Industrial Firewall for Automation Control Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation networks face security threats from unauthorized access and malicious attacks, such as viruses and hacking, due to increased networking, which can lead to denial of service and safety hazards, and existing IT path filtering is not suited to regulate access effectively.
Innovation Solution
Implementing an electronic communication firewall that monitors and filters communications within the automation control network using deep packet inspection and a filtering component to deny unauthorized access, and acting as a communication proxy to manage routing and addressing information, thereby securing the network from unauthorized communication and denial of service attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If automation control networks are connected to office networks and external entities, then data transfer and communication capability are improved, but security risks from unauthorized access and malicious attacks increase
Solution Approach 1:
The patent introduces an industrial firewall as an intermediary device positioned between the automation control network and external networks/office networks. This firewall monitors, filters, and controls all data packets passing through it, allowing legitimate communication while blocking unauthorized access and malicious attacks. The firewall acts as a mediator that enables safe interaction between previously isolated networks.
2Reliability
If IT path filtering is used to regulate access between networks, then some security control is achieved, but it is not suited to effectively regulate access to automation control networks
Solution Approach 1:
The patent changes the filtering parameters from standard IT network addressing (IP addresses, ports) to automation-specific parameters including device names, device types, process control functions, and automation protocol identifiers. This parameter transformation enables the firewall to understand and control access based on the semantic meaning of automation network communications rather than just network topology.
3Measurement precision
If deep packet inspection is implemented to inspect communication instances, then security monitoring capability is improved, but processing complexity and time increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring security rules, device profiles, and access policies in the firewall before actual communication occurs. The firewall is pre-loaded with knowledge of authorized devices, their functions, and permitted communication patterns. This allows the firewall to make rapid decisions based on pre-evaluated criteria rather than analyzing every packet from scratch.
Data Source
AI summary
Providing for employing a real time firewall to secure components of an automation control network from unauthorized communication to or from such components is disclosed herein. A monitoring component can inspect at least a portion of an instance of communication directed toward or originating from a component of the automation control network. Such inspection can, e.g., be a deep packet inspection based on information received from a communication request and/or response protocol. A filtering component can selectively admit or deny propagation of the instance of communication based on the inspection and a predetermined security criterion. In such a manner, the subject innovation can provide for limited access to network components from office network machines and for securing components of an automation control network from influence by unauthorized entities.


