PLC Virtual Patching for ICS Security Without Reboots
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial Control Systems (ICS) face challenges in security patching, requiring complete firmware updates and reboots, which can introduce new failures and vulnerabilities, and traditional patch management is manual and limited, increasing risk and cost in live production environments.
Innovation Solution
The implementation of virtual patching and automated distribution of security context information using a system with an industrial automation device, a distributed database, and a virtual patching engine security application that collects system information and applies virtual patches without reloading the software image, providing protection against vulnerabilities until a system upgrade can be performed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual patch management is performed, then patch compatibility can be tested, but productivity deteriorates due to long patch delays and increased operational time
Solution Approach 1:
The patent enables preliminary deployment of virtual patches before complete firmware updates are finalized or tested. The virtual patch can be applied immediately upon vulnerability identification, allowing the system to be protected in advance while compatibility testing of the full firmware update occurs in parallel, thereby accelerating overall patch deployment.
Solution Approach 2:
The patent applies partial patching by deploying only the essential security fix (virtual patch) without waiting for the complete firmware update package. This partial action provides immediate protection while the remaining firmware components are updated separately, significantly reducing the time to achieve security remediation.
2Reliability
If full system reboot is performed for security patching, then vulnerability is fixed, but loss of time increases due to production downtime
Solution Approach 1:
The patent segments the patching operation so that the critical security fix (virtual patch) can be applied without triggering a full system reboot. By separating the security fix from the complete firmware replacement, the system avoids mandatory downtime while still achieving vulnerability remediation.
Solution Approach 2:
The patent creates a virtual copy or representation of the security patch that can be deployed without replacing the actual firmware. This virtual patch copy provides the necessary security protection without requiring the system to undergo a complete firmware update and reboot cycle, thereby eliminating production downtime.
3Reliability
If external security controls are deployed at network level, then additional protection is provided, but device complexity increases and controls are limited by network-level constraints
Solution Approach 1:
The patent enables the PLC to self-protect by incorporating the virtual patching engine directly within the device. Instead of relying on external network-level security controls, the PLC autonomously applies security fixes through the virtual patch mechanism, reducing the need for complex external security infrastructure while providing more effective, device-specific protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system for virtual patching of security vulnerabilities in an industrial production environment includes an industrial automation device (e.g., a PLC). The industrial automation device comprises an instance of a distributed database spanning a plurality of industrial automation devices and storing one or more virtual patches and an app container comprising a virtual patching engine security application. The app container is configured to collect system information generated by the industrial automation device during operation, and apply the one or more virtual patches to the system information to identify one or more security attacks.