Industrial Communication Flow Monitoring for Hazardous Command Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process systems are vulnerable to malicious or unintentional commands, which can cause significant physical damage or injury due to the lack of security between master compute systems and industrial controllers, and between controllers and physical devices, leading to frequent failures and potential catastrophic outcomes.

Innovation Solution

A computer-implemented method that monitors communication flows within industrial processing systems, identifies hazardous commands through simulation, and generates mitigating commands to reduce the hazard level by predicting the effects of candidate commands and outputting them to relevant components within the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individual command validity checks are implemented, then command validation is improved, but system security against malicious commands remains insufficient

Engineering Contradiction:
Improvecommand validationVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent runs simulations to predict future system states before malicious commands take effect. By performing preliminary analysis of command sequences and their cumulative effects, the system identifies hazardous conditions before they materialize into actual damage, rather than merely validating individual commands in isolation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an external observation and correction system that acts as an intermediary between the master compute system and industrial controllers. This intermediary layer monitors communication packets, analyzes potential hazards through simulation, and can intervene to prevent malicious commands from executing, thereby enhancing security beyond what individual command checks can provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If simulation-based hazard identification is implemented, then system safety is improved, but computational resources and time consumption increase

Engineering Contradiction:
Improvesystem safetyVSAvoidcomputational time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies simulation selectively rather than to every command. It focuses simulation resources on identifying patterns indicative of malicious activity or sequences of commands that could lead to hazardous states, rather than exhaustively simulating all possible command variations. This partial application of simulation maintains safety while reducing computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system continuously monitors system states and adjusts its simulation and analysis activities based on feedback from actual system behavior. When the system operates normally, less intensive monitoring is applied. When anomalies or patterns suggesting malicious activity are detected, the system intensifies its simulation and analysis efforts, optimizing the balance between safety and computational resource usage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10955810B2Monitoring communications flow in an industrial system to detect and mitigate hazardous conditions
Publication Date: 2021.03.23 KYNDRYL INC
  • US10955810B2 patent drawing
  • US10955810B2 patent drawing
  • US10955810B2 patent drawing

AI summary

A computer-implemented method includes: monitoring, by a computing device, communication flows within an industrial processing system; identifying, by the computing device, a hazardous command based on monitoring the communication flows, wherein identifying the hazardous command includes running a simulation with the communication flows as an input to the simulation; generating, by the computing device, a set of one or more mitigating commands based on identifying the hazardous command; and outputting, by the computing device, the set of one or more mitigating commands to components within the industrial processing system, wherein outputting the set of the one or more mitigating commands reduces a level of hazard caused by the hazardous command.