Industrial IoT Firewall Control for Remote Device Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security devices, such as firewalls, are inadequate in protecting industrial IoT devices from cyber attacks and do not provide the necessary control mechanisms to prevent potential damage caused by compromised devices, especially since these devices often lack display or software for operator intervention and may be involved in physical tasks.

Innovation Solution

A new network security device that not only detects and blocks cyber attacks but also remotely controls and operates industrial IoT devices through two-way communication, using configurable rules and protocols like REST and HTTP, enabling operators to manage and isolate compromised devices to prevent harm.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to protect industrial IoT devices, then network security is improved, but the ability to control and isolate compromised devices is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network security device is designed to perform multiple functions: traditional firewall capabilities (packet filtering, intrusion detection) combined with industrial device control functions (remote operation, isolation, shutdown). This multi-functional approach allows a single device to both detect threats and execute control actions, eliminating the need for separate control systems and improving response effectiveness to cyber attacks on industrial IoT devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If industrial IoT devices are connected to the Internet for centralized control, then monitoring capability is improved, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improvecentralized monitoringVSAvoidcyber attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network security device implements preliminary protective measures by establishing security rules and control policies before cyber attacks occur. It pre-configures isolation mechanisms and control commands that can be immediately executed when threats are detected, rather than responding reactively. This allows industrial IoT devices to remain connected for monitoring purposes while having pre-established safety nets against potential attacks.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If firewalls block network attacks, then security is improved, but the ability to prevent physical damage from compromised devices is insufficient

Engineering Contradiction:
Improveattack blockingVSAvoidphysical damage risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The network security device acts as an intermediary between the external network and industrial IoT devices, and also as a mediator between operators and compromised devices. It receives control commands from operators and translates them into device-specific instructions, enabling remote shutdown or isolation of compromised devices before they can cause physical damage. This intermediary role bridges the gap between network security functions and physical safety control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11463409B2System and method of utilizing network security devices for industrial device protection and control
Publication Date: 2022.10.04 BARRACUDA NETWORKS INC
  • US11463409B2 patent drawing
  • US11463409B2 patent drawing
  • US11463409B2 patent drawing

AI summary

A new network security device/appliance is proposed to not only protect, but also to control and operate an industrial IoT device. Specifically, the network security device is configured to detect and block cyber attacks such as viruses, hacking attempts, and other types of cyber threats launched from an outside network against the industrial IoT device based on a set of configurable rules. In addition, the network security device is further configured to control and operate the industrial IoT device remotely in response to the cyber attacks by issuing and communicating certain instructions/command to the industrial IoT device. Besides accepting and executing control command from the network security device, the industrial IoT device is also configured to send a request to the network security device to make certain adjustments to the rules concerning network traffic directed to the industrial IoT device.