Dynamic Cyber-Security Risk Quantification in Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICS) face challenges in quickly determining and mitigating cyber-security risks due to complex interconnectivity among networked devices, with existing security measures failing to account for dynamic and inter-device dependent vulnerabilities.
Innovation Solution
A cyber-security risk analysis system and algorithm that dynamically quantify risks using inter-device dependencies and observed cyber behavior, incorporating a processor, memory device, and vulnerability database to modify risk assessments based on interconnectivity and frequency of occurrence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures (firewalls, separation) are used to protect industrial networks, then network security is improved, but the ability to quickly determine and mitigate cyber-security risks across interconnected devices deteriorates
Solution Approach 1:
The system continuously monitors cyber behavior across networked devices and dynamically updates risk quantifications based on observed behaviors and inter-device dependencies. This feedback mechanism enables real-time risk assessment and rapid mitigation response without compromising network security architecture.
Solution Approach 2:
The patent introduces a risk quantification system that acts as an intermediary layer between security measures and network devices. This intermediary dynamically assesses risks by analyzing inter-device dependencies and observed cyber behaviors, enabling quick risk determination without requiring changes to the underlying security infrastructure.
2Measurement precision
If comprehensive security monitoring is implemented across all networked devices, then risk detection capability is improved, but system complexity and computational requirements worsen
Solution Approach 1:
The patent segments the complex security monitoring task by focusing on specific inter-device dependencies and observed cyber behaviors rather than monitoring all possible parameters across all devices. This segmentation enables precise risk detection while managing system complexity through targeted analysis of critical relationships.
Solution Approach 2:
The system dynamically changes risk quantification parameters based on observed cyber behaviors and inter-device dependencies. By adapting parameters in real-time rather than using fixed comprehensive monitoring thresholds, the system achieves high detection precision with reduced computational overhead.
3Ease of operation
If static risk assessments are used for networked devices, then system simplicity is maintained, but the ability to account for dynamic and inter-device dependent vulnerabilities deteriorates
Solution Approach 1:
The patent transforms static risk assessments into dynamic evaluations by continuously updating risk quantifications based on observed cyber behaviors and inter-device dependencies. The system maintains operational simplicity through automated dynamic adjustments rather than requiring complex manual re-assessments, achieving both ease of operation and adaptability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system (100) and method (600) for analyzing cyber-security risk inter-dependencies in a control system (150) having networked devices (160). The system includes a central server (105) that has a processor (110) and a memory device (116) in communication with the processor. The memory device stores inter-device dependencies (362) and quantified individual risks (312) for each of the networked devices. The memory device also stores a dynamic quantification of risk (DQR) program (128). The central server is programmed to implement the DQR program. Responsive to observed cyber behavior, the central server changes one or more of the quantified individual risks to generate (616) at least one modified quantified individual risk (326). The inter-device dependencies for a first of the networked devices and the quantified individual risk for at least one other of the networked devices reflecting the modified quantified individual risk are used to dynamically modify the quantified individual risk for the first device to generate (618) an inter-device modified quantified individual risk (328).