Filtering network traffic based on a conformity status of a communication endpoint

By using compliance status-dependent filter rules, the method addresses the challenge of filtering network traffic in legacy systems, enhancing security and supporting real-time communication by preventing non-compliant endpoints from transmitting data.

WO2025113962A1PCT designated stage expired Publication Date: 2025-06-05SIEMENS AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/081799
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-28
Filing Date
2024-11-11
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing network systems struggle to effectively filter network traffic based on the compliance status of communication endpoints, especially in legacy systems that lack support for context checks or access to device compliance information.

Method used

A method for providing filter rules that depend on the compliance status of communication endpoints, allowing for the adjustment and updating of existing filter rules based on the compliance status of nodes within a communication connection.

Benefits of technology

This approach enables improved filtering of network traffic, preventing non-compliant communication endpoints from transmitting data, thereby enhancing security and reducing the risk of attacks or denial-of-service incidents, while also supporting real-time critical communication without delaying connection establishment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024081799_05062025_PF_FP_ABST
    Figure EP2024081799_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for providing at least one filter rule (aFR) for filtering network traffic between at least one first node (1) and at least one second node (2) of a communication connection, comprising the steps of: - calling on (S2) at least one conformity status of the first node (1) and / or the second node (2), - defining (S3) the at least one filter rule (aFR) based on the at least one conformity status, wherein the defining (S3) of the at least one filter rule (aFR) comprises: o adjusting (S3a) at least one existing filter rule (FR), and - providing (S4) the at least one filter rule (aFR). The invention also relates to a computer program product, a component and a superordinate system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Filtering network traffic based on a communication endpoint's compliance status

[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.

[0004] BACKGROUND OF THE INVENTION

[0005] Field of the invention

[0006] The invention relates to a method for providing at least one filter rule. Furthermore, the invention relates to a computer program product, a component for a network, and a higher-level system.

[0007] Description of the state of the art

[0008] Network devices (firewalls, routers, switches) are known for forwarding and filtering network packets on a transmission path between endpoints of an end-to-end communication connection (e.g., TCP, UDP, QUIC, OPC UA, HTTP, MQTT, GOOSE / SV / MMS / GSSE according to IEC 61850). The goal of filtering network packets is, among other things, to prevent a potentially dangerous network packet from reaching the receiving endpoint. To minimize security risks, network devices and filters must be continuously improved and developed.

[0009] It is known that an endpoint security application can be installed on a terminal device (PC, notebook) that filters the network traffic on the endpoint.

[0010] Regardless, it is known that an endpoint security application can be installed on a device (PC, notebook) that checks the compliance status of the endpoint. A failed compliance check, according to current technology, leads to remediation.

[0011] It is known from VPN solutions such as Zscaler that the VPN endpoint (Zscaler server) checks the compliance status of the accessing device and, depending on this, allows or rejects the establishment of a VPN to access resources.

[0012] It is known that a device management system can manage a device's compliance status. A device identified as non-compliant can be handled in different ways. Possible actions include, among others: sending an email or push notification; marking the device as non-compliant in a device directory service; remote locking; and retire (i.e., deleting company data from the device).

[0013] It is also known that device compliance status can be checked for access control decisions on a target system.

[0014] The object of the invention is to provide a solution for improved filtering of data within a communication connection.

[0015] SUMMARY OF THE INVENTION

[0016] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention will become apparent from the following description and the drawings.

[0017] The invention relates to a method for providing at least one filter rule for filtering network traffic between at least one first node and at least one second node of a communication connection, comprising the steps of: - Using at least one conformity status

[0018] (also referred to as "compliance status") of the first node and / or the second node,

[0019] - setting the at least one filter rule based on (also to be understood as "dependent on") the at least one conformity status, wherein setting the at least one filter rule comprises: o adjusting (also to be understood as updating) at least one existing filter rule, and

[0020] - providing at least one filter rule.

[0021] According to the invention, the provision of at least one filter rule depends on at least one conformity status of the first node and / or the second node, in particular at least one communication endpoint. For this purpose, the conformity status of the at least one communication endpoint is used, and the at least one filter rule for filtering the network traffic is defined based thereon.

[0022] The at least one existing filter rule is to be considered as at least one previous filter rule that already exists. In particular, it is at least one administratively previously established filter rule. In particular, the at least one existing filter rule is also designed as a filter rule determined by a previous execution of the method according to the invention. This is advantageous if the at least one conformity status changes and the method according to the invention is executed again.

[0023] By specifying at least one filter rule, at least one existing filter rule will be deleted and / or overwritten.

[0024] The at least one first node and / or the at least one second node are in particular designed as a first and a second end point of an end-to-end communication connection, ie a first and a second communication end point.

[0025] The at least one first node and / or the at least one second node are designed in particular as:

[0026] - an Internet of Things device,

[0027] - a control unit,

[0028] - an automation device, and / or

[0029] - a production cell.

[0030] With a state-of-the-art zero-trust security approach, every access attempt is verified by the target system. In addition to authenticating the accessing user, contextual information can also be verified. In particular, the compliance status of the accessing device used by the user can be checked—that is, whether it is configured according to the defined specifications.

[0031] However, according to the current state of the art, checking the compliance status requires the target system to be able to check the device's compliance status and that the target system has access to the device's compliance information. However, this may not always be the case in practice, especially if the target system is a brownfield system that does not support this context check, or if the target system is located in a different administration area for which the device's compliance status cannot be queried, especially since there is no access to the device management system or the device directory service.

[0032] With regard to the described problems of the previous state of the art, the invention offers, among other things, the advantage that a device compliance check, which is common in a zero-trust security strategy, can be implemented in existing systems (also referred to as "brownfield systems"). Communication endpoints that do not meet the specifications, i.e. are not compliant (also "non-compliant"), cannot communicate or can only communicate to a limited extent via the defined filter rule (and the implementing network component, in particular the firewall). Data from a node / device that does not meet the specifications is not initially rejected by the communication endpoint, but is (at least partially) blocked earlier along the communication connection (also known as the network transmission path). This limits the possibility that the affected communication endpoint can attack other devices or carry out a denial-of-service attack.It also avoids interference with real-time data transmission to other devices.

[0033] Furthermore, the device compliance check (determining at least one compliance status) can be performed independently of a specific access, i.e., a connection establishment. This has the advantage that the connection establishment is not delayed by zero-trust authorization checks.

[0034] Furthermore, communication protocols can be reused directly for the communication connection, i.e., without protocol adaptation and without tunneling them through a VPN. Therefore, this approach can also be applied to real-time-critical communication.

[0035] The communication connection is designed in particular as:

[0036] - An end-to-end communication connection (e.g. TCP, UDP, QUIC, OPC UA, HTTP, MQTT, GOOSE / SV / MMS / GSSE according to IEC61850),

[0037] - a real-time communication connection,

[0038] - a unicast connection,

[0039] - a multicast connection, and / or

[0040] - a group connection. A real-time communication connection can be, for example, a TSN real-time communication connection (TSN: Time Sensitive Networking), a DetNet real-time communication connection (DetNet: Deterministic Networking), a Profinet real-time communication connection, a Profibus real-time communication connection, a TSC real-time communication connection (TSC: Time-sensitive Communications), or a URLLC real-time communication connection (URLLC: Ultra-Reliable Low Latency Communication).

[0041] According to the invention, the at least one filter rule is defined based on the at least one conformity status of the first node and / or the second node. In the case of a unicast transmission, in particular the compliance status of one of the two communication endpoints or both communication endpoints is taken into account. In the case of a multicast transmission or group communication, in particular the compliance status of a communication endpoint, a subset of the communication endpoints or all communication endpoints of the multicast transmission or the group of communication endpoints is taken into account.

[0042] In a further variant, the compliance status of other network devices in the communication connection is also taken into account. This is advantageous if a plurality or multiplicity of components (in particular packet filters and / or firewalls) are provided for filtering network traffic using the at least one filter rule.

[0043] In a further development of the invention, the method according to the invention comprises the following steps:

[0044] - Determining at least one conformity status,

[0045] - storing (also referred to as depositing) the at least one conformity status (in particular in a list comprising the at least one first node and / or the at least one second node, each with the associated at least one conformity status), and / or retrieving the at least one conformity status.

[0046] The steps of this embodiment in particular precede the inventive use of at least one conformity status.

[0047] According to one embodiment, the at least one conformity status is determined when a connection is established between the at least one first node and the at least one second node of the communication connection.

[0048] Preferably, however, the at least one conformity status is determined in advance based on a list comprising the communication endpoints, i.e. comprising the at least one first node and / or the at least one second node. In particular, the compliance status of the communication endpoints contained in the list is determined periodically, in particular daily or hourly, and the at least one filter rule is defined depending thereon, in particular by adapting an existing filter rule, in particular a filter rule previously set up administratively. In one variant, the at least one conformity status is determined repeatedly, depending on an operating status of at least one production facility such as a robot or a machine tool.This has the advantage that the conformity status can be determined during a non-critical production phase, so that the production process is not influenced or impaired. Furthermore, it is possible for the filter rule to be made available during a non-critical production phase and / or to be defined only during a non-critical production phase. This has the advantage that no changed, modified or updated filter rule is defined during a critical production phase. The list of communication endpoints is, in particular, administratively specified, i.e., configured or projected. Furthermore, it is possible for the list of communication endpoints to be determined based on an existing filter rule, in particular a filter rule that was previously set up administratively.Furthermore, it is possible that the list of communication endpoints is determined automatically based on previous network traffic (i.e. data transmissions), in particular through prior training, e.g. using artificial intelligence.

[0049] In a further development of the invention, the determination of at least one conformity status is based on:

[0050] - Retrieving at least one directory entry relating to the at least one conformity status, in particular from a device management system or from a device directory service, for the at least one first node and / or the at least one second node,

[0051] - at least one integrity attestation of the at least one first node and / or of the at least one second node, and / or

[0052] - at least one fingerprint of the at least one first node and / or of the at least one second node, wherein the at least one fingerprint was determined in particular by scanning (scanning the communication connection) of the first node and / or the second node.

[0053] In a further development of the invention, the method according to the invention comprises the following steps:

[0054] - Using at least one filter rule, and

[0055] - filtering the network traffic between the first node and the second node of the communication connection using (also understood as "based on") the at least one filter rule. The steps of this embodiment follow in particular the provision of the at least one filter rule according to the invention.

[0056] In a further development of the invention, the use of at least one conformity status is preceded by:

[0057] - a notification concerning a change of at least one previous compliance status of the first node and / or the second node.

[0058] The change in the at least one previous conformity status thus triggers the inventive use of the at least one conformity status and thus in turn the subsequent specification of the at least one filter rule. According to this embodiment, the notification regarding the change in the at least one previous conformity status of the first node and / or the second node is used to specify the at least one filter rule. For this purpose, in particular a device management unit (also a device management system) or a device directory service, upon a detected change in the compliance status of the first node and / or the second node, provides a push message to the unit executing the inventive method in order to trigger the specification of the at least one filter rule (or in particular an adaptation / updating of an existing filter rule).

[0059] The change to the at least one previous conformity status of the first node and / or the second node is particularly designed as a deletion and / or an overwriting of the previous conformity status of the first node and / or the second node. The change to the at least one previous conformity status results in a determination of the at least one conformity status, which is used according to the invention to define the at least one filter rule based thereon. In a further development of the invention, the definition of the at least one filter rule also comprises:

[0060] - A definition of a monitoring intensity (also referred to as monitoring depth) of the communication connection by at least one filter rule.

[0061] By specifying a monitoring intensity, also known as the monitoring depth, of the communication connection, it is possible to define, and in particular adapt, at least one filter rule for affected network traffic in such a way that this network traffic is subjected to more intensive monitoring. This is implemented, in particular, by selecting a monitoring unit from several monitoring units, each with varying levels of monitoring, to which the affected network traffic is routed, depending on the compliance status.

[0062] In a further development of the invention, the network traffic comprises:

[0063] - at least one network packet,

[0064] - at least one data packet,

[0065] - at least one IP packet, and / or

[0066] - at least one Ethernet frame, each of which can also be described as an element of network traffic.

[0067] The at least one filter rule for filtering the network traffic is thus provided for filtering the elements of the network traffic according to this embodiment.

[0068] In a further development of the invention, the at least one filter rule:

[0069] - A blockade,

[0070] - a forwarding,

[0071] - a redirection (also referred to as a forwarding, especially to a mirror port), and / or

[0072] - assigning to a queue (in particular for quality-of-service-aware scheduling, e.g. for real-time data transmission) for at least part of the network traffic.

[0073] Redirection is specifically specified to save the redirected network traffic for later analysis ("full packet capture") and is performed depending on the compliance status.

[0074] The invention also comprises a computer program product comprising a computer program, wherein the computer program is loadable into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit.

[0075] The invention further encompasses a component for a network, in particular a network device and / or a network component, comprising a computer program product according to the invention, configured to execute the computer program. The component for the network is configured to be operated in the network.

[0076] In a further development of the invention, the “component for the network” according to the invention is designed as:

[0077] - a firewall, a packet filter, a router and / or a switch or

[0078] - a management component (also referred to as a "Network Security Manager") designed to manage a "further component for a network." The "further component for a network" is designed, in particular, as a firewall, a packet filter, a router, and / or a switch.

[0079] The functionality for determining the device compliance status and adjusting the filter rules is thus implemented either in a network component that is also configured for filtering: a firewall, a packet filter, and / or a router. Alternatively, the functionality for determining the device compliance status and adjusting the filter rules is implemented in a separate network component that is also located within the network. Specifically, this takes the form of a management component that performs the functionality for determining the device compliance status and adjusting the filter rules (e.g., via netconf / YANG or restconf / YANG), but not the filtering of network traffic itself.

[0080] The invention also comprises a higher-level system, in particular an industrial plant, comprising:

[0081] - A first terminal,

[0082] - a second device,

[0083] - a network, and

[0084] - an inventive component for the network.

[0085] BRIEF DESCRIPTION OF THE DRAWINGS

[0086] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.

[0087] It shows

[0088] Fig. 1 is a flow diagram of the method according to the invention,

[0089] Fig. 2 is a schematic representation of a system according to the invention and

[0090] Fig. 3 is a schematic representation of a component according to the invention for a network.

[0091] DETAILED DESCRIPTION OF THE INVENTION Fig. 1 shows a flow diagram of the inventive method for providing at least one filter rule for filtering network traffic between at least one first node and at least one second node of a communication connection, comprising the steps:

[0092] Step Sla : Optionally , a notification regarding a change of at least one previous conformance status of the first node and / or the second node , and / or

[0093] Step Slb : Optionally , determining at least one conformity status , and / or

[0094] Step Sic: Optionally, storing (also referred to as depositing) the at least one conformity status (in particular in a list comprising the at least one first node and / or the at least one second node, each with the associated at least one conformity status), and / or

[0095] Step Sld : Optionally , retrieving at least one conformance status , and

[0096] Step S2 : Using the minimum conformity status (also referred to as "compliance status") of the first node and / or the second node, and

[0097] Step S3: Setting the at least one filter rule based on (also to be understood as "dependent on") the at least one conformity status, wherein the setting of the at least one filter rule comprises: o Step S3a: Adjusting (also referred to as updating) at least one existing filter rule, and / or o Step S3b: Optionally, setting a monitoring intensity (also referred to as monitoring depth) of the communication connection by the at least one filter rule, and Step S: Providing the at least one filter rule, and optionally:

[0098] Step S5a: Applying the at least one filter rule, and

[0099] Step S5b: Filtering the network traffic between the first node and the second node of the communication link using (also understood as "based on") the at least one filter rule.

[0100] Fig. 2 shows a schematic representation of a system according to the invention, in particular an industrial automation and control system.

[0101] There are two production cells 1, 2 with:

[0102] - At least one programmable logic controller (PLC) (also known as a "programmable logic controller" PLC),

[0103] - a human-machine interface (HMI) (also referred to as a "human-user interface panel" HMI) in production cell 2, and a cell-internal control network (CN) (also referred to as a "control network" CN).

[0104] The programmable logic controllers PLC are connected to the physical real world P via sensors S and actuators A .

[0105] The two production cells 1, 2 are each connected to a factory network SN (also referred to as a "shop floor network" SN) via a firewall FW, e.g. a packet filter, a security gateway or an application firewall.

[0106] Furthermore, a wireless control network WCN (also referred to as "Wireless Control Network"), e.g. based on WLAN or 5G radio transmission, is provided, in particular to control driverless transport systems AGV (also referred to as "automated guided vehicles" AGV) by an AGV control system AGV-C (also referred to as "AGV Control" AGV-C). The factory network SN is coupled via a second firewall FW2 to a company network EN (also referred to as "Enterprise network" EN), which in turn is connected to the Internet I via a third firewall FW3.

[0107] A device management system DM (also referred to as "Device Manager" DM) can determine the compliance status of the devices it manages or of the production cells 1, 2 and store the current status in the device directory service DD (also referred to as "Device Directory Service" DD). The network security manager NSM implements the inventive functionality of adapting at least one, preferably several filter rules on at least one firewall FW, FW2, FW3 depending on the current device compliance status. If an adaptation of one or more filter rules takes place due to a change in a device compliance status, this event can be logged and forwarded accordingly. In this way, adaptations to the filter rules can be subsequently tracked (e.g. "adapted by admin", "adaptation due to change in device compliance status").

[0108] This implementation variant has the advantage that existing firewalls (FW2 and FW3) can continue to be used, provided they are remotely administrable. They only need to support packet filtering, e.g., based on MAC address, IP address, protocol, or port number. This also has the advantage that extremely high-performance filtering can be implemented, as it can be practically implemented in hardware, e.g., on an FPGA or ASIC, or on a network adapter.

[0109] Fig. 3 shows a component FW according to the invention for a network designed as a firewall FW.

[0110] The FR filter rules are set up via the AI ​​administration interface, where a FR filter rule can be specified as a filter criterion (in addition to IP / MAC address, protocol, port number) and additionally that this FR rule applies depending on a device compliance status (Device Trust Status) (e.g. "compliant", "not compliant", "unknown").

[0111] Furthermore, the administration interface AI can be used to set up the DL list of devices for which the firewall FW automatically determines the current device compliance status and stores it locally (e.g., by querying a device directory service or by performing an independent check). During operation, the firewall FW repeatedly determines the current device compliance status of the devices contained in the DL list using a monitoring unit ME, e.g., hourly or daily. Depending on this, an adaptation unit AE creates the currently active filter rules aFR (or adapts the filter rules accordingly using the adaptation unit AE). These filter rules are applied by the filter engine FE when forwarding data packets between the network interfaces NI.

[0112] Although the invention has been illustrated and described in detail by the embodiments, the invention is not limited by the disclosed examples and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.

Claims

Patent claims 1. A method for providing at least one filter rule (aFR) for filtering network traffic between at least one first node (1) and at least one second node (2) of a communication connection, comprising the steps: - Using (S2) at least one conformity status of the first node (1) and / or the second node (2), wherein the at least one conformity status comprises context information of an accessing device used by the first account and / or second account, wherein the context information indicates whether the accessing device is configured according to defined specifications, - setting (S3) the at least one filter rule (aFR) based on the at least one conformity status, wherein setting (S3) the at least one filter rule (aFR) comprises: o adapting (S3a) at least one existing filter rule (FR), and - providing (S4) at least one filter rule (aFR).

2. Method according to claim 1, comprising the further steps: - Determining (Slb) at least one conformity status, - storing (Sic) at least one conformity status, and / or - a retrieval (Sld) of at least one conformity status.

3. The method according to claim 2, wherein determining (Slb) the at least one conformity status is based on: - Retrieving at least one directory entry (DL) relating to at least one conformity status, - at least one integrity attestation of the at least one first node (1) and / or the at least one second node (2), and / or - at least one fingerprint of the at least one first node (1) and / or the at least one second node (2).

4. Method according to one of the preceding claims, with the further steps: - Using (S5a) at least one filter rule (aFR), and - filtering (S5b) the network traffic between the first node (1) and the second (2) node of the communication connection using the at least one filter rule (aFR).

5. Method according to one of the preceding claims, wherein the use (S2) of the at least one conformity status is preceded by: - a retrieval (Sla) of a notification regarding a change of at least one previous conformity status of the first node (1) and / or the second node (2).

6. Method according to one of the preceding claims, wherein the setting (S3) of the at least one filter rule (aFR) further comprises: - Setting (S3b) a monitoring intensity of the communication connection by the at least one filter rule (aFR).

7. The method according to any one of the preceding claims, wherein the network traffic comprises: - at least one network packet, - at least one data packet, at least one IP packet, and / or at least one Ethernet frame.

8. Method according to one of the preceding claims, wherein the at least one filter rule (aFR): - A blockade, - a forwarding, - a redirection, and / or - specifies an assignment to a queue for at least part of the network traffic.

9. Method according to one of the preceding claims, wherein the at least one first node (1) and / or the at least one second node (2) is designed as: - an endpoint (1, 2) of an end-to-end communication connection, in particular a communication endpoint and / or - a terminal device (1, 2) .

10. Method according to one of the preceding claims, wherein the at least one first node (1) and / or the at least one second node (2) is designed as: - an Internet of Things device, - a control unit, - an automation device, and / or - a production cell.

11. A computer program product comprising a computer program, wherein the computer program is loadable into a memory device of a computing unit, wherein the steps of a method according to one of claims 1 to 10 are carried out with the computer program when the computer program is executed on the computing unit.

12. Component (FR) for a network, comprising a computer program product according to claim 11, configured to execute the computer program.

13. Component (FR) according to claim 12, designed as: - a firewall (FR), a packet filter, a router and / or a switch or - a management component, designed to further component for a network.

14. A higher-level system comprising: - a first terminal (1), - a second terminal (2) , - a network (CN), and - a component (FR) according to claim 12 or 13.

Citation Information

Patent Citations

  • Event monitoring and management

    US20050015624A1

  • Cloud policy enforcement based on network trust

    US20210029119A1

  • Classification and forwarding of network traffic flows

    US20230246971A1