Integrated Cyber-Physical Security Evaluation Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security evaluation methods fail to comprehensively assess and address the interconnected security risks in both physical and cyber domains of infrastructure facilities, allowing adversaries to exploit vulnerabilities in one domain to compromise the other.

Innovation Solution

A computer-implemented security evaluation system that models and analyzes both physical and cyber domains of a facility, using a computing system with processing, storage, and user interface components to simulate attacks, assess vulnerabilities, and provide risk information through Monte Carlo discrete event simulations and timely detection methodologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security evaluation methods focus on only one domain (physical or cyber), then the evaluation process is simpler, but the security risk assessment is incomplete and fails to identify interconnected vulnerabilities

Engineering Contradiction:
Improvesecurity risk assessment completenessVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines physical security evaluation and cyber security evaluation into a single integrated system. The system models both physical facilities (buildings, security personnel, physical barriers) and cyber infrastructure (networks, software, hardware) within one unified framework, allowing simultaneous assessment of both domains and their interconnections without requiring separate evaluation processes

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The evaluation system is designed to perform multiple functions: it can evaluate physical security measures, cyber security measures, and the interactions between them. The same system framework handles diverse evaluation tasks including assessing physical barriers, cyber vulnerabilities, and hybrid attack scenarios, making it a universal security evaluation platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the security evaluation system models both physical and cyber domains comprehensively, then the security risk identification improves, but the computational resources and time required increase significantly

Engineering Contradiction:
Improvesecurity evaluation reliabilityVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-modeling the facility's physical and cyber infrastructure, establishing baseline security configurations and potential attack vectors before actual evaluation begins. This preparatory modeling allows the system to quickly execute scenario-based assessments without rebuilding the entire model each time, reducing evaluation time while maintaining comprehensive coverage

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial action by allowing users to select specific evaluation scenarios and focus on particular domains or attack vectors of interest. Rather than requiring complete evaluation of all possible physical and cyber interactions in every case, the system enables targeted assessments that reduce computational overhead while maintaining reliability for the specific evaluation objectives

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If the system integrates both physical and cyber security evaluations, then the identification of interconnected vulnerabilities improves, but the device and method complexity increases

Engineering Contradiction:
Improvevulnerability information completenessVSAvoidsystem integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the complex integrated evaluation into distinct modules: physical security modeling components, cyber security modeling components, and interaction analysis components. Each segment handles specific aspects of the evaluation independently, then integrates results to identify interconnected vulnerabilities, making the overall complex system manageable and maintainable

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9092631B2Computer-implemented security evaluation methods, security evaluation systems, and articles of manufacture
Publication Date: 2015.07.28 BATTELLE MEMORIAL INST
  • US9092631B2 patent drawing
  • US9092631B2 patent drawing
  • US9092631B2 patent drawing

AI summary

Computer-implemented security evaluation methods, security evaluation systems, and articles of manufacture are described. According to one aspect, a computer-implemented security evaluation method includes accessing information regarding a physical architecture and a cyber architecture of a facility, building a model of the facility comprising a plurality of physical areas of the physical architecture, a plurality of cyber areas of the cyber architecture, and a plurality of pathways between the physical areas and the cyber areas, identifying a target within the facility, executing the model a plurality of times to simulate a plurality of attacks against the target by an adversary traversing at least one of the areas in the physical domain and at least one of the areas in the cyber domain, and using results of the executing, providing information regarding a security risk of the facility with respect to the target.