Cyber-security Risk Analysis System for Industrial Control Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) lack a centralized interface to aggregate cyber-security state and risk, making it difficult to provide situational awareness, decision support, and prioritize vulnerabilities for pre-emptive security actions, especially given the complexity and volume of events generated by networked devices.

Innovation Solution

A cyber-security risk analysis system and algorithm that compiles potential vulnerabilities in ICS networks, prioritizes them based on risk, and displays aggregated categories of security state and cyber-risk on a user interface, utilizing domain-specific knowledge and continuous near-real-time monitoring to guide users in mitigating vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a centralized interface is implemented to aggregate cyber-security state and risk, then situational awareness and decision support are improved, but device complexity and system integration requirements increase

Engineering Contradiction:
Improvecyber-security information aggregationVSAvoidsystem integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple security data sources, vulnerability databases, and monitoring functions into a single centralized interface that aggregates cyber-security state and risk information. This consolidation allows operators to view comprehensive security information in one location rather than分散 across multiple tools, directly resolving the information aggregation need while managing complexity through integrated architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized interface is designed to perform multiple functions simultaneously: aggregating security events, evaluating vulnerabilities, assessing risks, and providing decision support. This multi-functional approach consolidates what would otherwise require separate systems, improving information availability while containing complexity through a unified platform that handles diverse security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If continuous real-time monitoring is implemented across all networked devices, then security risk detection is improved, but processing load and data volume increase significantly

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidevent data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts and focuses on critical security events and vulnerabilities from the continuous stream of network data, rather than processing all generated events equally. By identifying and extracting only the most significant security-relevant information, the system maintains reliable monitoring while reducing the effective data volume that requires detailed processing and operator attention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes parameters by prioritizing and weighting different security events based on their risk significance. Instead of treating all events uniformly, the system adjusts evaluation parameters to focus computational resources on high-risk vulnerabilities and critical security states, thereby maintaining monitoring reliability while managing processing load through intelligent parameter-based filtering.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive vulnerability scanning is performed on all devices, then security coverage is improved, but time required for assessment and response increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidvulnerability assessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-evaluating and prioritizing vulnerabilities based on their potential risk impact before full assessment is required. Vulnerabilities are pre-categorized and ranked, allowing the system to quickly present the most critical issues first while maintaining comprehensive scanning capabilities in the background, thus improving response time without sacrificing coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors security events and adjusts vulnerability scanning priorities based on observed threats and system state. This dynamic feedback allows the system to focus scanning resources on areas of highest risk in real-time, maintaining comprehensive coverage while reducing assessment time for low-priority areas where threats are less likely.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3180891B1Analyzing cyber-security risks in an industrial control environment
Publication Date: 2019.11.13 HONEYWELL INTERNATIONAL INC
  • EP3180891B1 patent drawingFigure 1
  • EP3180891B1 patent drawingFigure 2A
  • EP3180891B1 patent drawingFigure 2B

AI summary

A method (300) of analyzing cyber-security risks in an industrial control system (ICS) (150) including a plurality of networked devices (145) includes providing (301) a processor (110) and a memory (115) storing a cyber-security algorithm. The processor runs the cyber-security algorithm and implements data collecting (302) to compile security data including at least vulnerability data including cyber-risks (risks) regarding the plurality of networked devices by scanning the plurality of devices, processing (303) the security data using a rules engine (122) which associates a numerical score to each of the risks, aggregating (304) data including ranking the risks across the plurality of networked devices and arranging the risks into at least one logical grouping, and displaying (305) the logical grouping(s) on a user station (125).