Peripheral Device Authorization Rules for ICS Vulnerability Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial control systems (ICS), identifying vulnerable computing products and performing regular maintenance is challenging due to limited resources and downtime-related productivity losses, and there is a difficulty in efficiently managing authorization for peripheral devices, which can lead to security vulnerabilities and disruptions.

Innovation Solution

The implementation of methods and apparatuses that use hash data analytics to programmatically define authorization rules for peripheral devices based on categorization and device-level data, and to detect vulnerabilities by generating and comparing file hashes with threat intelligence databases, thereby improving security and reducing resource and storage requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vulnerability analysis and maintenance checkups are performed in industrial control systems, then security vulnerabilities can be detected and addressed, but system downtime increases leading to productivity loss

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidindustrial production output
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs vulnerability analysis and maintenance assessments in advance by monitoring file hashes and device authorization patterns before critical failures occur. This allows maintenance to be scheduled during planned downtime rather than causing unplanned production interruptions, thus preserving productivity while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The industrial control system automatically monitors its own security state by tracking file hash changes, device authorization rules, and vulnerability patterns without requiring continuous manual intervention. This self-monitoring capability enables the system to identify and address security issues autonomously, reducing the need for downtime-intensive manual security audits.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive vulnerability analysis is performed on all computing products in the industrial control system, then security coverage is improved, but resource consumption including CPU and memory increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The vulnerability analysis system divides the industrial control system into discrete segments, analyzing file hashes and device authorizations individually rather than performing exhaustive full-system scans. This segmented approach maintains comprehensive security coverage by checking each component while consuming minimal computing resources, as only specific files and devices are analyzed at any given time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameters of vulnerability analysis from continuous full-system scanning to event-triggered analysis based on file hash changes or authorization rule modifications. This parameter change allows the system to maintain high security coverage by analyzing only when changes occur, significantly reducing overall CPU and memory consumption during normal operation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If regular maintenance checkups are performed to address potential vulnerabilities, then system security is improved, but downtime increases causing productivity loss

Engineering Contradiction:
Improvesystem securityVSAvoidmaintenance downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary vulnerability assessments by monitoring file hashes and authorization patterns continuously in the background, identifying security issues before they require intervention. This allows maintenance to be performed proactively during scheduled downtime rather than reactively causing unplanned outages, thus improving security while minimizing productivity loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback monitoring of file hash changes and device authorization states, providing real-time visibility into security conditions. This feedback mechanism enables the system to schedule maintenance only when actually needed based on monitored conditions, reducing unnecessary downtime while maintaining high security standards through continuous surveillance.

Inventive Principle:
Principle #23Feedback

4Reliability

If manual authorization management for peripheral devices is implemented, then security control is achieved, but system complexity and human error increase

Engineering Contradiction:
Improveauthorization controlVSAvoidauthorization management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically manages peripheral device authorization by monitoring device connections, comparing device identifiers against stored authorization rules, and enforcing access control decisions without manual intervention. This self-service authorization management maintains high security control while eliminating the complexity and human error associated with manual authorization processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical authorization processes with automated electronic verification of device identifiers against stored authorization rules. This substitution eliminates the need for human operators to manually configure and manage device authorizations, reducing system complexity while maintaining or improving authorization control reliability through consistent automated enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11592811B2Methods and apparatuses for defining authorization rules for peripheral devices based on peripheral device categorization
Publication Date: 2023.02.28 HONEYWELL INTERNATIONAL INC
  • US11592811B2 patent drawing
  • US11592811B2 patent drawing
  • US11592811B2 patent drawing

AI summary

Method, apparatus and computer program product for detecting vulnerability in an industrial control system, predicting maintenance in an industrial control system, and defining authorization rules for peripheral devices based on peripheral device categorization are described herein.