HMI Server Defense Suite for ICS Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) networks are vulnerable to attacks through the human-machine interface (HMI), primarily due to human errors and malicious activities, and existing solutions often require additional devices or foreign installations, which are not feasible for safety reasons.

Innovation Solution

The HMI defense suite is installed on the HMI server, featuring a network protection engine, learning engine, and operating system protection engine to monitor and analyze network traffic, detect suspicious activities, and prevent unauthorized access, thereby enhancing security without the need for new devices or foreign installations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional security devices are installed in the ICS network, then security protection capability is improved, but device complexity and system safety risks increase

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The defense suite merges multiple security functions (packet sniffing, learning, protection, and analysis modules) into a single integrated software system installed on the HMI server, eliminating the need for separate physical security devices while maintaining comprehensive protection capability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The HMI server is made multi-functional by installing the defense suite, enabling it to simultaneously perform its original HMI functions and additional security functions (traffic monitoring, anomaly detection, and network protection) through its existing communication privileges

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If foreign installations are added to the HMI server, then security functionality is improved, but system safety and compatibility risks increase

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem safety risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The defense suite combines security functionality with the existing HMI server platform, using the server's existing operating system, network stack, and communication protocols rather than introducing foreign software layers that could create compatibility or security risks

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If the HMI server's communication privileges are restricted, then network safety is improved, but security monitoring and protection capability deteriorate

Engineering Contradiction:
Improvenetwork safetyVSAvoidsecurity monitoring capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The HMI server performs security monitoring and protection functions using its own existing communication privileges and network access capabilities, turning the server into a self-protecting system that leverages its inherent permissions rather than requiring additional access rights

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11621972B2System and method for protection of an ICS network by an HMI server therein
Publication Date: 2023.04.04 ICS SECURITY 2014 LTD
  • US11621972B2 patent drawing
  • US11621972B2 patent drawing
  • US11621972B2 patent drawing

AI summary

A defense suite for an industrial control system (ICS) network is disclosed. The defense suite is installed and executed on a network server hosting the human-machine interface (HMI) function of the network, thereby gaining communication privileges of the HMI server to query and perform other operations with programmable logic controllers (PLCs) and other assets of the network. The defense suite further comprises a network protection engine (NWPE) that alerts a defense suite user of suspicious activity in the network. Normal behavior of the network is obtained by a learning engine, during a learning period. The learning engine can be reactivated after a configuration change in the network. The data suite also comprises an operating system protection engine (OSPE), for preventing removable devices from accessing the HMI server and a preventing execution of unauthorized executables. The OSPE is also trained for which programs are authorized through its own program discovery module.