Asset Discovery Engine for Industrial Network Vulnerability Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial networks face challenges in network security management due to the large number of assets with varying software and hardware configurations, making them susceptible to cyberattacks, especially in industrial automation and control systems.

Innovation Solution

An asset discovery engine with a deep vulnerabilities scanner is implemented to perform cybersecurity vulnerability assessments by aggregating asset property data and using asset vulnerability signature data to identify and mitigate potential threats, reducing the likelihood of cyberattacks and improving network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security management methods are used in industrial networks with thousands of assets, then the system structure remains simple and easy to manage, but the network becomes highly susceptible to cyberattacks due to inability to perform deep vulnerability assessments

Engineering Contradiction:
Improvenetwork securityVSAvoidasset management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the industrial network into multiple zones (OT network, IT network, DMZ) with dedicated security components in each zone. The vulnerability assessment system is divided into separate modules: asset discovery component, vulnerability assessment component, and response component, allowing independent management and operation of each segment while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A dedicated vulnerability assessment system acts as an intermediary between the OT network assets and the IT security infrastructure. This intermediary system performs deep vulnerability assessments without directly interfering with OT operations, translating asset vulnerabilities into actionable security information while protecting the core OT network from direct exposure to complex security management tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep vulnerability assessments are performed on all assets, then cybersecurity threats are better identified, but the time and computational resources required increase significantly

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary asset discovery and classification before conducting vulnerability assessments. The asset discovery component continuously monitors the network to build an up-to-date inventory of assets, their types, and locations. This preliminary information is used to prioritize vulnerability assessments, allowing the system to focus computational resources on high-risk assets first while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability assessment system dynamically adjusts assessment parameters based on asset criticality, network conditions, and threat intelligence. For high-priority assets, the system performs deep comprehensive assessments with multiple scanning techniques. For lower-priority assets, it uses streamlined assessment protocols, thereby optimizing the balance between detection accuracy and resource consumption.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive asset property data is collected for all assets, then vulnerability assessment accuracy is improved, but the data aggregation complexity and storage requirements increase

Engineering Contradiction:
Improveasset characterization precisionVSAvoiddata aggregation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system collects and stores different types of property data tailored to specific asset types rather than uniformly for all assets. For example, OT assets like PLCs and RTUs have specific property schemas focused on control functionality and protocol information, while IT assets have different property schemas. This localized data collection approach improves assessment accuracy for each asset type while reducing overall data aggregation complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The asset discovery component is designed with multi-functional capabilities to collect various types of property data through a unified interface. It can discover assets across multiple network zones, collect diverse property information (technical specifications, operational parameters, security attributes), and standardize this data into a common format that serves multiple assessment purposes, thereby reducing data aggregation complexity through universal processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the vulnerability assessment system is integrated directly into the OT network, then real-time security monitoring is achieved, but the operational stability of the control system may be compromised

Engineering Contradiction:
Improvesecurity monitoring real-time capabilityVSAvoidcontrol system stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The vulnerability assessment system is deployed as an intermediary component in the DMZ zone rather than directly in the OT control network. It monitors asset vulnerabilities and security threats in real-time through controlled communication channels, providing security intelligence without directly interfering with control system operations. This architectural separation maintains control system stability while enabling real-time security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring function is segmented from the control system operations. The vulnerability assessment component operates independently in the security infrastructure, collecting and analyzing security data without executing control functions. This segmentation ensures that security monitoring activities cannot compromise control system stability while maintaining real-time security visibility into OT assets.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12137111B2Asset discovery engine with deep vulnerabilities scanner
Publication Date: 2024.11.05 HONEYWELL INTERNATIONAL INC
  • US12137111B2 patent drawing
  • US12137111B2 patent drawing
  • US12137111B2 patent drawing

AI summary

Various embodiments described herein relate to an asset discovery engine with a deep vulnerabilities scanner with respect to assets in an industrial network. In an embodiment, a request to perform an asset vulnerability assessment of one or more assets within a network is received, the request comprising an asset descriptor describing the one or more assets. In response to the request, aggregated asset property data associated with the one or more assets is obtained based on the asset descriptor. Furthermore, the asset vulnerability assessment is performed based on the aggregated asset property data and asset vulnerability signature data stored in an asset vulnerability signature repository. In response to determining that the asset vulnerability assessment satisfies a defined criterion, one or more actions associated with the network are performed.