Automated IIoT Vulnerability Detection via OPC UA Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face increasing cybersecurity threats due to unaddressed security vulnerabilities in connected devices, which traditional cybersecurity solutions like antivirus and firewalls often cannot keep pace with, leading to potential disruptions and unsafe conditions.

Innovation Solution

An intelligent automated security vulnerability detection and analysis system for Industrial Internet of Things (IIoT) devices, utilizing a processor to generate a mapped dataset of a server compatible with machine-to-machine protocol communication, identifying input data to test for errors, performing targeted attacks, and monitoring responses to detect and report errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity solutions (antivirus, firewalls) are used to protect industrial control systems, then basic security protection is provided, but they cannot keep pace with new threats and unaddressed vulnerabilities

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidability to respond to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by automatically detecting and analyzing security vulnerabilities before malicious actors can exploit them. The automated vulnerability detection system continuously scans and identifies weaknesses in industrial control systems, addressing security issues proactively rather than reactively, thus keeping pace with emerging threats without requiring manual intervention for each new vulnerability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security testing is performed to detect all vulnerabilities, then security coverage is improved, but the complexity and time required for testing increases

Engineering Contradiction:
Improvesecurity vulnerability detection coverageVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability detection system performs self-service by automatically executing security tests, analyzing results, and generating reports without requiring extensive manual configuration or intervention. The system autonomously manages the complex testing processes, including selecting appropriate test cases, interpreting vulnerability data, and prioritizing findings, thereby maintaining comprehensive security coverage while minimizing the operational complexity burden on users.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual security vulnerability analysis is performed, then detailed examination of each vulnerability is possible, but the process is time-consuming and cannot keep pace with new threats

Engineering Contradiction:
Improvevulnerability analysis depthVSAvoidtime to detect and respond to vulnerabilities
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces manual mechanical analysis with automated computational analysis. The automated vulnerability detection system uses software-based scanning, testing, and analysis mechanisms to examine security vulnerabilities at scale and speed impossible for human analysts. This substitution maintains detailed examination capabilities through systematic automated testing while reducing analysis time from days or weeks to minutes or hours, enabling timely response to emerging threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10764319B2Intelligent automated security vulnerability detection and analysis for industrial internet of things (IIOT) devices
Publication Date: 2020.09.01 HONEYWELL INTERNATIONAL INC
  • US10764319B2 patent drawing
  • US10764319B2 patent drawing
  • US10764319B2 patent drawing

AI summary

A method, an electronic device, and a computer readable medium for vulnerability detection are disclosed. The method includes generating a mapped dataset of a portion of an OPC UA server by mapping the portion of the server, wherein the server is compatible with OPC UA machine to machine (M2M) protocol communication including transport encodings and services. The method also includes identifying input test data to test the portion of the server based in part on the mapped dataset set in order to detect errors. The method further includes performing a plurality of targeted attacks by loading the input test data onto the portion of the server. In response to loading the input test data into the server, the method includes monitoring responses of the server to detect an error. Further, in response to detecting the error the method includes generating a report that indicates the detect error.