Industrial Network Cybersecurity System for IoT Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional industrial networks face vulnerabilities and cybersecurity threats due to the integration of wireless IoT devices, which are difficult to detect and manage, leading to potential cyberattacks that can disrupt industrial processes and compromise network security.

Innovation Solution

An industrial network cybersecurity system that monitors network traffic data, identifies new devices, and classifies them as trusted or untrusted, automatically generating asset device instances and updating metadata to detect anomalies and malicious activity, triggering alerts and automatic mitigation actions when predefined threat levels are exceeded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless IoT devices are integrated into industrial networks to improve connectivity and resource usage, then network versatility and ease of operation are improved, but network security and reliability deteriorate due to undetected devices and vulnerabilities to cyberattacks

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by continuously monitoring network traffic data before cyberattacks can succeed. It proactively identifies new wireless devices, classifies them as trusted or untrusted, and modifies configuration parameters preemptively to prevent security breaches, rather than reacting after threats materialize

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cybersecurity system acts as an intermediary layer between wireless devices and the industrial network. It intercepts and analyzes network traffic, classifies devices through metadata comparison, and mediates security decisions by automatically modifying configuration parameters of untrusted devices, preventing direct access to critical infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional network monitoring is used to maintain system simplicity, then device complexity is reduced, but the ability to detect and respond to cybersecurity threats deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidthreat detection capability
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The cybersecurity system performs self-service by automatically monitoring network traffic, classifying devices, and modifying configuration parameters without requiring constant human intervention. The system autonomously compares metadata against predefined criteria, identifies untrusted devices, and executes security policies independently, reducing operational complexity while maintaining high detection capability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters by dynamically modifying configuration parameters of asset devices based on security assessments. It adjusts network access rights, isolation levels, and security policies automatically when untrusted devices are detected, enabling complex threat response through automated parameter modification rather than manual system reconfiguration

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240163300A1Cybersecurity threat mitigation for industrial networks
Publication Date: 2024.05.16 HONEYWELL INTERNATIONAL INC
  • US20240163300A1 patent drawing
  • US20240163300A1 patent drawing
  • US20240163300A1 patent drawing

AI summary

In various embodiments, network traffic data associated with an industrial network is monitored based on a networking event rule set related to defined networking events. The network traffic data is related to a set of asset devices in communication via the industrial network, and the networking event rule set is used to determine a networking event associated with the set of asset devices. A cybersecurity event level for the networking event is determined based on a comparison between a networking event feature set for the networking event and a predefined cybersecurity event feature set for a set of predefined cybersecurity events. In response to a determination that the cybersecurity event level for the networking event satisfies a predefined cybersecurity threat level threshold, a modification is made to one or more configuration parameters for one or more asset devices from the set of asset devices associated with the networking event.