Dynamic Cyber-Security Risk Rule Customization for Industrial Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face challenges in managing cyber-security vulnerabilities due to the complexity of customizing security rules, which can lead to unaddressed risks disrupting operations or causing unsafe conditions, especially given the diverse and often un inventoried equipment from various vendors.

Innovation Solution

A risk manager system that interacts with users to define and map customizable rules for monitoring connected devices, providing an intuitive interface for configuring parameters and displaying outputs based on device status, thus enabling dynamic customization of cyber-security risk item rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional control and automation systems use diverse equipment from multiple vendors, then system functionality and versatility are improved, but cyber-security vulnerability management becomes more complex and difficult

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity rule complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The risk manager system provides a universal platform that can manage security risks across diverse equipment from multiple vendors through a single interface. The system maps vendor-specific risk items to universal risk categories, enabling centralized security management that works across heterogeneous devices without requiring vendor-specific security tools or expertise.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The risk manager system acts as an intermediary between diverse control devices and security monitoring tools. It provides a common language and mapping layer that translates between different vendor-specific risk frameworks and a unified risk assessment model, simplifying security management for operators while maintaining compatibility with various device types.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security monitoring is implemented across all connected devices, then security coverage is improved, but the complexity of defining and managing security rules increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security risk management into discrete, manageable risk items that can be individually defined, mapped, and monitored. Each risk item represents a specific security concern that can be independently configured and tracked, allowing comprehensive coverage to be achieved through modular rule management rather than monolithic complex rule sets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system allows dynamic parameter adjustment for risk monitoring, enabling users to modify risk thresholds, monitoring frequencies, and alert conditions without redefining entire rule sets. This parameter-based approach simplifies rule management while maintaining comprehensive security coverage across all connected devices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10686841B2Apparatus and method for dynamic customization of cyber-security risk item rules
Publication Date: 2020.06.16 HONEYWELL INTERNATIONAL INC
  • US10686841B2 patent drawing
  • US10686841B2 patent drawing
  • US10686841B2 patent drawing

AI summary

This disclosure provides an apparatus and method for dynamic customization of cyber-security risk item rules. A method includes interacting with a user, by a risk manager system, to define a plurality of rules for risk items to be monitored among a plurality of connected devices. The method also includes mapping each of the rules to a corresponding one or more of the connected devices by the risk manager system. The method further includes monitoring the connected devices according to the rules by the risk manager system. In addition, the method includes displaying an output based on the rules and a status of the connected devices by the risk manager system.