Energy Delivery System Exposure Monitoring for Cyber Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Critical infrastructure systems, such as the power grid, face increased cybersecurity risks due to the convergence of operational technology (OT) and information technology (IT), with energy delivery systems (EDS) often exposed to the public internet, making them vulnerable to cyber threats and attacks.
Innovation Solution
A risk assessment framework and web-based dashboard application that continuously monitors and identifies exposed devices, using web spider databases and vulnerability scoring systems to estimate cyberattack vulnerability risks, classify devices, and provide real-time alerts and historical tracking, enabling utilities to proactively mitigate risks without requiring deep technical expertise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If EDS devices are connected to the public internet to enable remote control and coordination, then productivity and operational flexibility are improved, but cybersecurity vulnerability and risk of cyberattacks increase
Solution Approach 1:
The patent introduces a risk assessment framework and web-based dashboard as an intermediary layer between the EDS devices and the public internet. This dashboard mediates by continuously monitoring device exposures, assessing vulnerabilities through banner grabbing and CVE matching, and providing risk scores without requiring direct internet connectivity for the EDS devices themselves, thus maintaining productivity while reducing cybersecurity vulnerability
Solution Approach 2:
The system performs preliminary risk assessment actions by continuously monitoring EDS devices for internet exposures before cyberattacks can occur. By proactively identifying vulnerable devices through banner information collection and CVE matching, the system enables utilities to take preventive measures ahead of potential attacks, thus improving security without compromising operational flexibility
2Reliability
If continuous monitoring and risk assessment systems are implemented to identify and detect cyber threats, then cybersecurity reliability is improved, but device complexity and resource requirements increase
Solution Approach 1:
The risk assessment framework operates autonomously by automatically collecting banner information from EDS devices, matching against CVE databases, calculating risk scores, and generating reports without requiring manual intervention. The web-based dashboard self-updates with new vulnerability information from external sources, reducing the need for complex manual monitoring systems while maintaining high reliability
Solution Approach 2:
The web-based dashboard serves multiple functions simultaneously: it monitors device exposures, collects banner information, matches CVEs, calculates risk scores, generates reports, and provides historical tracking. By consolidating these functions into a single universal platform, the system improves cybersecurity reliability without proportionally increasing device complexity
3Measurement precision
If detailed vulnerability assessment and device classification are performed to accurately identify risks, then measurement precision of vulnerability scores is improved, but loss of time and computational resources increase
Solution Approach 1:
The system performs partial vulnerability assessment by focusing on banner information collection and CVE matching for identified exposures rather than comprehensive deep scanning of all devices. This targeted approach maintains measurement precision for exposed devices while reducing the time and computational resources required compared to exhaustive assessment methods
Data Source
AI summary
Method include receiving banner information from one or more queries of a network connecting a set of devices, wherein the banner information of one or more of the devices includes common vulnerability and exposure identifiers (CVEs) and the banner information of one or more of the devices does not include a CVE, identifying the devices based on the banner information including classifying devices without known CVEs by a device type, determining vulnerability scores for the devices with known CVEs based on retrieved CVE information, and determining vulnerability scores for the devices without CVEs based on a series of exploitability and impact parameter estimates associated with the device type classifications. Some methods include estimating a cyberattack vulnerability risk for the devices using the determined vulnerability scores.


