Security function execution device
By identifying node criticality and mediating communication only between non-critical nodes, the method addresses the challenge of securing legacy OT systems without updates, ensuring effective security while preserving critical communication integrity.
Patent Information
- Application Number
- JP2024111611
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-07-19
- Filing Date
- 2024-07-11
- Publication Date
- 2025-06-19
- Estimated Expiration
- 2044-07-11
AI Technical Summary
Legacy operational technology (OT) systems face challenges in enabling security measures without system updates or configuration changes, and existing methods like network mediation can cause communication delays and resource depletion.
A method that identifies attributes of nodes communicating on a network, determines the criticality of each node, and mediates communication between non-critical nodes to perform security functions, thereby avoiding unnecessary communication mediation with critical nodes.
This approach enables effective security measures for legacy OT systems without disrupting critical communications, minimizing delays and resource exhaustion, and prioritizing protection of critical assets.
Smart Images

Figure 0007696046000001 
Figure 0007696046000002 
Figure 0007696046000003
Abstract
Description
Technical Field
[0001] The present disclosure is generally directed to methods and devices for performing security functions.
Background Art
[0002] Enabling security measures in legacy operational technology (OT) systems such as factory automation (FA) and process automation (PA) is particularly troublesome due to the need for system updates and / or partial replacements. In most cases, it is difficult to update all OT systems just to address security issues because the engineering costs are high. To enhance cybersecurity, the evaluation of cybersecurity risks and the planning of cost-effective countermeasures, including enabling temporary security measures for OT system users, are the areas of focus.
[0003] Network mediation (man-in-the-middle (MitM)) is useful for securing communication between two nodes with respect to legacy networks. However, using MitM on Internet Protocol-based (IP-based) networks (such as wired networks like Ethernet or wireless networks like WiFi) may cause communication delays and resource depletion. The resulting loss of control can have a significant impact on legacy OT systems. Therefore, it is difficult to apply the MitM approach to legacy IP-based network systems in OT systems.
[0004] In related art, a method for enabling a security function using a proxy server is disclosed. The proxy server implements the execution of the security function by mediating communication between nodes. However, the mediation of communication is performed for all communication between any two nodes on the network. This causes communication delays and reduces resource availability. Since production stoppages and losses of safety features may occur as a result of the communication delays, the impact is particularly significant for businesses that utilize legacy OT systems.
[0005] In addition, vulnerabilities are not the same across all nodes. For example, assume that two nodes are connected to one network (Network A), the first node is a Windows® personal computer (PC) connected to an enterprise system, and the other is an embedded system connected to another network through Network A. In that case, the Windows PC node is relatively more vulnerable than the embedded system node. An adversary may attack a critical node through a node that is more vulnerable than the critical node. Related art does not explain any rules for narrowing down communication to obtain an effective security effort.
[0006] There is a need to enable security measures in legacy OT systems without changing the system configuration and without additional updates. SUMMARY OF THE INVENTION
[0007] Aspects of the present disclosure include an innovative method for performing a security function. The method may include identifying, by a processor, attributes of a plurality of nodes communicating with a network; determining, by the processor, a criticality of each of the plurality of nodes based on the attributes; and mediating, by the processor, communication between nodes determined to be non-critical among the plurality of nodes and performing a security function on the mediated communication.
[0008] Aspects of the present disclosure include an innovative non - transitory computer - readable medium storing instructions for performing security functions. The instructions include identifying attributes of a plurality of nodes communicating with a network, determining the criticality of each node among the plurality of nodes based on the attributes, mediating communication between nodes determined to be non - critical among the plurality of nodes, and performing a security function on the mediated communication.
[0009] Aspects of the present disclosure include an innovative device communicating with a network for performing security functions. The device may include a processor, which is configured to identify attributes of a plurality of nodes communicating with the network, determine the criticality of each node among the plurality of nodes based on the attributes, mediate communication between nodes determined to be non - critical among the plurality of nodes, and perform a security function on the mediated communication.
[0010] Aspects of the present disclosure include an innovative system for performing security functions. The system may include means for identifying attributes of a plurality of nodes communicating with a network, means for determining the criticality of each node among the plurality of nodes based on the attributes, and means for mediating communication between nodes determined to be non - critical among the plurality of nodes and performing a security function on the mediated communication.
[0011] Hereinafter, a general architecture for implementing various features of the present disclosure will be described with reference to the drawings. The drawings and the related description are provided to illustrate exemplary realizations of the present disclosure and do not limit the scope of the present disclosure. Throughout the drawings, reference numerals are reused to indicate corresponding relationships between the elements being referred to.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
[0013] The following detailed description provides details of the drawings and exemplary implementations of the present application. Reference numerals and descriptions of overlapping elements between the drawings are omitted for clarity. The terms used throughout the description are provided by way of example and are not intended to be limiting. For example, the use of the term "automatic" may include fully automatic implementations or semi-automatic implementations that require user or administrator control for specific aspects of the implementation, depending on the desired implementation by those skilled in the art of practicing the implementations of the present application. The selection can be implemented by the user through a user interface or other input means, or can be realized through a desired algorithm. Exemplary implementations as described herein can be used alone or in combination, and the functionality of the exemplary implementations can be realized through any means according to the desired implementation.
[0014] Exemplary implementations of the present invention relate to a method and system for executing a security function for intercepting communication between flagged nodes. The flags are defined based on the criticality of each node connected to the network. The criticality is defined based on the role and processing state of the node's system architecture. The security function is executed while restricting communication mediation for nodes with low criticality. Network data collection can be performed on the network of the target system or on nodes connected to the network through any automatic or manual method. At the same time, based on the role and state of each node, attributes regarding criticality can also be determined. Exemplary implementations also enable security functions such as detailed packet anomaly analysis, packet filtering, and authentication functions.
[0015] Figure 1 shows a communication system 20 according to an exemplary implementation example. As shown in Figure 1, the communication system 20 may include components such as, but not limited to, a device 100, a network switch (SW) 110, a network gateway (GW) 120, a human-machine interface (HMI) 130, a plurality of programmable logic controllers (PLCs) (e.g., PLC 140 and PLC 150), an enterprise network 160, etc.
[0016] The device 100 has the ability to join any IP-based network. Regarding an Ethernet-based network, the device 100 has the ability to join the network via a free port of the network switch 110. The device 100 can obtain its own Internet Protocol (IP) address for the network manually or automatically (DHCP, network capture, self-IP assignment, etc.). When obtaining its own IP address, the device 100 collects information about the network. The device 100 attempts to scan the network by using a network and port scanning method or by loading a packet capture (PCAP) file that can be obtained from the network switch 110. The device 100 also has the ability to load information manually input by the user via a graphical user interface (GUI) or a command-line interface (CLI).
[0017] The device 100 determines the criticality of each node identified by the device 100 within the network by an algorithm processed by the computing features of the device 100. The criticality is represented as a set of attributes or as a numerical value such as a level for each node. The numerical values can be calculated from those attributes. Table T1 as shown in Figure 1 shows the criticality associated with various nodes of the communication system 20. For example, the "non-critical" criticality is associated with the network GW 120.
[0018] Communication mediation between any two nodes joined to the same network is performed by device 100. Specifically, device 100 uses the criticality associated with each node to select the communication to be mediated. Communication mediation is performed between nodes determined to be non-critical, and communication between nodes that are critical is excluded from communication mediation. Taking the table T1 in FIG. 1 as an example, the communication with the network GW 120 and the HMI 130 is selected to be mediated because it has a criticality of "non-critical". FIG. 2 shows an example diagram illustrating the application of the security function to communication according to an exemplary implementation. In the case of nodes determined to be non-critical assets (for example, node 202 and node 204), the security function 208 of device 100 can be applied to the communication between the nodes to ensure communication security.
[0019] Referring to FIG. 1 again, device 100 does not mediate the communication between PLC 140 and PLC 150. In most cases, the communication between PLCs includes control data that is critical and essential for the system control process. If the communication between PLCs is mediated, this may lead to loss of data communication and problems in control operations. As shown in FIG. 2, the communication with node 206 (for example, a PLC) is excluded from communication mediation by device 100, and thus the security function 208 is not applied. Therefore, device 100 enables effective security measures against legacy systems while restricting the communication to be mediated.
[0020] Devices that utilize current enterprise operating systems tend to be more vulnerable than those that do not. For example, when network GW 120 is connected to enterprise network 160, network GW 120 becomes more vulnerable than other nodes on the same network. An adversary may attack PLCs (e.g., PLC 140, PLC 150, etc.) via network GW 120. Therefore, it is necessary to protect the communication between network GW 120 and the PLCs with higher priority than the communication between PLCs.
[0021] Figure 3 shows a system 300 of an example of device 100 according to an exemplary implementation. As shown in Figure 3, system 300 may include components such as a security function execution management unit 302, an interface unit 304, a user interface (UI) unit 306, a node management unit 308, a MitM unit 310, and an asset scan and management unit 312. Interface unit 304 causes device 100 to join a network controlled by network switch 110. UI unit 306 supports communication with the user through graphic image display and / or command line input.
[0022] Node management unit 308 manages the nodes detected by device 100 through node characteristic management, which may include identification and population of node addresses and attributes. MitM unit 310 performs communication mediation between the nodes joined to the network. Asset scan and management unit 312 performs node scan and analysis of the nodes joined to the network. In addition, asset scan and management unit 312 can connect to a database on the secondary memory of device 100, refer to the database, retrieve the attributes associated with each node, and perform additional processing.
[0023] The security function execution and management unit 302 performs security function execution such as detailed packet anomaly analysis, packet filtering, and authentication for the communication mediated by the device 100. Each security function may be implemented by different security modules of the security function execution and management unit 302 (for example, detailed packet anomaly analysis may be implemented by the security module 314, packet filtering may be implemented by the security module 316, authentication may be implemented by the security module 318, etc.).
[0024] In some exemplary implementations, the various units can be realized by a software library including OS native functions, and the software data is stored in the secondary memory of the device 100. In some exemplary implementations, some or all of the functions of each unit may be realized as hardware logic.
[0025] FIG. 4 shows a hardware architecture example of the device 100 according to an exemplary implementation. The hardware architecture may include components such as a central processing unit (CPU) 402, a random access memory (RAM) 404, a user interface (UI) 406, a network interface (IF) 408, and a secondary memory 410. In some exemplary implementations, the secondary memory 410 is a non-volatile memory device. The secondary memory 410 stores program data / programs 414 such as instructions for implementing the functions of the device 100, as well as any tools such as network scans, UI applications, database management, and other support applications. The secondary memory 410 may also include a database 416 for referring to the criticality associated with each node. The various components communicate with each other through a bus 412.
[0026] The criticality of a node means to what extent a security function execution device should not affect the business functions processed by the node. Criticality can be expressed by expressions such as "critical" or "non-critical". The criticality of each node is defined based on the role and processing state of the node's system architecture.
[0027] A node is critical if the following conditions are met: (a) the node handles critical processes of business operations, and (b) the node does not have sufficient computing resources and the unintended consumption of resources may affect its business functions. In some exemplary implementations, the sufficiency of computing resources is determined by determining whether the computing resources are above a resource threshold. If the computing resources are less than the resource threshold and the node is used to handle critical processes of business operations, the node is determined to be critical. A node is non-critical if the following conditions are met: (a) the node does not handle critical processes of business operations, and (b) the node has sufficient computing resources and the unintended consumption of resources is acceptable to a certain extent. For example, if the computing resources are above the resource threshold and the node does not handle critical processes of business operations, the node is determined to be non-critical.
[0028] In some exemplary implementations, criticality can be determined from the system architecture and / or processing state. The system architecture may include the network structure (whether connected to an external network), the type of device (e.g., enterprise OS, embedded device, etc.), and the application type (e.g., server, data logging, field control, visualization of control, etc.). The processing state may include the resources defined for each node (e.g., CPU, memory, etc.) and the processing state (e.g., "stopped", "running", etc.).
[0029] In some exemplary implementations, the criticality can be determined by using a determination algorithm. Such an algorithm may include a rule-based algorithm (e.g., decision tree, decision matrix, etc.). In addition, the criticality can also be determined based on a predetermined business category model or asset state model.
[0030] FIG. 5 shows an example of a business category model for determining criticality according to an exemplary implementation. The Purdue (registered trademark) Enterprise Reference Architecture (PERA, ISA-95) is shown in FIG. 5. PERA is an architecture reference model commonly used in industrial automation and control systems.
[0031] Six levels of business functions, including software components and hardware components, are defined using PERA. Lv.0 corresponds to the field device layer and may include sensors, actuators, signals, etc. Lv.1 corresponds to the controller layer and may include basic control. Lv.2 corresponds to the supervisory control and data acquisition (SCADA) layer and may include supervisory control. Lv.3 corresponds to the manufacturing operations management (MOM) / manufacturing execution system (MES) layer and may include manufacturing operations, etc. Lv.4 corresponds to the enterprise resource planning (ERP) system and business strategy layer and may include business management operations. Finally, Lv.5 corresponds to the Internet and cloud layer that links external services. As shown in FIG. 5, the criticality is lowest at Lv.5 and highest at Lv.0.
[0032] The asset status model is a relational model between the asset status and the criticality. The asset status such as hardware, platform software such as operating systems, network connectivity or computing, and data processing performance can be used to determine the criticality of the asset. If a node is an embedded device with limited computing resources or a device with very low communication response performance, the criticality of the node is "high".
[0033] In some exemplary implementations, if a node is a device having an enterprise OS (e.g., Windows®, Linux®, etc.), a device with high communication response performance, or a device connected to an external network such as the Internet, the criticality of the node is set to "low". Such nodes are known to have high data processing performance and high security risks.
[0034] In some exemplary implementations, the criticality of a node can be determined by the feature quantity associated with the node. The feature quantity can be obtained from information or data obtained from the node, the network to which the node belongs, the system design document, or user input information.
[0035] FIG. 6 shows a criticality determination flow 600 of an example using a feature quantity decision tree according to an exemplary implementation. As shown in FIG. 6, if a node has a feature quantity of "connected to any external network", the node is determined to be non-critical. If a node has a feature quantity of "not connected to any external network", additional feature quantity determination for the application type is performed. Specifically, if a node has a feature quantity of "field control", the node is determined to be critical. On the other hand, if the feature quantity associated with the application is other than field control, the node is determined to be non-critical.
[0036] Figure 7 shows a process flow 700 of an example of implementing communication mediation according to an exemplary implementation. The process flow 700 may be started when the device 100 joins the network or at any time determined by the user. The process starts at step S702, where the device 100 determines its network address. At step S704, the device 100 analyzes the network to obtain data / information about the network. At step S706, the device 100 determines the attributes of each node. In some exemplary implementations, the attributes of each node can be manually input by the user via the UI unit 306.
[0037] Next, at step S708, the device 100 determines the criticality of each node based on the received attributes. The criticality of each node is determined by attributes such as device type (e.g., host device, embedded device, etc.), operating system (OS) (e.g., Microsoft Windows®, Linux®, non-enterprise OS, etc.), and other software such as application software or middleware, the network to which the node is connected, and the role in the system (e.g., control device, data collection, engineering, monitoring data management, web application, networking, etc.). In some exemplary implementations, the device 100 can also determine the criticality from risk assessment results generated by human or automated methods using the attributes.
[0038] The process then proceeds to step S710, where device 100 generates data that includes node information such as an IP or Media Access Control (MAC) address. The node data is generated in a reusable format such as JSON, YAML, SQL, and any other data format supported by a database management system. Any program / software running on device 100, or other applications running outside of device 100 but given access to the node data, can retrieve those data at any time as needed.
[0039] In step S712, device 100 determines the communications to be mediated. Finally, in step S714, device 100 determines possible security measures and executes them among the selected communications.
[0040] Device 100 also has the ability to join an IP-based wireless network. FIG. 8 shows a communication system 800 according to an exemplary implementation. Device 100 has the ability to join an IP-based wireless network 804 controlled by an access point (AP) 802. The device also has the ability to masquerade as an AP210, which can be masqueraded by device 100 using any wireless-based intermediary method. Communications between any two nodes within the wireless network managed by AP210 can be mediated using device 100.
[0041] The above-described exemplary implementations can have various benefits and advantages. For example, it enables security measures such as detailed packet anomaly analysis, packet filtering, and authentication in legacy systems, and can minimize system communication delays and resource exhaustion. In addition, effective security measures can be implemented to protect critical assets from attacks via vulnerable nodes.
[0042] FIG. 9 illustrates an example computing environment having an example computer device suitable for use in some exemplary implementations. The computer device 905 of the computing environment 900 can include one or more processing devices, cores, or processors 910, a memory 915 (e.g., RAM, ROM, and / or others), internal storage 920 (e.g., magnetic, optical, solid state storage, and / or organic), and / or an IO interface 925, all of which can be coupled by a communication mechanism or bus 930 that communicates information, or can be embedded within the computer device 905. The IO interface 925 can also be configured to receive images from a camera or provide images to a projector or display, depending on the desired implementation.
[0043] The computer device 905 can be communicatively coupled to an input / user interface 935 and an output device / interface 940. Either or both of the input / user interface 935 and the output device / interface 940 can be a wired or wireless interface and can be removable. The input / user interface 935 can include any physical or virtual device, component, sensor, or interface (e.g., buttons, touch screen interface, keyboard, pointing / cursor control, microphone, camera, braille, motion sensor, accelerometer, optical reader, and / or others) that can be used to provide input. The output device / interface 940 can include a display, television, monitor, printer, speaker, braille, etc. In some exemplary implementations, the input / user interface 935 and the output device / interface 940 can be embedded within or physically coupled to the computer device 905. In other exemplary implementations, other computer devices can function as or provide the functionality of the input / user interface 935 and the output device / interface 940 of the computer device 905.
[0044] Examples of computer device 905 may include, but are not limited to, highly mobile devices (such as smartphones, devices in automobiles and other machinery, devices carried by people and animals, etc.), mobile devices (such as tablets, notebooks, laptops, personal computers, portable TVs, radios, etc.), and devices not designed for mobility (such as desktop computers, other computers, information kiosks, TVs with one or more processors embedded therein and / or TVs to which they are coupled, radios, etc.).
[0045] Computer device 905 can be communicatively coupled to external storage 945 and network 950 (e.g., via IO interface 925) for communicating with any number of networked components, devices, and systems including one or more computer devices of the same or different configurations. Computer device 905, or any connected computer device, can function as, provide services as, or be referred to by the name of a server, client, synserver, general-purpose machine, dedicated machine, or another label.
[0046] IO interface 925 can include wired and / or wireless interfaces that use any communication or IO protocol or standard (such as Ethernet, 802.11x, Universal System Bus (USB), WiMAX, modems, cellular network protocols, etc.) for communicating information between at least all connected components, devices, and networks of computing environment 900, but is not limited thereto. Network 950 can be any network or combination of networks (such as the Internet, local area network, wide area network, telephone network, cellular network, satellite network, etc.).
[0047] The computer device 905 can use and / or communicate using computer-usable or computer-readable media, including transient media and non-transient media. Transient media includes transmission media (e.g., metal cables, optical fibers), signals, carrier waves, etc. Non-transient media includes magnetic media (e.g., disks and tapes), optical media (e.g., CD ROM, digital video disks, Blu-ray disks), solid media (e.g., RAM, ROM, flash memory, solid state storage), and other non-volatile storage or memory.
[0048] The computer device 905 can be used to implement technologies, methods, applications, processes, or computer-executable instructions in some computing environment examples. Computer-executable instructions can be retrieved from transient media and stored in and retrieved from non-transient media. The executable instructions can be by one or more of any programming, scripting, and machine languages (e.g., C, C++, C#, Java, Visual Basic, Python, Perl, JavaScript, etc.).
[0049] The processor 910 can execute under any operating system (OS) (not shown) in a native or virtual environment. One or more applications can be deployed, including a logic unit 960, an application programming interface (API) unit 965, an input unit 970, an output unit 975, and an inter-unit communication mechanism 995 for the different units to communicate with each other, with the OS, and with other applications (not shown). The described units and elements can vary in design, function, configuration, or implementation and are not limited to the provided description. The processor 910 can be in the form of a hardware processor such as a central processing unit (CPU) or a combination of hardware and software units.
[0050] In some exemplary implementations, when information or execution instructions are received by API unit 965, they may be communicated to one or more other units (e.g., logic unit 960, input unit 970, output unit 975). In some examples, logic unit 960 may control the information flow between units and, in some of the exemplary implementations described above, may be configured to direct the services provided by API unit 965, input unit 970, and output unit 975. For example, the flow of one or more processes or implementations may be controlled by logic unit 960 alone or in combination with API unit 965. Input unit 970 may be configured to obtain inputs for the calculations described in the exemplary implementations, and output unit 975 may be configured to provide outputs based on the calculations described in the exemplary implementations.
[0051] Processor 910 can be configured to identify the attributes of multiple nodes in communication with a network as shown in FIGS. 2 and 6 - 7. Processor 910 may also be configured to determine the criticality of each of the multiple nodes based on the attributes, as shown in FIGS. 2 and 6 - 7. Processor 910 may also be configured to mediate communication between nodes determined to be non - critical among the multiple nodes and perform security functions on the mediated communication, as shown in FIGS. 2 and 6 - 7.
[0052] Some portions of the detailed description are presented in terms of algorithms and symbolic representations of operations within a computer. These algorithmic descriptions and symbolic representations are the means used by those skilled in the data processing arts to convey the essence of their technological innovations to others skilled in the art. An algorithm is a series of defined steps leading to a desired final state or result. In the exemplary implementations, the steps taken involve physically manipulating physical quantities to achieve a tangible result.
[0053] Unless otherwise specifically stated, as will be apparent from the discussion, throughout the description, discussions using terms such as "processing", "computing", "calculating", "determining", "displaying", etc. can involve operating on data presented as physical (electronic) quantities in the registers and memories of a computer system and converting it into other data presented as physical quantities in the memory or registers of the computer system or other information storage devices, transmission devices, or display devices, and can be recognized as including the operations and processes of a computer system or other information processing device.
[0054] Exemplary implementations may also relate to an apparatus for performing the operations of this specification. This apparatus may be specially constructed for the required purposes or may include one or more general-purpose computers selectively activated or reconfigured by one or more computer programs. Such computer programs may be stored on a computer-readable medium such as a computer-readable storage medium or a computer-readable signal medium. The computer-readable storage medium may include a tangible medium such as, but not limited to, optical disks, magnetic disks, read-only memory, random access memory, solid-state devices, and drives, or any other type of tangible or non-transitory medium suitable for storing electronic information. The computer-readable signal medium may include a medium such as a carrier wave. The algorithms and displays presented herein are not inherently related to any particular computer or other device. The computer programs can include pure software implementations that include instructions for performing the operations of the desired implementation.
[0055] A variety of general-purpose systems may be used with the programs and modules according to the examples herein, or it may prove convenient to construct more specialized devices that perform the desired method steps. Additionally, the exemplary implementations are not described with reference to any particular programming language. It will be recognized that various programming languages may be used to implement the teachings of the exemplary implementations as described herein. The instructions of a programming language may be executed by one or more processing devices, such as a central processing unit (CPU), a processor, or a controller.
[0056] As is known in the art, the operations described above can be implemented by hardware, software, or some combination of software and hardware. Various aspects of the exemplary implementations may be realized using circuits and logic devices (hardware), and other aspects may be realized using instructions stored on a machine-readable medium (software) that, when executed by a processor, cause the processor to implement the method of the implementations of this application. Further, some of the exemplary implementations of this application may be implemented by hardware alone, and other exemplary implementations may be implemented by software alone. Further, the various functions described can be implemented in a single unit or spread across multiple components in various ways. When implemented by software, the method may be executed by a processor, such as a general-purpose computer, based on instructions stored on a machine-readable medium. If desired, the instructions can be stored on the medium in a compressed and / or encrypted form.
[0057] Furthermore, other implementations of this application will be apparent to those skilled in the art upon consideration of this specification and practice of the teachings of this application. The various aspects and / or components of the described exemplary implementations may be used alone or in any combination. This specification and the exemplary implementations are regarded as merely illustrative, and the true scope and spirit of this application are to be indicated by the following claims.
Claims
1. 1. A security function performing device in communication with a network, comprising: a processor, the processor comprising: identifying attributes of a plurality of nodes in communication with said network; determining a criticality of each node among the plurality of nodes based on the attributes; Mediating only communications between nodes determined to be non-critical among the plurality of nodes, and executing a security function for the mediated communications The device is configured to:
2. determining a criticality of each node among the plurality of nodes based on the attribute; determining a criticality of a node connected to an external network among the plurality of nodes as non-critical; determining a criticality of a node having a field control application among the plurality of nodes as critical; determining a criticality of a node having an application other than a field control among the plurality of nodes as non-critical; The device of claim 1 , comprising:
3. The device of claim 2 , further comprising, for a node of the plurality of nodes determined to be critical, excluding the node from communication mediation.
4. determining a criticality of each node among the plurality of nodes based on the attribute; determining a criticality of a node associated with a critical process of a business operation among the plurality of nodes as critical; For a node among the plurality of nodes determined to have a computing resource less than a resource threshold, determining a criticality of the node as critical; determining a criticality of a node among the plurality of nodes that is not associated with a critical process of a business operation as non-critical; determining a criticality of a node among the plurality of nodes that is determined to have a computing resource equal to or greater than the resource threshold as non-critical; The device of claim 1 , comprising:
5. The device of claim 1 , wherein identifying attributes of the plurality of nodes in communication with the network comprises automatically retrieving the attributes of the plurality of nodes from the network.
6. the plurality of nodes includes software components, hardware components, or a combination of software and hardware components; The software components include a supervisory control and data acquisition (SCADA) system, a manufacturing execution system (MES), a manufacturing operations management (MOM) system, and an enterprise resource planning (ERP) system; The hardware components include field devices, controllers, and servers; The device of claim 1 .
7. The device of claim 1 , wherein the attributes include a network structure, a device type, an application, a resource, and a processing state associated with the plurality of nodes.
8. the network is a wireless network, and the plurality of nodes communicate with the wireless network through an access point that manages the wireless network; identifying attributes of the plurality of nodes in communication with the network includes identifying the attributes of the plurality of nodes by scanning the access points; The device of claim 1 .
9. identifying, by a processor, attributes of a plurality of nodes in communication with the network; determining, by the processor, a criticality of each node of the plurality of nodes based on the attributes; mediating, by the processor, only communications between nodes determined to be non-critical among the plurality of nodes, and executing a security function for the mediated communications; 23. A method for performing a security function, comprising:
10. determining a criticality of each node among the plurality of nodes based on the attribute; determining a criticality of a node connected to an external network among the plurality of nodes as non-critical; determining a criticality of a node having a field control application among the plurality of nodes as critical; determining a criticality of a node having an application other than a field control among the plurality of nodes as non-critical; 10. The method of claim 9, comprising:
11. With respect to a node determined to be critical among the plurality of nodes, excluding the node from communication mediation. The method of claim 10 further comprising:
12. determining a criticality of each node among the plurality of nodes based on the attribute; determining a criticality of a node associated with a critical process of a business operation among the plurality of nodes as critical; For a node among the plurality of nodes determined to have a computing resource less than a resource threshold, determining a criticality of the node as critical; determining a criticality of a node among the plurality of nodes that is not associated with a critical process of a business operation as non-critical; determining a criticality of a node among the plurality of nodes that is determined to have a computing resource equal to or greater than the resource threshold as non-critical; 10. The method of claim 9, comprising:
13. 10. The method of claim 9, wherein identifying attributes of the plurality of nodes in communication with the network comprises automatically retrieving the attributes of the plurality of nodes from the network.
14. the plurality of nodes includes software components, hardware components, or a combination of software and hardware components; The software components include a supervisory control and data acquisition (SCADA) system, a manufacturing execution system (MES), a manufacturing operations management (MOM) system, and an enterprise resource planning (ERP) system; The hardware components include field devices, controllers, and servers; 10. The method of claim 9.
15. The method of claim 9 , wherein the attributes include a network structure, a device type, an application, a resource, and a processing state associated with the plurality of nodes.
16. the network is a wireless network, and the plurality of nodes communicate with the wireless network through an access point that manages the wireless network; identifying attributes of the plurality of nodes in communication with the network includes identifying the attributes of the plurality of nodes by scanning the access points; 10. The method of claim 9.
Citation Information
Patent Citations
A routing planning method for power backbone transmission network based on multi-attribute decision-making
CN105376156B
Mediation method and system for authentication
JP2009086802A
Security groups for VLANs
US20050190758A1