Network Orchestration Platform for ICS Visibility and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face challenges in network visibility and security due to the lack of availability and deficiencies in conventional network monitoring tools like SPAN and TAPs, which hinder the detection of time-based attacks and require extensive infrastructure for data capture, especially in deterministic and ruggedized industrial networks.

Innovation Solution

A network orchestration and security platform that initiates operational connections between security zones, sends messages in the clear through secure conduits, and validates fingerprints to ensure authorized communication, leveraging software-defined networking for enhanced visibility and security in ICS networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If SPAN is used to capture network stream, then data capture is enabled, but frame timing is altered and data stream may be bypassed during peak loading

Engineering Contradiction:
Improvenetwork data captureVSAvoidframe timing accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent introduces a network TAP (Test Access Point) as an intermediary device that captures network traffic without altering frame timing. The TAP sits between network segments and provides a passive copy of the data stream, avoiding the active processing that causes timing distortion in SPAN implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network monitoring function is segmented from the main network traffic flow. Instead of aggregating traffic through a central switch CPU (which causes timing issues), the monitoring capability is distributed to dedicated TAP devices that operate independently and preserve original frame timing.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If TAPs are used to capture network stream, then exact copy of data stream is obtained, but tremendous amount of sensors and out of band cabling infrastructure are required

Engineering Contradiction:
Improvedata stream accuracyVSAvoidinfrastructure requirements
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent combines multiple TAP sensing capabilities into a unified network monitoring platform. Instead of requiring separate TAP sensors for each network segment, the system integrates sensing, analysis, and response capabilities into a single consolidated infrastructure that reduces overall complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network monitoring platform is designed with universal functionality that can monitor multiple security zones and protocol types through a single infrastructure. The system can handle various industrial protocols (Modbus, DNP3, IEC 61850, etc.) and security zone configurations without requiring dedicated hardware for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security zones are implemented for ICS network, then security control is improved, but network visibility and threat detection capability are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a network TAP as an intermediary device that captures network traffic without altering frame timing. The TAP sits between network segments and provides a passive copy of the data stream, avoiding the active processing that causes timing distortion in SPAN implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous monitoring and analysis of network traffic across security zones, providing feedback about potential threats and anomalies. This enables security personnel to detect and respond to threats while maintaining the security zone architecture.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10742683B2Network asset characterization, classification, grouping and control
Publication Date: 2020.08.11 VERACITY IND NETWORKS INC
  • US10742683B2 patent drawing
  • US10742683B2 patent drawing
  • US10742683B2 patent drawing

AI summary

Techniques applicable to a network orchestration and security platform for a network, such as an industrial control system (ICS) network, are disclosed. Such techniques include, for example, methods to characterize and classify networked industrial devices based upon conversation patterns, generate security zones for ICS networked assets based upon conversation characteristics and patterns, to identify and record ICS networked devices in a non-intrusive way, to create secure conduits between security zones for ICS networked devices with no impact to endpoint hose devices, and systems therefor.