Network Security System for Automated OT Policy Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring network security systems for OT environments is a time-consuming and labor-intensive process, particularly in generating and updating whitelisting policies, which are crucial for protecting against cyber threats and ensuring the safety of critical infrastructure.
Innovation Solution
A network security system that monitors data traffic between devices in a sandboxed environment to automatically generate whitelisting policies, including allowed commands and metadata, and sends alert messages for unauthorized commands, allowing administrators to update policies dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of whitelisting policies is performed, then policy accuracy and security can be ensured, but time consumption and labor intensity increase significantly
Solution Approach 1:
The system performs self-service by automatically monitoring data traffic, identifying commands, and generating whitelisting policies without human intervention. The network security device autonomously captures commands from data traffic, associates metadata with each command, and generates policies based on this information, eliminating the need for manual configuration while maintaining policy accuracy.
Solution Approach 2:
The system performs preliminary action by proactively monitoring and capturing commands from data traffic before security threats can exploit gaps in policy coverage. By continuously observing network traffic and pre-identifying legitimate commands, the system establishes comprehensive whitelisting policies in advance, ensuring security coverage is maintained without waiting for manual updates.
2Reliability
If manual updates of whitelisting policies are performed, then security coverage can be maintained, but productivity and efficiency decrease
Solution Approach 1:
The system implements feedback by continuously monitoring data traffic for new commands and automatically updating whitelisting policies based on observed traffic patterns. When new legitimate commands are detected in the network traffic, the system captures them, associates appropriate metadata, and updates the whitelisting policies to include these commands, ensuring security coverage keeps pace with evolving network usage without manual intervention.
Solution Approach 2:
The system maintains continuous security coverage by perpetually monitoring data traffic and continuously updating whitelisting policies as new commands are observed. This uninterrupted process ensures that security coverage evolves alongside network activity, maintaining protection against threats while adapting to legitimate changes in network usage patterns.
3Productivity
If automated policy generation is implemented, then productivity and speed improve, but system complexity increases
Solution Approach 1:
The system merges multiple functions into a single integrated network security device that performs traffic monitoring, command capture, metadata association, and policy generation simultaneously. By combining these previously separate tasks into one unified system, the patent achieves automated policy generation without proportionally increasing overall system complexity, as the functions work together in a coordinated manner within a single device architecture.
Data Source
AI summary
A network security system monitors data traffic being transmitted between a first device and a second device in a network to identify a plurality of commands being transmitted between the first device and the second device. The network security system then generates a whitelisting policy based on the plurality of commands being transmitted between the first device and the second device. After generating the whitelisting policy, the network security system receives subsequent data traffic being transmitted between the first device and the second device, and determines, based on the subsequent data traffic, a first command being transmitted between the first device and the second device. In response to determining that the first command is not included in the whitelisting policy, the network security system generates an alert in relation to the first command.


