the hardware component . In other words , the vulnerability intelligence module 112 further causes the processing unit 202 to generate a f irst map between the generated plurality of tokens based on an analysis of the generated f irst set of tokens . The f irst map comprises the generated plurality of interconnections between two or more tokens of the f irst set of tokens . In one example , the f irst map is stored as a plurality of knowledge graph triples . The vulnerability intelligence module 112 further causes the processing unit 202 to generate a f irst knowledge graph based on the analysis of the plurality of dependency trees . The generated f irst knowledge graph comprises information the determined plurality of interconnections between two or more tokens of the f irst set of tokens comprising information about the plurality of hardware components 108A-N and the plurality of software components 109A-N . In other words , the generated f irst knowledge graph comprises information about the plurality of interdependencies between the plurality of hardware components 108A-N and the plurality of software components 109A-N .
[0102] In one example , the generated f irst knowledge graph comprises a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with a specif ic hardware component or a specif ic software component of the plurality of software components and the plurali ty of hardware components . In one example , a plurality of graph database technologies or graph representation formats like such as SPARQL and Resource Description Framework is used to store data in and manage the generated f irst knowledge graph . The generated f irst knowledge graph is an engineering behaviour ontological schema . In other words , the vulnerability intelligence module 112 further causes the processing unit 202 to generate the engineering behavior ontological schema based on an analysis of the plurality of engi neering data obj ects and the information associated with the plurality of past vulnerability attacks .
[0103] In one example , the plurality of software components 109A-N comprises a plurality of code segments in a PLC code and the information about the plurality of hardware components 108A-N comprises information associated with a performance of the plurality of hardware components 108A-N when each hardware component executes the plurality of code segments . In such a case , the engineering behaviour ontological schema is a knowledge graph representation comprising information associ ated with a plurality of interconnections and dependencies between a plurality of code segments in the PLC code , and a performance of the plurality of hardware components 108A-N associated with the plurality of code segments . In another example , the plurality of engineering data obj ects comprises information associated with the plurality of input parameters and the plurality of output parameters associated with each of the plurality of software components 109A-N and the plurality of hardware components 108A-N of the automation system 102 . In such a case , the engineering behaviour ontological schema comprises information associated with the plurality of dependencies between the plurality of input parameters and the plurality of output parameters , when during a state of the automation system 102 at which the automation system 102 is not subj ect to an potential vulnerability attack . Advantageously, the processing unit 202 is conf igured to automati cally generate the engineering behaviour ontological schema which comprises information about a behaviour of the plurali ty of hardware components 108A-N and the plurality of soft ware components 109A-N under the normal operation of the automation system 102 .
[0104] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze the plurality of engineering data obj ects and the information about the plurality of past vulnerability attacks by application of the NLP algorithm on the information associated with the plurality of past vulnerability attacks . The vulnerability intelligence module 112 further causes the processing unit 202 to generate a second set of tokens from the information associated with the plurality of past vulnerability attacks based on analysis of in- formation associated with the plurality of past vulnerability attacks . Each token of the second set of tokens comprises information associated with a specif ic past vulnerability at tack of the plurality of past vulnerability attacks . The processing unit 202 is further conf igured to generate the second set of tokens by application of the tokenization algorithm on the analysed plurality of engineering data obj ects and the information associated with the plurality of past vulnerabil ity attacks .
[0105] The vulnerability intelligence module 112 further causes the processing unit 202 to apply a dependency parsing algorithm on the second set of tokens to analyze a syntactic structure of one or more tokens of the second set of tokens . The dependency parsing algorithm is conf igured to identify a plurality of grammatical relationships between two of more tokens of the second set of tokens and the grammatical relationships are represented by the dependency parsing algorithm as a dependency tree . Thus , the processing unit is further conf igured to generate a plurality of dependency trees . Each dependency tree of the plurality of dependency trees is representative of the plurality of grammatical relationships between two or more tokens of the second set of tokens . It is noted that each token of the second set of tokens is indicative of information about one or more past vulnerability at tacks of the plurality of vulnerability attacks .
[0106] The vulnerability intelligence module 112 further causes the processing unit 202 to extract information associated with the plurality of past vulnerability attacks . In one example , the processing unit is further configured to f ilter the second set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of each vulnerability attack of the plurality of past vulnerability attacks . In one example , the identif ied mentions of each vulnerability attack comprises the vulnerability ID of the vulnerability attack .
[0107] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze a plurality of dependencies in the plurality of dependency trees and the identif ied mentions of the plurality of past vulnerability attacks by application of a semantic role labelling algorithm . The semantic role labelling algorithm is conf igured to assign semantic roles to the identif ied mentions of the plurality of past vulnerabil ity attacks based on the plurality of dependency trees . The semantic roles of each component of the plurality of past vulnerability attacks is indicative of an ef fect of plurality of past vulnerability attacks on the plurality of hardware components and the plurality of software components .
[0108] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze the plurality of grammatic relationships and the plurality of assigned semantic roles to determine a plurality of interconnections between two or more tokens in the f irst set of tokens and the second set of tokens . The plurality of interconnections between one or more tokens among the second set of tokens is indicative of a plurality of interdependencies between behaviour of the plurali ty of software components and the plurality of hardware components and the plurality of past vulnerability attacks . For example , the plurality of interdependencies are indicative of the plurality of interdependencies between the plurality of past vulnerability attacks with a behaviour of the plurality of software components and the plurality of hardware components . For example , the plurality of interdependencies are indicative of variations in the plurality of input parameters and the plurality of output parameters in the event of at least one vulnerability attack of the plurality of past vul nerability attacks . In another example , the plurality of interdependencies are indicative of a ratio between the plurality of input parameters and the plurality of output parameters in the event of at least one vulnerability attack of the plurality of past vulnerability attacks . In yet another example , the plurality of interdependencies comprises information about a plurality of anomalies in the plurality of input parameters and the plurality of output parameters during each of the plurality of past vulnerability attacks .
[0109] The vulnerability intelligence module 112 further causes the processing unit 202 to generate a second knowledge graph to represent the determined plurality of interconnections between two or more tokens of the f irst set of tokens and the second set of tokens . It is noted that the second set of tokens comprises information about the plurality of past vul nerability attacks . In other words , the generated second knowledge graph comprises information about the plurality of interdependencies between the plurality of hardware components 108A-N and the plurality of software components 109A-N during each of the plurality of past vulnerability attacks .
[0110] Furthermore , the generated second knowledge graph comprises information associated with the plurality of anomalies in values of the plurality of input parameters and the plurality of output parameters of the automation system 102 . The second knowledge graph further comprises information associated with a mapping between the plurality of anomalies , the plurality of input parameters , and the plurality of output parameters . In other words , the method comprises generating , by the processing unit 202 , a second map between the generated second set of tokens based on an analysis of the generated second set of tokens . In one example , the second generated knowledge graph compris es a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with a specif ic vulnerability attack of the plurality of vul nerability attacks or a specif ic component of the plurality of software components 109A-N and the plurality of hardware components 108A-N . In one example , a plurality of graph database technologies or graph representation formats like such as SPARQL and Resource Description Framework is used to store data in and manage the generated knowledge graph . The generated second knowledge graph is a vulnerability ontological schema . In other words , the vulnerability intelligence module 112 further causes the processing unit 202 to generate the vulnerability ontological schema based an analysis of the plurality of engineering data obj ects and information associ ated with the plurality of past vulnerability attacks .
[0111] In one example , the vulnerability ontological schema compris es information associated with the plurality of anomalies as sociated with the plurality of past vulnerability attacks . Examples of the plurality of anomalies associated each of the plurality of past vulnerability attacks includes one or more anomalies in the plurality of input parameters and the plurality of output parameters of the automation system 102 during each vulnerability attack of the plurality of past vul nerability attacks . An anomaly is indicative of a variation of the plurality of input parameters and the plurality of output parameters from one or more parameter values indicated by the engineering behaviour ontological schema . The vulnerability ontological schema further comprises information about a plurality of dependencies between the plurality of anomalies and the plurality of past vulnerability attacks . Thus , each anomaly of the plurality of anomalies is mapped by the vulnerability ontological schema to a specif ic past vulnera- bility attacks of the plurality of past vulnerability at tacks .
[0112] The vulnerability intelligence module 112 further causes the processing unit 202 to analyze the second set of tokens , by the processing unit 202 , to extract information associated with an ef fect of each vulnerability attack of the plurality of past vulnerability attacks on the automation system 102 . The vulnerability intelligence module 112 further causes the processing unit 202 to generate a third knowledge graph comprising information associated with an ef fect of each vulnerability attack , of the plurality of past vulnerability at tacks , on the plurality of software components 109A-N and the plurality of hardware components 108A-N . In one example , the third knowledge graph comprises information associated ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components 108A-N and the plurality of software components 109A-N .
[0113] In one example , the information associated with ef fect of each of the plurality of past vulnerability attacks comprises information associated with at least one of a stoppage , a slowness , a crash, a malfunction, a data theft , and a code replication, a list of inputs inj ected by the vulnerability into the automation system 102 , a change in workf low of the automation system 102 caused by the vulnerability attack , a change in process of the automation system 102 by the vulnerability attack , a change in processing power of the automation system 102 which has occurred on the automation system 102 as a result of each of the plurality of past vulnerabil ity attacks . It is noted that , the ef fect of each of the plurality of past vulnerability attacks is manually recorded by the security consultant during the one or more vulnerability snif f ing operations conducted by the security consultant on the automation system 102 . In one example , the generated third knowledge graph comprises a plurality of nodes and a plurality of edges . Each node of the plurality of nodes comprises information associated with an ef fect of a specif ic vulnerability attack of the plurality of vulnerability attacks on a specif ic component of the plurality of software components and the plurality of hardware components . In one example , the generated third knowledge graph comprises information associated each of the plurality of past vulnerability attacks . The ef fect of the plurality of past vulnerability attacks include , but is not limited to a list of inputs inj ected by the vulnerability into the automation system 102 , a change in workf low of the automation sys tem 102 caused by the vulnerability attack , a change in process of the automation system 102 by the vulnerability at tack , a change in processing power of the automation system 102 caused by the vulnerability attack . Advantageously, the processing unit 202 is conf igured to automatically generate the attack ef fect ontological schema which comprises information about an ef fect of each of the plurality of past vul nerability attacks .
[0114] The generated third knowledge graph is an attack ef fect ontological schema . In other words , the vulnerability intelli gence module 112 further causes the processing unit 202 to generate the attack ef fect ontological schema . In one example , the attack ef fect ontological schema comprises information associated with an ef fect of each of the plurality of past vulnerability attacks on the plural ity of software components and the plurality of hardware components . For example , information stored in the attack ef fect ontological schema comprises but is not limited to a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system caused by the vulnerability attack , a change in process of the automation system by the vulnerability attack , a change in processing power of the automation system caused by the vulnerability attack . Furthermore , the attack ef fect ontological schema comprises information associated with a plurality of interdependencies between the ef fect of each vulnerability attack of the plurality of past vulnerability attacks on the plurality of software components and the plurality of hardware components . In other words , the attack ef fect ontological schema comprises information associated with the ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components 108A-N and the plurality of software components 109A-N .
[0115] The vulnerability intelligence module 112 further causes the processing unit 202 to receive a set of input parameters and a f irst set of output parameters from the automation system . The set of input parameters comprises a plurality of inputs received by the plurality of software components 109A-N and the plurality of hardware components 108A-N . Examples of the set of input parameters include , but is not limited to a sensor input , a user input , a workf low detail , a plurality of scan cycle parameters associated with the plurality of soft ware components 109A-N and the plurality of hardware components 108A-N . The f irst set of output parameters comprises information about memory usage of the plurality of software components 109A-N and the plurality of hardware components 108A-N . The f irst set of output parameters further comprises a data output , a processing power consumption data , and information about a processing speed of the plurality of soft ware components 109A-N and the plurality of hardware components 108A-N .
[0116] The vulnerability intelligence module 112 further causes the processing unit 202 to apply the engineering behaviour ontological schema on the received set of input parameters and the f irst set of output parameters . In one example , to apply the engineering behavior ontological schema on the received set of input parameters and the received f irst set of output parameters , the processing unit 202 is conf igured to query the engineering behavior ontological schema based on the received set of input parameters . It is noted that the engi neering behaviour ontological schema comprises information associated with the plurality of dependencies between the plurality of input parameters and the plurality of output parameters of the automation system 102 under a normal operation of the automation system 102 . The normal operation of the automation system is a mode of operation of the automation system 102 in which the automation system 102 is not subj ect to an potential vulnerability attack by a malicious entity such as a hacker . Thus , by querying the engineering behaviour ontological schema , the processing unit 202 is conf igured to generate a second set of output parameters based on the set of input parameters .
[0117] The second set of output parameters are indicative of one or more output parameters which are generated by the automation system 102 , when the automation system processes the set of input parameters during the normal operation of the automation system 102 . Advantageously, the processing unit 202 is enabled to compare the f irst set of output parameters with the second set of output parameters to detect one or more anomalies in the f irst set of output parameters and thereby detect an potential vulnerability attack on the automation system 102 .
[0118] The processing unit 202 is further conf igured to generate the second set of output parameters by querying the engineering behavior ontological schema using the received set of input parameters . The vulnerability intelligence module 112 further causes the processing unit 202 to compare the f irst set of output parameters with the second set of output parameters . The processing unit 202 is conf igured to compare the f irst set of output parameters and the second set of output parameters by application of a comparison algorithm on the f irst set of output parameters and the second set of output parameters . Examples of the comparison algorithm compri ses , but is not limited to mean absolute error based algorithm, Root Mean Squared Error based algorithm, and a cosine similarity algorithm .
[0119] The vulnerability intelligence module 112 further causes the processing unit 202 to determine at least one anomaly in the f irst set of output parameters based on the comparison . The at least one anomaly is indicative of a dif ference between the f irst set of output parameters and the second set of out put parameters . In other words , the determined at least one anomaly is indicative of a deviation of a behaviour of the automation system 102 from a behaviour expressed in the engi neering behaviour ontological schema . Thus , the detected at least one anomaly is an indication of an potential vulnerability attack on the automation system 102 .
[0120] The vulnerability intelligence module 112 further causes the processing unit 202 to compare the determined at least one anomaly with the plurality of anomalies depicted in the vul nerability ontological schema . It is noted that each anomaly of the plurality of anomalies is associated with a specif ic vulnerability attack of the plurality of past vulnerability attacks . Furthermore , each node of the plurality of nodes of the vulnerability ontology schema is representative of a specif ic vulnerability attack of the plural ity of past vulnerability attacks . In one example , the determined at least one anomaly is compared with the plurality of anomalies by appli cation of a similarity algorithm on the determined at least one anomaly and the plurality of anomalies . Examples of the similarity algorithm includes a cosine similarity algorithm and a Jaccard similarity algorithm . The similarity algorithm is conf igured to determine a similarity of the at least one anomaly to a set of anomalies stored in the vulnerability ontology schema . In a case where the at least one anomaly is similar to the set of anomalies , the similarity algorithm is conf igured to match the at least one anomaly to the set of anomalies .
[0121] The vulnerability intelligence module 112 further causes the processing unit 202 to match the determined at least one anomaly with at least one node of the plurality of nodes of the vulnerability ontology schema . The at least one node of the plurality of nodes comprises information associated with the set of anomalies which are similar to the determined at least one anomaly . Furthermore , the at least one node of the plurality of nodes comprises information associated with a set of past vulnerability attacks which caused the set of anomalies in the past . The vulnerability intelligence module 112 further causes the processing unit 202 to predict an potential vulnerability attack on the automation system based on the detected at least one node of the plurality of nodes . In other words , the method further comprises predicting an potential vulnerability attack on the automation system based on the detected at least one anomaly in the automation sys tem .
[0122] The vulnerability intelligence module 112 further causes the processing unit 202 to compare the detected at least one node of the vulnerability ontological schema with each node of the attack ef fect ontological schema based on an analysis of the detected potential vulnerability attack and the vulnerability ontological schema . In one example , the detected at least one node of the vulnerability ontological schema is compared with each node of the attack ef fect ontological schema by applica- tion of a similarity algorithm on the detected at least one node of the vulnerability ontological schema and each node of the attack ef fect ontological schema . Examples of the simi larity algorithm includes a cosine similarity algorithm and a Jaccard similarity algorithm .
[0123] The vulnerability intelligence module 112 further causes the processing unit 202 to detect at least one node of the attack ef fect ontology schema based on the comparison . The detected at least one node of the attack ef fect ontology schema is indicative of information associated with a list of ef fects caused by the determined set of past vulnerability attacks on the automation system 102 in the past . In other words , the processing unit 202 is conf igured to detect a list of ef fects caused by the determined set of past vulnerability attacks on the automation system 102 . Since the detected potential vul nerability attack is similar to the determined set of past vulnerability attacks , the list of ef fect caused by the determined set of past vulnerability attacks is indicative of a set of possible ef fects of the predicted potential vulnerability attack . The vulnerability intelligence module 112 further causes the processing unit 202 to determine the set of possible ef fects of the potential vulnerability attack based on an analysis of the at least one node of the attack ef fect ontology schema . In other words , the vulnerability intelli gence module 112 further causes the processing unit 202 to predicting the potential vulnerability attack and a set of possible ef fects of the predicted potential vulnerability at tack based on the determined at least one anomaly .
[0124] In one example , the information associated with the set of possible ef fects caused by the potential vulnerability attack comprises information associated with at least one of a stoppage , a slowness , a crash, a malfunction, a data theft , and a code replication, a list of inputs inj ected by the vulnera- bility into the automation system 102 , a change in workf low of the automation system 102 which may be caused by the potential vulnerability attack , a change in process of the automation system by the potential vulnerability attack , a change in processing power of the automation system which has occurred on the automation system as a result of the potential vulnerability attack . Furthermore , the information associated with the set of possible ef fects of the potential vul nerability attack further comprises a list of components of the plurality of software components 109A-N and the plurality of hardware components 108A-N which may be af fected by the potential vulnerability attack . Advantageously, the processing unit is conf igured to generate a list of possible ef fects of the potential vulnerability attack on the automation system 102 . Thus , a security consultant is enabled to take appropriate steps to neutralize the potential vulnerability attack .
[0125] The vulnerability intelligence module 112 further causes the processing unit 202 to initiate a vulnerability snif f ing operation on the automation system 102 based on the prediction of the potential vulnerability attack and the determined set of possible ef fects of the potential vulnerability attack . The vulnerability snif f ing operation refers to a process of actively scanning the automation system 102 to identify vul nerabilities or weaknesses that could potentially be exploit ed by malicious actors . Examples of the vulnerability snif f ing operation includes , but is not limited to Port Scanning based vulnerability snif f ing operation, Vulnerability Scanners based vulnerability snif f ing operation, Network Mapping based vulnerability snif f ing operation, and Web Application Scanning based vulnerability snif f ing operation . The vulnerability snif f ing operation is executed to validate a presence of the potential vulnerability attack on the automation sys tem 102 . The vulnerability intelligence module 112 further causes the processing unit 202 to validate a prediction of the detected vulnerability attack based on a result of the vulnerability snif f ing operation . In one example , the result of the vulnerability snif f ing operation indicates a presence of a vulnerability in the automation system 102 . In such a case , the predicted potential vulnerability attack is validated by the processing unit 202 . Advantageously, the processing unit ini tiates the vulnerability snif f ing operation based on the detection of the potential vulnerability attack on the automation system 102 .
[0126] The vulnerability intelligence module 112 further causes the processing unit 202 to generate a user alert based on the validation of the detected potential vulnerability attack on the automation system 102 . In one example , the user alert is at least one of a voice based, a image based or a text based user alert . The vulnerability intelligence module 112 further causes the processing unit 202 to output the generated user alert comprising information about the predicted potential vulnerability attack and the detected set of possible ef fects of the detected potential vulnerability attack to a user . In one example , the generated user alert is output by the processing unit 202 via an output device such as a computer monitor .
[0127] In one example , the generated user alert comprises information associated with the detected potential vulnerability attack . For example , the information associated with the detected potential vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerabil ity Description, the list of Components af fected by the vul - nerability, the Vulnerability Type , the Severity of the vul nerability, the Exploitability of the vulnerability, the Mit igation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulnerability attack of the plurality of past vulnerability attacks .
[0128] In one example , the generated user alert comprises information associated with the predicted potential vulnerability attack . For example , the information associated with the predicted potential vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerabil ity Description, the list of Components af fected by the vul nerability, the Vulnerability Type , the Severity of the vul nerability, the Exploitability of the vulnerability, the Mit igation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulberability attack of the plurality of past vulnerability attacks .
[0129] Referring back to FIG . 2 , the storage unit 206 may be a non- transitory storage medium conf igured for storing a database ( such as database 118 ) which comprises server version of the plurality of programming blocks associated with the set of industrial domains .
[0130] The communication interface 208 is conf igured for establishing communication sessions between the one or more client devices 120A-N and the engineering system 102 . The communication interface 208 allows the one or more engineering applications running on the client devices 120A-N to import / export engineering proj ect f iles into the engineering system 102 . The input-output unit 210 may include input devices a keypad, touch- sensitive display, camera (such as a camera receiving gesture-based inputs) , etc. capable of receiving one or more input signals, such as user commands to process engineering project file. Also, the input-output unit 210 may be a display unit for displaying a graphical user interface which visualizes the behavior model associated with the modified engineering programs and also displays the status information associated with each set of actions performed on the graphical user interface. The set of actions may include execution of predefined tests, download, compile and deploy of graphical programs. The bus 214 acts as interconnect between the processor 202, the memory 204, and the input-output unit 210.
[0131] The network interface 212 may be configured to handle network connectivity, bandwidth and network traffic between the engineering system 102, client devices 120A-N and the technical installation .
[0132] Those of ordinary skilled in the art will appreciate that the hardware depicted in FIG 2 may vary for particular implementations. For example, other peripheral devices such as an optical disk drive and the like, Local Area Network (LAN) , Wide Area Network (WAN) , Wireless (e.g. , Wi-Fi) adapter, graphics adapter, disk controller, input / output (I / O) adapter also may be used in addition or in place of the hardware depicted. The depicted example is provided for the purpose of explanation only and is not meant to imply architectural limitations with respect to the present disclosure.
[0133] Those skilled in the art will recognize that, for simplicity and clarity, the full structure and operation of all data processing systems suitable for use with the present disclosure is not being depicted or described herein. Instead, only so much of an engineering system 102 as is unique to the present disclosure or necessary for an understanding of the present disclosure is depicted and described. The remainder of the construction and operation of the engineering system 102 may conform to any of the various current implementation and practices known in the art.
[0134] FIG 3 is a block diagram of a vulnerability intelligence module 112, such as those shown in FIG 2, in which an embodiment of the present invention can be implemented. In FIG 3, the remodeller module 112 comprises a request handler module 302, an ontological schema generation module 304, an analysis module 306, a natural language processing module 308, an engineering data object database 310, a validation module 312 and a deployment module 314. FIG. 3 is explained in conjunction with FIG. 1 and FIG. 2.
[0135] The request handler module 302 is configured for receiving a request from a user to predict a vulnerability attack on the automation system 102. For example, the request is received from one of the one or more users external to the industrial environment 100 via the network 104. In alternative embodiment, the request is received from the one or the one or more client devices 120A-N via the network 104.
[0136] The ontological schema generation module 304 is configured for generating the vulnerability ontological schema, the engineering behaviour ontological schema, the vulnerability ontological schema, and the attack effect ontolological schema.
[0137] The analysis module 306 is configured for analyzing the plurality of engineering data objects. The analysis module 306 is further configured to analyze the information associated with the plurality of past vulnerability attacks. The natural language processing module 308 is conf igured for apply the natural language processing algorithm on the plurality of engineering data obj ects and the information associated with the plurality of past vulnerability attacks .
[0138] The engineering data obj ect database 310 is conf igured to store the plurality of engineering data obj ects associated with the automation system 102 .
[0139] The validation module 312 is conf igured to validate the prediction of the potential vulnerability attack on the automation system 102 . The validation module 312 is further conf igured to initiate the vulnerability snif f ing operation .
[0140] The deployment module 314 is conf igured to execute one or more conf iguration changes on the automation system 102 to neutralize the predicted potential vulnerability attack on the automation system 102 .
[0141] FIG 4A- F is a process f lowchart illustrating an exemplary method 400 of predicting a vulnerability attack on an automation system, according to an embodiment of the present invention . FIG 4A-E is described in conj unction with FIG 1 , 2 , and 3 .
[0142] At step 402 , a plurality of engineering data obj ects associ ated with the automation system 102 are received by the processing unit 202 . Furthermore , at 402 , information associated with a plurality of past vulnerability attacks on the automation system 106 are received by the processing unit 202 .
[0143] At step 404 , the plurality of engineering data obj ects and the information about the plurality of past vulnerability at tacks are analyzed by the processing unit 202 by application of a natural language processing algorithm on the plurality of engineering data obj ects and the information on the plurality of past vulnerability attacks on the automation system 102 .
[0144] At step 406 , a f irst set of tokens are generated by the processing unit 202 , from the plurality of engineering data obj ects . The f irst set of tokens are generated based on the analysis .
[0145] At step 408 , a dependency parsing algorithm is applied by the processing unit 202 on the f irst set of tokens to analyze a syntactic structure of interdependencies between one or more tokens of the f irst set of tokens .
[0146] At step 410 , information associated with the plurality of software components 109A-N and the plurality of hardware components 108A-N of the automation system 102 is extracted by the processing unit 202 from the f irst set of tokens . In one example , the processing unit 202 is conf igured to f ilter the f irst set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of the plurality of software components 109A-N and the plurality of hardware components 108A-N in the f irst set of tokens .
[0147] At step 412 , a plurality of dependencies are analyzed by the processing unit 202 in the plurality of dependency trees and the identif ied mentions of the plurality of software components 109A-N and the plurality of hardware components 108A-N by application of a semantic role labelling algorithm on the f irst set of tokens .
[0148] At step 414 , the plurality of grammatic relationships and the plurality of assigned semantic roles are analyzed by the processing unit 202 to determine a plurality of interconnections between tokens in the f irst set of tokens . The plurality of interconnections between tokens among the f irst set of tokens is indicative of a plurality of interdependencies between be- haviour of the plurality of software components and the plurality of hardware components .
[0149] At step 416 , a f irst map between the generated plurality of tokens is generated by the processing unit 202 , based on an analysis of the generated f irst set of tokens . The f irst map comprises the generated plurality of interconnections between two or more tokens of the f irst set of tokens . In one example , the f irst map is stored as a plurality of knowledge graph triples .
[0150] At step 418 , a f irst knowledge graph is generated by the processing unit 202 based on the generated f irst map . The f irst knowledge graph represents the determined plurality of interconnections between two or more tokens of the f irst set of tokens comprising information about the plurality of hardware components 108A-N and the plurality of software components 109A-N . In other words , the vulnerability intelligence module 112 further causes the processing unit 202 to generate the engineering behavior ontological schema based on an analysis of the plurality of engineering data obj ects and the information associated with the plurality of past vulnerability attacks .
[0151] At step 420 , the plurality of engineering data obj ects and the information about the plurality of past vulnerability at tacks are analyzed by the processing unit 202 by application of the NLP algorithm on the information associated with the plurality of past vulnerability attacks .
[0152] At step 422 , a second set of tokens are generated by the processing unit 202 from the information associated with the plurality of past vulnerability attacks based on analysis of information associated with the plurality of past vulnerabil ity attacks . Each token of the second set of tokens comprises information associated with a specif ic past vulnerability at tack of the plurality of past vulnerability attacks . The processing unit 202 is further conf igured to generate the second set of tokens by application of the tokenization algorithm on the analysed plurality of engineering data obj ects and the information associated with the plurality of past vulnerabil ity attacks .
[0153] At step 424 , a dependency parsing algorithm is applied by the processing unit 202 on the second set of tokens to analyze a syntactic structure of one or more tokens of the second set of tokens . The dependency parsing algorithm is conf igured to identify a plurality of grammatical relationships between two of more tokens of the second set of tokens and the grammati cal relationships are represented by the dependency parsing algorithm as a dependency tree . Thus , the processing unit is further conf igured to generate a plurality of dependency trees . Each dependency tree of the plurality of dependency trees is representative of the plurality of grammatical relationships between two or more tokens of the second set of tokens . It is noted that each token of the second set of tokens is indicative of information about one or more past vulnerability attacks of the plurality of vulnerability attacks .
[0154] At step 426 , the information associated with the plurality of past vulnerability attacks is extracted by the processing unit 202 . In one example , the processing unit is further conf igured to f ilter the second set of tokens with one or more named entity recognition (NER) algorithms to identify mentions of each vulnerability attack of the plurality of past vulnerability attacks . In one example , the identif ied mentions of each vulnerability attack comprises the vulnerabil ity ID of the vulnerability attack . At step 428 , a plurality of dependencies in the plurality of dependency trees and the identif ied mentions of the plurality of past vulnerability attacks are generated by the processing unit 202 by application of a semantic role labelling algorithm . The semantic role labelling algorithm is conf igured to assign semantic roles to the identif ied mentions of the plurality of past vulnerability attacks based on the plurality of dependency trees . The semantic roles of each component of the plurality of past vulnerability attacks is indicative of an ef fect of the plurality of past vulnerability attacks on the plurality of hardware components and the plurality of software components .
[0155] At step 430 , the plurality of grammatic relationships and the plurality of assigned semantic roles are analyzed by the processing unit 202 to determine a plurality of interconnections between two or more tokens in the f irst set of tokens and the second set of tokens .
[0156] At step 432 , a second knowledge graph is generated by the processing unit 202 to represent the determined plurality of interconnections between two or more tokens of the f irst set of tokens and the second set of tokens . It is noted that the second set of tokens comprises information about the plurali ty of past vulnerability attacks . In other words , the generated second knowledge graph comprises information about the plurality of interdependencies between the plurality of hardware components 108A-N and the plurality of software components 109A-N during each of the plurality of past vulnerabil ity attacks .
[0157] At step 434 , the second set of tokens are analysed by the processing unit 202 , to extract information associated with an ef fect of each vulnerability attack of the plurality of past vulnerability attacks on the automation system 102 . The vulnerability intelligence module 112 further causes the processing unit 202 to generate a third knowledge graph compris ing information associated with an ef fect of each vulnerabil ity attack , of the plurality of past vulnerabil ity attacks , on the plurality of software components 109A-N and the plurality of hardware components 108A-N . In one example , the third knowledge graph comprises information associated ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components 108A-N and the plurality of software components 109A-N .
[0158] The generated third knowledge graph is an attack ef fect ontological schema . In other words , the vulnerability intelli gence module 112 further causes the processing unit 202 to generate the attack ef fect ontological schema . In one example , the attack ef fect ontological schema comprises information associated with an ef fect of each of the plurality of past vulnerability attacks on the plural ity of software components and the plurality of hardware components . For example , information stored in the attack ef fect ontological schema comprises but is not limited to a list of inputs inj ected by the vulnerability into the automation system, a change in workf low of the automation system caused by the vulnerability attack , a change in process of the automation system by the vulnerability attack , a change in processing power of the automation system caused by the vulnerability attack . Furthermore , the attack ef fect ontological schema comprises information associated with a plurality of interdependencies between the ef fect of each vulnerability attack of the plurality of past vulnerability attacks on the plurality of software components and the plurality of hardware components . In other words , the attack ef fect ontological schema comprises information associated with the ef fect of each of the plurality of past vulnerability attacks on the plurality of hardware components 108A-N and the plurality of software components 109A-N .
[0159] At step 436 , a set of input parameters and a f irst set of output parameters are received by the processing unit 202 from the automation system 102 . The f irst set of input parameters comprises a plurality of inputs received by the plural ity of software components 109A-N and the plurality of hardware components 108A-N . Examples of the set of input parameters include , but is not limited to a sensor input , a user input , a workf low detail , a plurality of scan cycle parameters associated with the plurality of software components 109A-N and the plurality of hardware components 108A-N . The first set of output parameters comprises information about memory usage of the plurality of software components 109A-N and the plurality of hardware components 108A-N . The f irst set of output parameters further comprises a data output , a processing power consumption data , and information about a processing speed of the plurality of software components 109A-N and the plurality of hardware components 108A-N .
[0160] At step 438 , the engineering behaviour ontological schema is applied by the processing unit 202 on the received set of input parameters and the f irst set of output parameters . In one example , to apply the engineering behavior ontological schema on the received set of input parameters and the received f irst set of output parameters , the processing unit 202 is conf igured to query the engineering behavior ontological schema based on the received set of input parameters . It is noted that the engineering behaviour ontological schema comprises information associated with the plurality of dependencies between the plurality of input parameters and the plurality of output parameters of the automation system 102 under a normal operation of the automation system 102 . At step 440 , at least one anomaly is determined by the processing unit 202 in the f irst set of output parameters based on the comparison . The at least one anomaly is indicative of a dif ference between the f irst set of output parameters and the second set of output parameters . In other words , the determined at least one anomaly is indicative of a deviation of a behaviour of the automation system 102 from a behaviour expressed in the engineering behaviour ontological schema . Thus , the detected at least one anomaly is an indication of an potential vulnerability attack on the automation system 102 .
[0161] At step 442 the determined at least one anomaly is compared with the plurality of anomalies depicted in the vulnerability ontological schema . At step 444 , the determined at least one anomaly is matched by the processing unit 202 with at least one node of the plurality of nodes of the vulnerability ontology schema . At step 446 , an potential vulnerability attack on the automation system 102 is predicted by the processing unit 202 based on the detected at least one node of the plurality of nodes . In other words , the method 400 further comprises predicting an potential vulnerability attack on the automation system based on the detected at least one anomaly in the automation system 102 .
[0162] At step 448 , the detected at least one node of the vulnerability ontological schema is compared by the processing unit 202 with each node of the attack ef fect ontological schema based on an analysis of the detected potential vulnerability attack and the vulnerability ontological schema . In one example , the detected at least one node of the vulnerability ontological schema is compared with each node of the attack ef fect ontological schema by application of a similarity algorithm on the detected at least one node of the vulnerability ontological schema and each node of the attack ef fect onto- logical schema . Examples of the similarity algorithm includes a cosine similarity algorithm and a Jaccard similarity algorithm .
[0163] At step 450 , at least one node of the attack ef fect ontology schema is detected by the processing unit 202 based on the comparison . The detected at least one node of the attack ef fect ontology schema is indicative of information associated with a list of ef fects caused by the determined set of past vulnerability attacks on the automation system 102 in the past . In other words , the processing unit 202 is conf igured to detect a list of ef fects caused by the determined set of past vulnerability attacks on the automation system 102 . Since the detected potential vulnerability attack is similar to the determined set of past vulnerability attacks , the list of ef fect caused by the determined set of past vulnerability attacks is indicative of a set of possible ef fects of the predicted potential vulnerability attack . The vulnerability intelligence module 112 further causes the processing unit 202 to determine the set of possible ef fects of the potential vulnerability attack based on an analysis of the at least one node of the attack ef fect ontology schema . In other words , the vulnerability intelligence module 112 further causes the processing unit 202 to predict the potential vulnerability attack and a set of possible ef fects of the predicted potential vulnerability attack based on the determined at least one anomaly .
[0164] In one example , the information associated with the set of possible ef fects caused by the potential vulnerability attack comprises information associated with at least one of a stoppage , a slowness , a crash, a malfunction, a data theft , and a code replication, a list of inputs inj ected by the vulnerability into the automation system 102 , a change in workf low of the automation system 102 which may be caused by the po- tential vulnerability attack , a change in process of the automation system by the potential vulnerability attack , a change in processing power of the automation system which has occurred on the automation system as a result of the potential vulnerability attack . Furthermore , the information associated with the set of possible ef fects of the potential vul nerability attack further comprises a list of components of the plurality of software components 109A-N and the plurality of hardware components 108A-N which may be af fected by the potential vulnerability attack . Advantageously, the processing unit is conf igured to generate a list of possible ef fects of the potential vulnerability attack on the automation system 102 . Thus , a security consultant is enabled to take appropriate steps to neutralize the potential vulnerability attack .
[0165] At step 452 , a vulnerability snif f ing operation is initiated by the processing unit 202 on the automation system 102 based on the prediction of the potential vulnerability attack and the determined set of possible ef fects of the potential vul nerability attack . The vulnerability snif f ing operation refers to a process of actively scanning the automation system 102 to identify vulnerabilities or weaknesses that could potentially be exploited by malicious actors . Examples of the vulnerability snif f ing operation includes , but is not limited to Port Scanning based vulnerability snif f ing operation, Vul nerability Scanners based vulnerability snif f ing operation, Network Mapping based vulnerability snif f ing operation, and Web Application Scanning based vulnerability snif f ing operation . The vulnerability snif f ing operation is executed to validate a presence of the potential vulnerability attack on the automation system 102 .
[0166] At step 454 , a prediction of the detected vulnerability at tack is validated by the processing unit based on a result of the vulnerability snif f ing operation . In one example , the resuit of the vulnerability snif f ing operation indicates a presence of a vulnerability in the automation system 102 . In such a case , the predicted potential vulnerability attack is validated by the processing unit 202 . Advantageously, the processing unit initiates the vulnerability snif f ing operation based on the detection of the potential vulnerability attack on the automation system 102 .
[0167] Aty step 456 , a user alert is generated by the processing unit 202 based on the validation of the detected potential vulnerability attack on the automation system 102 . In one example , the user alert is at least one of a voice based, a image based or a text based user alert . The vulnerability intelligence module 112 further causes the processing unit 202 to output the generated user alert comprising information about the predicted potential vulnerability attack and the detected set of possible ef fects of the detected potential vulnerability attack to a user . In one example , the generated user alert is output by the processing unit 202 via an output device such as a computer monitor . in one example , the generated user alert comprises information associated with the detected potential vulnerability attack . For example , the information associated with the detected potential vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerabil ity Description, the list of Components af fected by the vul nerability, the Vulnerability Type , the Severity of the vul nerability, the Exploitability of the vulnerability, the Mit igation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulnerability attack of the plurality of past vulnerability attacks .
[0168] In one example , the generated user alert comprises information associated with the predicted potential vulnerability attack . For example , the information associated with the predicted potential vulnerability attack comprises information associated with a specif ic vulnerability of the plurality of vulnerabilities . The information associated with the specif ic vulnerability includes the vulnerability ID , the Vulnerabil ity Description, the list of Components af fected by the vul nerability, the Vulnerability Type , the Severity of the vul nerability, the Exploitability of the vulnerability, the Mit igation Measure deployed in the past to nullify the vulnerability, and the Date at which the vulnerability was exploited by a hacker to conduct at least one vulberability attack of the plurality of past vulnerability attacks .
[0169] FIG 5 is a schematic representation of an exemplary process of predicting an potential vulnerability attack on an automation system, in accordance to an embodiment of the present invention .
[0170] FIG . 5 illustrates the automation system 102 which transmits a set of input parameters and a f irst set of output parameters to the vulnerability intelligence module 112 . At step 502 , the processing unit 202 is conf igured to apply an engi neering behavior ontological schema 505 on the set of input parameters and the f irst set of output parameters to detect at least one anomaly in the f irst set of output parameters . The engineering behavior ontological schema 505 comprises a plurality of nodes 510A . At step 503 , the processing unit 202 is conf igured to apply a vulnerability intelligence ontologi cal schema 506A on the detected at least one anomaly . The vulnerability intelligence ontological schema 506A comprises a plurality of nodes 510B. Further, at step 503, the processing unit 202 is configured to predict an potential vulnerability attack on the automation system 102 based on the application of the vulnerability intelligence ontological schema 506A on the detected at least one anomaly. Further, at step 504, the processing unit 202 is configured to apply the attack effect ontological schema 506B on the predicted potential vulnerability schema. Further, at step 504, the processing unit 202 is configured to determine a set of possible effects of the predicted potential vulnerability attack on the automation system 102 based on the application of the attack effect ontological schema 506B on the predicted potential vulnerability attack.
[0171] At step 507, the processing unit 202 is configured to initiate a vulnerability sniffing operation on the automation system 102. At step 508, the processing unit 202 is configured to validate the prediction of the potential vulnerability attack on the automation system 102. At step 509, the processing unit 202 is configured to generate a user alert based on the predicted potential vulnerability attack on the automation system 102.
[0172] The present invention can take a form of a computer program product comprising program modules accessible from computer- usable or computer- readable medium storing program code for use by or in connection with one or more computers, processors, or instruction execution system. For the purpose of this description, a computer-usable or computer- readable medium can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The medium can be electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device) or a propagation mediums in and of them- selves as signal carriers are not included in the def inition of physical computer- readable medium include a semiconductor or solid state memory, magnetic tape , a removable computer diskette , random access memory (RAM) , a read only memory (ROM) , a rigid magnetic disk and optical disk such as compact disk read-only memory (CD-ROM) , compact disk read / write , and DVD . Both processors and program code for implementing each aspect of the technology can be centralized or distributed (or a combination thereof ) as known to those skilled in the art .
[0173] While the present invention has been described in detail with reference to certain embodiments , it should be appreciated that the present invention is not limited to those embodi ments . In view of the present disclosure , many modif ications and variations would be present themselves , to those skilled in the art without departing from the scope of the various embodiments of the present invention, as described herein . The scope of the present invention is , therefore , indicated by the following claims rather than by the foregoing description . All changes , modif ications , and variations coming within the meaning and range of equivalency of the claims are to be considered within their scope . All advantageous embodi ments claimed in method claims may also be apply to sys - tem / apparatus claims .
Claims
Patent Claims1. A method of predicting a vulnerability attack on an automation system, the method comprising: receiving, by a processing unit (202) : a plurality of engineering data objects associated with the automation system (102) , and information associated with a plurality of past vulnerability attacks on the automation system (102) ; analysing, by the processing unit (202) , the plurality of engineering data objects and the information associated with the plurality of past vulnerability attacks on the automation system (102) ; generating, by the processing unit (202) , an engineering behavior ontological schema (505) , a vulnerability ontological schema (506A) , and an attack effect ontological schema (506B) based on the analysis; receiving, by the processing unit (202) , a set of input parameters and a first set of output parameters associated with the automation system (102) ; determining, by the processing unit (202) at least one anomaly in the first set of output parameters based on an analysis of the engineering behavior ontological schema (505) , the set of input parameters and the first set of output parameters; predicting, by the processing unit (202) , a potential vulnerability attack on the automation system (102) and a set of possible effects of the potential vulnerability attack on the automation system (102) based on an analysis of the determined at least one anomaly, the vulnerability ontological schema (506A) and the attack effect ontological schema (506B) ; and outputting, by the processing unit (202) , a user alert comprising information associated with the pre-dieted potential vulnerability attack and the detected set of possible effects of the predicted potential vulnerability attack, wherein the vulnerability ontological schema (506A) includes information on anomalies from past vulnerability attacks, and wherein the attack effect ontological schema (506B) includes information on one or more effects of past vulnerability attacks on the automation system (102) .
2. The method according to claim 1, wherein generating the engineering behavior ontological schema comprises: analyzing, by the processing unit (202) , the plurality of engineering data objects by application of a natural language processing algorithm on the plurality of engineering data objects; generating, by the processing unit (202) , a first set of tokens from the plurality of engineering data objects based on the analysis, wherein each token of the first set of tokens comprises information associated with a specific data object of the plurality of engineering data objects; and generating, by the processing unit (202) , the engineering behavior ontological schema based on the analysis of the first set of tokens.
3. The method (400) according to claims 1 and 2, further comprising : applying, by the processing unit (202) , a dependency parsing algorithm on the generated first set of tokens to analyze a syntactic structure of interdependencies between one or more tokens of the first set of tokens ; generating, by the processing unit (202) , a plurality of dependency trees based on the application of the dependency parsing algorithm; andgenerating, by the processing unit (202) , the engineering behavior ontological schema based on an analysis of the plurality of dependency trees.
4. The method according to claims 1, 2, and 3, wherein generating the vulnerability ontology schema and the attack effect ontological schema comprises: analyzing, by the processing unit (202) , the plurality of engineering data objects and the information associated with the plurality of past vulnerability attacks on the automation system of the industrial plant (106) ; and generating, by the processing unit (202) , a second set of tokens from the information associated with the plurality of past vulnerability attacks based on the analysis, wherein each token of the plurality of tokens comprises information associated with a specific past vulnerability attack of the plurality of past vulnerability attacks.
5. The method (400) according to claims 1, 2, 3, and 4, wherein generating the vulnerability ontology schema and the attack effect ontological schema further comprises: generating, by the processing unit (202) , the vulnerability ontological schema and the attack effect ontological schema based on an analysis of the generated second set of tokens .
6. The method (400) according to claims 1, 2, 3, 4, and 5, wherein determining at least one anomaly in the set of input parameters and the first set of output parameters comprises : applying, by the processing unit, the engineering behavior ontological schema on the received set of inputparameters to generate a second set of output parameters for the automation system; comparing, by the processing unit, the first set of output parameters and the second set of output parameters; and determining, by the processing unit, the at least one anomaly based on the comparison of the first set of output parameters and the second set of output parameters .
7. The method (400) according to claims 1, 2, 3, 4, 5, and 6, wherein predicting the potential vulnerability attack and the set of possible effects of the potential vulnerability attack comprises: comparing, by the processing unit (202) , the detected at least one anomaly with the plurality of anomalies depicted in the vulnerability ontological schema; matching, by the processing unit (202) , the detected at least one anomaly with a specific node of the vulnerability ontological schema based on the comparison; predicting, by the processing unit (202) , the potential vulnerability attack on the automation system 102 based on an analysis of the specific node of the vulnerability ontological schema; comparing, by the processing unit (202) , the specific node of the vulnerability ontological schema with a second node of the attack effect ontological schema based on an analysis of the detected at least one vulnerability attack and the vulnerability ontological schema ; determining, by the processing unit (202) , that the specific node of the vulnerability ontological schema matches with the second node of the attack effect onto- logical schema; anddetecting, by the processing unit (202) , the set of possible effects of the predicted potential vulnerability attack based on the determination.
8. The method according to claims 1 to 7, wherein outputting the user alert further comprises: initiating, by the processing unit (202) , a vulnerability sniffing operation on the automation system (102) based on the prediction of the potential vulnerability attack and the detected set of possible effects of the potential vulnerability attack; validating, by the processing unit (202) , the prediction of the potential vulnerability attack based on a result of the vulnerability sniffing operation; generating, by the processing unit (202) , the user alert based on the validation of the predicted potential vulnerability attack; and outputting, by the processing unit (202) , the generated user alert comprising information about the predicted vulnerability attack and the detected set of possible effects of the predicted potential vulnerability attack .
9. The method according to claims 1 to 8, wherein the engineering behavior ontological schema is a first knowledge graph comprising information associated with a plurality of interrelationships and a plurality of dependencies between a plurality of software components (109A-N) and a performance of a plurality of hardware objects (108A- N) associated with the plurality of software components (109A-N) .
10. The method according to claim 1 to 9, wherein the vulnerability ontological schema is a second knowledgegraph comprising information associated with a plurality of dependencies between a plurality of anomalies in the plurality of input parameters and the plurality of output parameters, and the plurality of past vulnerability attacks .
11. The method of according to claims 1 to 10, wherein the attack effect ontological schema is a third knowledge graph comprising information associated with a plurality of interrelationships and dependencies between the plurality of past vulnerability attacks on the automation system, and an effect of each of the plurality of past vulnerability attacks on the automation system.
12. An automation system configured to detect vulnerability attacks on the automation system, wherein the automation system comprises: one or more processor(s) (202) ; and a memory (204) coupled to the one or more processor (s) , wherein the memory comprises a vulnerability intelligence module (112) stored in the form of machine-readable instructions executable by the one or more processor (s) , wherein the vulnerability intelligence module (112) is capable of performing a method according to any of the claims 1 - 11.
13. A computer-program product, having machine-readable instructions stored therein, that when executed by a processing unit (202) , cause the processors to perform a method according to any of the claims 1-11.