Emulated Cyber Range for Industrial Control Vulnerability Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable due to the difficulty in replicating and testing their physical components, leading to unpatched and unchanged software and infrastructure, making them susceptible to exploits and vulnerabilities.

Innovation Solution

A testbed system that integrates a physical environment with a virtual environment, using a processor to simulate industrial processes and control systems, allowing for vulnerability testing without downtime, by linking physical and virtual components through a virtual bridge, and generating scenarios to display simulation results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical components of industrial control systems are replicated for testing, then vulnerability testing and analysis can be performed, but the physical components cannot be easily replicated due to their nature

Engineering Contradiction:
Improvevulnerability testing capabilityVSAvoidreplicability of physical components
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates virtual copies of physical industrial control system components through virtualization technology. Virtual machines and containers replicate the functional behavior of physical PLCs, sensors, and actuators, enabling security testing without requiring physical duplication. This allows penetration testing and vulnerability analysis to be performed on virtual representations that mirror the attack surface of the actual physical systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between physical control systems and testing environments. This virtual layer acts as a mediator that captures and reproduces the behavior of physical components, allowing security researchers to test vulnerabilities indirectly through virtual models while the physical systems remain operational and unaffected by testing activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If industrial control systems undergo penetration testing and downtime for analysis, then vulnerabilities can be identified and patched, but critical environments cannot tolerate the required downtime

Engineering Contradiction:
Improvevulnerability identificationVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs penetration testing and security analysis in advance on virtual replicas of industrial control systems. Security vulnerabilities are identified and patched in the virtual environment before the same tests would need to be conducted on physical systems. This preliminary security hardening occurs without disrupting production operations, as the virtual testing environment operates independently from the critical physical infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the testing function from the production function by creating separate virtual environments for security testing. This segmentation allows penetration testing to occur in isolated virtual sandboxes that do not interfere with the operational continuity of physical control systems. The virtualized testing infrastructure can be created, configured, and destroyed without affecting the availability of the actual industrial control systems.

Inventive Principle:
Principle #1Segmentation

3Productivity

If software and supporting infrastructure remain unchanged for long periods to maintain operational continuity, then system availability is maintained, but systems become vulnerable to new exploits

Engineering Contradiction:
Improvesystem availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements periodic security testing and validation through virtualized environments. Virtual replicas of the control system software and infrastructure are regularly created and subjected to penetration testing, vulnerability scanning, and security analysis. This periodic security assessment occurs in the virtual domain without requiring changes or downtime of the production software, enabling continuous security monitoring while maintaining operational stability.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes the state parameter of the testing environment from physical to virtual. By transforming the testing substrate from physical hardware to virtualized software environments, the system can rapidly provision, configure, and decompose test environments without modifying the actual production software versions. This allows security parameters to be tested and updated in virtual space while the production system maintains its stable software configuration for continuous operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230168646A1Scalable emulated cyber range environment
Publication Date: 2023.06.01 UCHICAGO ARGONNE LLC
  • US20230168646A1 patent drawing
  • US20230168646A1 patent drawing
  • US20230168646A1 patent drawing

AI summary

At least one embodiments relates to a system for testing industrial processes and industrial control systems including a physical environment, including at least one industrial control system hardware and at least one physical model, and a computer system comprising a processor and a memory, wherein the processor is set up to perform operations, embodied in instructions on computer-readable medium. The operations include virtually linking the physical environment and a virtual environment, inputting at least one document comprising supporting software and a scenario instruction set, generating a scenario according to the scenario instruction set, simulating the scenario, and displaying simulation results of the simulated scenario.