Fault tolerance component for controlling the activity of a system component
The fault tolerance component addresses the challenge of maintaining system resilience by controlling activity levels of system components based on event evaluations, ensuring continued functionality during critical events and facilitating gradual recovery.
Patent Information
- Application Number
- PCT/EP2024/081857
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-11
- Publication Date
- 2025-06-12
AI Technical Summary
Existing systems lack effective mechanisms to maintain resilience and functionality in the face of unforeseen events, such as attacks or malfunctions, which can lead to complete system failure.
A fault tolerance component that receives event evaluations from a criticality evaluation component, allowing it to control system components by switching their activity levels, thereby ensuring continued functionality even under critical conditions.
The solution enhances system availability by allowing it to maintain reduced but reliable functionality during critical events, and enables gradual recovery of full functionality once the threat has subsided.
Smart Images

Figure EP2024081857_12062025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Fault tolerance component for controlling the activity of a system component
[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identity are included.
[0004] BACKGROUND OF THE INVENTION
[0005] Field of invention
[0006] The present invention relates to a fault-tolerance component for a system. Furthermore, the invention relates to a higher-level system and network, as well as to an associated method.
[0007] Description of the state of the art
[0008] Particularly in critical infrastructures it is necessary to maintain the functionality of systems, especially devices. In particular an event, particularly in the form of an impairment, can lead to the full functionality of a system, especially a device, no longer being guaranteed or maintained. An event or impairment is understood to be an attack, the exploitation or occurrence (detection) of a security gap, a malfunction of a system component, a modification of a system component, in particular a deliberate modification of a system component and / or a failure of a system component. The ability to maintain system functionality despite the impairment is also referred to as resilience or "graceful degradation"."Graceful degradation" is thus the property of a system to be able to react in a graduated manner to unforeseen or undesired events. For network-based systems and / or end systems, measures are known, in particular to isolate infected systems from the network and thus maintain the availability of the network for communication between components. It is typically assumed that a component of a network-based system can fail completely if tampered with.
[0009] Also known is:
[0010] The ETSI EN303645 (Consumer IoT Security) standard defines resilience requirements in Section 5.9. An IoT device must perform its basic functionality even without network connectivity (for example, a networked stove must be usable as a stove even when there is no internet connectivity).
[0011] From patent EP3702947-B1 it is known to provide additional functionalities for HW apps, e.g. for monitoring the execution environment.
[0012] Patent EP3428756-B1 discloses testing an industrial plant for integrity violations. This involves targeted integrity measurements of physical boundary conditions to be used for a plausibility check against the expected state.
[0013] It is known to store the status of a software component in a central inventory.
[0014] Specifically to protect integrity, IT measures are known to protect individual aspects:
[0015] It is well known that the boot process of an IT system can be checked (Secure Boot, Trusted Boot, Verified Boot, Measured Boot). This is intended to ensure, or rather, to verify during operation, that only untampered software (operating system, drivers) is loaded. It is well known that the integrity and / or authenticity of a file system can be checked. For this purpose, checksums of files are calculated and compared with reference values. Virus scanners are also known to detect known malware.
[0016] Physical tamper-evident measures are known for IT systems, such as seals or a PC case switch. These can be used to detect the opening of a case.
[0017] Network Admission Control is well known: When an IT system (client) logs on to the network, it transmits configuration information that is used to grant access to a regular network or a quarantine network. In particular, only clients that do not have an up-to-date virus scanner or that do not have the latest security patches installed can connect to a quarantine network. MIBs for network protocols are known, which provide information about the type, size, and frequency of certain network telegrams, thus enabling denial-of-service attack detection.
[0018] Mechanisms are known to harden software implementations against the exploitation of vulnerabilities, e.g. using Address Space Layout Randomization (ASLR), Stack Protection, Control Flow Integrity (CFI).
[0019] Isolation mechanisms in hardware (e.g. separation of memory areas using ARM Trustzone) or the operating system (e.g. process isolation) are known to protect parts of a device software against another, possibly compromised part of the device software.
[0020] The object of the invention is to provide a solution for improved resilience with regard to an unforeseen event on a system, i.e. an event unplanned by the system operator.
[0021] SUMMARY OF THE INVENTION The invention results from the features of the independent claims. Advantageous further developments and refinements are the subject of the dependent claims. Refinements, possible applications, and advantages of the invention emerge from the following description and the drawings.
[0022] The invention relates to a fault tolerance component (also referred to as "Graceful Device Functionality Degradation Component") for a system, based on:
[0023] - A receiving unit designed to receive an event evaluation (in particular from a criticality evaluation component, also referred to as a "Criticality Evaluation Component"), wherein the event evaluation is designed as an evaluation with respect to a criticality (also referred to as a criticality evaluation) of at least one event on the system and / or in a network to which the system is connected,
[0024] - a control unit designed to control at least one system component of the system depending on the event evaluation (and thereby depending on the criticality), whereby an (individual) activity level is switched for the at least one system component, wherein the activity level specifies which at least one activity can be carried out by the respective system component.
[0025] The event can therefore occur simultaneously on the system and the network or only on / in one of them.
[0026] The event has in particular effects on the system and / or the network to which the system is connected, i.e. it leads to a changed behavior of the system, i.e. a change in how the system behaves when the control of the system remains unchanged. The criticality of the at least one event describes how critical the effects of the event on the system are, in particular what consequences the event can be expected to have on system behavior and whether this entails undesirable system behavior and / or leads to security risks. In addition, the criticality in connection with the effects of the at least one event on the at least one system component describes in particular how critical any functionality of the at least one system component that may have been changed by the event is.
[0027] The event is detected in particular by a component for detecting at least one event (“Event Detection Component”, in particular “Attack Detection Component”). The component for detecting at least one event connects to an event evaluation component, which in turn connects to the fault tolerance component according to the invention, and the latter provides in particular a message regarding the event evaluation of the at least one event on the system and / or in a network to which the system is connected.
[0028] The activity level thus specifies, at least indirectly, which at least one activity can be carried out by the respective system component and thus by the system.
[0029] According to the invention, the control unit is designed to control at least one system component of the system depending on the event evaluation, whereby an (individual) activity level is switched for each of the at least one system component. "Switched" in this context is to be understood in particular as "specified and thereby controlled and activated". In particular, the at least one system component is thereby deactivated (inactivated), switched off, partially switched off in its activity, restricted in its activity and / or reduced in its activity.By switching the individual activity level, a multi-level restriction (and subsequently a multi-level extension) can be achieved, whereby the system component and thus the system as a whole can still reliably provide the remaining functionality even if a critical event occurs, especially if the system has been attacked. If a critical event no longer occurs, a previously imposed restriction can be revoked.
[0030] One aspect of the invention is therefore to reliably provide a limited functionality (reduced activity) on a system in the event of an unforeseen, unwanted and / or involuntary event (in particular an attack, a security gap, a malfunction of a component of the system, a possibly deliberate modification).
[0031] The invention offers, among other advantages, that the proposed solution increases the general availability of systems even under the influence of events, in particular potential system disruptions, e.g., due to attacks or known vulnerabilities. The respective activity levels can ensure reduced service availability, even under the influence of potential attacks. "Probing" can also be used to attempt to return to the previous (undisturbed) state. Probing here means gradually reactivating the (temporarily) deactivated components in order to gradually expand the remaining functionality back to full functionality.
[0032] In a further development of the invention, the event is designed as:
[0033] - an attack,
[0034] - an emerging, i.e. a detected security vulnerability,
[0035] - an occurring, ie a detected malfunction, - a modif ication, in particular a willful modif i cation and / or
[0036] - a failure, either on the system and / or in the network to which the system is connected.
[0037] In a further development of the invention, the event leads to an impairment of the system and / or the network to which the system is connected.
[0038] In a further development of the invention, the event assessment includes an assessment regarding a criticality (also referred to as a criticality assessment) of the impairment - in addition to the assessment regarding the criticality of the at least one event itself.
[0039] The event evaluation can be provided in a tamper-proof manner, preferably cryptographically and / or physically tamper-proof. Furthermore, backup event evaluation information can be used if no event evaluation or no valid event evaluation is received within a specified period of time. This allows the control unit to automatically switch activation levels of at least one system component if no event evaluation is received within the specified period of time.
[0040] In a further development of the invention, at least one system component is designed as:
[0041] - at least one software component and / or
[0042] - at least one hardware component.
[0043] One embodiment of a switchable component is a network module in a protection device. If the protection device determines that the network module is endangering normal operation (in particular the protective function of a power grid), especially if a DoS attack (denial of service attack) occurs, then this component is switched off. The protection device then still fulfills the protective function locally based on its own measured values. If the network module is switched off in this case, the missing communication can be detected by a monitoring system in the network. Based on this, further actions can be initiated or carried out.
[0044] In a further development of the invention, the fault tolerance component also has:
[0045] - a database configured to store an inventory, the inventory comprising an operational assessment for each of the at least one system component, wherein the respective operational assessment is configured as an assessment of the operational criticality of the at least one system component.
[0046] According to this embodiment, a local inventory (also referred to as "inventory") of the system components used, in particular software components (assets), is maintained on the fault tolerance component, or possibly generally on the system. This inventory is created locally by an inventory unit. It can also be compared with a central inventory. The inventory also contains information on a security status of at least one system component (in particular on known vulnerabilities in the system components / CVEs and in particular their locations).
[0047] The operational criticality of at least one system component can be configured in various ways, in particular by:
[0048] - A local configuration of the operational criticality of the at least one system component, manually and / or automatically, in particular by reading in a (plant) configuration and / or a central configuration of the operational criticality of the at least one system component, system-specific and / or in the context of a plant configuration.
[0049] Operational criticality describes the criticality of the operation of at least one system component in general. This includes how essential the at least one system component is for providing the functionality of the system, in particular a specific service to be performed by the system. Operational criticality is different from the criticality of the at least one event. Operational criticality is an assessment that is, in particular, independent of the effects of the at least one event. Depending on the event, it is also possible that the operational criticality is influenced by the event. The operational criticality of at least one system component can be preconfigured by the device manufacturer, or it can be configured by an operator or integrator via a configuration interface.
[0050] In a further development of the invention, each operational evaluation is designed as a function of an application case of the respective at least one system component.
[0051] The application case of the respective at least one system component is also to be understood as an area of use, an operating environment and / or application environment in the system and / or network.
[0052] According to this embodiment, the operational criticality (in addition to the attack criticality) of the respective system component is determined for the actual use case. The operational criticality of the respective system component is determined by the actual use case (functionality, operating environment, etc.). This means that a system component installed in different end systems can be affected differently by the event and is therefore assessed differently in terms of its operational necessity and / or priority.
[0053] In a further development of the invention, the control unit is also designed to control at least one system component as a function of the operational evaluation.
[0054] This has the advantage that the inventory and operational evaluation are used by the control unit to control the system components. This, in turn, allows less mission-critical system components (compared to more mission-critical system components) to be deactivated and / or their activity and / or functionality to be reduced.
[0055] In a further development of the invention, the activity level which is switched by the control unit for at least one system component:
[0056] - inactivity (also to be considered as switching off and / or turning off),
[0057] - a reduced (limited) available activity compared to previous activity,
[0058] - a reduced (also referred to as "restricted") available activity compared to the maximum activity planned for at least one system component, and / or
[0059] - an increased (also referred to as "increased") available activity compared to the previously available activity, for which at least one system component is fixed (also referred to as "specified").
[0060] The activity level is also to be understood as a functionality level. A plurality of activity levels is provided, which in particular form a hierarchy and / or can be divided into categories. According to the invention, by switching the individual activity level, a multi-level restriction is achieved, whereby the end system still provides the reliably available residual functionality even if a critical event occurs, in particular if the system has been attacked. According to one embodiment, depending on the currently existing attack criticality, individual software components that are executed by an operating system or an execution environment are thus deactivated step by step and / or partially in several stages, i.e. terminated or stopped, or their access options are restricted or blocked.
[0061] The available activity is to be understood as an activity that can be controlled by the at least one system component. The controllable activity of the at least one system component comprises a functionality of the at least one system component. In particular, the controllable / available activity thus comprises a functionality that can be executed by the at least one system component, i.e. is executable. The available activity is therefore also to be understood as an available functionality. A reduced or restricted activity therefore also means residual functionality. Since a large number of different activity levels are provided for the activity levels, this also applies in particular to the available activity.
[0062] The previous activity describes a temporally prior activity of at least one system component. The activity level of the reduced (limited) available activity compared to the previous activity is thus an activity level that specifies that the activity of at least one system component is lower than the activity before the activity level was switched.
[0063] The maximum activity provided for at least one system component describes an activity of at least one system component that can be executed by default (also referred to as "preset" and / or "default"). The activity level of the reduced (limited) available activity compared to the maximum activity provided for at least one system component is therefore an activity level that specifies that the activity of at least one system component is lower than the activity provided for the system component by default. Thus, by switching this activity level, functionalities that can be executed by default can no longer be executed or used.
[0064] The increased (increased) available activity compared to the previous (i.e. previous, in particular directly previous) available activity is particularly relevant if previously (i.e. previous, in particular directly previous) the reduced (limited) available activity was switched on compared to the previous activity or the reduced (limited) available activity was switched on compared to the maximum activity intended for at least one system component. It corresponds to a reactivation and / or a switching back of the activity of the system component, in particular if the event on the system or in the network to which the system is connected is classified / assessed as less critical.In particular, when the assessment of events, particularly attacks, becomes less critical, a temporarily deactivated system component is gradually reactivated and the remaining functionality is gradually expanded.
[0065] The switching / determination of the reduced activity / functionality of the system component includes in particular the following activity characteristics / parameters: a switch-off, a switch-off for a specified period of time, - a switch-off up to a triggering value (also referred to as a "trigger value", which is in particular measurable locally and / or can be provided via a communication interface) and / or
[0066] - Disabling partial functionality of the system component (in particular, with a network module, only allowing certain events, only certain users who can authenticate via SSH, etc.). With a protective device, the partial functionality can be, in particular, the TRIP message to an actuator to trigger a network disconnection in the event of a danger.
[0067] In a further development of the invention, the control unit is also designed to control the at least one system component as a function of an event progression evaluation, wherein the event progression evaluation is an evaluation with respect to a criticality (also referred to as a criticality progression evaluation):
[0068] - a temporal progression and / or
[0069] - a temporal past of the at least one event on the system or in the network to which the system is connected.
[0070] In particular, it is possible to switch the increased (increased) available activity compared to the previously available activity. This makes it possible to control and / or reduce the activity / functionality of the system components for a limited period of time. A temporary shutdown enables verification of whether, in particular, the actual disturbance / effect caused by the event has been eliminated and a fallback / return to normal operation of the at least one system component. In a further development of the invention, the fault tolerance component also comprises:
[0071] - a transmitting unit configured to send a message regarding the switched activity level.
[0072] In this advanced variant, the message, in particular information about reduced functionality, which is specified by the switched activity level, is sent; in particular, it is reported to a SIEM system in order to be able to derive a system-wide status of the system, in particular of a plant.
[0073] In a more advanced variant, information about reduced functionality is reported to a SIEM system via a separate interface. This enables a hardware-based separation of the functionalities for the actual operation of the system / device and for monitoring the system / device, and also allows for notification to a central system in the event of a malfunction without affecting the actual functionality of the system / device.
[0074] The invention also includes a system comprising the fault tolerance component according to the invention.
[0075] In a further development of the invention, the system according to the invention is designed as:
[0076] - A device,
[0077] - an end system,
[0078] - a terminal device,
[0079] - a control unit,
[0080] - a network device,
[0081] - an Internet of Things (IoT) device,
[0082] - a security device and / or
[0083] - a protective device. In a further development of the invention, the system also comprises:
[0084] - A component for detecting the event (in particular at least one event) (also referred to as an "Event Detection Component", in particular as an "Attack Detection Component") on the system or in the network to which the system is connected, and / or
[0085] - A criticality evaluation component (also referred to as a "Criticality Evaluation Component"), designed to create the event evaluation, designed as the evaluation regarding the criticality (also referred to as a criticality assessment) of the at least one event on the system or in the network to which the system is connected.
[0086] The system, in particular an end system, uses the criticality assessment component to determine the criticality of an event, in particular the attack criticality of an attempted or successful attack (= manipulation), on the end system (in particular a terminal device) and / or in the network to which the end system is connected. Depending on the determined criticality and its assessment (event assessment), the fault tolerance component determines which components, in particular software components, of the end system are to be controlled, in particular deactivated, under this attack scenario.
[0087] The components according to the invention (ie the component for detecting events (Event Detection Component, in particular Attack Detection Component), the criticality evaluation component (Criticality Evaluation Component) and / or specifically the fault tolerance component (Graceful Device Functionality Degradation Component)) can be executed in particular as independent hardware modules (e.g. FPGA, PCIe expansion card, special chips / ASICs) and / or as specially protected software components on the main CPU (in particular by being separated from the remaining execution environment (operating system (OS) and software components (SWC)) by means of a hypervisor or hardware isolation mechanisms).
[0088] The component for detecting at least one event (“Event Detection Component”, in particular “Attack Detection Component”) is particularly designed to detect:
[0089] - an external trigger, in particular by a SIEM system based on known vulnerabilities in a system component of the system or via already detected events and / or attacks on other systems and / or devices and / or irregularities in the monitored system and / or
[0090] - an internal trigger, in particular via a HIDS or via irregularities in the operation of the system that deviate from a normal situation (in particular denial of service attacks).
[0091] The invention also comprises a network (as a higher-level system, in particular an automation network) comprising:
[0092] - A plurality (i.e. at least two) of systems according to the invention, and
[0093] - a security information and event management system (SIEM system),
[0094] - a network gateway, and / or
[0095] - a control unit (also referred to as a "control center").
[0096] The multitude of systems is connected to the control unit, particularly via the network gateway. Furthermore, the multitude of systems is connected, in particular, to the security information and event management system (SIEM system). The SIEM system is connected locally to the multitude of systems or implemented in the control unit.
[0097] Furthermore, a connection to an inventory can exist in order to be able to derive a status of all the components present in the system.
[0098] The invention also comprises a method for controlling at least one system component of a system depending on an event evaluation (by a fault tolerance component (also referred to as "Graceful Device Functionality Degradation Component"), comprising the steps of:
[0099] - Receiving the event evaluation (which is received by a criticality evaluation component, also referred to as a "Criticality Evaluation Component"), wherein the event evaluation is designed as an evaluation with respect to a criticality (also referred to as a criticality evaluation) of at least one event on the system and / or in a network to which the system is connected,
[0100] - Controlling the at least one system component of the system as a function of the event evaluation, whereby a switching of an (individual) activity level for the at least one system component is carried out, wherein the activity level specifies which at least one activity can be carried out by the respective system component.
[0101] BRIEF DESCRIPTION OF THE DRAWINGS
[0102] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.
[0103] Fig. 1 is a schematic representation of a system according to the invention and
[0104] Fig. 2 is a schematic representation of a network according to the invention.
[0105] DETAILED DESCRIPTION OF THE INVENTION
[0106] Fig. 1 shows a system 1 according to the invention, in particular a control unit 1, with a processor 2 (CPU 2), program and configuration memory 3 (Flash 3), working memory 4 (RAM 4), a communication module 5 (ComMod 5), a security element 6, an input / output interface 7 (I / O 7) for connecting sensors and actuators including network communication.
[0107] The control unit 1 further comprises a component for detecting attacks and evaluating their criticality (8). The component for detecting attacks and evaluating their criticality (8) comprises a unit for detecting attacks (8a) and a unit for evaluating their criticality (8b). An attack pattern database (8al) is used to detect attacks. An attack criticality policy (8bl) is used to evaluate criticality.
[0108] Depending on the currently existing attack criticality, individual software components 9, which are executed by an operating system 10 (OS 10) or an execution environment 10 (RTE, Runtime Environment 10), are deactivated, i.e., terminated or stopped, in several stages by the inventive fault tolerance component 11 (Graceful Device Functionality Degradation Component 11). The fault tolerance component 11 has a fault tolerance manager 11a and an associated software component database 11b, which has entries relating to the operational criticality of the software components 9. The component for detecting attacks and for evaluating their criticality 8 (Attack Detection and Criticality Evaluation Component 8) and the fault tolerance component 11 (Graceful Device Functionality Degradation 11) can, as shown in Fig. 1, be implemented as independent hardware modules (e.g.FPGA, PCIe expansion card, special chips / ASICs), or even as specially protected software components on the main CPU (e.g. by separating them from the rest of the execution environment with operating system 10 (OS 10) and software components 9 using a hypervisor or hardware isolation mechanisms).
[0109] Fig. 2 shows the field devices FD1 and FD2 (they each have the fault tolerance component according to the invention and are embodiments of the system according to the invention, designated by reference numerals 1 and 11 in Fig. 1 respectively) and a network transition GW from an automation network AN to a control center CC (control unit CC). The entire Fig. 2 is an embodiment of the network according to the invention. In Fig. 2, field device FD1 has switched off the network module (represented by the dashed arrow) because problems were detected. This corresponds to an event on the field device FD1. As a result, the security information and event management system SIEM (local here, but can also be in the control center CC) does not receive any monitoring information from field device FD1 and can initiate corresponding actions and contact the component for detecting at least one event (represented by reference numeral 8a in Fig. 1).
[0110] The component for detecting at least one event ("Event Detection Component", in particular "Attack Detection Component") is also provided by the field devices FD1 and FD2. It is particularly designed to detect: - an external trigger, in particular by a SIEM system based on known vulnerabilities in a system component of the system or also via already detected events and / or attacks on other systems and / or devices and / or
[0111] - an internal trigger, in particular via an EIDS or via irregularities in the operation of the system that deviate from a normal situation (in particular denial of service attacks).
[0112] The component for detecting at least one event connects to the criticality assessment component (shown in Fig. 1 with reference number 8b) and this in turn connects to the fault tolerance component according to the invention and provides a message regarding the at least one event on the system and / or in a network to which the system is connected.
[0113] If field device FD1 has deactivated the network module and is otherwise still functional to a limited extent, it can continue to be used with reduced functionality. This is initiated by the fault tolerance component and its control unit.
[0114] Although the invention has been illustrated and described in detail by means of the embodiments, the invention is not limited by the disclosed examples and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.
Claims
Patent claims 1. Fault tolerance component (11) for a system (1), comprising: - A receiving unit configured to receive an event assessment, wherein the event assessment is configured as an assessment regarding a criticality of at least one event on the system (1) and / or in a network (AN) to which the system (1) is connected, - a control unit (11a), designed to control at least one system component (9) of the system (1) depending on the event evaluation, whereby an activity level is switched for each of the at least one system component (9), wherein the activity level specifies which at least one activity can be carried out by the respective system component (9), and a database (11b), designed to store an inventory, the inventory comprising an operational evaluation for each of the at least one system component (9), wherein the respective operational evaluation is designed as an evaluation of the operational criticality of the at least one system component (9), wherein the control unit (11a) is also designed to control the at least one system component (9) depending on the operational evaluation.
2. Fault tolerance component (11) according to claim 1, wherein the event is configured as: - an attack, - a security gap that occurs, - a malfunction occurring, - a modification and / or - a failure, in each case on the system (1) and / or in the network (AN) to which the system (1) is connected.
3. Fault tolerance component (11) according to one of the preceding claims, wherein the event leads to an impairment of the system (1) and / or the network (AN) to which the system (1) is connected, and wherein the event assessment includes an assessment regarding a criticality of the impairment.
4. Fault tolerance component (11) according to one of the preceding claims, wherein the at least one system component (9) is designed as: - at least one software component (9) and / or - at least one hardware component (9) .
5. Fault tolerance component (11) according to one of the preceding claims, wherein the respective operational evaluation is designed in each case as a function of an application case of the respective at least one system component (9).
6. Fault tolerance component (11) according to one of the preceding claims, wherein the activity level which is switched by the control unit (11a) for the at least one system component (9): - inactivity, - reduced available activity compared to previous activity, - a reduced available activity compared to the maximum activity provided for the at least one system component (9), and / or - an increased available activity compared to the previously available activity, for which at least one system component (9) specifies.
7. Fault tolerance component (11) according to one of the preceding claims, wherein the control unit (11a) is further designed to control the at least one system component (9) as a function of an event history evaluation, wherein the event history evaluation is an evaluation with respect to a criticality: - a temporal progression and / or - a temporal past of the at least one event on the system (1) or in the network (AN) to which the system (1) is connected.
8. Fault tolerance component (11) according to one of the preceding claims, further comprising: - a transmitting unit configured to send a message regarding the switched activity level.
9. System (1) comprising a fault tolerance component (11) according to one of the preceding claims.
10. System (1) according to claim 9, designed as: - A device, - an end system, - a terminal device, - a control unit, - a network device, - an Internet of Things device, - a security device and / or - a protective device.
11. System (1) according to claim 9 or 10, further comprising: - A component for detecting the event (8a) on the system (1) or in the network (AN) to which the system (1) is connected, and / or - A criticality assessment component (8b) designed to create the event assessment, designed as the assessment regarding the criticality of the at least one event on the system (1) or in the network (AN) to which the system (1) is connected.
12. Network (AN) comprising: - A plurality of systems (1) according to any one of claims 9 to 11, and - a security information and event management system (SIEM), - a network gateway (GW), and / or - a control unit (CG).
13. Method for controlling at least one system component (9) of a system (1) depending on an event evaluation, comprising the steps: - receiving the event assessment, wherein the event assessment is designed as an assessment regarding a criticality of at least one event on the system (1) and / or in a network (AN) to which the system (1) is connected, - controlling the at least one system component (9) of the system (1) as a function of the event evaluation, whereby switching of one activity level at a time for the at least one system component (9) is carried out, wherein the activity level specifies which at least one activity can be carried out by the respective system component (9).
Citation Information
Patent Citations
Integrity monitoring in automation systems
EP3428756B1
Method for verifying at runtime of a hardware-application component a current configuration setting of an execution environment provided by a configurable hardware module
EP3702947B1
Threat mitigation system and method
US20230353594A1