PLC State-Transition Analysis for Cyberattack Risk Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing interconnection of information and operational technologies in industrial systems expands their attack surface, necessitating a convergence of safety and security analysis to effectively identify and mitigate cyberattack risks on programmable logic controllers.

Innovation Solution

A method utilizing a data processing device to generate a digital representation of a minimized finite-state transducer, identifying sensitive states and critical transitions, and assessing the risk of data corruption, which involves the creation of computer files to store sensitive state transitions and input data at risk, along with a risk analysis to determine the probability and severity of potential cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the interconnection of information technologies and operational technologies is increased to enhance system functionality, then the system becomes more versatile and integrated, but the attack surface of industrial systems expands, increasing vulnerability to cyberattacks

Engineering Contradiction:
Improvesystem integrationVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the controller logic into a finite-state transducer model with distinct states and transitions. This segmentation allows for systematic identification of critical transitions and sensitive data elements, enabling targeted security analysis without requiring analysis of the entire interconnected system, thus addressing the expanded attack surface while maintaining system integration benefits

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security analysis layer that sits between the interconnected IT/OT systems and the actual controller logic. This intermediary performs automated security analysis by generating finite-state transducers and identifying critical transitions, acting as a mediator that enables secure integration without directly exposing the attack surface

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security analysis is performed on all controller logic to identify all potential vulnerabilities, then security coverage is improved, but the complexity and computational resources required increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the critical transitions and sensitive data elements from the complete controller logic using automated finite-state transducer generation. This extraction approach provides comprehensive security coverage by focusing on the essential vulnerable points without requiring analysis of all controller logic, thereby reducing computational complexity while maintaining thorough security assessment

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary security analysis by generating finite-state transducers and identifying critical transitions before actual cyberattacks occur. This preliminary action enables proactive identification of vulnerabilities in controller logic, allowing security measures to be implemented ahead of time without requiring complex real-time analysis during operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240211607A1Method and device for identifying risks of cyberattacks
Publication Date: 2024.06.27 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • US20240211607A1 patent drawing
  • US20240211607A1 patent drawing
  • US20240211607A1 patent drawing

AI summary

The present description concerns a method of identification of risks of cyberattacks on a programmable logic controller, the method comprising: the generation of a digital representation of a minimized finite-state transducer based on a specification of a controller logic of the programmable logic controller, the minimized finite-state transducer comprising a set of source states, a set of destination states, and a set of transitions from a source state to a destination state based on an input data value; the generation of a second computer file, based on a first computer file identifying a subset of sensitive states, the second file comprising a list of critical transitions associated with the sensitive states, and for each transition, a list of the input data; and the generation of a fourth computer file indicating input data to be protected which are both associated with critical transitions and with a corruption risk.