Process Control Integrity Guard for Security Vulnerability Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems face security vulnerabilities when communicating externally, risking breaches that can lead to malicious modifications and unauthorized access, which existing security measures fail to adequately address.

Innovation Solution

An integrity guard is implemented within process control nodes to monitor and verify the system's file system, network communications, and active processes, using profiles and hash values to detect irregularities and alert administrators, thereby preventing unauthorized changes and ensuring system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If process control systems communicate via electronic communication systems (e.g., Internet), then information sharing capability is improved, but security vulnerability increases

Engineering Contradiction:
Improveinformation sharing capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an integrity guard as an intermediary component that mediates between the process control system and external communication systems. The integrity guard monitors file system changes, network traffic, and process executions, acting as a security buffer that allows information sharing while preventing direct exposure to external threats. This resolves the contradiction by enabling communication capability while blocking security vulnerabilities through the intermediary monitoring layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If process control systems are isolated from outside communications, then security is improved, but information sharing capability deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidinformation sharing capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into two parts: the isolated process control system core and the external communication interface. The integrity guard resides at the boundary, allowing the core system to remain isolated for security while enabling controlled information sharing through monitored channels. This segmentation resolves the contradiction by maintaining security isolation while providing selective information sharing capability.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If integrity monitoring is implemented continuously, then detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improvedegradation detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The integrity guard implements periodic monitoring of file system integrity, network traffic patterns, and process executions rather than continuous monitoring. It uses thresholds and anomaly detection to trigger detailed analysis only when necessary, reducing resource consumption while maintaining effective degradation detection capability through periodic assessment cycles.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9349011B2Methods and apparatus to identify a degradation of integrity of a process control system
Publication Date: 2016.05.24 FISHER ROSEMOUNT SYST INC
  • US9349011B2 patent drawing
  • US9349011B2 patent drawing
  • US9349011B2 patent drawing

AI summary

Methods and apparatus to identify a degradation of integrity of a process control system are disclosed. An example method includes identifying a file on a file system of the process control system. The example method further includes determining if the file is identified in a system profile, the system profile identifying files expected to be present. A degradation of integrity of the process control system is identified when the file is not identified in the system profile.