DMZ Proxy Server Whitelist Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face challenges in securely updating configurations of secure proxies in DMZs to access cloud-based systems like AVEVA Wonderware Online Cloud, balancing security with the need for information flow without exposing systems to new attack vectors.
Innovation Solution
A server system with a demilitarized zone proxy server system that digitally signs configurations using specific certificates, allowing secure data transfer connections and automatically updating a whitelist of necessary sites to prevent unauthorized access and tampering, thereby reducing manual updates and system downtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a DMZ proxy server is used to allow information flow from control systems to cloud-based systems, then access to valuable business information is enabled, but security protection is reduced due to increased exposure to attack vectors
Solution Approach 1:
The patent employs a DMZ proxy server as an intermediary component positioned between the internal control system network and external cloud-based systems. This proxy server mediates all communications, allowing authorized information flow while maintaining a security buffer that prevents direct exposure of internal systems to external attack vectors. The intermediary enables the beneficial access function while isolating the harmful security risks.
2Reliability
If manual configuration updates are performed on proxy servers, then configuration accuracy is maintained, but system downtime increases and productivity decreases
Solution Approach 1:
The patent implements a configuration management system that prepares and stages configuration updates in advance. The system maintains an updated configuration database and can push changes to proxy servers during scheduled maintenance windows or low-activity periods. This preliminary preparation of configuration data allows for rapid deployment without requiring lengthy manual update processes, thereby maintaining accuracy while minimizing downtime.
Solution Approach 2:
The system enables automated self-service configuration updates where the configuration management server automatically pushes updated configurations to proxy servers without requiring manual intervention on the proxy systems themselves. The proxy servers automatically apply the pushed configurations, eliminating the need for operators to manually log in and update each server individually, thus reducing downtime and increasing productivity while maintaining reliability.
3Object-affected harmful factors
If security measures are strengthened to prevent unauthorized access, then protection against malware and viruses is improved, but ease of operation for legitimate access is reduced
Solution Approach 1:
The patent implements a feedback mechanism where the configuration management system continuously monitors proxy server configurations and communication patterns. The system receives feedback about legitimate access requirements and automatically adjusts configuration policies to maintain security while enabling authorized operations. This feedback loop allows the system to distinguish between legitimate access attempts and malicious activity, strengthening protection against malware while preserving ease of operation for authorized users.
Data Source
AI summary
A server system can include an internal computer network including at least one client server configured to establish a data transfer connection to an external computer network, and at least one proxy server system positioned between the internal computer network and the external computer network. The proxy server system can include a proxy server positioned between a first firewall and a second firewall, where the first firewall is positioned between the first proxy server and the internal computer network, and the second firewall is positioned between the proxy server and the external computer network. The server system can develop and maintain a proxy server system that includes a whitelist of sites deemed necessary and/or desirable for system operation. The whitelist can be updated as a user works with and uses the system. Such updates can take place continuously in real or near-real time or periodically as frequently as desired. A single party can be the only entity that can update the whitelist, ensuring the whitelist contains all required sites. Whitelist updates can be automatically delivered to all proxy instances as the whitelist changes over time.


