Network Security Rule Generation from Power IED Configuration Files
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity solutions for industrial control systems in power grids, particularly for intelligent electronic devices and communication nodes, rely on IT-based security measures that do not fully account for the specific roles and functions of these devices, leading to incomplete network security and potential vulnerabilities in communication links.
Innovation Solution
A system that analyzes settings and configuration files of intelligent electronic devices and communication nodes to create and distribute security rulesets to network security devices, enabling secure communication channel establishment, violation detection, and alert signaling, using processors and memory to manage and log security events across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IT-based security measures are used for power system IEDs and CNs, then security monitoring capability is provided, but the security rules do not fully account for specific device roles and functions leading to incomplete network security
Solution Approach 1:
The system performs preliminary analysis of device settings and configuration files during the design and commissioning phase to extract communication parameters and generate security rules before deployment. This preliminary action ensures that security rules are tailored to specific device roles and functions from the outset, rather than applying generic IT-based security measures that fail to account for power system device characteristics.
Solution Approach 2:
The patent introduces an intermediary component that acts as a bridge between device configuration data and security rule generation. This intermediary analyzes configuration files, extracts communication parameters, and transforms them into device-specific security rules, thereby enabling the security system to adapt to the specific roles and functions of power system IEDs and CNs.
2Reliability
If security rules are customized for each device based on configuration files, then device-specific security is achieved, but system complexity increases due to distributed rule generation and management
Solution Approach 1:
The system creates simplified copies or representations of device configuration data in the form of security rules. Instead of managing complex raw configuration files directly, the system generates structured security rules that capture essential communication parameters, making them easier to distribute, store, and enforce across multiple network security devices without requiring deep interpretation of original configuration files.
Solution Approach 2:
The patent segments the security rule management process into distinct components: configuration file analysis, rule generation, rule distribution, and rule enforcement. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity by breaking down the monolithic security management function into manageable modular operations that can be distributed across the network.
3Measurement precision
If comprehensive analysis of configuration files is performed to extract communication parameters, then accurate security rules are generated, but processing time and computational resources increase
Solution Approach 1:
The system extracts only the essential communication parameters needed for security rule generation from device configuration files, rather than performing comprehensive analysis of all configuration data. This selective extraction focuses on critical elements such as communication protocols, ports, and device roles, achieving sufficient rule accuracy while significantly reducing processing time and computational resource requirements.
Solution Approach 2:
The patent applies partial action by generating security rules based on a subset of configuration parameters that are most critical for security enforcement. Rather than analyzing every detail in configuration files, the system identifies and processes only the necessary communication parameters, achieving adequate security coverage with reduced processing overhead.
Data Source
AI summary
A system and method for improving the security and reliability of industrial control system (ICS) and supervisory control and data acquisition (SCADA) communication networks utilized within power systems is provided. For power system intelligent electronic devices (IEDs) that comprise these networks, a number of settings are created and stored inside the device settings files that define the IED's communication parameters. Inspection of a settings and configuration file (SCF) allows the identification and extraction of the device's configured and therefore permissible communication characteristics. Using this extracted information, rulesets are generated and subsequently pushed to one or more network security devices, e.g. firewalls, managed switches, and intrusion detection/prevention systems. In such a manner, the described innovation is able to derive a perspective of the allowable system communication and issue rulesets and settings to network security devices (NSDs). The NSDs are subsequently able to control communication links and/or detect deviations from the acceptable communication parameters as per the function and design of the NSD.


