Passive Industrial Network Security Assessment via Attack Trees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial security providers face challenges in evaluating the quality of access control lists (ACLs) in industrial control system networks, as existing methods are invasive, prone to errors, and fail to simulate the impact of vulnerabilities, leading to increased attack vectors and risk of malicious infiltration.
Innovation Solution
A computer-implemented method and system that retrieves topology and network traffic data to generate an attack tree, updating a customer model database and outputting a security assessment, using passive network data collectors to avoid intrusive probing and provide non-intrusive security verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active network probing techniques are used to evaluate ACL quality, then network security assessment capability is improved, but industrial control equipment may enter fault states and network disruption occurs
Solution Approach 1:
The patent converts the harmful effect of network probing (which causes fault states in legacy PLCs) into a beneficial passive observation approach. By using port mirroring and span ports to capture network traffic without active probing, the system achieves security assessment while avoiding the harmful fault states that would otherwise occur with active scanning tools like NMAP.
Solution Approach 2:
The patent introduces an intermediary approach by using network switches with port mirroring capabilities as mediators. Instead of directly probing industrial control equipment, the system uses the switch's span port to create a copy of network traffic, which is then analyzed by the security assessment system. This intermediary mechanism eliminates direct harmful interactions with legacy PLCs while maintaining assessment capability.
2Measurement precision
If manual inspection and correlation of ACLs is performed by security analysts, then detailed security evaluation is achieved, but the process is time-consuming and prone to human errors
Solution Approach 1:
The patent implements self-service by enabling the security assessment system to automatically correlate ACL configurations with captured network traffic without requiring manual analyst intervention. The system automatically compares configured access control rules against actual observed traffic patterns, generating security assessments autonomously. This eliminates the time-consuming manual review process while maintaining detailed evaluation capability.
Solution Approach 2:
The patent applies feedback by automatically comparing ACL configuration data with actual network traffic capture data. The system continuously monitors traffic patterns and compares them against the configured access control rules, providing automated feedback on whether the ACLs are effectively enforcing security policies. This closed-loop feedback mechanism replaces manual correlation with automated, error-free comparison.
3Productivity
If conventional automated assessment tools are used to audit firewall configurations, then automation efficiency is improved, but connection requirements create access difficulties in segregated industrial networks
Solution Approach 1:
The patent uses network switches with span port capabilities as intermediaries to bridge the gap between automated assessment tools and segregated industrial networks. By configuring the switch to mirror traffic to a designated port, the assessment system can observe network traffic without requiring direct connections to firewalls, multilayer switches, or routers that may be restricted by third-party MSPs. This intermediary approach maintains automation efficiency while overcoming access barriers.
Solution Approach 2:
The patent extracts the network traffic data from the production network through span ports without disrupting the original network flow. By separating the assessment function from the production network while maintaining observational capability, the system achieves automated security assessment without requiring intrusive connections to network infrastructure that would be restricted by access control policies.
4Measurement precision
If periodic firewall config audit is performed to assess security, then security configuration evaluation is improved, but the attack surface of the controlled environment is exposed and risk of malicious infiltration increases
Solution Approach 1:
The patent converts the harmful exposure of attack surface during periodic audits into a beneficial passive observation mode. By continuously capturing and analyzing network traffic through span ports rather than performing periodic active audits, the system maintains security evaluation capability while minimizing exposure. The passive nature of traffic capture means no additional attack vectors are created, as the assessment system merely observes existing traffic flows without initiating connections or probes.
Solution Approach 2:
The patent transforms periodic firewall configuration audits into continuous passive traffic observation. Instead of periodically connecting to devices for configuration retrieval (which exposes attack surfaces), the system continuously captures traffic through configured span ports. This continuous passive monitoring provides ongoing security assessment without the periodic exposure risks associated with active audit connections.
Data Source
AI summary
A computer-implemented method for assessing and managing network security for a network includes retrieving topology data and network traffic data with a processor, where the topology data is indicative of a topology of the network. The method may further include retrieving, via the processor, network flow data from a plurality of network data collectors, generating, via the processor, an attack tree based on the topology data and the network flow data, updating a customer model database with the attack tree and the topology data, and outputting a security assessment based on the attack tree and the topology data.


