ICS Hash Analytics for Vulnerability Detection and Maintenance Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial control systems (ICS), detecting vulnerabilities and predicting maintenance is challenging due to limited resources and infrequent maintenance checkups, which can lead to productivity losses and security threats.

Innovation Solution

A method and apparatus using hash analytics to detect vulnerabilities by generating file hashes from industrial control files, querying a database for threat and predictive indicators, and outputting vulnerability analyses through a secure media exchange portal, enabling continuous monitoring without requiring ICS components to access the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If regular maintenance checkups are performed to address potential vulnerabilities, then security reliability is improved, but productivity is worsened due to required downtime

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary vulnerability assessments by continuously monitoring and analyzing ICS computing components in the background before actual security threats materialize. Hash values of running files are continuously compared against known vulnerability databases, allowing maintenance to be scheduled during planned downtime rather than requiring unexpected shutdowns, thus maintaining productivity while improving security reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability detection system operates autonomously within the ICS environment, continuously self-monitoring computing components without requiring external intervention or system shutdowns. The hash-based comparison mechanism automatically identifies vulnerable files and generates maintenance predictions, enabling the system to serve its own security needs while maintaining continuous operation and productivity

Inventive Principle:
Principle #25Self-service

2Difficulty of detecting and measuring

If comprehensive vulnerability analysis is performed on ICS computing components, then security detection capability is improved, but resource consumption is worsened due to limited CPU, memory, and I/O constraints

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidresource consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The system extracts only the essential identification feature (hash value) from ICS computing component files for vulnerability analysis, rather than analyzing entire files. By computing and comparing hash values against a vulnerability database, the system achieves comprehensive vulnerability detection with minimal resource consumption, as hash computation is computationally lightweight compared to full file analysis

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms the vulnerability detection problem from analyzing complex file contents to comparing simple hash parameters. By changing the detection parameter from full file analysis to hash value comparison, the system maintains high detection capability while dramatically reducing CPU, memory, and I/O resource requirements in the constrained ICS environment

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If ICS computing components access the internet for vulnerability updates, then detection accuracy is improved, but system security is worsened due to increased attack surface

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system introduces a secure hash comparison mechanism as an intermediary between ICS computing components and vulnerability information. Instead of direct internet access, the system computes local hash values and compares them against a vulnerability database through a controlled interface, maintaining detection accuracy while eliminating the security risks associated with internet connectivity in air-gapped environments

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11568056B2Methods and apparatuses for vulnerability detection and maintenance prediction in industrial control systems using hash data analytics
Publication Date: 2023.01.31 HONEYWELL INTERNATIONAL INC
  • US11568056B2 patent drawing
  • US11568056B2 patent drawing
  • US11568056B2 patent drawing

AI summary

Method, apparatus and computer program product for detecting vulnerability and predicting maintenance in an industrial control system are described herein.