Energy Delivery System Exposure Monitoring for Cyber Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Critical infrastructure systems, such as the power grid, face increased cybersecurity risks due to the convergence of operational technology (OT) and information technology (IT), with energy delivery systems (EDS) often exposed to the public internet, making them vulnerable to cyber threats and attacks.

Innovation Solution

A risk assessment framework and web-based dashboard application that continuously monitors and identifies exposed devices, using web spider databases and vulnerability scoring systems to estimate cyberattack vulnerability risks, classify devices, and provide real-time alerts and historical tracking, enabling utilities to proactively mitigate risks without requiring deep technical expertise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If EDS devices are connected to the public internet to enable remote control and coordination, then productivity and operational flexibility are improved, but cybersecurity vulnerability and risk of cyberattacks increase

Engineering Contradiction:
Improveremote control and coordination capabilityVSAvoidcybersecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a risk assessment framework and web-based dashboard as an intermediary layer between the EDS devices and the public internet. This dashboard mediates by continuously monitoring device exposures, assessing vulnerabilities through banner grabbing and CVE matching, and providing risk scores without requiring direct internet connectivity for the EDS devices themselves, thus maintaining productivity while reducing cybersecurity vulnerability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary risk assessment actions by continuously monitoring EDS devices for internet exposures before cyberattacks can occur. By proactively identifying vulnerable devices through banner information collection and CVE matching, the system enables utilities to take preventive measures ahead of potential attacks, thus improving security without compromising operational flexibility

Inventive Principle:
Principle #10Preliminary action

2Reliability

If continuous monitoring and risk assessment systems are implemented to identify and detect cyber threats, then cybersecurity reliability is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvecybersecurity monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The risk assessment framework operates autonomously by automatically collecting banner information from EDS devices, matching against CVE databases, calculating risk scores, and generating reports without requiring manual intervention. The web-based dashboard self-updates with new vulnerability information from external sources, reducing the need for complex manual monitoring systems while maintaining high reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The web-based dashboard serves multiple functions simultaneously: it monitors device exposures, collects banner information, matches CVEs, calculates risk scores, generates reports, and provides historical tracking. By consolidating these functions into a single universal platform, the system improves cybersecurity reliability without proportionally increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed vulnerability assessment and device classification are performed to accurately identify risks, then measurement precision of vulnerability scores is improved, but loss of time and computational resources increase

Engineering Contradiction:
Improvevulnerability score accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial vulnerability assessment by focusing on banner information collection and CVE matching for identified exposures rather than comprehensive deep scanning of all devices. This targeted approach maintains measurement precision for exposed devices while reducing the time and computational resources required compared to exhaustive assessment methods

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12124582B2Mitigation of external exposure of energy delivery systems
Publication Date: 2024.10.22 BATTELLE MEMORIAL INST
  • US12124582B2 patent drawing
  • US12124582B2 patent drawing
  • US12124582B2 patent drawing

AI summary

Method include receiving banner information from one or more queries of a network connecting a set of devices, wherein the banner information of one or more of the devices includes common vulnerability and exposure identifiers (CVEs) and the banner information of one or more of the devices does not include a CVE, identifying the devices based on the banner information including classifying devices without known CVEs by a device type, determining vulnerability scores for the devices with known CVEs based on retrieved CVE information, and determining vulnerability scores for the devices without CVEs based on a series of exploitability and impact parameter estimates associated with the device type classifications. Some methods include estimating a cyberattack vulnerability risk for the devices using the determined vulnerability scores.