Offline Patch Management for Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face increased security vulnerabilities and complex patch management challenges due to their large size, complexity, and interconnectivity, leading to difficulties in tracing and isolating system failures, and requiring time-consuming and resource-intensive manual processes for patch deployment, which can disrupt critical infrastructure.

Innovation Solution

An offline patch change management system that includes a reader device, memory device, and processor to scan cyber assets, generate a patch status report, and determine a deployment temporal period for patches, facilitating automated and secure patch deployment with minimal disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual patch management processes are used, then flexibility and control over patch deployment are improved, but time consumption and resource intensity increase significantly

Engineering Contradiction:
Improvecontrol over patch deploymentVSAvoidtime consumption for patch management
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically evaluating patches against vulnerability databases and asset inventories before deployment, generating pre-approved patch recommendations that reduce on-site decision time and manual evaluation effort

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A centralized patch management server acts as an intermediary between patch sources and distributed industrial control systems, automatically processing patch evaluations, generating deployment recommendations, and coordinating deployment timing across multiple sites

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated patch deployment is implemented, then time efficiency and productivity are improved, but system reliability and risk of disruptions worsen

Engineering Contradiction:
Improvepatch deployment speedVSAvoidsystem stability during patching
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs comprehensive preliminary evaluations including vulnerability matching, compatibility checks, and impact assessments before automated deployment, ensuring patches are pre-validated for safety and compatibility with specific industrial control systems

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts deployment automation levels based on risk assessments, allowing fully automated deployment for low-risk patches while requiring manual approval for high-risk patches, and can rollback changes if issues are detected

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive security scanning is performed across all cyber assets, then measurement precision of patch status is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvepatch status accuracyVSAvoidscanning system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The scanning system is segmented into distributed agents deployed at each site that perform local asset discovery and patch status collection, then report findings to a centralized server that aggregates and analyzes data, dividing the complex scanning task into manageable distributed components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The scanning system uses universal communication protocols and standardized data formats to interface with diverse industrial control systems, allowing a single scanning platform to evaluate patch status across multiple vendor systems and device types without requiring vendor-specific complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8869133B2Method and system for use in facilitating patch change management of industrial control systems
Publication Date: 2014.10.21 BAKER HUGHES CO
  • US8869133B2 patent drawing
  • US8869133B2 patent drawing
  • US8869133B2 patent drawing

AI summary

An offline patch change management system for an industrial facility includes at least one reader device configured to read patch update information stored on computer-readable storage media inserted therein. The industrial facility includes an industrial control system that includes at least cyber asset. The system also includes a memory device coupled to the reader device. The memory device is configured to store the patch update information. The system further includes a processor coupled to the memory device. The processor is programmed to scan the at least one cyber asset. The processor is also programmed to generate a scan report including a patch status for at least one patch not operatively resident on the at least one cyber asset. The scan report includes a deployment temporal period value for deployment of the patch.